Skip to main content Skip to search Skip to main navigation
Go to homepage

Privacy policy

Updated: 1.9.2026

Welcome to our website and thank you for your interest. The protection of your personal data is important to us. We therefore conduct our activities in accordance with the applicable legal provisions on the protection of personal data and data security. We would like to inform you below about which data from your visit is used for which purposes.

Controller for processing in accordance with the GDPR

The controller within the meaning of the General Data Protection Regulation and other data protection laws applicable in the Member States of the European Union and other provisions of a data protection nature is the:

Ifolor Oy
Karhumäenkuja 2
01530 Vantaa
Finland

https://www.ifolor.fi/en

dataprotectionofficer@ifolor.fi

What is personal data?

The term "personal data" is defined in the Federal Data Protection Act and the EU GDPR. Accordingly, this is individual information about the personal or factual circumstances of an identified or identifiable natural person. This includes, for example, your civil name, your address, your telephone number or your date of birth. Find out more about what exactly data protection is here.

Scope of anonymous data collection and data processing

Unless otherwise stated in the following sections, no personal data is collected, processed or used when you use our websites. However, through the use of analysis and tracking tools, we obtain certain technical information based on the data transmitted by your browser (e.g. browser type/version, operating system used, websites visited on our site including length of visit, previously visited website). We only evaluate this information for statistical purposes.

Relevant legal bases for the processing of personal data

  1. Insofar as we obtain the consent of the data subject for the processing of personal data, Art. 6 para. 1 lit. a) EU General Data Protection Regulation (GDPR) serves as the legal basis for the processing of personal data.
  2. When processing personal data that is necessary for the performance of a contract to which the data subject is a party, Art. 6 para. 1 lit. b) GDPR serves as the legal basis. This also applies to processing operations that are necessary to carry out pre-contractual measures.
  3. Insofar as the processing of personal data is necessary to fulfill a legal obligation to which our company is subject, Art. 6 para. 1 lit. c) GDPR serves as the legal basis.
  4. In the event that vital interests of the data subject or another natural person require the processing of personal data, Art. 6 para. 1 lit. d) GDPR serves as the legal basis.
  5. If the processing is necessary to safeguard a legitimate interest of our company or a third party and if the interests, fundamental rights and freedoms of the data subject do not outweigh the former interest, Art. 6 para. 1 lit. f) GDPR serves as the legal basis for the processing.

Use of cookies

The Internet pages of the Ifolor Oy use cookies. Cookies are data that are stored by the Internet browser on the user's computer system. The cookies can be transmitted to a page when it is called up and thus enable the user to be identified. Cookies help to simplify the use of Internet pages for users.

It is possible to object to the setting of cookies at any time by changing the settings in your Internet browser. Cookies that have been set can be deleted. Please note that if you deactivate cookies, you may not be able to use all the functions of our website to their full extent. The user data collected in this way is pseudonymized by technical precautions. When accessing our website, users are informed by an info banner about the use of cookies for analysis purposes and referred to this privacy policy. In this context, there is also a reference to how the storage of cookies can be prevented in the browser settings. The legal basis for the processing of personal data using technically necessary cookies is Art. 6 para. 1 lit. f) GDPR. The legal basis for the processing of personal data using cookies for analysis purposes is Art. 6 para. 1 lit. a) GDPR if the user has given consent to this. To find out whether and to what extent cookies are used on our website, please refer to our cookie banner and our information in this privacy policy.

Creation of log files

Each time the website is accessed, Ifolor Oy collects data and information through an automated system. This data is stored in the server log files. The data is also stored in the log files of our system. This data is not stored together with other personal data of the user.
The following data may be collected:

(1) Information about the browser type and version used
(2) The user's operating system
(3) The user's internet service provider
(4) The IP address of the user
(5) Date and time of access
(6) Websites from which the user's system accesses our website (referrer)
(7) Websites that are accessed by the user's system via our website

Duration of storage of personal data

Personal data is stored for the duration of the respective statutory retention period. After this period has expired, the data is routinely deleted unless it is necessary for the initiation or fulfillment of a contract.

Images and related data of customer orders are automatically deleted no later than 30 days after the delivery of the order, unless a different procedure has been specifically agreed between the parties.

Possibilities for making contact

There is a contact form on the Ifolor Oy website that can be used to contact us electronically. Alternatively, contact can be made via the e-mail address provided. If the data subject contacts the controller via one of these channels, the personal data transmitted by the data subject are automatically stored. The data is stored solely for the purposes of processing or contacting the data subject. The data will not be passed on to third parties. The legal basis for the processing of the data is Art. 6 para. 1 lit. a) GDPR if the user has given consent. The legal basis for the processing of data transmitted in the course of sending an e-mail is Art. 6 para. 1 lit. f) GDPR. If the e-mail contact is aimed at the conclusion of a contract, the additional legal basis for the processing is Art. 6 para. 1 lit. b) GDPR. The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. For the personal data from the input screen of the contact form and those sent by E-Mail, this is the case when the respective conversation with the user has ended. The conversation is ended when it can be inferred from the circumstances that the matter in question has been conclusively clarified.

Newsletter & Braze

If you subscribe to our company's newsletter, the data in the respective input mask will be transmitted to the controller. Subscription to our newsletter takes place in a so-called double opt-in procedure. This means that after registering, you will receive an E-Mail asking you to confirm your registration. This confirmation is necessary so that no-one can register with other people's E-Mail addresses. When registering for the newsletter, the user's IP address and the date and time of registration are stored. This serves to prevent misuse of the services or the e-mail address of the person concerned. The data is not passed on to unauthorized third parties. However, data required for the purpose of sending the newsletter may be transmitted to corresponding service providers. There is also an exception if there is a legal obligation to pass on the data. The data is used exclusively for sending the newsletter. The subscription to the newsletter can be canceled by the data subject at any time. Consent to the storage of personal data can also be revoked at any time. There is a corresponding link for this purpose in every newsletter. The legal basis for the processing of data after the user has subscribed to the newsletter is the user's consent.

If you have subscribed to our newsletter, it will be sent via the technical service provider Braze Inc. in the USA (Braze), to whom we pass on the data you provided when registering for the newsletter. This transfer serves our legitimate interest in using an effective, secure and user-friendly newsletter system. Braze uses this information to send and statistically evaluate the newsletters on our behalf using pseudonymised data. You can unsubscribe from the newsletter at any time in writing or directly in the newsletter.

We also use Braze to send you other electronic messages/emails, e.g. for order confirmation. Accordingly, Braze may receive your personal data within the scope of the order processing agreement we have with them. The data is stored there for the duration for which storage is otherwise lawful for the purposes set out in this privacy policy, i.e. in particular for contractual communication within the scope of existing contracts with you or for advertising communication.

More information about Braze can be found below.

Privacy Notice for the Monthly Gift Voucher Draw

All subscribers to the ifolor newsletter are automatically entered into a monthly prize draw in which the prize is an ifolor gift voucher worth €50.

The organizer of the draw processes participants’ personal data (email address and any contact details required for prize delivery) for the purposes of conducting the draw, contacting the winner, and delivering the prize. Participation is based on an active newsletter subscription.

Personal data is processed in accordance with applicable data protection legislation and is not used for purposes other than newsletter communications and administration of the draw. The organizer does not disclose personal data to third parties without a lawful basis.

The winner will be contacted personally by email. If the winner cannot be reached within a reasonable period of time, the organizer reserves the right to draw a new winner.

Newsletter subscriptions can be cancelled at any time via the unsubscribe link included in each newsletter. Cancelling the subscription will remove eligibility for future prize draws.

The company responsible for managing personal data:

Ifolor Oy (Business ID: 0871712-9)
Karhumäenkuja 2
FI-01530 Vantaa
Finland

Shipping Services (PostNord)

We disclose the personal data necessary for the delivery of orders to PostNord Finland Oy. The data disclosed includes the customer’s name, delivery address, phone number, email address, and delivery-related order information. PostNord processes personal data to carry out the delivery, enable shipment tracking, and communicate with customers regarding the delivery, such as sending delivery notifications.

The processing of personal data is based on the performance of a contract (Art. 6(1)(b) GDPR). PostNord acts as an independent data controller with respect to delivery services. For more information about PostNord’s processing of personal data, please see their privacy policy: https://www.postnord.fi/en/privacy-policy

Online Shop

We use your personal data to process your online purchases (your orders and returns are processed via our online services) and to send you delivery status notifications or notifications in the event of problems with the delivery of your items. We use your personal data to process your payments. We also use your data to process complaints and product warranty claims. Your personal data is used to verify your identity, to ensure that you have reached the minimum legal age for online purchases and to check your address with external partners. We would like to offer you several payment methods and carry out analyses to find out which payment options are available to you, including your payment history and credit checks.

Forwarding of data when using online payment service providers

If you decide to pay with one of the online payment service providers offered by us as part of your order process, your contact details will be transmitted to them as part of the order triggered in this way. The electronic payment process (exception: payment by invoice) is handled by our certified payment service provider, Datatrans AG, Kreuzbühlstr. 26, CH-8008 Zurich. During payment, your payment data will be exchanged directly between you and our payment service provider and stored exclusively with the latter for a limited period of time for the purpose of payment processing and for any complaints or credit notes. The applicable data protection provisions of Datatrans can be at https://www.weareplanet.com/legal .

The lawfulness of the transfer of data results from Art. 6 para. 1 lit. b) GDPR, for the execution of the payment method selected by you as well as our legitimate interests pursuant to Art. 6 para. 1 lit. f) GDPR to enable user-friendly and uncomplicated payment processing. The personal data transmitted to the online payment service provider is usually first name, surname, address, IP address, email address or other data required for order processing, as well as data related to the service, such as type of service, identity of the recipient, invoice amount and taxes as a percentage, billing information, etc. This transmission is necessary to perform the service with the payment method you have selected, in particular to confirm your identity, to administer your payment and the customer relationship.

Please note, however, that personal data may also be passed on by the online payment service provider to service providers, subcontractors or other affiliated companies if this is necessary to fulfill the contractual obligations arising from your order or if the personal data is to be processed on our behalf. Depending on the selected payment method, e.g. invoice or direct debit, the personal data transmitted to the provider will be transmitted by the provider to credit agencies. This transmission is used to check your identity and creditworthiness in relation to the order you have placed. You can find out which credit agencies are involved here and which data is generally collected, processed, stored and passed on by the respective provider in the respective data protection declarations of the providers:

  1. Datatrans AG, Kreuzbühlstrasse 26, 8008 Zurich, Switzerland

Your payments are processed for us by our partner Datatrans AG in Switzerland, except in the case of payment against invoice. We only receive transaction data from Datatrans, such as the amount of the transaction and a payment confirmation. You can find information about data protection in Datatrans' privacy policy: https://www.weareplanet.com/legal

  1. Paytrail Oyj (Business ID: 2552865-3), Innova 2, Lutakonaukio 7, FI-40100 Jyväskylä at https://www.paytrail.com/en/data-privacy-notice-paytrail-payment-service
  2. Mastercard Europe SA, Chaussée de Tervuren 198A, B-1410 Waterloo, Belgium at https://www.mastercard.com/global/en/privacy-notice.html
  3. Visa Europe Services Inc, London Branch, 1 Sheldon Square , London W2 6TT , United Kingdom at https://www.visa.com/en-us/legal/global-privacy-notice
  4. Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden at https://www.klarna.com/international/privacy-policy/

Transfer to third countries

We would like to inform you that your personal data may also be transmitted to a server abroad and therefore processed outside EU. Please refer to the linked data protection information of the providers for the respective foreign countries.

Duration

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you withdraw your consent or request the deletion of your personal data.

Contractual or legal obligation to provide personal data

The provision of personal data is not required by law or contract and is not necessary for the conclusion of a contract. You are also not obliged to provide the personal data. However, failure to provide this data may mean that you will not be able to use this service or will not be able to use it to its full extent.

Registration on our website for orders, project reminders and sending promotions & discounts

Description, purpose and legal basis

If the data subject uses the option to register on the controller's website by providing personal data, the data in the respective input mask is transmitted to the controller. The data is stored exclusively for internal use by the controller. The data is deleted as soon as it is no longer required for the purpose for which it was collected. During registration, the user's IP address and the date and time of registration are stored. This serves to prevent misuse of the services. The registration of data is necessary for the provision of content or services. In addition, you will receive e-mails with reminders for started projects of a photo project in the Web Designer or Desktop Designer if you have not completed a started project (4 reminders within 90 days). The legal basis is therefore Art. 6 para. 1 lit. b) GDPR and Art. 6 para. 1 lit. f) GDPR. Our legitimate overriding interest is to fulfill our contractual and pre-contractual obligations in relation to our customers and interested parties and, in this context, to remind them of open projects so that started and processed projects are not deleted due to our retention periods and the data subjects have the opportunity to finalize progress in the project before the respective progress is lost due to the limited storage period. Registered persons have the option of having the stored data deleted or amended at any time. The data subject can obtain information about their stored personal data at any time.

As part of the registration process, you have the option of subscribing to a newsletter for promotions and discounts. If you have given your consent (incl. double opt-in procedure) by ticking the corresponding checkbox, you will receive emails from us as part of our E-Mail campaigns with promotions & discounts on various Ifolor products and services. The legal basis for emails with promotions & discounts is your consent (Art. 6 para. 1 lit. a) GDPR ).

Storage duration

The storage period for started projects is 90 days on the web.

Recipients & Transmissions

The newsletter service providers Selligent SA from Belgium (Selligent) and Braze Inc. from the USA (Braze) are used to send the emails. Further information about Selligent can be found in this privacy policy in the section ‘Newsletter & Selligent’ or in the section on ‘Braze’.

