PRIVACY POLICY

Crema is committed to protecting your privacy and being transparent about the information collected on our website. This privacy policy provides a summary of how we collect and process information when you visit our website and purchase our products.

1. Data Controller

Name: PPL Media Oy / Crema
Business ID: FI19724199
Address: Hankasuontie 11 B, 00390 Helsinki, Finland
Email: [email protected]
Phone number: 89 87 96 11
Website: www.cremashop.dk

2. Contact Person for Data Protection Matters

Name: Samuli Seppävuori
Email: [email protected]
Phone number: +358 10 322 4484

3. Collected Personal Data

We collect the following information about the customer: name, address, email address, phone number, payment method, IP address. For corporate customers, we also collect the business ID and company name. For orders, we collect order information, order number, purchase event, and delivery details. Information is collected from users during the order process. IP addresses and other similar technical information are collected automatically using cookies and other tracking technologies. Collected information can be updated by the user or through customer service. Registered users can update their information on the website through their user profile.

4. Purpose and Legal Basis of Processing Personal Data

Purpose of processing:
• Information is used for orders and customer service. When registering as a user, information is used to enable login to your personal page in the online store, to allow you to track your order history, and to save information for future purchases.
• With the help of cookies, marketing consent is collected, and information from customers who have given their consent is used for marketing via email and post, as well as for advertising on the internet.
• With the help of cookies, statistical and tracking consent is collected, and information from customers who have given their consent is used to improve the customer experience and develop the business (e.g., anonymized data).

Legal basis:
• Contract and legal obligation (orders and customer service)
• Consent (marketing)

5. Disclosure and Transfer of Data

Disclosed data and recipients:
• Our payment service provider is Adyen, and they handle all payment information in their system.
• For invoice payments, the customer's and order's information is transferred to the invoicing company (e.g., Klarna). For corporate invoicing, the customer's credit information is checked by a third party, e.g., Suomen Asiakastieto Oy. Overdue receivables are forwarded to a collection agency.
• Information is also disclosed to logistics companies for delivery.
• For deliveries outside the EU, order information is transferred to the destination country's customs / tax authorities.
• Information may be disclosed to authorities in legally mandated situations.
• In the case of possible direct deliveries from the wholesaler, the order information is disclosed to the product supplier.
• We use HelpScout software for customer service.
• We use Mailchimp software, Google, Meta, and Pinterest for marketing.

Transfer of data outside the EU/EEA:
• Mailchimp, Google, Meta, Pinterest, and HelpScout may transfer data outside the EU. We have ensured that these companies maintain an adequate level of data protection by using the European Commission's standard contractual clauses and ensuring that the companies comply with EU data protection laws, e.g., the EU-U.S. Data Privacy Framework.

Data is not disclosed to third parties without the user's consent, except in the aforementioned cases.

6. Data Retention Periods

Data is retained for 6 full calendar years after the customer's most recent order. Retention periods are based on legal obligations and business needs. Data retention periods are reviewed regularly, and data is deleted when it is no longer necessary to retain it.

7. Data Subject Rights

The data subject can exercise their rights under the GDPR legislation:

Right of access: The data subject has the right to access the data that has been stored about them.
Right to rectification: The data subject has the right to request the correction of incorrect data.
Right to erasure: The data subject has the right to request the erasure of their data in certain situations.
Right to restriction of processing: The data subject has the right to request the restriction of the processing of their data in certain situations.
Right to object: The data subject has the right to object to the processing of their data in certain situations.
Right to data portability: The data subject has the right to have their data transferred from one system to another.

If you wish to exercise these rights, please contact the data controller or the contact person for data protection matters via email (sections 1 and 2). To process the requests, we need identification information such as an email address and order number, as well as information about which right is being exercised. Additionally, the data subject must attach identification information (e.g., a copy of an ID) to their request to ensure information security. The data subject also has the right to lodge a complaint with the data protection authority if they believe that their personal data is being processed unlawfully.

8. Cookies and Tracking Technologies

We use cookies, and customers can manage them using our tool, which appears on the first visit. You can edit the cookie settings at the bottom of the page under “Cookie settings.”

Necessary cookies

Necessary cookies enable core functionality such as page navigation and access to secure areas. The website cannot function properly without these cookies, and can only be disabled by changing your browser preferences.

Cookie Domain Description
ppl_cid .cremashop.dk We maintain your shopping basket through this cookie. You will find the items still in your shopping basket when you next visit us.
PHPSESSID .cremashop.dk We maintain the state of your current visit through this cookie.
cf_clearance .cremashop.dk Used for security and bot-mitigation through Cloudflare.
__cflb .cremashop.dk Used for security and bot-mitigation through Cloudflare.
__cfruid .cremashop.dk Used for security and bot-mitigation through Cloudflare.
_cfuvid .cremashop.dk Used for security and bot-mitigation through Cloudflare.
cf_chl2 .cremashop.dk Used for security and bot-mitigation through Cloudflare.
CookieControl .cremashop.dk Used for cookie management.

Functional cookies

Functional cookies make it possible to save information that changes the way the website appears or acts. For instance your preferred language or region.

Cookie Domain Description
ppl_prefs .cremashop.dk We store your preferences, such as country and currency.
REMEMBERME .cremashop.dk You will stay logged into our shop as long as you do not log out yourself.

Analytics cookies

Analytical cookies help us to improve our website by collecting and reporting information on its usage. All our analytical cookies are used by Google Analytics.

Cookie Domain Description
_ga .cremashop.dk Used by Google Analytics.
_ga_XXX .cremashop.dk Used by Google Analytics.
_gid .cremashop.dk Used by Google Analytics.
cfz_google-analytics .cremashop.dk Used by Google Analytics.
cfzs_google-analytics .cremashop.dk Used by Google Analytics.

Marketing cookies

We use marketing cookies to help us improve the relevancy of advertising campaigns you receive.

Cookie Domain Description
_gcl_au .cremashop.dk Used for tracking the success of campaigns running on Google Ads.
cfz_facebook-pixel .cremashop.dk Used for tracking the success of campaigns running on Meta services, such as Facebook and Instagram.
_uetsid .cremashop.dk Used for tracking the success of campaigns running on Bing (Microsoft).
_uetvid .cremashop.dk Used for tracking the success of campaigns running on Bing (Microsoft).
MUID .bing.com Used for tracking the success of campaigns running on Bing (Microsoft).
IDE .doubleclick.net Used for tracking the success of campaigns running on Google Ads.

Privacy policies of third party services:

Google Ads / YouTube https://policies.google.com/technologies/ads
Meta (Facebook) Pixel https://www.facebook.com/privacy/policies/cookies/
Microsoft Advertising (UET) https://about.ads.microsoft.com/en-us/resources/policies/microsoft-advertising-privacy-policy

You can manage your cookie settings at any time by clicking the Cookie Control icon in the bottom left corner of the website. The user can also manage and delete cookies from their browser settings regardless of the settings chosen on the website.

9. Information Security

Information security measures:
• To protect personal data, we use appropriate technical and organizational measures, such as data encryption, access control, and regular security audits.

Information security measures are evaluated and updated regularly to address new threats and legal requirements. Staff is regularly trained in information security and data protection practices.

10. Changes to the Privacy Policy

Changes to the privacy policy:
• We will inform you of any changes to the privacy policy on our website. For significant changes, we will also notify our customers via email. Changes will be announced at least 30 days before they come into effect to give the user time to familiarize themselves with the changes.

11. User Responsibilities

The website user is responsible for keeping their contact information up to date. Information can be updated by contacting the data controller, contact information in section 1.

Basket
Your shopping basket is empty