1. Introduction
This Privacy Policy describes how Tlaxyroniochim collects, uses, processes, and protects your personal information when you visit our website at tlaxyroniochim.world or use our services. We are committed to protecting your privacy and ensuring transparency in our data processing practices in accordance with the General Data Protection Regulation (GDPR) and Finnish data protection legislation.
By using our website and services, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein.
2. Data Controller Information
The data controller responsible for processing your personal data is:
Company Name: Tlaxyroniochim
Registered Address: Mestarintie 3, 01730 Vantaa, Finland
Contact Phone: +358 10 426 3000
Contact Email: ask@tlaxyroniochim.world
Website: https://tlaxyroniochim.world
For any questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact us using the information provided above.
3. Personal Data We Collect
We collect and process various categories of personal data depending on how you interact with our website and services:
3.1 Information You Provide Directly
When you place an order, contact us, or interact with our website, you may provide us with the following information:
- Contact Information: Full name, email address, phone number, postal address
- Order Information: Product selections, quantities, delivery preferences, special requests or messages
- Payment Information: Billing address, payment method details (processed securely through third-party payment processors)
- Communication Data: Content of messages, inquiries, feedback, or correspondence you send to us
- Account Information: If you create an account, username, password (encrypted), and account preferences
3.2 Information Collected Automatically
When you visit our website, we automatically collect certain technical information:
- Device Information: IP address, browser type and version, operating system, device identifiers
- Usage Data: Pages visited, time spent on pages, links clicked, referring website, date and time of visits
- Location Data: Approximate geographic location based on IP address
- Cookies and Tracking Technologies: Information collected through cookies, web beacons, and similar technologies (see our Cookies Policy for details)
3.3 Information from Third Parties
We may receive information about you from third-party sources, including:
- Payment processors and financial institutions for transaction verification
- Delivery and logistics partners for shipment tracking
- Marketing and analytics service providers
- Social media platforms if you interact with our social media presence
4. Legal Basis for Processing
Under GDPR, we process your personal data based on the following legal grounds:
4.1 Contractual Necessity
Processing is necessary to fulfill our contract with you, including processing orders, delivering products, providing customer support, and managing your account.
4.2 Legitimate Interests
We process data based on our legitimate business interests, such as improving our services, preventing fraud, ensuring network and information security, and conducting business analytics. We always balance these interests against your rights and freedoms.
4.3 Legal Obligations
We process data to comply with legal obligations, including tax laws, accounting requirements, and regulatory compliance.
4.4 Consent
Where required by law, we process data based on your explicit consent, such as for marketing communications or certain cookies. You may withdraw consent at any time without affecting the lawfulness of processing based on consent before withdrawal.
5. How We Use Your Personal Data
We use your personal data for the following purposes:
5.1 Order Processing and Fulfillment
- Processing and confirming your orders
- Arranging product delivery and shipment tracking
- Processing payments and preventing fraudulent transactions
- Handling returns, refunds, and exchanges
- Communicating with you about your orders
5.2 Customer Service and Support
- Responding to your inquiries, questions, and requests
- Providing technical support and troubleshooting
- Resolving complaints and disputes
- Conducting customer satisfaction surveys
5.3 Marketing and Communications
- Sending promotional emails about new products, special offers, and updates (with your consent)
- Personalizing marketing content based on your preferences and behavior
- Conducting market research and analyzing customer trends
- Managing loyalty programs and promotional campaigns
5.4 Website Improvement and Analytics
- Analyzing website usage patterns and user behavior
- Improving website functionality, design, and user experience
- Testing new features and conducting A/B testing
- Generating statistical reports and business intelligence
5.5 Legal and Security Purposes
- Complying with legal obligations and regulatory requirements
- Preventing, detecting, and investigating fraud and security incidents
- Protecting our rights, property, and safety, and those of our customers
- Enforcing our terms and conditions and other agreements
- Responding to legal requests from authorities
6. Data Sharing and Disclosure
We may share your personal data with the following categories of recipients:
6.1 Service Providers
We engage trusted third-party service providers who process data on our behalf, including:
- Payment Processors: To securely process payments and prevent fraud
- Shipping and Logistics Partners: To deliver products to your address
- Cloud Hosting Providers: To store data and host our website infrastructure
- Email Service Providers: To send transactional and marketing emails
- Analytics Providers: To analyze website traffic and user behavior
- Customer Support Tools: To manage customer inquiries and support tickets
All service providers are contractually obligated to protect your data and use it only for specified purposes.