Revocation & objection

If your consent is the legal basis, you have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

In the event that the legal basis for the processing of your personal data is our overriding legitimate interest, you have the right to object to the processing of your personal data at any time in accordance with Art. 21 (1) GDPR. If you exercise your right, processing for this purpose will no longer take place.

Contractual or legal obligation

There is no legal obligation to provide the data. However, if you register and conclude a contract with us, we cannot fulfill our contractual obligations without the provision of certain personal data.

Further data protection information

The applicable data protection provisions of Selligent may be retrieved under https://www.selligent.com/privacy-policy-europe/.

Routine deletion and blocking of personal data

The controller processes and stores personal data of the data subject only for as long as is necessary to achieve the purpose of storage. Data may also be stored if this has been provided for by the European or national legislator in EU regulations, laws or other provisions to which the controller is subject. As soon as the storage purpose no longer applies or a storage period prescribed by the aforementioned regulations expires, the personal data is routinely blocked or deleted.

Rights of the data subject

If your personal data is processed, you are a data subject within the meaning of the GDPR and you have the following rights vis-à-vis the controller:

Right to information pursuant to Art. 15 GDPR

You can request confirmation from the controller as to whether personal data concerning you is being processed by us. If such processing is taking place, you can request the following information from the controller:

  1. the purposes for which the personal data are processed;
  2. the categories of personal data that are processed;
  3. the recipients or categories of recipients to whom your personal data have been or will be disclosed;
  4. the planned duration of the storage of your personal data or, if specific information on this is not possible, criteria for determining the storage period;
  5. the existence of a right to rectification or erasure of your personal data, a right to restriction of processing by the controller or a right to object to such processing;
  6. the existence of a right of appeal to a supervisory authority;
  7. all available information about the origin of the data if the personal data is not collected from the data subject;
  8. the existence of automated decision-making, including profiling in accordance with Art. 22 (1) and (4) GDPR and - at least in these cases - meaningful information on the logic involved and the scope and intended effects of such processing for the data subject.

You have the right to request information about whether your personal data is transferred to a third country or to an international organization. In this context, you may request to be informed about the appropriate safeguards pursuant to Art. 46 GDPR in connection with the transfer.

Right to rectification pursuant to Art. 16 GDPR

You have a right to rectification and/or completion vis-à-vis the controller if the processed personal data concerning you is incorrect or incomplete. The controller must make the correction without delay.

Right to erasure pursuant to Art. 17 GDPR

(1) You may request the controller to delete your personal data immediately and the controller is obliged to delete this data immediately if one of the following reasons applies:

  1. The personal data concerning you are no longer necessary for the purposes for which they were collected or otherwise processed.
  2. You revoke your consent on which the processing was based pursuant to Art. 6 para. 1 lit. a) or Art. 9 para. 2 lit. a) GDPR and there is no other legal basis for the processing.
  3. You object to the processing pursuant to Art. 21 (1) GDPR and there are no overriding legitimate grounds for the processing, or you object to the processing pursuant to Art. 21 (2) GDPR.
  4. The personal data concerning you has been processed unlawfully.
  5. The deletion of personal data concerning you is necessary to fulfill a legal obligation under Union law or the law of the Member States to which the controller is subject.
  6. The personal data concerning you was collected in relation to information society services offered in accordance with Art. 8 para. 1 GDPR.

(2) If the controller has made your personal data public and is obliged to erase it pursuant to Art. 17 (1) GDPR, the controller, taking account of available technology and the cost of implementation, shall take reasonable steps, including technical measures, to inform controllers which are processing the personal data that you as the data subject have requested the erasure by such controllers of any links to, or copy or replication of, those personal data.

(3) The right to erasure does not exist if the processing is necessary

  1. to exercise the right to freedom of expression and information;
  2. for compliance with a legal obligation which requires processing by Union or Member State law to which the controller is subject or for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller;
  3. for reasons of public interest in the area of public health pursuant to Art. 9 para. 2 lit. h) and i) and Art. 9 para. 3 GDPR;
  4. for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes in accordance with Art. 89 para. 1 GDPR, insofar as the right referred to in para. 1 is likely to render impossible or seriously impair the achievement of the objectives of that processing, or
  5. for the assertion, exercise or defense of legal claims.

Right to restriction of processing pursuant to Art. 18 GDPR

You may request the restriction of the processing of your personal data under the following conditions:

  1. if you contest the accuracy of your personal data for a period enabling the controller to verify the accuracy of the personal data;
  2. the processing is unlawful and you oppose the erasure of the personal data and request the restriction of their use instead;
  3. the controller no longer needs the personal data for the purposes of the processing, but they are required by you for the establishment, exercise or defense of legal claims, or
  4. if you have objected to the processing pursuant to Art. 21 (1) GDPR and it is not yet certain whether the legitimate reasons of the controller outweigh your reasons.

If the processing of your personal data has been restricted, this data - apart from its storage - may only be processed with your consent or for the establishment, exercise or defense of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest of the Union or of a Member State. If the restriction of processing has been restricted in accordance with the above conditions, you will be informed by the controller before the restriction is lifted.

Right to information pursuant to Art. 19 GDPR

If you have asserted the right to rectification, erasure or restriction of processing against the controller, the controller is obliged to notify all recipients to whom the personal data concerning you have been disclosed of this rectification or erasure of the data or restriction of processing, unless this proves impossible or involves a disproportionate effort. You have the right vis-à-vis the controller to be informed about these recipients.

Right to data portability pursuant to Art. 20 GDPR

You have the right to receive your personal data, which you have provided to the controller, in a structured, commonly used and machine-readable format. You also have the right to transmit this data to another controller without hindrance from the controller to which the personal data has been provided, where

  1. the processing is based on consent pursuant to Art. 6 para. 1 lit. a) GDPR or Art. 9 para. 2 lit. a) GDPR or on a contract pursuant to Art. 6 para. 1 lit. b) GDPR and
  2. the processing is carried out by automated means. In exercising this right, you also have the right to have your personal data transmitted directly from one controller to another, where technically feasible. The freedoms and rights of other persons must not be affected by this. The right to data portability does not apply to the processing of personal data necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.

Right to object pursuant to Art. 21 GDPR

You have the right to object, on grounds relating to your particular situation, at any time to processing of your personal data which is based on point (e) or (f) of Article 6(1) GDPR, including profiling based on those provisions.

The controller will no longer process your personal data unless the controller demonstrates compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defense of legal claims.

If your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for the purpose of such marketing; this also applies to profiling insofar as it is associated with such direct marketing.

If you object to processing for direct marketing purposes, your personal data will no longer be processed for these purposes.

You have the option, in connection with the use of information society services - notwithstanding Directive 2002/58/EC - to exercise your right to object by means of automated procedures that use technical specifications.

Right to revoke the declaration of consent under data protection law pursuant to Art. 7 para. 3 GDPR

You have the right to withdraw your declaration of consent under data protection law at any time. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal.

Right to lodge a complaint with a supervisory authority pursuant to Art. 77 GDPR

Without prejudice to any other administrative or judicial remedy, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work or place of the alleged infringement if you consider that the processing of your personal data infringes the GDPR. The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint, including the possibility of a judicial remedy pursuant to Art. 77 GDPR.

Automated decision in individual cases including profiling

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you. This does not apply if the decision

  1. is necessary for the conclusion or performance of a contract between you and the controller,
  2. is authorized by Union or Member State law to which the controller is subject and which also lays down suitable measures to safeguard your rights and freedoms and legitimate interests; or
  3. with your express consent.

However, these decisions may not be based on special categories of personal data pursuant to Art. 9 para. 1 GDPR, unless Art. 9 para. 2 lit. a) or g) applies and appropriate measures have been taken to protect the rights and freedoms as well as your legitimate interests.

With regard to the cases referred to in a. and c., the data controller shall implement suitable measures to safeguard your rights and freedoms and legitimate interests, at least the right to obtain human intervention on the part of the controller, to express your point of view and to contest the decision.

Integration of other third-party services and content

Description and purpose

Third-party content, such as videos, fonts or graphics from other websites, may be integrated into this online offering. This always presupposes that the providers of this content (hereinafter referred to as "third-party providers") are aware of the user's IP address. Without the IP address, they would not be able to send the content to the respective user's browser. The IP address is therefore required to display this content. We endeavor to only use content whose respective providers only use the IP address to deliver the content. However, we have no influence on whether the third-party providers store the IP address, e.g. for statistical purposes. Insofar as we are aware of this, we will inform users of this. We would like to provide and improve our online offering through these integrations.

Legal basis

The legal basis for the integration of other third-party services and content is Art. 6 para. 1 lit. f) GDPR. Our overriding legitimate interest lies in the intention to present our online presence accordingly and to provide user-friendly and economically efficient services on our part. Further information can be found in the respective data protection information of the providers.

Contractual or legal obligation to provide personal data

The provision of personal data is not required by law or contract and is not necessary for the conclusion of a contract. You are also not obliged to provide the personal data. However, failure to provide this data may mean that you will not be able to use this function or will not be able to use it to its full extent.

Data transfer to third countries

The controller may transfer personal data to a third country. In principle, the controller can ensure an adequate level of protection for the processing operations by means of various appropriate safeguards. It is possible to transfer data on the basis of an adequacy decision, internal data protection regulations, approved codes of conduct, standard data protection clauses or an approved certification mechanism pursuant to Art. 46 para. 2 lit. a) - f) GDPR.

If the controller carries out a transfer to a third country on the legal basis of Art. 49 (1) (a) GDPR, you will be informed here about the possible risks of data transfer to a third country.

There is a risk that the third country receiving your personal data may not have an equivalent level of protection compared to the protection of personal data in the European Union. This may be the case, for example, if the EU Commission has not issued an adequacy decision for the respective third country or if certain agreements between the European Union and the respective third country are declared invalid. Specifically, there are risks in some third countries with regard to the effective protection of EU fundamental rights through the use of surveillance laws (e.g. USA). In such a case, it is the responsibility of the controller and the recipient to assess whether the rights of the data subjects in the third country enjoy an equivalent level of protection as in the Union and can also be effectively enforced.

However, the General Data Protection Regulation should not undermine the level of protection of natural persons ensured throughout the Union when personal data are transferred from the Union to controllers, processors or other recipients in third countries or to international organizations, including when personal data are onward transferred from a third country or an international organization to controllers or processors in the same or another third country or to the same or another international organization.

Usercentrics

Description and purpose

This website uses Usercentrics' cookie consent technology to obtain your consent to the storage of certain cookies on your device and to document and record this consent in accordance with data protection regulations. As soon as you enter this website, the following personal data is transferred to Usercentrics:

  • Your consent(s) or the withdrawal of your consent(s)
  • Your IP address
  • Information about your browser (http agent, http referrer),
  • Information about your end device
  • Time of your visit to the website

The following additional data will be added:

  • Opt-in and opt-out data
  • Referrer URL
  • User Agent
  • User settings
  • Consent ID and Consent Number
  • Information on whether implicit or explicit consent has been given
  • Time (date and time) of consent
  • Consent type
  • Template version
  • Banner language

Usercentrics also stores a cookie in your browser in order to be able to assign the consents you have given or revoke them. The data collected in this way will be stored until you ask us to delete it, delete the Usercentrics cookie yourself or the purpose for storing the data no longer applies. Mandatory statutory retention obligations remain unaffected.

Legal basis

Usercentrics is used to obtain the legally required consent for the use of cookies. The legal basis for the processing of your personal data is Art. 6 para. 1 lit. c) GDPR.

Receiver

The recipient of your personal data is Usercentrics GmbH, Rosental 4, 80331 Munich, Germany.

Transfer to third countries

Your personal data will not be transferred to a third country. However, we are aware of our responsibility and regularly review the framework conditions and legal changes. In the event of a transfer to a third country, we will update this information as soon as possible.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Contractual and legal obligation

Furthermore, the personal data that we are legally obliged to collect must be provided (or) the provision of this data is necessary to fulfill a legal obligation. The legal obligation is determined by Union law or the law of the Member States to which the controller is subject. In this case, the legal obligation arises from: Section 25 (1) TTDSG in conjunction with Art. 7 GDPR. Failure to provide the data would mean that this legal obligation cannot be fulfilled.

Further data protection information

Further information on the processing of your personal data can be found here:

https://usercentrics.com/privacy-policy

Further functions of the website

Google APIs (in particular Google Photos)

On our websites and in our applications, you can use Google APIs, in particular Google Photos, to select images and import them into your ifolor project. If you use this function, you will be redirected to Google or connected to Google. The connection is only established after you have actively started the function and granted the relevant authorization to Google.

As part of this integration, we process the personal data and content that you make available to us via Google or release for import. This may include, in particular, selected photos and videos, technical information relating to the selected files (e.g. file format, resolution or creation date), basic information related to your Google account (e.g. e-mail address or profile name, where required for allocation), and technical log and authentication data. We process this data to provide the import and use function requested by you, to assign the selected content to your project, to technically perform the import, and to prevent abuse or disruptions.

The legal basis for the processing is Art. 6(1)(b) GDPR to the extent that the processing is necessary to provide the function requested by you. To the extent that individual processing steps are based on your consent, the legal basis is Art. 6(1)(a) GDPR. To the extent that we process technical log and security data to prevent abuse or ensure system security, the legal basis is Art. 6(1)(f) GDPR.

Use of this function is voluntary. We do not receive your Google password. Depending on the Google API used and the permissions you grant, data may also be processed by Google or within the Google group of companies. Processing in third countries, in particular in the United States, cannot be ruled out. Please note that Google’s privacy policy and terms of use also apply to Google’s processing of your data.

