Privacy policy
PRIVACY POLICY / GDPR
DATA CONTROLLER
Medanta Oy (Business ID: 2206754-8)
Hämeentie 155 C
00560 Helsinki, Finland
Customer Service Contact Information
Phone: +358 20 7280010 (Monday - Friday 9am–3pm)
Email: info@medanta.fi
CONTACT PERSON RESPONSIBLE FOR THE REGISTER
Anu Kivelä / Medanta Oy
Hämeentie 155 C, 00560 Helsinki
Email: anu.kivela@medanta.fi
REGISTER NAME
Customer register for Medanta Oy's online store
PURPOSE OF PROCESSING PERSONAL DATA
Medanta Oy is committed to protecting your privacy when you use our services. We handle personal data in accordance with applicable data protection legislation and good data processing practices.
The primary purpose of processing personal data is to maintain Medanta Oy's online store customer register. Personal data is processed to provide and develop our e-commerce services.
The register stores information about users' purchases and the use of Medanta Oy's services. Purchase and usage data is used for:
-
identifying customers based on customer numbers
-
delivering products and contacting customers if delivery times change
-
sales and marketing
-
responding to inquiries and sending customer notifications
-
managing customer relationships, analyzing and compiling service statistics
CONTENTS OF THE REGISTER
The register may contain the following data and updates to it:
Basic Information:
-
Name
-
Contact information (delivery and billing addresses, phone numbers, email addresses)
-
Gender
-
Language
-
Information on occupation or position in the organization
Customer Information:
-
Usernames and passwords for electronic services
-
Information on purchases made while logged in
-
Communications and actions related to the customer relationship, such as complaints and feedback
-
Recordings of customer service calls
-
Warranty-related information
-
Collection-related information
-
Marketing actions targeted at the customer and related data
-
Direct marketing consents and bans
-
Declared interests
-
Technical data sent by the user’s browser to the controller's server
REGULAR SOURCES OF INFORMATION
Personal data is primarily collected from the data subject themselves. Purchase and behavior data is collected from Medanta Oy's cash register and digital systems.
Information may also be collected and updated from other registers managed by Medanta Oy, from partners, and from public authorities and service providers.
DISCLOSURE AND TRANSFER OF DATA
Personal data is not disclosed for direct marketing purposes.
Medanta Oy may disclose customer data within the limits permitted or required by law. Data may be transferred to the controller's direct marketing registers, unless the data subject has opted out.
DATA SECURITY
Electronic personal data is protected using industry-standard security measures such as firewalls and passwords. Non-electronic data is stored in facilities with restricted access.
Only designated employees of the controller or authorized partner companies may access personal data, based on granted permissions.
We never sell, trade, or transfer your data to third parties for marketing purposes.
RIGHTS OF THE DATA SUBJECT
To exercise your rights, contact the data controller.
Right to Access
You have the right to confirm whether we process your personal data and to access the data we hold about you. You may request a copy of this data. If you request multiple copies, we may charge a reasonable fee.
Right to Rectification
You have the right to request that inaccurate or incomplete information be corrected or supplemented without undue delay.
Right to Erasure
You have the right to request that we delete your personal data without undue delay if:
-
the data is no longer needed for its original purpose
-
you withdraw consent and no other legal basis for processing exists
-
you object to processing based on personal reasons and no justified grounds override your objection
-
we have processed the data unlawfully
-
deletion is required to comply with legal obligations
Right to Restrict Processing
You may request that we restrict the processing of your personal data if:
-
you contest the accuracy of the data
-
processing is unlawful and you oppose deletion
-
we no longer need the data but you require it for legal claims
-
you have objected to processing and await verification of legitimate grounds
Right to Data Portability
You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller, if:
-
processing is based on consent or contract
-
processing is automated
This right must not adversely affect the rights of others.
Right to Object
You have the right to object to the processing of your data based on personal grounds, if no compelling legitimate grounds exist.
Right to Withdraw Consent
You have the right to withdraw your consent for processing personal data for direct marketing purposes.
RIGHT TO LODGE A COMPLAINT
You have the right to lodge a complaint with a supervisory authority if you believe your rights under the GDPR have been violated. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (www.tietosuoja.fi).