6.2 Business Transfers
In the event of a merger, acquisition, reorganization, sale of assets, or bankruptcy, your personal data may be transferred to the successor entity or acquiring party.
6.3 Legal Requirements
We may disclose your data when required by law, court order, or governmental authority, or when necessary to protect our legal rights, prevent fraud, or ensure safety.
6.4 With Your Consent
We may share your data with other parties when you have given explicit consent for such sharing.
We do not sell, rent, or trade your personal data to third parties for their marketing purposes.
7. International Data Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA) where our service providers are located. When we transfer data internationally, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission
- Adequacy decisions recognizing equivalent data protection standards
- Binding Corporate Rules for intra-group transfers
- Your explicit consent where required
We take all reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable data protection laws.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected and to comply with legal obligations:
- Order and Transaction Data: Retained for 7 years to comply with accounting and tax regulations
- Customer Account Data: Retained until you request account deletion or after 3 years of inactivity
- Marketing Data: Retained until you withdraw consent or unsubscribe, then deleted within 30 days
- Website Analytics Data: Typically retained for 26 months in aggregated form
- Customer Support Records: Retained for 3 years after the last interaction
- Legal and Compliance Data: Retained as required by applicable laws and regulations
After the retention period expires, we securely delete or anonymize your personal data. Anonymized data may be retained indefinitely for statistical and research purposes.
9. Data Security
We implement appropriate technical and organizational security measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:
- Encryption: Data transmitted over the internet is encrypted using SSL/TLS protocols (HTTPS)
- Access Controls: Strict access controls ensure only authorized personnel can access personal data
- Secure Storage: Data is stored on secure servers with regular security updates and patches
- Firewalls and Intrusion Detection: Network security measures to prevent unauthorized access
- Regular Security Audits: Periodic assessments to identify and address vulnerabilities
- Employee Training: Staff are trained on data protection principles and security practices
- Data Backup: Regular backups to prevent data loss
- Incident Response Plan: Procedures to respond to and mitigate data breaches
While we strive to protect your personal data, no method of transmission or storage is completely secure. We cannot guarantee absolute security but continuously work to enhance our security measures.
10. Your Rights Under GDPR
As a data subject under GDPR, you have the following rights regarding your personal data:
10.1 Right of Access
You have the right to request confirmation of whether we process your personal data and to obtain a copy of your data along with information about the processing.
10.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete personal data we hold about you.
10.3 Right to Erasure (Right to be Forgotten)
You have the right to request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected or when you withdraw consent.
10.4 Right to Restriction of Processing
You have the right to request that we restrict processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.
10.5 Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
10.6 Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we have compelling legitimate grounds.
10.7 Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
10.8 Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, workplace, or where an alleged infringement occurred. In Finland, the supervisory authority is:
Office of the Data Protection Ombudsman
Website: https://tietosuoja.fi/en/
Email: tietosuoja@om.fi
Address: P.O. Box 800, FI-00531 Helsinki, Finland
10.9 Exercising Your Rights
To exercise any of these rights, please contact us at ask@tlaxyroniochim.world or +358 10 426 3000. We will respond to your request within one month, though this period may be extended by two additional months for complex requests. We may request additional information to verify your identity before processing your request.
11. Children's Privacy
Our website and services are not intended for children under the age of 18. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately, and we will take steps to delete such information from our systems.
12. Automated Decision-Making and Profiling
We may use automated decision-making and profiling techniques to personalize your experience, such as recommending products based on your browsing history or tailoring marketing content. You have the right to object to automated decision-making that produces legal effects or similarly significantly affects you. If you wish to exercise this right, please contact us.
13. Third-Party Links
Our website may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices or content of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make material changes, we will notify you by updating the "Last Updated" date at the top of this policy and, where appropriate, by sending you an email notification or displaying a prominent notice on our website. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
Email: ask@tlaxyroniochim.world
Phone: +358 10 426 3000
Postal Address: Tlaxyroniochim, Mestarintie 3, 01730 Vantaa, Finland
We are committed to resolving any privacy concerns you may have and will respond to your inquiries as promptly as possible.