To the extent that imported content is stored in your ifolor project, we process it in accordance with the general provisions of this privacy policy regarding projects, orders and image files. You can manage or revoke any authorization granted to Google at any time in your Google account. Please note that revoking the Google connection stops future transfers, but does not automatically delete data already transferred to ifolor. The deletion of such data is governed by the general deletion rules in this privacy policy.

Google Ads, Conversion Linker & Conversion Tracking

Description and purpose

To draw attention to our services and products, we place Google Ads ads and use Google Conversion Tracking and the Google Conversion Linker as part of this. The conversion linker tracks conversion data when a user accesses a website via an ad. Google Ads is a service provided by Google LLC. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). These ads are displayed after search queries on websites in the Google advertising network. We have the option of combining our ads with specific search terms. We also use Ads remarketing lists for search ads. This allows us to customize search ad campaigns for users who have previously visited our website. The services allow us to combine our ads with certain search terms or to place ads for previous visitors, e.g. advertising services that visitors have viewed on our website. An analysis of online user behavior is necessary for interest-based offers. Google uses cookies to carry out this analysis. When you click on an advertisement or visit our website, Google places a cookie on the user's computer. This information is used to target the visitor in a subsequent search query. Further information on the cookie technology used can also be found in Google's notes on website statistics and in the privacy policy. With the help of this technology, Google and we as a customer receive information that a user has clicked on an ad and has been redirected to our websites to contact us via the contact form. Google and we as the customer also receive information via Google forwarding numbers that a user has clicked on one of our telephone numbers on and contacted us by telephone. The information obtained in this way is used exclusively for statistical analysis to optimize advertising. We do not receive any information with which visitors can be personally identified. The statistics provided to us by Google include the total number of users who have clicked on one of our ads and, if applicable, whether they were redirected to a page on our website with a conversion tag. Based on these statistics, we can see which search terms were clicked on our ad particularly often and which ads lead to the user contacting us via the contact form or by telephone. With regard to telephone contact by interested parties or customers, the statistics provided by Google include the start time, the end time, the status (missed or received), the duration (seconds), the caller's area code, the telephone costs and the call type.

Legal basis

The legal basis for the processing of your personal data is consent (per service) pursuant to Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Google LLC. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA). The data controller responsible for processing your information depends on your usual place of residence, unless otherwise stated in the privacy notice of a particular service:

  • Google Ireland Limited for users of Google services who have their habitual residence in the European Economic Area or Switzerland
  • Google LLC for users of Google services who have their habitual residence in the United Kingdom.

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification under the EU-US Data Privacy Framework, which is why a sectoral adequacy decision pursuant to Art. 45 GDPR exists.

Duration of data storage

They are stored for a period of 9 - 18 months. In addition, the data will be deleted if you assert your right to deletion and no retention periods prevent deletion.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and takes effect for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual and legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here: www.google.com/policies/privacy/

Google Customer Match

We use Google Customer Match through Google Ads and Google Marketing Platform, in particular Display & Video 360, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Dublin, D04 E5W5, Ireland (“Google”). Customer Match enables us, through Google Ads and Display & Video 360, to reach existing customers and relevant audiences with interest- and audience-based advertising, or to exclude certain customer groups from individual advertising campaigns, on supported Google services and advertising inventory, in particular Google Search, Google Shopping, YouTube, Gmail and the Google Display Network.

If you have consented to the use of Google Customer Match or to personalised advertising, we may use customer data that you have provided to us or that has arisen in connection with your use of our services for matching with Google accounts. This includes, in particular, email address, telephone number, first and last name, address, country, postal code, customer number or other identifiers assigned by us, as well as information about orders and broad interests. Direct identifiers are normalised in accordance with Google’s specifications and converted into a string using the SHA-256 hashing method before being transferred to Google. Where we use country and postal code for matching, these may be transferred unhashed in accordance with Google’s specifications. Hashing does not mean that the data is anonymous, because Google can compare the hash values with data from Google accounts.

Google compares the hash values transmitted by us with the corresponding hash values of Google accounts. If there is a match, the relevant Google account may be added to a Customer Match audience. We may then use these audiences to personalise advertising, re-engage existing customers, reach similar or relevant audiences, exclude certain customer groups from campaigns, measure and optimise conversions, and perform audience analysis and market research.

In connection with the delivery, measurement and optimisation of advertising, Google and we may also process cookies, online identifiers and information about ad impressions, clicks, browsing and search behaviour, search terms, interests and usage information, provided that consent has been given for this or the processing is otherwise permitted.

For the personalisation of our advertising, we may assign customers to segments. We generally use only simple, non-sensitive criteria for this purpose, in particular language and region, e.g. country, region, postal code area or language; purchase phase based on order date, e.g. new customers, active customers or inactive customers; order value or customer value in ranges, e.g. low, medium or high basket value; order frequency, e.g. one-time purchasers, repeat purchasers or regular customers; and broad product or category interests, e.g. interest in certain product groups or accessories, provided that these categories do not reveal special categories of personal data or other sensitive personal data.

We do not use special categories of personal data or other sensitive personal data for this purpose, in particular no data concerning health, political opinions, religious or philosophical beliefs, sex life or sexual orientation, ethnic origin, genetic or biometric data, trade union membership, criminal convictions or offences, social welfare or similarly sensitive information. We do not carry out any credit checks, do not apply individual price increases, and do not make automated individual decisions that have legal effects concerning you or similarly significantly affect you.

Recipients of the data are Google Ireland Limited and, where applicable, other companies of the Google group, in particular Google LLC and Alphabet Inc., as well as subprocessors engaged by Google. Processing primarily takes place in the European Union. Transfers to countries outside the European Union or the European Economic Area, in particular to the USA, Singapore, Chile or Taiwan, cannot be excluded. According to Google, such transfers are based on appropriate safeguards, in particular adequacy decisions, certifications under the Data Privacy Framework, standard contractual clauses or comparable protection mechanisms.

According to Google, uploaded Customer Match files are processed to match customers to Google accounts and to check compliance with Google policies. Once the matching and compliance checks have been completed, Google states that the uploaded files are deleted. Customer Match list memberships may remain valid at Google for up to 540 days. We store and use Customer Match audiences only for as long as necessary for the purposes described above or until you withdraw your consent.

The use of Google Customer Match is based on your consent pursuant to Art. 6(1)(a) GDPR. Where information is stored on or accessed from your terminal device in connection with Google Customer Match, this is additionally based on your consent pursuant to Section 205 of the Finnish Act on Electronic Communications Services (917/2014).

You may withdraw your consent at any time with effect for the future via the cookie or privacy settings on our website. After withdrawal, we will take this into account in our consent management system and will no longer include your data in new Customer Match uploads. During the current technical transition phase, we generally update Customer Match lists manually every 30 days. Data records that have already been uploaded will therefore be removed from the relevant Customer Match lists, or will no longer be used for Google Customer Match, with the next regular list update or deletion upload, but no later than within 30 days after your withdrawal. Until this technical deletion has been implemented, it cannot be completely ruled out that you may still see advertising based on an existing Customer Match list membership.

Independently of this, you can also manage personalised advertising in Google’s ad settings. Further information on data processing by Google is available in Google’s Business Data Responsibility information, Google’s Cookie Policy and via Google’s privacy contact form:

https://business.safety.google/privacy/?hl=en
https://policies.google.com/technologies/cookies?hl=en
https://support.google.com/policies/troubleshooter/7575787?hl=en

Meta Customer List Custom Audiences (“Customer Match”) and Lookalike Audiences

Description and purpose

We use Meta’s “Customer List Custom Audiences” and “Lookalike Audiences” advertising features. Customer List Custom Audiences allow us to target people who have consented to this use of their personal data with advertising on Facebook and Instagram or to exclude them from certain advertising campaigns. This enables us to make our advertising more relevant and to avoid unnecessary advertising contacts.

To create a Custom Audience, we transfer selected contact and identification data, in particular your email address and/or telephone number, to Meta only where you have given the relevant consent in advance. Before the matching process, the data is converted into values that are not directly readable using a cryptographic hashing process.

Hashing does not anonymise the data; it only pseudonymises it. The hash values remain personal data because Meta can compare them with hashed identifiers associated with Meta accounts. Where a match is found, the relevant Meta account may be included in or excluded from the audience defined by us. Assigning an account to an audience also involves processing the information that the person concerned belongs to the relevant audience segment defined by us.

We may also use a Custom Audience as the source audience for a Lookalike Audience. Meta then automatically identifies additional people who, based on the characteristics and signals available to Meta, display similarities to the source audience. These people may subsequently be shown our advertising.

The creation and use of these audiences may involve automated analysis and profiling for advertising-selection purposes. However, it does not result in any decision by us based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

Legal basis

The processing is carried out exclusively on the basis of your consent pursuant to Article 6(1)(a) GDPR. The requirements of Article 7 GDPR also apply to the granting and withdrawal of consent.

Your consent covers the selection and transfer of the relevant data, its matching with Meta accounts, inclusion in or exclusion from a Custom Audience and, where we use this function, the use of the Custom Audience as the source audience for a Lookalike Audience.

Recipients

Recipients of your personal data may include Meta Platforms Ireland Limited, Meta Platforms, Inc., other companies affiliated with Meta and service providers used by Meta insofar as they provide Facebook, Instagram or the advertising, matching and audience functions used for this purpose.

Transfers of personal data to third countries

Meta may process personal data outside the European Union and the European Economic Area, in particular in the United States. A transfer of personal data to the United States therefore cannot be ruled out.

Where a transfer to Meta Platforms, Inc. is covered by a valid certification under the EU-U.S. Data Privacy Framework, we rely on the corresponding adequacy decision of the European Commission pursuant to Article 45 GDPR.

Where a transfer is not covered by an adequacy decision, it will take place only in compliance with the requirements of Articles 44 et seq. GDPR. This may include, in particular, standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR and, where necessary, supplementary technical, contractual or organisational safeguards.

Retention period

We retain and update the selection and transfer lists compiled for matching purposes and the related audience assignments only for as long as they are required for the purposes described above or until you withdraw your consent.

Following a withdrawal, we will exclude your identifiers from future transfers and update or delete the relevant customer list or Custom Audience so that your identifiers are no longer used for this purpose.

This does not affect the continued retention of the same contact data for other purposes described in this Privacy Policy, in particular for the performance of a contract or compliance with statutory retention obligations. Any additional retention and deletion by Meta is governed by Meta’s Customer List Custom Audiences Terms and Privacy Policy.

Withdrawal of consent and voluntary provision

You may withdraw your consent at any time with effect for the future through the privacy or consent settings provided for this purpose. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

There is no legal or contractual requirement to provide your personal data for this purpose. Refusing or withdrawing your consent does not affect your use of our online shop or your ability to place orders with us.

Even after withdrawing your consent, you may still be shown advertising from ifolor where it is selected on the basis of other criteria and does not rely on the relevant customer list or audience assignment.

Further privacy information

Further information about Meta’s processing of your personal data is available in the Meta Privacy Policy and the  Customer List Custom Audiences Terms.

The current certification status of Meta Platforms, Inc. under the EU-U.S. Data Privacy Framework can be viewed in the  official Data Privacy Framework register. You can also manage your personalised advertising settings in your Meta account.

Adjust (including data sharing with Google Ads)

Description and purpose

We use Adjust in connection with our mobile applications. Adjust is a mobile measurement and fraud prevention service. The service helps us analyze how our apps are used and how effective our marketing activities are, optimize campaigns, detect fraud, and segment user groups. If the relevant integration and data sharing are enabled, Adjust may also transfer data to Google Ads so that app installs, sessions, and post-install events can be attributed to campaigns, measured, analyzed, and used for reporting and campaign optimization.

Legal basis

The legal basis for the processing of personal data is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with future effect by using the privacy or consent settings made available to you.

Purposes of processing

Adjust is used for analytics, marketing, optimization, fraud prevention, and segmentation.

Technologies used

The service uses web beacons, cookies, mobile SDK, and API.

Data processed

In particular, the following data may be processed in connection with the use of the service: viewed advertisements, app downloads, application data, IP address, identifiers, user agent, interaction data, device information, and referrer URL.

Recipients

The service provider is Adjust GmbH, Saarbrücker Str. 37A, 10405 Berlin, Germany. For data protection-related inquiries, the service provider can be contacted by email at privacy@adjust.com. Data recipients are Adjust GmbH, Adjust Inc., and Acquired IO LLC. If the relevant data sharing with Google Ads is enabled, data may also be transferred to Google Ads for attribution, conversion measurement, reporting, and campaign optimization.

Place of processing and transfers to third countries

Data is processed primarily in the European Union. However, in connection with the use of this service, data may also be transferred to other countries. In particular, data may be transferred to the United States of America, Japan, China, Brazil, and Singapore. Please note that data may also be transferred to countries that may not provide a level of data protection equivalent to the GDPR. Further information on the safeguards in place can be found in the provider’s privacy policy or obtained directly from the provider.

Storage period

Data is stored for a maximum of 25 months. The data is deleted as soon as it is no longer required for the purposes stated above.

