Privacy Policy
This is the register and privacy policy of SSN Trading Oy in accordance with the EU General Data Protection Regulation (GDPR). Created on August 1, 2019. Last updated on March 13, 2025.
By using our services, website, or contacting us, you agree that we may process your personal data in accordance with this privacy policy. If you do not accept these terms, we will likely be unable to serve you.
1. Data Controller
As of August 1, 2019: SSN Trading Oy (Business ID: 3012123-3) Kinospolku 1, 13500 Hämeenlinna, Finland For inquiries regarding data protection and the processing of personal data, please contact: myynti@dreamcare.fi.
2. Name of the Register
The registers are:
a) SSN Trading Oy Customer Register
b) SSN Trading Oy Marketing and Communication Register
3. Legal Basis and Purpose of Personal Data Processing
The legal bases for processing personal data under the EU General Data Protection Regulation (GDPR) are:
- The data subject has given consent to the processing of their personal data for one or more specific purposes (GDPR Art. 6(1)(a));
- Processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps at the request of the data subject prior to entering into a contract (GDPR Art. 6(1)(b));
- Processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party (GDPR Art. 6(1)(f)).
Personal data is processed for purposes related to managing and maintaining customer relationships, fulfilling contractual obligations, providing and delivering products and services, and developing operations. Personal data is also processed for handling potential complaints and other claims. Additionally, personal data is used for customer-targeted marketing and other communications.
Certain e-commerce functions are based on the legitimate interests of the data controller to provide the best possible service experience. These include personalized website content, surveys, product review requests, and customer relationship-based reminders.
The data is not used for automated decision-making or profiling.
4. Data Content of the Register
a) Customer Register: The data stored includes the individual’s name, company/organization, contact details (address, phone number, email), information about ordered products and services, changes to them, billing details, and other information related to the customer relationship and ordered products and services. b) Marketing and Communication Register: The data stored includes the individual’s name, company/organization, contact details (address, phone number, email), and permissions or prohibitions regarding direct marketing.
Data collected in the register is retained only for as long and to the extent necessary for the purposes for which the personal data was collected. The need to retain personal data is reviewed every six months, at which point customer accounts inactive for over two years are closed, and all orders older than two years are anonymized by removing personal and contact information. An exception applies to accounting documents, which are legally required to be retained for six years after the end of the financial year. Order data from companies and organizations is not anonymized if the orders involve medical devices subject to traceability requirements under the MDR regulation. Such order data is retained for 10 years.
Personal data is primarily processed by our company’s personnel in the course of their duties. We may disclose data to fulfill contractual obligations or as required by law or competent authorities. We may also disclose your data in the context of a corporate or business transaction.
5. Regular Sources of Data
The data stored in the register is obtained from customers through, for example, e-commerce orders, messages sent via web forms, email, phone, social media services, contracts, customer meetings, and other situations where the customer provides their information.
Data about contact persons of companies and other organizations may also be collected from public sources, such as websites, directory services, and other companies.
We use cookies on our website to provide the best possible user experience for visitors. Cookies are small text files stored by the web server on the user’s device. Cookies provide us with information about how users interact with our website. We may use cookies to improve our services and website, analyze website usage, and target and optimize marketing efforts.
Website users can consent to or prohibit the use of cookies through their browser settings. Most browsers allow cookies automatically. Customers can also manage cookies using our website’s cookie management tool, which is displayed upon first visiting the site or when a decision has not yet been made. A list of the cookies used and the option to change your decision are provided at the end of this privacy policy. Cookies are categorized into essential, statistical, and marketing cookies. Please note that blocking cookies may limit the functionality of our website.
6. Regular Disclosures and Transfers of Data Outside the EU or EEA
We share data with the following third parties:
- Analytics and statistics partners
- Product recommendation and personalization partners
- Email marketing partners for newsletter subscriptions
- Transport companies, if the order is delivered to the customer or a pickup point via a transport company
- Payment service providers when payments are made through Paytrail, PayPal, or Posti payment methods
- Invoice operators when a corporate invoice is selected as the payment method
- Product suppliers for custom-made products ordered by the customer
- Debt collection agencies in case of overdue invoices
Some subcontractors or servers processing data may be located outside the EU/EEA. We do not otherwise regularly transfer personal data outside the EU/EEA.
We ensure that the processing, transfer, and storage of your data comply with legal requirements and are protected by adequate safeguards.
7. Principles of Register Protection
The processing of the register is carried out with due care, and data processed through information systems is appropriately protected. Data is stored on our service provider’s servers, which are secured in accordance with industry standards. The data controller ensures that stored data and other information obtained based on the customer relationship are handled confidentially and only by personnel whose job duties require it.
8. Right of Access and Right to Request Data Correction
Every individual in the register has the right to check the data stored about them and to request the correction of inaccurate data or the completion of incomplete data. If an individual wishes to check or request corrections to their data, the request must be sent in writing to the contact person responsible for the register. The data controller may, if necessary, request the requester to verify their identity. The data controller will respond to the customer within the timeframe stipulated by the EU GDPR (generally within one month).
9. Other Rights Related to Personal Data Processing
Individuals in the register have the right to request the deletion of their personal data from the register ("right to be forgotten"). Data subjects also have other rights under the EU GDPR, such as the right to restrict processing in certain situations. Requests must be sent in writing to the contact person responsible for the register. The data controller may, if necessary, request the requester to verify their identity. The data controller will respond to the customer within the timeframe stipulated by the EU GDPR (generally within one month).
If you believe that the processing of your personal data is not lawful, you may file a complaint with the competent supervisory authority. However, the "right to be forgotten" may not be fully implemented if we are legally obligated to continue processing personal data, for example, due to accounting obligations.
Additionally, if the processing of personal data is based on separate consent, you have the right to withdraw your consent at any time. Please note that this does not affect the lawfulness of processing carried out before the withdrawal of consent.