Further data protection information

Further information can be found in Adjust’s privacy policy: https://www.adjust.com/terms/privacy-policy/

Google Enhanced Conversion

Description and purpose

On our website, we use the Google Enhanced Versions service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Enhanced Conversions is a function with which we can improve the accuracy of our conversion measurement and activate more powerful bids. It supplements the existing conversion tags by sending hashed first-party conversion data from the website to Google in a privacy-safe manner. The function uses a secure unidirectional hashing algorithm.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification under the EU-US Data Privacy Framework, which is why a sectoral adequacy decision pursuant to Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and takes effect for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

Privacy Policy - Privacy & Terms -

Speed Kit

Description and purpose

On our website, we use the Speed Kit service from Baqend GmbH, Stresemannstr. 23, 22769 Hamburg, Germany, to reduce page load times. For this purpose, publicly visible data is delivered via the infrastructure of the Speed Kit provider. No personalized or personal content is transmitted or stored. IP addresses are anonymized immediately after transmission.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. f) GDPR. Our predominantly legitimate interest lies in improving the presentation of our online presence.

Receiver

The recipient of your personal data is Baqend GmbH, Stresemannstr. 23, 22769 Hamburg.

Transfer to third countries

The personal data is processed in Germany.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Contradiction

In the event that the legal basis for the processing of your personal data is Art. 6 para. 1 lit. f) GDPR, you have the right to object to the processing of your personal data at any time in accordance with Art. 21 para. 1 GDPR. If you exercise your right, processing for this purpose will no longer take place.

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

Privacy | Speed Kit

Microsoft Ads

Description and purpose

On the website, we use technologies from Bing Ads (bingads.microsoft.com), which are provided and operated by Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA ("Microsoft"). Microsoft places a cookie on your device if you have reached our website via a Microsoft Bing ad. In this way, Microsoft Bing and the website operator can recognize that someone has clicked on an ad, has been redirected to our website and has reached a previously determined target page (conversion page). We only learn the total number of users who clicked on a Bing ad and were then redirected to the conversion page. Microsoft collects, processes and uses information via the cookie, from which user profiles are created using pseudonyms. These user profiles are used to analyze visitor behavior and are used to display advertisements. No personal information about the identity of the user is processed.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA ("Microsoft") and stored there.

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Microsoft Corp. has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists

Duration of data storage

The following table summarizes which personal data is processed and for how long. In addition, the data will be deleted if you assert your right to deletion and no retention periods prevent deletion.

Name

Storage duration

Memory type

Contents

Link

MUID

1 year

Cookie

Widely used by Microsoft as a unique user ID. The cookie enables user tracking by synchronizing the ID in many Microsoft domains.

More info...

_uetsid

30 minutes

Cookie

This cookie is used by Bing to collect anonymous information about how visitors use our website.

More info...

_uetvid

approx. 16 hours

Cookie

This cookie is used by Bing to determine which ads are displayed that may be relevant to the end user visiting the website.

More info...

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual and legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://privacy.microsoft.com/en-US/privacystatement

Microsoft Advertising Customer Match

We use “Customer Match” within Microsoft Advertising, a service provided by Microsoft Ireland Operations Limited, One Microsoft Place, South County Business Park, Leopardstown, Dublin 18, D18 P521, Ireland (“Microsoft”). Customer Match enables us to use customers’ email addresses to create customer-list audiences and to reach them with targeted search and audience advertising, adapt advertising content or exclude specific customer groups from individual campaigns across supported parts of the Microsoft Advertising Network.

We use your email address for this purpose only if you have consented to Microsoft Customer Match or the corresponding personalised advertising. Before transmission, we normalise the email address and convert it into a SHA-256 hash. Hashing constitutes pseudonymisation rather than anonymisation because Microsoft can compare the hash with hashes or identifiers associated with Microsoft accounts. We do not transmit telephone numbers, names or postal codes for Microsoft Customer Match.

Microsoft attempts to match the transmitted hashes against account information held by Microsoft. Where a match is found, the relevant Microsoft account may be included in or excluded from an audience defined by us. We use these audiences to re-engage existing customers, adapt advertising messages and campaigns, exclude selected customer groups from campaigns, and evaluate and optimise the effectiveness of our advertising.

The recipient of the hashes is Microsoft Ireland Operations Limited. Microsoft Corporation, other Microsoft group companies and service providers may also process personal data in connection with the provision of the service. Microsoft processes the transmitted data in accordance with the applicable Microsoft Customer Match Terms, Microsoft Advertising Agreement and related Microsoft policies. Microsoft may also process data generated within Microsoft services and the Microsoft advertising platform under its own responsibility and in accordance with its privacy statement.

Processing may take place outside the European Economic Area, in particular in the United States. Where the relevant country is not covered by an adequacy decision, Microsoft states that transfers are based on appropriate safeguards, such as applicable standard contractual clauses or other recognised transfer mechanisms.

We limit membership in our Microsoft Customer Match lists to a maximum of 390 days. Data is removed earlier where it is no longer required for the relevant advertising purposes or where you withdraw your consent. The underlying customer data in our own systems is retained in accordance with the other provisions of this Privacy Policy.

The legal basis for this processing is your consent under Article 6(1)(a) GDPR. Your consent is voluntary and may be withdrawn at any time with effect for the future through our privacy or advertising settings or by contacting us. Following withdrawal, we will prevent any further uploads and arrange for removal from the Customer Match lists managed by us during the next list update, and no later than within 30 days. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

You may additionally manage personalised advertising settings in your Microsoft account. Microsoft account settings do not, however, replace withdrawal of your consent from us.

Further information about Microsoft’s processing of personal data is available in the Microsoft Privacy Statement: https://www.microsoft.com/en-gb/privacy/privacystatement

YouTube

Description and purpose

We use the YouTube.com platform to post our own videos and make them publicly accessible. YouTube is a service provided by Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA. Some of our website pages contain links or connections to the YouTube service. In general, we are not responsible for the content of linked websites. However, if you follow a link to YouTube, we would like to point out that YouTube stores the data of its users (e.g. personal information, IP address) in accordance with its own data usage guidelines and uses it for business purposes. We also directly integrate videos stored on YouTube on some of our websites. During this integration, content from the YouTube website is displayed in parts of a browser window. However, the YouTube videos are only called up by clicking on them separately. This technique is also known as "framing". When you call up a (sub)page of our website on which YouTube videos are integrated in this form, a connection to the YouTube servers is established and the content is displayed on the website by notifying your browser.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Google LLC, 1600 Amphitheatre Parkway Mountain View, CA 94043, USA.

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual and legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://policies.google.com/privacy

Meta pixel

Description and purpose

To recognize your user behavior, we use the so-called meta pixel from Meta Platforms Inc, 1 Hacker Way, Menlo Park, California 94025, USA. This is an analysis tool that can be used to measure the effectiveness of advertising. It is a code snippet for the website that can be used to measure, optimize and build target groups for advertising campaigns. Conversion measurement allows us to track across devices (including cell phones, tablets and desktop computers) what actions people take after seeing our Facebook ads. By creating a meta pixel and adding it to our pages where the conversions are made (e.g. the purchase confirmation page), we can identify which people are making conversions as a result of our Facebook ads. The pixel is used to further monitor the actions that people take after clicking on our ads. Here we can determine on which device our customers saw the ad and on which devices they ultimately carried out the conversion. According to Facebook, the data collected includes

  • HTTP header:

HTTP headers contain a range of information that is sent via a standard web protocol between any browser request and any server on the Internet. HTTP headers contain information such as IP addresses (which in Germany can only be evaluated at the general country level), information about the web browser, page location, document, URI reference and user agent of the web browser.

  • Pixel-specific data:

This includes the pixel ID and Facebook cookie data used to link events to a specific Facebook advertising account and associate them with a person known to Facebook.

  • Optional values:

Developers and marketers can optionally send additional information about the visit via standard and custom data events. Typical custom data events include information about whether a purchase was made on a page, the conversion value and much more. You can find more information about custom data events here. With your consent, we use the "visitor action pixel" of Meta Platforms Inc, 1 Hacker Way, Menlo Park, California 94025, USA or, if you are based in the EU, Meta Platforms Ireland Limited, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland, within our website. This conversion tool allows us to track your actions after you have seen or clicked on a Facebook ad. This is used to monitor and analyze the effectiveness of our Facebook ads for statistical and market research purposes. Although we can only recognize this data in anonymized form, this data is also stored and processed by Facebook. We do not know exactly what Facebook does with this data, but it can be assumed that Facebook can and will link this data to your Facebook account. Facebook can use this information for the purposes of advertising, market research and the needs-based design of Facebook pages. For this purpose, Facebook and its partners create usage, interest and relationship profiles, e.g. to evaluate your use of our website with regard to the advertisements displayed to you on Facebook, to inform other Facebook users about your activities on our website and to provide other services associated with the use of Facebook. Cookies may also be stored on your PC for this purpose. The purpose and scope of the data collection and the further processing and use of the data by Facebook as well as your rights in this regard and setting options to protect your privacy can be found in Facebook's data protection information. The data may be merged with other Facebook services, such as Custom Audiences.

Extended adjustment

Advertisers can optionally enable the advanced meta pixel matching feature by sending encrypted information such as E-Mail address or phone number to Facebook. Advertisers can send one or more of the following identifiers for matching: E-Mail address, phone number, first name, last name, city, state, zip code, date of birth or gender.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Meta Platforms Inc (1 Hacker Way, Menlo Park, California 94025, USA) and Meta Platforms Ireland Limited (4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland).

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Meta Platforms Inc. has a corresponding certification under the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual and legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here: https://www.facebook.com/about/privacy

You can find more information about the meta pixel here: https://www.facebook.com/business/help/742478679120153?id=1205376682832142

Playable

Description and purpose

We use a platform provided by Playable ApS (Denmark) for our digital campaigns, such as quizzes and raffles. Playable acts as a data processor and processes the data on our behalf in accordance with the GDPR. We collect contact information (name, email) and game-specific responses from participants to target our marketing and improve customer understanding. The collected data is stored securely in the EU/EEA. We do not share your data with third parties unless you have given your consent or we have integrated Playable directly into our marketing automation system (e.g. Braze). You can request the deletion of your data by contacting our data protection officer.

Data collected

This list represents all (personal) data that is collected by or through the use of this service.

  • IP address
  • Data and time of visit
  • Pages visited
  • Browser settings
  • URL

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Playable ApS Tueager 1, 8200 Aarhus, Denmark.

Transfer to third countries

The collected data is stored securely in the EU/EEA. We do not share your data with third parties unless you have given your consent or we have integrated Playable directly into our marketing automation system (e.g. Braze).

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://playable.com/privacy-policy-for-playable-aps

Pinterest

Description and purpose

Our online offering uses the “Pinterest Tag” of Pinterest Inc., 808 Brannan St, San Francisco, CA 94103, USA. If a Pinterest user sees or clicks on an advert, other actions and target groups that have shown interest are compiled and tracked. Using them allows us to ensure that Pinterest adverts are only shown to Pinterest users who have already shown an interest in our offering and that they also match the potential interest of the user. This data helps us to measure the conversion of the respective campaign. It is used for statistical and market research purposes and helps to optimize campaigns.

Data collected

This list represents all (personal) data that is collected by or through the use of this service.

  • Information about your browser
  • Operating system info
  • Date and time of visit
  • Campaign type and content
  • Reaction to the respective campaign (e.g. transaction, newsletter registration)

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

Pinterest Inc.808 Brannan Street San Francisco, CA 94103-490, USA.

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Pinterest Inc. has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://policy.pinterest.com/fi/privacy-policy

TikTok

Description and purpose

Our online offer uses “TikTok Pixel” from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (“TikTok”). TikTok Pixel enables TikTok to determine website visitors as target groups to display ads. Accordingly, we use TikTok Pixel to display our TikTok ads only to TikTok users who have also shown an interest in our online offerings or who exhibit certain characteristics that we communicate to TikTok. TikTok Pixel also allows us to statistically analyse our TikTok ads. Data processing by TikTok is carried out within the framework of TikTok’s data use policy.

Data collected

This list represents all (personal) data that is collected by or through the use of this service.

  • Information about your browser
  • Operating system info
  • Date and time of visit
  • Campaign type and content
  • Reaction to the respective campaign (e.g. transaction, newsletter registration)

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

TikTok Information Technologies UK Limited Aviation House, 125 Kingsway Holborn, London, WC2B 6NH, UK.

Transfer to third countries

Your personal data will be processed in Singapore and the United States. The transfer is subject to appropriate safeguards in the form of standard data protection clauses. In addition, we are aware of our responsibility and, where necessary, take further measures to protect the rights and freedoms of natural persons to ensure the protection of personal data. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. TikTok Ltd. has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://www.tiktok.com/legal/privacy-policy

Trustpilot reviews

Description and purpose

We use Trustpilot to collect and publish customer reviews. If you leave a review, Trustpilot will process the personal data you provide in accordance with its privacy policy. Reviews and related user profiles are public on Trustpilot. If we send you a review invitation, we will share your email address with Trustpilot to send the invitation based on our legitimate interest.

Data collected

This list represents all (personal) data that is collected by or through the use of this service.

  • IP address
  • Browser settings
  • Name and email address (if the customer writes a review or creates an account)
  • Review content, star rating, images and videos

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. f) GDPR, collecting and publishing customer reviews or Art. 6 para. 1 lit. a) GDPR if if marketing-related invitations are sent.

Receiver

Trustpilot A/S, Pilestraede 58, 5th floor, DK-1112 Copenhagen K.

Transfer to third countries

Trustpilot A/S is located in Denmark, so the processing of personal data primarily takes place within the EU/EEA. Trustpilot may also use sub-processors outside the EU, in which case it will use appropriate data protection mechanisms (such as contractual safeguards).

Duration of data storage

Reviews remain on Trustpilot as long as the user keeps their profile active or deletes their review. The company only keeps the contact details in the customer register that are necessary to send review invitations. Other data is deleted as soon as it is no longer needed for the purpose for which it was collected. In addition, the data is deleted if the user exercises their right to erasure pursuant to Art. 17 para. 1 GDPR.

Revocation

Trustpilot offers users extensive control over their personal data. Users can view the data stored in their profile in Trustpilot’s settings (“My Settings”). The data can be edited, corrected or deleted (Art. 17 para. 1 lit. b) GDPR). Reviews can also be deleted or anonymized.

Further data protection information

Further information on the processing of your personal data can be found here:

https://corporate.trustpilot.com/legal/for-reviewers/privacy-policy

Google Maps

Description and purpose

This website uses Google Maps API from Google LLC. ( 1600 Amphitheatre Parkway Mountain View, CA 94043, USA) to visually display geographical information. When Google Maps is used, Google also collects, processes and uses data about the use of the Maps functions by visitors to the website.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Google LLC (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://policies.google.com/privacy?hl=en&gl=fi

Google Tag Manager

Description and purpose

We use Google Tag Manager (Google LLC. 1600 Amphitheatre Parkway Mountain View, CA 94043, USA) on our website. Google Tag Manager allows us to manage website tags via an interface and is a cookie-free domain that does not collect personal information, but can trigger other tags that collect data. Google pseudonymizes the data and the IP address transmitted by your browser as part of Google Analytics is not merged with other Google data.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Google LLC. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual and legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://policies.google.com/privacy?hl=en&gl=fi

Google Ads Remarketing

Description and purpose

We use the remarketing function within the Google Ads service. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Our aim with the remarketing function is to be able to present users of our website with advertisements based on their interests on websites within the Google advertising network (in Google Search or on YouTube, so-called "Google Ads" or on other websites). For this purpose, the interaction of users on our website is analyzed, e.g. which offers a user was interested in, in order to be able to display targeted advertising to users on other sites even after they have visited our website. This requires Google to store cookies on the end devices (e.g. cell phones) of users who visit certain Google services or websites in the Google Display Network. These cookies are used to record the visits of these users. The cookies are used to uniquely identify a web browser on a specific end device (e.g. cell phone) and not to identify a person.

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. a) GDPR.

Receiver

The recipient of your personal data is Google LLC, headquartered at 1600 Amphitheatre Parkway, Mountain View, California 94043 and Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland.

Transfer to third countries

It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion within the meaning of Art. 17 para. 1 GDPR.

Revocation

You have the right to withdraw your consent at any time, see Art. 7 para. 3 sentence 1 GDPR. This can be done informally and without giving reasons and is effective for the future. Withdrawal of consent does not affect the lawfulness of the processing carried out prior to withdrawal. Further information on this can be found above in our privacy policy under "Rights of data subjects".

Contractual and legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://policies.google.com/privacy?hl=en&gl=fi

Google Analytics 4

Description and purpose

This website uses the service "Google Analytics 4", which is offered by Google LLC, to analyze website usage by users. The service uses "cookies" - text files that are stored on your end device. First-party cookies are used for this purpose. With a first-party cookie, the user can only be recognized by the page from which the cookie originates, not across multiple domains. The information collected by the cookies is usually sent to a Google server in the USA and stored there. If necessary, Google Analytics on this website is extended by the code "gat._anonymizeIp();" in order to ensure anonymized collection of IP addresses (so-called IP masking). Please also note the following information on the use of Google Analytics: The IP address of users is truncated within the member states of the EU and the European Economic Area. This shortening eliminates the personal reference of your IP address. For EU citizens, the IP address is also only used to derive location data and then deleted again. You also have the option of activating or deactivating the collection of detailed location and device data for individual regions (tracking settings). As part of the order processing agreement that the website operators have concluded with Google LLC, the latter uses the information collected to compile an analysis of website usage and website activity and provides services associated with internet usage.

Receiver

The recipient of your personal data is Google LLC. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).

Disclosure abroad

The personal data is processed on a server in European Servers. It cannot currently be ruled out that personal data will be disclosed to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC has a corresponding certification according to the EU-US Data Privacy Framework. Ifolor Oy has concluded standard contractual clauses with Google LLC for the disclosure of personal data to the USA.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion and no retention periods prevent deletion

Further data protection information

Further information on the processing of your personal data can be found here: https://support.google.com/analytics/answer/6004245?hl=en https://policies.google.com/privacy?hl=en&gl=fi

Link to Microsoft Clarity

We link Google Analytics 4 to the "Microsoft Clarity" service in order to evaluate aggregated usage metrics from Google Analytics 4 within Clarity, thereby better identifying usage problems and optimising our offering. Data from Google Analytics 4 and Microsoft Clarity can be merged; processing is pseudonymised (e.g. via cookie/online identifiers) and is used exclusively for analysis and optimisation purposes. The link and evaluation only takes place if you have consented to the use of both services (via our consent tool).

Microsoft Clarity

Description and purpose

We use "Microsoft Clarity", a service for analysing the use of our website. This service records interactions (e.g. clicks, scrolls, mouse movements), technical events (e.g. error and performance information) and information about the display of the page in order to create heat maps and session replays and to improve user-friendliness and our offerings (analysis and optimisation). Content in recordings can be masked/suppressed by Clarity or by our configuration. The data is collected using cookies and similar technologies. The legal basis (where applicable) is your consent in accordance with Art. 6(1)(a) GDPR, which you can revoke at any time via our consent tool.

Data collected

This list contains all (personal) data collected by or through the use of this service.

  • IP address
  • Date and time of visit
  • Unique user ID
  • Session ID
  • User behaviour
  • Interaction data
  • Mouse movements
  • Clicks
  • Scrolling activity

Recipient

The recipient of the data is Microsoft (Microsoft Ireland Operations Limited One, Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521, Ireland and, depending on the constellation, affiliated companies such as Microsoft Corporation). Clarity is operated by Microsoft as a (joint) controller; further details can be found in the Microsoft notices.

Below you will find the E-Mail address of the data protection officer of the processing company.

https://www.microsoft.com/en-GB/concern/privacy

Disclosure abroad / transfer to third countries

Clarity data is processed in the Microsoft Azure cloud. For customers in the EU, the contractual relationship is with Microsoft Ireland Operations Limited (MIOL); standard contractual clauses (SCCs) exist between MIOL and Microsoft Corporation (USA) for intra-group transfers. A transfer to the USA cannot therefore be ruled out.

Duration of data storage

Clarity typically stores recording data for 30 days; heat map data and click/aggregation data are typically retained for up to 13 months (marked/favoured sessions also for up to 13 months).

Link to Google Analytics 4

If you have consented to the use of Google Analytics 4 and Microsoft Clarity, we can link the two services so that Clarity can retrieve data from Google Analytics 4 and display it in the Clarity interface. Clarity and Google Analytics data can be combined; processing is pseudonymised and carried out exclusively for analysis and optimisation purposes.

Further data protection information / opt-out

Further information on data processing by Microsoft can be found in the Microsoft Privacy Statement. You are also required to inform users that Clarity uses cookies; you can control consent via our consent tool (revocation possible at any time).

Customer Relationship Management (CRM)

Description and purpose

The data is collected, stored and, if necessary, passed on by us to the extent necessary to enable the administration of customer data, which also records the movement of goods. The collection, storage and forwarding is therefore carried out for the purpose of fulfilling a contract with the data subject and/or for the purpose of pre-contractual measures at the request of the data subject. Failure to provide this data may mean that goods and/or services cannot be delivered or cannot be delivered promptly.

Legal basis

The legal basis is Art. 6 para. 1 lit. b) GDPR and Art. 6 para. 1 lit. f) GDPR. The overriding legitimate interest is to make contact with interested customers and to offer corresponding services in connection with the ordering of photos.

Receiver

The recipient of your personal data is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Third country transfer

The personal data is processed on a server in Europe. It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Microsoft Corporation has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

With regard to the duration of the processing of personal data, we refer to Microsoft's privacy policy.

Opt-Out:

https://account.microsoft.com/privacy/ad-settings/signedout?ru=https:%2F%2Faccount.microsoft.com%2Fprivacy%2Fad-settings

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://www.microsoft.com/en-us/privacy/privacystatement

Enterprise Resource Planning (ERP)

Description and purpose

The data is processed by us to the extent necessary to enable the management of customer data, including the recording of goods movements. The processing of personal data serves the purpose of fulfilling a contract with the data subject or the purpose of pre-contractual measures at the request of the data subject. Failure to provide this data may mean that goods and/or services cannot be delivered or cannot be delivered promptly.

Legal basis

The legal basis is Art. 6 para. 1 lit. b) GDPR and Art. 6 para. 1 lit. f) GDPR. The overriding legitimate interest is to plan and manage our company's resources in order to enable effective resource planning.

Receiver

The recipient is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Transfer to the third country

The personal data is processed on a server in the Netherlands. It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Microsoft Corporation has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

With regard to the duration of the processing of personal data, we refer to Microsoft's privacy policy.

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://privacy.microsoft.com/en-us/privacystatement

Hosting (Microsoft Azure)

Description and purpose

The operator of this website uses the functions of Microsoft Azure. In this context, our website and our ecommerce store are hosted in the Azure data center on European servers. The customer login and uploaded photos are also stored on Azure. The processing of personal data serves the purpose of fulfilling a contract with the data subject or for the purpose of pre-contractual measures at the request of the data subject. Failure to provide this data may mean that goods and/or services cannot be delivered or cannot be delivered promptly.

The provider is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA. Azure offers a so-called globally distributed content delivery network with DNS. Technically, the transfer of information between your browser and our services is routed via the Azure network. Microsoft Azure is therefore able to analyze the data traffic between you and our services, for example to detect and ward off attacks on our services. Azure Front Door may also store cookies on your end device for optimization and analysis purposes. In addition, Azure offers us the option of dynamically adapting content in the services.

Legal basis

The legal basis is Art. 6 para. 1 lit. b) GDPR and Art. 6 para. 1 lit. f) GDPR. The overriding legitimate interest is to manage projects of interested parties and customers and, in this context, to enable the processing and ordering of various products and services.

Receiver

The recipient is Microsoft Corporation, One Microsoft Way, Redmond, WA 98052-6399, USA.

Transfer to the third country

The personal data is processed on a server in the Netherlands. It cannot currently be ruled out that personal data will be transferred to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Microsoft Corporation has a corresponding certification in accordance with the EU-US Data Privacy Framework, which is why a sectoral adequacy decision within the meaning of Art. 45 GDPR exists.

Duration of data storage

With regard to the duration of the processing of personal data, we refer to Microsoft's privacy policy.

Contractual or legal obligation

There is no contractual or legal obligation to provide the data.

Further data protection information

Further information on the processing of your personal data can be found here:

https://privacy.microsoft.com/en-us/privacystatement

Braze

Service Description

This is a service for cross-channel campaign management. We use Braze to design personalised customer experiences across web, E-Mail, and app. This includes promotional emails/newsletters (e.g. offers, updates) as well as transactional emails such as order/shipping confirmations, invoice dispatch, and payment reminders. Additionally, we utilise web push/in-browser messages and analyse interactions (e.g. page views, clicks, conversions) for real-time campaign management. Technically, cookies, web SDKs, and local storage may be used for these purposes.

Recipient

The recipient of your personal data is Braze, Inc., 330 W 34th St, 18th Floor, New York, NY 10001, USA.

Legal Basis

The legal basis for sending promotional emails and newsletters is your consent pursuant to Art. 6(1)(a) GDPR , which is obtained via a double opt-in process. For the processing of transactional emails and the provision of the service, the legal basis is Art. 6(1)(b) GDPR (performance of a contract) as well as our legitimate interest pursuant to Art. 6(1)(f) GDPR in security, troubleshooting, and efficient customer communication.

Purposes of Data Processing and Collected Data

Processing is carried out for the purpose of providing services, marketing, analysis, fraud protection, and compliance with legal obligations. The following categories of data are collected: first and last name, E-Mail address, address, telephone number, IP address, device and operating system information, location information, usage data (e.g. pages viewed, search history), and the date and time of interactions.

Transfer to Third Countries

Personal data is transferred to the USA. Braze, Inc. is certified under the Swiss-U.S. Data Privacy Framework (or the EU-U.S. DPF respectively). This certification confirms that Braze ensures an adequate level of data protection that complies with European standards. The transfer is also subject to appropriate safeguards pursuant to Art. 46 GDPR .

Duration of Data Storage

Data is deleted as soon as it is no longer required to achieve the purpose for which it was collected. Deletion takes place as soon as the processing purposes cease to apply and no legal retention obligations prevent deletion.

Right to Object and Withdraw Consent

You have the right to withdraw any consent given at any time with effect for the future. Furthermore, pursuant to Art. 21(1) GDPR , you have the right to object to processing based on legitimate interests. In the event of a withdrawal of consent or a justified objection, your data will no longer be processed for these purposes.

Contractual and Legal Obligation

There is no contractual or legal obligation to provide the data. However, without the provision of certain data (such as your E-Mail address), the corresponding services (e.g. newsletters or shipping confirmations) cannot be provided.

Further Data Protection Information

Further information on the processing of your personal data and the provider's cookie policy can be found at:

https://www.braze.com/company/legal/privacy

https://www.braze.com/company/legal/cookies/

Data recipient

If this is permitted or required by law or if you have given your consent, we will also share your personal data with other recipients who provide services for us. We limit the disclosure of your personal data to what is necessary. In some cases, our service providers receive your personal data as processors and are then strictly bound by our instructions when handling your personal data (data processing agreement pursuant to Art. 28 GDPR). In some cases, the recipients act independently with your data that we transfer to them. The following categories of service providers/recipients may receive your data:

  • Service provider in the field of applications to support the selection of applicants
  • Service provider for development work, including programming, development, maintenance and support of software applications
  • Service provider for postal services
  • External legal advice
  • Marketing agencies/ website support
  • Other IT service providers (e.g. system houses)
  • Other services and tools

The service providers commissioned by us must meet strict confidentiality requirements. They are only given the necessary access to your data in order to fulfill the assigned tasks.

In the event of suspicion of a criminal offense, data may be passed on to law enforcement authorities.

Security

We have taken extensive technical and operational precautions to protect your data from accidental or intentional manipulation, loss, destruction or access by unauthorized persons. Our security procedures are regularly reviewed and adapted to technological progress. In addition, we ensure data protection on an ongoing basis by constantly auditing and optimizing our data protection organization.

Conclusion

Ifolor Oy reserves all rights to make changes and updates to this privacy policy.

Privacy Policy for Ifolor Oy, Vantaa (Finland)

Updated: 12.8.2026

Summary

We have created this privacy policy to show you that we process your photos and personal data in an appropriate manner. Each of our customers is considered a data subject as specified by the EU General Data Protection Regulation.

In order to use Ifolor services, you must agree to the terms and conditions contained in this privacy policy.

This document describes the types of personal data (data associated with a specific person or data that allows a specific person to be identified) that we collect about you both when visiting the Ifolor website and when placing an order with us as well as the ways with which we use and process this data. Additionally, this document describes how we use cookies.

We use personal data to:

  • Provide easy-to-use and secure services,
  • Improve our customer services and marketing and
  • Further develop our online storefront.

Data file controller and the controller’s contact details

The customer register that stores personal data is controlled by

Ifolor Oy (Business ID: 0871712-9)
Karhumäenkuja 2
FI-01530 Vantaa
Finland

Contact details for further information about data protection and personal data processing:

E-mail: dataprotectionofficer@ifolor.fi
Mail: Ifolor Oy Data protection officer
Karhumäenkuja 2
FI-01530 Vantaa
Finland

What personal data does Ifolor collect about me?

We collect and process only data that is absolutely necessary for maintaining our relationship with you and processing your orders in a professional manner.

Information you have provided personally or that can be used to identify you:

  • Your name and other similar identification data
  • Your contact details, such as your address, e-mail address and a telephone number used to manage the customer relationship.
  • Your payment details, such as your billing information.
    • We do not store your full credit card information.
  • By your consent, we may store your location data, which we use to estimate delivery times.
  • By your consent, we may store your birth date, which we use for targeted marketing e.g. birthday congratulations.
  • Account number (only when refund to account)

Data collected when you use our services and data derived from analytics:

  • Your purchase history, including the products you have ordered and the associated price data,
  • Delivery details, such as the delivery method you have selected and the delivery address you have provided
  • Access and browsing data associated with our online storefront and your terminal’s (device’s/browser’s) details, such as the IP address.

How will Ifolor use my personal data?

We use your personal data to:

  • process your orders and deliver the products you have ordered
  • customer care and maintenance
  • improve your customer experience
  • develop our operations and services
  • generate statistics
  • produce personalised content and marketing
  • prevent misconduct
  • provide better customer service.

We will process your personal data in a confidential manner. We will not disclose your data to third party processors. However, Ifolor reserves the right to disclose personal data to processors operating in Switzerland or in EU member states in cases where this is required in order to process your order. In such cases, we will ensure an adequate level of protection by following the instructions specified in the EU General Data Protection Regulation and by concluding GDPR-compliant agreements with our suppliers.

How does Ifolor store and protect my personal data?

The Ifolor data file where your personal data is stored is continuously protected with appropriate technical and organisational measures that prevent both data loss and the misuse of personal data. Your personal data is stored in a safe environment that is inaccessible to the public. We maintain a very high level of technical and organisational security across our data centres, processes and online storefront data systems. Our servers are protected against unauthorised access and denial of service attacks.

If we need to transmit your personal data, for example, when you log in or make a payment, we encrypt your personal data using Secure Socket Layer (SSL) technology. What this means in practice is that as long as your web browser supports SSL (https) technology, the communications between your computer and Ifolor’s server is protected by the most widely-adopted encryption method in the world.

Whenever possible, we observe good data protection practices (such as data consolidation and anonymisation) in personal data processing and incorporate them in our data processing planning. We have updated our data processing operations to meet the requirements of the EU General Data Protection Regulation, which came into effect on 25 May 2018.

Who is allowed to process my personal data?

Only Ifolor Oy’s internal staff will have access to our customer data. Furthermore, our staff is trained in the safe and ethical use of personal data.

We use a number of trusted contract partners to whom we may transmit personal data. These partners are contractually bound to the requirements specified in the EU General Data Protection Regulation and other applicable data protection laws.

Shipping Services (PostNord)

We disclose the personal data necessary for the delivery of orders to PostNord Finland Oy. The data disclosed includes the customer’s name, delivery address, phone number, email address, and delivery-related order information. PostNord processes personal data to carry out the delivery, enable shipment tracking, and communicate with customers regarding the delivery, such as sending delivery notifications.

The processing of personal data is based on the performance of a contract (Art. 6(1)(b) GDPR). PostNord acts as an independent data controller with respect to delivery services. For more information about PostNord’s processing of personal data, please see their privacy policy: https://www.postnord.fi/en/privacy-policy.

Payment process

Our electronic payment process (excluding paying by invoice) is handled by a certified payment service provider, Datatrans AG Zürich. Your payment details are transmitted directly to this company, which will store your personal data for a short period of time for processing your payment and any reimbursement you might require.

Online payment is provided by Paytrail Oyj (Business ID: 2552865-3), Innova 2, Lutakonaukio 7, FI-40100 Jyväskylä. Following information is collected to Paytrail registry during payment:

  • Payment method 
  • Date/time of payment 
  • IP address 
  • Bank account number

Paytrail’s privacy policy: https://www.paytrail.com/en/data-privacy-notice-paytrail-payment-service.

Newsletter

If you have subscribed to our newsletter, it will be sent via the technical service provider Selligent SA in Belgium (Selligent) or Braze Inc. in the USA (Braze), to whom we pass on the data you provided when registering for the newsletter. This transfer serves our legitimate interest in using an effective, secure and user-friendly newsletter system. Selligent/Braze uses this information to send and statistically evaluate the newsletters on our behalf using pseudonymised data. You can unsubscribe from the newsletter at any time in writing or directly in the newsletter.

We also use Selligent/Braze to send you other electronic messages/emails, e.g. for order confirmation. Accordingly, Selligent/Braze may receive your personal data within the scope of the order processing agreement we have with them. The data is stored there for the duration for which storage is otherwise lawful for the purposes set out in this privacy policy, i.e. in particular for contractual communication within the scope of existing contracts with you or for advertising communication.

The applicable Selligent Privacy Policy can be found at https://www.selligent.com/privacy-policy-europe/. More information about Braze can be found here: https://www.braze.com/company/legal/privacy

Privacy Notice for the Monthly Gift Voucher Draw

All subscribers to the ifolor newsletter are automatically entered into a monthly prize draw in which the prize is an ifolor gift voucher worth €50.

The organizer of the draw processes participants’ personal data (email address and any contact details required for prize delivery) for the purposes of conducting the draw, contacting the winner, and delivering the prize. Participation is based on an active newsletter subscription.

Personal data is processed in accordance with applicable data protection legislation and is not used for purposes other than newsletter communications and administration of the draw. The organizer does not disclose personal data to third parties without a lawful basis.

The winner will be contacted personally by email. If the winner cannot be reached within a reasonable period of time, the organizer reserves the right to draw a new winner.

Newsletter subscriptions can be cancelled at any time via the unsubscribe link included in each newsletter. Cancelling the subscription will remove eligibility for future prize draws.

The company responsible for managing personal data:

Ifolor Oy (Business ID: 0871712-9)
Karhumäenkuja 2
FI-01530 Vantaa
Finland

How long will Ifolor store my personal data?

We will store your personal data and image files only as long as necessary to fulfil the purposes indicated in this privacy policy. However, we may store some of your data for a longer period of time to fulfil certain statutory obligations (such as those concerning accounting and consumer transactions) and to demonstrate that we have appropriately fulfilled our obligations.

You may request us to anonymise your personal data or remove the data from our system or prohibit us from using the data for the purposes specified in this privacy policy.

We are required by law to retain certain types of data for a longer period of time. Some examples are provided below: 

  • The Accounting Act (Finlex 1336/1997) specifies an extensive retention period for accounting materials regardless of whether they include personal data.
  • In order to provide a legitimate and secure online storefront for our clients, we collect and store system log data in accordance with statutory requirements.
  • We make sufficient backups of our online storefront’s databases and systems to prevent data loss, to support failure recovery and to ensure data security and service continuity.

Images and related data of customer orders are automatically deleted no later than 30 days after the delivery of the order, unless a different procedure has been specifically agreed between the parties.

What are my rights?

As a customer, you have the right to:

  • Receive the details of the personal data we store about you (by written request)
  • Request us to rectify any inaccurate personal data concerning you
  • Notify us, in writing, that you wish to prohibit us from continuing to process your personal data, with the reservation that we will retain the right to process personal data to the extent necessary (for invoicing purposes, for instance).

If your personal data is processed solely based on your consent, you will have the right to withdraw your consent at any time. Please note, that this will not have any bearing in the legality of any processing that has taken place before withdrawing your consent.

If you wish to make a request concerning the exercise of your rights, please contact our customer services. Ifolor reserves the right to ask you to identify yourself appropriately before processing any requests concerning the rights specified above.

If you notice any deficiencies in the processing of your personal data or find it to be unlawful, you will have the right to file a complaint with the Data Protection Ombudsman.

How do I find out what personal data Ifolor holds about me?

To request us to provide you with the personal data stored in our systems, please contact us via e-mail, address: dataprotectionofficer@ifolor.fi. We will process your request within 30 days of receiving the request.

How do I change how my information is used?

Ifolor Oy is committed to providing its customers with opportunities to determine to what extent their data is collected and used.

You can personally determine what kind of personalised marketing we will send you or to completely opt out of marketing communications from us. If you do not wish to receive any marketing communications from us, please contact our customer services. To unsubscribe from our newsletter, simply click on the link provided in any of our newsletter e-mails.

Will my personal data be disclosed to third parties?

We use customer data with third parties for analytical purposes and research as well as for providing personalised content. We may disclose purchase behaviour and browsing data to our partners in order to keep you up to date with products and promotions relevant to you. Whenever possible, the information used for research, analysis and creating personalised content will be anonymised or pseudonymised. Only we can associate your pseudonymised data with your name.

You can limit the scope of personal data disclosed for marketing purposes by contacting our customer services.

If necessary, we will also fulfil requests for personal data by public authorities. Law permitting, we will notify you of any such request.

Further functions of the website

Google APIs (in particular Google Photos)

On our websites and in our applications, you can use Google APIs, in particular Google Photos, to select images and import them into your ifolor project. If you use this function, you will be redirected to Google or connected to Google. The connection is only established after you have actively started the function and granted the relevant authorization to Google.

As part of this integration, we process the personal data and content that you make available to us via Google or release for import. This may include, in particular, selected photos and videos, technical information relating to the selected files (e.g. file format, resolution or creation date), basic information related to your Google account (e.g. e-mail address or profile name, where required for allocation), and technical log and authentication data. We process this data to provide the import and use function requested by you, to assign the selected content to your project, to technically perform the import, and to prevent abuse or disruptions.

The legal basis for the processing is Art. 6(1)(b) GDPR to the extent that the processing is necessary to provide the function requested by you. To the extent that individual processing steps are based on your consent, the legal basis is Art. 6(1)(a) GDPR. To the extent that we process technical log and security data to prevent abuse or ensure system security, the legal basis is Art. 6(1)(f) GDPR.

Use of this function is voluntary. We do not receive your Google password. Depending on the Google API used and the permissions you grant, data may also be processed by Google or within the Google group of companies. Processing in third countries, in particular in the United States, cannot be ruled out. Please note that Google’s privacy policy and terms of use also apply to Google’s processing of your data.

To the extent that imported content is stored in your ifolor project, we process it in accordance with the general provisions of this privacy policy regarding projects, orders and image files. You can manage or revoke any authorization granted to Google at any time in your Google account. Please note that revoking the Google connection stops future transfers, but does not automatically delete data already transferred to ifolor. The deletion of such data is governed by the general deletion rules in this privacy policy.

Google Ads – Enhanced Conversions / Google Enhanced Conversions

We use the “Enhanced Conversions” / “Google Enhanced Conversions” feature on our website in connection with Google Ads. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Depending on the technical and contractual setup, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and other companies of the Google group may also be involved in the processing.

Enhanced Conversions help us measure the effectiveness of our Google Ads more accurately and optimise our advertising campaigns. The feature supplements the existing Google Ads conversion tracking. It enables us to better understand whether our Google ads lead to specific actions on our website, such as orders, registrations, contact requests or other conversions defined by us.

If a user clicks on one of our Google ads and then completes a conversion on our website, for example by placing an order or submitting a form, data provided by the user may be used for conversion measurement. This may include, in particular, email address, name, postal address and/or telephone number. In addition, technical data may be processed, such as IP address, cookie or client identifiers, device and browser information, referrer URL and information relating to the respective conversion, such as conversion event, time of the event, transaction ID, order value or currency.

Directly identifying contact data is hashed before being transmitted to Google using a secure one-way hashing method, in particular SHA-256. The data is transmitted to Google in hashed form. Google may compare this hashed data with data from signed-in Google Accounts in order to attribute conversions to Google advertising interactions and improve conversion measurement.

Because attribution by Google may be possible in certain cases, we also treat hashed data as personal data. We do not receive information from Google that enables us to personally identify individual Google users, but only reports and aggregated information for measuring and optimising our advertising.

The legal basis for the processing of personal data is consent pursuant to Art. 6(1)(a) GDPR. To the extent that the processing involves storing cookies, pixels, tags or similar technologies on the user’s device or accessing information on the device, we obtain consent in accordance with the applicable rules on electronic communications.

The user may withdraw consent at any time with effect for the future via the cookie or privacy settings. The withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.

Recipients of personal data may include Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, Google LLC, 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA, and other companies of the Google group. Service providers engaged by Google may also process personal data on behalf of or under the responsibility of Google.

Personal data may be processed within the European Union, the European Economic Area and other countries, in particular the United States. For transfers of personal data to the United States, the EU-U.S. Data Privacy Framework may apply, provided that the recipient is certified under this framework. Google LLC states that it complies with the principles of the EU-U.S. Data Privacy Framework.

Where personal data is transferred to a country for which no adequate level of data protection has been established, Google states that it relies on appropriate safeguards, in particular the European Commission’s standard contractual clauses, or other transfer mechanisms permitted under applicable data protection law.

We do not store any additional personal data in plain text solely because of Google Enhanced Conversions beyond the data that we already process as part of customer, order, payment or contact processes. The transmission to Google takes place in hashed form.

Personal data is processed only for as long as necessary for the stated purposes or as required by statutory retention obligations. Thereafter, the data is deleted, anonymised or restricted, unless deletion is not possible or not permitted. Google’s retention is governed by the applicable Google terms and settings.

There is no statutory or contractual obligation to consent to the use of Google Enhanced Conversions. Without consent, the transmission of hashed first-party data to Google described here will not take place. The website and online shop can generally still be used; however, the measurement and optimisation of our Google Ads campaigns may be less precise.

Further information on how Google processes personal data can be found in Google’s privacy policy and terms of use, as well as in Google’s information on Enhanced Conversions.

Google Customer Match

We use Google Customer Match through Google Ads and Google Marketing Platform, in particular Display & Video 360, a service provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Dublin, D04 E5W5, Ireland (“Google”). Customer Match enables us, through Google Ads and Display & Video 360, to reach existing customers and relevant audiences with interest- and audience-based advertising, or to exclude certain customer groups from individual advertising campaigns, on supported Google services and advertising inventory, in particular Google Search, Google Shopping, YouTube, Gmail and the Google Display Network.

If you have consented to the use of Google Customer Match or to personalised advertising, we may use customer data that you have provided to us or that has arisen in connection with your use of our services for matching with Google accounts. This includes, in particular, email address, telephone number, first and last name, address, country, postal code, customer number or other identifiers assigned by us, as well as information about orders and broad interests. Direct identifiers are normalised in accordance with Google’s specifications and converted into a string using the SHA-256 hashing method before being transferred to Google. Where we use country and postal code for matching, these may be transferred unhashed in accordance with Google’s specifications. Hashing does not mean that the data is anonymous, because Google can compare the hash values with data from Google accounts.

Google compares the hash values transmitted by us with the corresponding hash values of Google accounts. If there is a match, the relevant Google account may be added to a Customer Match audience. We may then use these audiences to personalise advertising, re-engage existing customers, reach similar or relevant audiences, exclude certain customer groups from campaigns, measure and optimise conversions, and perform audience analysis and market research.

In connection with the delivery, measurement and optimisation of advertising, Google and we may also process cookies, online identifiers and information about ad impressions, clicks, browsing and search behaviour, search terms, interests and usage information, provided that consent has been given for this or the processing is otherwise permitted.

For the personalisation of our advertising, we may assign customers to segments. We generally use only simple, non-sensitive criteria for this purpose, in particular language and region, e.g. country, region, postal code area or language; purchase phase based on order date, e.g. new customers, active customers or inactive customers; order value or customer value in ranges, e.g. low, medium or high basket value; order frequency, e.g. one-time purchasers, repeat purchasers or regular customers; and broad product or category interests, e.g. interest in certain product groups or accessories, provided that these categories do not reveal special categories of personal data or other sensitive personal data.

We do not use special categories of personal data or other sensitive personal data for this purpose, in particular no data concerning health, political opinions, religious or philosophical beliefs, sex life or sexual orientation, ethnic origin, genetic or biometric data, trade union membership, criminal convictions or offences, social welfare or similarly sensitive information. We do not carry out any credit checks, do not apply individual price increases, and do not make automated individual decisions that have legal effects concerning you or similarly significantly affect you.

Recipients of the data are Google Ireland Limited and, where applicable, other companies of the Google group, in particular Google LLC and Alphabet Inc., as well as subprocessors engaged by Google. Processing primarily takes place in the European Union. Transfers to countries outside the European Union or the European Economic Area, in particular to the USA, Singapore, Chile or Taiwan, cannot be excluded. According to Google, such transfers are based on appropriate safeguards, in particular adequacy decisions, certifications under the Data Privacy Framework, standard contractual clauses or comparable protection mechanisms.

According to Google, uploaded Customer Match files are processed to match customers to Google accounts and to check compliance with Google policies. Once the matching and compliance checks have been completed, Google states that the uploaded files are deleted. Customer Match list memberships may remain valid at Google for up to 540 days. We store and use Customer Match audiences only for as long as necessary for the purposes described above or until you withdraw your consent.

The use of Google Customer Match is based on your consent pursuant to Art. 6(1)(a) GDPR. Where information is stored on or accessed from your terminal device in connection with Google Customer Match, this is additionally based on your consent pursuant to Section 205 of the Finnish Act on Electronic Communications Services (917/2014).

You may withdraw your consent at any time with effect for the future via the cookie or privacy settings on our website. After withdrawal, we will take this into account in our consent management system and will no longer include your data in new Customer Match uploads. During the current technical transition phase, we generally update Customer Match lists manually every 30 days. Data records that have already been uploaded will therefore be removed from the relevant Customer Match lists, or will no longer be used for Google Customer Match, with the next regular list update or deletion upload, but no later than within 30 days after your withdrawal. Until this technical deletion has been implemented, it cannot be completely ruled out that you may still see advertising based on an existing Customer Match list membership.

Independently of this, you can also manage personalised advertising in Google’s ad settings. Further information on data processing by Google is available in Google’s Business Data Responsibility information, Google’s Cookie Policy and via Google’s privacy contact form:

https://business.safety.google/privacy/?hl=en-US
https://policies.google.com/technologies/cookies?hl=en-US
https://support.google.com/policies/troubleshooter/7575787?hl=en

Meta Customer List Custom Audiences (“Customer Match”) and Lookalike Audiences

Description and purpose

We use Meta’s “Customer List Custom Audiences” and “Lookalike Audiences” advertising features. Customer List Custom Audiences allow us to target people who have consented to this use of their personal data with advertising on Facebook and Instagram or to exclude them from certain advertising campaigns. This enables us to make our advertising more relevant and to avoid unnecessary advertising contacts.

To create a Custom Audience, we transfer selected contact and identification data, in particular your email address and/or telephone number, to Meta only where you have given the relevant consent in advance. Before the matching process, the data is converted into values that are not directly readable using a cryptographic hashing process.

Hashing does not anonymise the data; it only pseudonymises it. The hash values remain personal data because Meta can compare them with hashed identifiers associated with Meta accounts. Where a match is found, the relevant Meta account may be included in or excluded from the audience defined by us. Assigning an account to an audience also involves processing the information that the person concerned belongs to the relevant audience segment defined by us.

We may also use a Custom Audience as the source audience for a Lookalike Audience. Meta then automatically identifies additional people who, based on the characteristics and signals available to Meta, display similarities to the source audience. These people may subsequently be shown our advertising.

The creation and use of these audiences may involve automated analysis and profiling for advertising-selection purposes. However, it does not result in any decision by us based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.

Legal basis

The processing is carried out exclusively on the basis of your consent pursuant to Article 6(1)(a) GDPR. The requirements of Article 7 GDPR also apply to the granting and withdrawal of consent.

Your consent covers the selection and transfer of the relevant data, its matching with Meta accounts, inclusion in or exclusion from a Custom Audience and, where we use this function, the use of the Custom Audience as the source audience for a Lookalike Audience.

Recipients

Recipients of your personal data may include Meta Platforms Ireland Limited, Meta Platforms, Inc., other companies affiliated with Meta and service providers used by Meta insofar as they provide Facebook, Instagram or the advertising, matching and audience functions used for this purpose.

Transfers of personal data to third countries

Meta may process personal data outside the European Union and the European Economic Area, in particular in the United States. A transfer of personal data to the United States therefore cannot be ruled out.

Where a transfer to Meta Platforms, Inc. is covered by a valid certification under the EU-U.S. Data Privacy Framework, we rely on the corresponding adequacy decision of the European Commission pursuant to Article 45 GDPR.

Where a transfer is not covered by an adequacy decision, it will take place only in compliance with the requirements of Articles 44 et seq. GDPR. This may include, in particular, standard contractual clauses adopted by the European Commission pursuant to Article 46(2)(c) GDPR and, where necessary, supplementary technical, contractual or organisational safeguards.

Retention period

We retain and update the selection and transfer lists compiled for matching purposes and the related audience assignments only for as long as they are required for the purposes described above or until you withdraw your consent.

Following a withdrawal, we will exclude your identifiers from future transfers and update or delete the relevant customer list or Custom Audience so that your identifiers are no longer used for this purpose.

This does not affect the continued retention of the same contact data for other purposes described in this Privacy Policy, in particular for the performance of a contract or compliance with statutory retention obligations. Any additional retention and deletion by Meta is governed by Meta’s Customer List Custom Audiences Terms and Privacy Policy.

Withdrawal of consent and voluntary provision

You may withdraw your consent at any time with effect for the future through the privacy or consent settings provided for this purpose. The withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

There is no legal or contractual requirement to provide your personal data for this purpose. Refusing or withdrawing your consent does not affect your use of our online shop or your ability to place orders with us.

Even after withdrawing your consent, you may still be shown advertising from ifolor where it is selected on the basis of other criteria and does not rely on the relevant customer list or audience assignment.

Further privacy information

Further information about Meta’s processing of your personal data is available in the Meta Privacy Policy and the Customer List Custom Audiences Terms.

The current certification status of Meta Platforms, Inc. under the EU-U.S. Data Privacy Framework can be viewed in the official Data Privacy Framework register. You can also manage your personalised advertising settings in your Meta account.

Does your online storefront use cookies and what are they?

The Ifolor website is designed to be as user-friendly and streamlined as possible. To achieve this, we use cookies and Flash Local Shared Objects (LSOs) on our website. You can personally determine whether you will allow our software to place cookies on your computer. By changing the settings on your web browser, you can disable cookies completely, allow only certain websites to place cookies or set the browser to prompt you to accept or reject cookies. Please note, that blocking cookies from the Ifolor website may limit or prevent access to some of the website’s functions or services. For your own convenience, we would advise you to enable cookies in your web browser. The cookies placed by our server on your browser will persist for up to 30 days.

Google Tag Manager

This website uses Google Tag Manager.The Tool Tag Manager itself (which implements the tags) is a domain without cookies which does not collect any personal details.The tool ensures the activation of other tags which themselves potentially collect data.

Google Tag Manager does not access these data.If a deactivation is carried out at domain or cookie level, this shall remain in effect for all tracking tags that are implemented with Google Tag Manager.

In the following the required legal basis for the processing of data is listed:
- Art. 6 para. 1 s. 1 lit. a GDPR

Adjust (including data sharing with Google Ads)

We use Adjust in connection with our mobile applications. Adjust is a mobile measurement and fraud prevention service. The service helps us analyze how our apps are used and how effective our marketing activities are, optimize campaigns, detect fraud, and segment user groups. If the relevant integration and data sharing are enabled, Adjust may also transfer data to Google Ads so that app installs, sessions, and post-install events can be attributed to campaigns, measured, analyzed, and used for reporting and campaign optimization.

The legal basis for the processing of personal data is your consent pursuant to Art. 6(1)(a) GDPR. You may withdraw your consent at any time with future effect by using the privacy or consent settings made available to you.

Adjust is used for analytics, marketing, optimization, fraud prevention, and segmentation.

The service uses web beacons, cookies, mobile SDK, and API.

In particular, the following data may be processed in connection with the use of the service: viewed advertisements, app downloads, application data, IP address, identifiers, user agent, interaction data, device information, and referrer URL.

The service provider is Adjust GmbH, Saarbrücker Str. 37A, 10405 Berlin, Germany. For data protection-related inquiries, the service provider can be contacted by email at privacy@adjust.com. Data recipients are Adjust GmbH, Adjust Inc., and Acquired IO LLC. If the relevant data sharing with Google Ads is enabled, data may also be transferred to Google Ads for attribution, conversion measurement, reporting, and campaign optimization.

Data is processed primarily in the European Union. However, in connection with the use of this service, data may also be transferred to other countries. In particular, data may be transferred to the United States of America, Japan, China, Brazil, and Singapore. Please note that data may also be transferred to countries that may not provide a level of data protection equivalent to the GDPR. Further information on the safeguards in place can be found in the provider’s privacy policy or obtained directly from the provider.

Data is stored for a maximum of 25 months. The data is deleted as soon as it is no longer required for the purposes stated above.

Further information can be found in Adjust’s privacy policy: https://www.adjust.com/terms/privacy-policy/

Meta Pixel / Facebook Pixel

This website uses Facebook Pixel to analyse your use of our website. The service is provided by Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04 X2K5, Irland (‘Facebook’). It is used to track interactions of visitors with websites ("Events") after they have clicked on an ad placed on Facebook or other services provided by Meta ("Conversion").

Our legal basis for setting the cookie and the connected data processing is your consent (Article 6 (1) a) GDPR)

Here you can find the way to contact Data Protection Officer of the processing company: https://www.facebook.com/help/contact/1650115808681298

LinkedIn Insight Tag

The LinkedIn Insight Tag is a lightweight JavaScript tag that is added to our website to enable in-depth campaign reporting and to help us to optimize our LinkedIn campaigns.

The LinkedIn Insight Tag creates a unique LinkedIn browser cookie on a visitor's browser and enables the collection of the following metadata with the cookie:

  • IP address 
  • timestamp 
  • page events e.g. page views.

LinkedIn does not share personal data with Ifolor. It only provides reports about our website visitors and ad performance. These reports do not identify individual users at any point. LinkedIn users can control the use of their data for advertising purposes through their account settings. The data controller is LinkedIn Ireland Unlimited Company Company, Wilton Place, Dublin 2, Ireland.

Legal basis for this process is your consent, Article 6 (1) (a), Article 7 GDPR. You can object the measuring of your usage during your visit by clicking on the following link https://www.linkedin.com/psettings/guest-controls/retargeting-opt-out.

LinkedIn’s privacy policy: https://www.linkedin.com/legal/privacy-policy.

Pinterest-Tag

Our online offering uses the “Pinterest Tag” of Pinterest Inc., 808 Brannan St, San Francisco, CA 94103, USA. If a Pinterest user sees or clicks on an advert, other actions and target groups that have shown interest are compiled and tracked. Using them allows us to ensure that Pinterest adverts are only shown to Pinterest users who have already shown an interest in our offering and that they also match the potential interest of the user. This data helps us to measure the conversion of the respective campaign. It is used for statistical and market research purposes and helps to optimise campaigns.

If you log into your Pinterest account after visiting our website or if you visit our website while you are still logged in, your data may be stored and processed by Pinterest. Pinterest is able to connect this data to your Pinterest account and use it for advertising purposes.

To do this, information is collected, evaluated and transmitted by your browser each time you visit. It is collected via a Java script and cookies. The following information is collected anonymously and processed for statistical purposes:

  • Browser used 
  • Operating system used 
  • Time of visit 
  • Type and content of campaign 
  • Reaction to the respective campaign (e.g. transaction, newsletter registration) 
  • etc.

If you are directed by a Pin on Pinterest to our online offering, we store a cookie on your computer that interacts via JavaScript code with a “Tag” that has also been implemented by Pinterest. These cookies become invalid after 180 days and are not used for personal identification.

You can object to this particular data processing at any time at https://help.pinterest.com/en/article/personalization-and-data, either by turning off the settings for this under “Personalization” in your Pinterest account, or by selecting “Do Not Track” in your browser.

You can access Pinterest’s current Privacy Policy at https://policy.pinterest.com/en/privacy-policy.

In the following the required legal basis for the processing of data is listed:
- Art. 6 para. 1 s. 1 lit. a GDPR

Playable

We use a platform provided by Playable ApS (Denmark) for our digital campaigns, such as quizzes and raffles. Playable acts as a data processor and processes the data on our behalf in accordance with the GDPR.

We collect contact information (name, email) and game-specific responses from participants to target our marketing and improve customer understanding.

The collected data is stored securely in the EU/EEA. We do not share your data with third parties unless you have given your consent or we have integrated Playable directly into our marketing automation system (e.g. Braze). You can request the deletion of your data by contacting our data protection officer.

Playable’s privacy policy can be found here: https://playable.com/privacy-policy-for-playable-aps/.

TikTok

Our online offer uses “TikTok Pixel” from TikTok Technology Limited, 10 Earlsfort Terrace, Dublin, D02 T380, Ireland (“TikTok”). TikTok Pixel enables TikTok to determine website visitors as target groups to display ads. Accordingly, we use TikTok Pixel to display our TikTok ads only to TikTok users who have also shown an interest in our online offerings or who exhibit certain characteristics that we communicate to TikTok. TikTok Pixel also allows us to statistically analyse our TikTok ads. Data processing by TikTok is carried out within the framework of TikTok’s data use policy.

Each time you access our website, information transmitted by your browser is collected and evaluated for this purpose. The collection takes place via a JavaScript as well as cookies. The following information is collected anonymously and processed statistically:

  • browser used
  • operating system used
  • access time
  • type as well as content of the campaign
  • the reaction to the respective campaign (e.g. purchase, newsletter subscription)

Cookies are set to recognize returning visitors in pseudonymised form. These cookies lose their validity after 13 months and are not used for personal identification. If you do not agree to the storage and evaluation of usage measurement from your visit, you can object to this by clicking on the circular fingerprint icon in the bottom left corner of the page.

This will allow you to place a so-called opt-out cookie in your browser. This means that the service will not set cookies for usage measurement and no session data will be collected. Please note: If you delete your cookies, the opt-out cookie will also be deleted and you may have to activate it again.

TikTok also processes your personal data outside of Switzerland/EEA and has entered into standard contractual clauses to ensure an adequate level of data protection. TikTok’s current privacy policy can be found at https://www.tiktok.com/legal/privacy-policy.

Required legal basis for the processing of data is listed Art. 6 para. 1 s. 1 lit. a GDPR.

Trustpilot reviews

Description and purpose

We use Trustpilot to collect and publish customer reviews. If you leave a review, Trustpilot will process the personal data you provide in accordance with its privacy policy. Reviews and related user profiles are public on Trustpilot. If we send you a review invitation, we will share your email address with Trustpilot to send the invitation based on our legitimate interest.

Data collected

This list represents all (personal) data that is collected by or through the use of this service.

  • IP address 
  • Browser settings 
  • Name and email address (if the customer writes a review or creates an account) 
  • Review content, star rating, images and videos

Legal basis

The legal basis for the processing of your personal data is Art. 6 para. 1 lit. f) GDPR, collecting and publishing customer reviews or Art. 6 para. 1 lit. a) GDPR if if marketing-related invitations are sent.

Receiver

Trustpilot A/S, Pilestraede 58, 5th floor, DK-1112 Copenhagen K.

Transfer to third countries

Trustpilot A/S is located in Denmark, so the processing of personal data primarily takes place within the EU/EEA. Trustpilot may also use sub-processors outside the EU, in which case it will use appropriate data protection mechanisms (such as contractual safeguards).

Duration of data storage

Reviews remain on Trustpilot as long as the user keeps their profile active or deletes their review. The company only keeps the contact details in the customer register that are necessary to send review invitations. Other data is deleted as soon as it is no longer needed for the purpose for which it was collected. In addition, the data is deleted if the user exercises their right to erasure pursuant to Art. 17 para. 1 GDPR.

Revocation

Trustpilot offers users extensive control over their personal data. Users can view the data stored in their profile in Trustpilot’s settings (“My Settings”). The data can be edited, corrected or deleted (Art. 17 para. 1 lit. b) GDPR). Reviews can also be deleted or anonymized.

Further data protection information

Further information on the processing of your personal data can be found here: https://corporate.trustpilot.com/legal/for-reviewers/privacy-policy

Further information about cookies and browser settings can be found by clicking on the circular fingerprint icon in the bottom left corner of the page.

Who is allowed to process my personal data?

Only Ifolor Oy’s internal staff will have access to our customer data. Furthermore, our staff is trained in the safe and ethical use of personal data.

We use a number of trusted contract partners to whom we may transmit personal data. These partners are contractually bound to the requirements specified in the EU General Data Protection Regulation and other applicable data protection laws.

Does your online store or ordering software make use of analytics services?

Our goal is to provide as user-friendly and streamlined online experience as possible. To achieve this, we use online analytics services that allow us to keep track of the number of visitors to our website, their visit frequency and the devices and software they use to access the website. Ifolor does not use this software to collect personal data or unique IP addresses. Instead, this information is used anonymously and in summary form for statistical purposes and to further develop our website.

Google Analytics 4

Description and purpose

This website uses the service “Google Analytics 4”, which is offered by Google LLC, to analyze website usage by users. The service uses “cookies” - text files that are stored on your end device. First-party cookies are used for this purpose. With a first-party cookie, the user can only be recognized by the page from which the cookie originates, not across multiple domains. The information collected by the cookies is usually sent to a Google server in the USA and stored there. If necessary, Google Analytics on this website is extended by the code “gat._anonymizeIp();” in order to ensure anonymized collection of IP addresses (so-called IP masking). Please also note the following information on the use of Google Analytics: The IP address of users is shortened within the member states of the EU and the European Economic Area. This shortening eliminates the personal reference of your IP address. For EU citizens, the IP address is also only used to derive location data and then deleted again. You also have the option of activating or deactivating the collection of detailed location and device data for individual regions (tracking settings). As part of the order processing agreement that the website operators have concluded with Google LLC, the latter uses the information collected to compile an analysis of website usage and website activity and provides services associated with internet usage.

Recipients

The recipient of your personal data is Google LLC. (1600 Amphitheatre Parkway Mountain View, CA 94043, USA).

Disclosure abroad

The personal data is processed on a server in European Servers. It cannot currently be ruled out that personal data will be disclosed to the United States of America. An adequacy decision (EU-US Data Privacy Framework) has been in place for the USA since July 10, 2023. Google LLC is certified in accordance with the EU-US Data Privacy Framework. Ifolor AG has concluded standard contractual clauses with Google LLC for the disclosure of personal data to the USA.

Duration of data storage

The data will be deleted as soon as it is no longer required to achieve the purpose for which it was collected. In addition, the data will be deleted if you assert your right to deletion and no retention periods prevent deletion.

Further data protection information

Further information on the processing of your personal data can be found here:

https://support.google.com/analytics/answer/6004245?hl=en
https://policies.google.com/privacy?hl=en&gl=uk

Opt-out disclosure:

If you do not agree with the storage and analysis of the analysis data from your visit, you can object to this by editing your settings from cookie manager on this site. They can be found by clicking on the circular fingerprint icon in the bottom left corner of the page.

However, we would appreciate if you would agree to the use of analytics tools, as they will help us to regularly improve our website and services and to optimise them to your needs.

The legal basis is our legitimate interest, Art. 6(1) point f GDPR, to provide you with a smooth order process and to make our website more user-friendly and effective overall.

In addition to the above, Ifolor utilises the Adjust analysis service to track visits to our ordering software. This service helps us to improve our services and optimise them to customer needs. This tracking data is collected anonymously. If you do not wish to collect this kind of tracking data, many browsers include the option to block tracking.

Microsoft Clarity

We use "Microsoft Clarity", a service for analysing the use of our website. This service records interactions (e.g. clicks, scrolls, mouse movements), technical events (e.g. error and performance information) and information about the display of the page in order to create heat maps and session replays and to improve user-friendliness and our offerings (analysis and optimisation). Content in recordings can be masked/suppressed by Clarity or by our configuration. The data is collected using cookies and similar technologies. The legal basis (where applicable) is your consent in accordance with Art. 6(1)(a) GDPR, which you can revoke at any time via our consent tool.

Data collected

This list contains all (personal) data collected by or through the use of this service. 

  • IP address 
  • Date and time of visit 
  • Unique user ID 
  • Session ID 
  • User behaviour 
  • Interaction data 
  • Mouse movements 
  • Clicks 
  • Scrolling activity
Recipient

The recipient of the data is Microsoft (Microsoft Ireland Operations Limited One, Microsoft Place, South County Business Park, Leopardstown, Dublin 18 D18 P521, Ireland and, depending on the constellation, affiliated companies such as Microsoft Corporation). Clarity is operated by Microsoft as a (joint) controller; further details can be found in the Microsoft notices. 

Below you will find the E-Mail address of the data protection officer of the processing company. https://www.microsoft.com/en-GB/concern/privacy

Disclosure abroad / transfer to third countries

Clarity data is processed in the Microsoft Azure cloud. For customers in the EU, the contractual relationship is with Microsoft Ireland Operations Limited (MIOL); standard contractual clauses (SCCs) exist between MIOL and Microsoft Corporation (USA) for intra-group transfers. A transfer to the USA cannot therefore be ruled out.

Duration of data storage

Clarity typically stores recording data for 30 days; heat map data and click/aggregation data are typically retained for up to 13 months (marked/favoured sessions also for up to 13 months).

Link to Google Analytics 4

If you have consented to the use of Google Analytics 4 and Microsoft Clarity, we can link the two services so that Clarity can retrieve data from Google Analytics 4 and display it in the Clarity interface. Clarity and Google Analytics data can be combined; processing is pseudonymised and carried out exclusively for analysis and optimisation purposes.

Further data protection information / opt-out

Further information on data processing by Microsoft can be found in the Microsoft Privacy Statement. You are also required to inform users that Clarity uses cookies; you can control consent via our consent tool (revocation possible at any time).

Can this privacy policy be revised?

We reserve the right to revise this privacy policy to account for service improvements or changes in applicable laws and regulations. We will notify you of any material changes to our privacy policy whenever we update their terms and conditions.

This privacy policy supersedes our previous Privacy Policy.

Who should I contact?

If you have any questions about this privacy policy, please contact us via e-mail, address: dataprotectionofficer@ifolor.fi

or mail, address:

Ifolor Oy
Data protection officer
Karhumäenkuja 2
FI-01530 Vantaa
Finland

*Volume discount on Digital photos (same size and finish): 1-49 pcs. from 0,28 €, 50-99 pcs. from 0,20 €, 100 pcs. or more -50 % from 0,14 €. Free delivery on digital photo orders with code KUVAT10 when the order value is min. 10 €. 

Cannot be combined with other offers. Ifolor reserves the right to change prices. Offers are valid until 7.10.2026.