menu

 

Privacy Policy

Fishheart Oy Ltd.

This is the Privacy Policy and Register Description of Fishheart Oy Ltd. in accordance with the Finnish Personal Data Act (Sections 10 and 24) and the EU General Data Protection Regulation (GDPR). Prepared on June 10, 2025. Updated on September 17, 2025.

 

1. Controller

Fishheart Oy Ltd.
Teollisuuskatu 6
95420 Tornio
Finland

 

2. Contact person for register matters

Minna Toivonen
Fishheart Oy Ltd.
Teollisuuskatu 6
95420 Tornio
Finland

+358 050 339 9087
firstname@fishheart.com

 

3. Name of register

Eco Egg Box (Ekomätirasia) Online Store Order Form

 

4. Legal basis and purpose for processing personal data

The legal basis for processing personal data in accordance with the EU General Data Protection Regulation is the data subject's consent.

The purpose of processing personal data is to:

In addition, we process data for the purpose of analyzing and improving our website. For this we use Google Analytics 4 (“GA4”), a web analytics service provided by Google. The processing of analytics data is based on the data subject’s consent (GDPR Art. 6(1)(a)), which is collected via the cookie banner on our website. The purpose of this processing is to understand how visitors use our website, improve the user experience, and develop our services.

 

5. Data content of the register

The following data is stored in the register:

In connection with GA4, the following technical and usage data may also be collected:

This information is not used to identify individual users but to generate aggregated statistics.

 

6. Regular sources of information

The data stored in the register is obtained from information sent by the customer to the register controller via the order form.

 

7. Regular disclosures of data and transfer of data outside the EU or EEA

Data is not regularly disclosed to other parties. Data may be published only to the extent agreed upon with the customer.

As a rule, personal data is not transferred outside the EU or EEA. However, in connection with the use of Google Analytics 4, certain technical data about website usage is transferred to Google LLC, which may process the data on servers located outside the EU/EEA, including the United States. Such transfers are based on the EU–US Data Privacy Framework or on Standard Contractual Clauses approved by the European Commission, which provide appropriate safeguards for the protection of personal data.

 

8. Principles of register protection

The processing of the register is carried out with due care, and the data processed by means of information systems is properly protected. When register data is stored on Internet servers, the physical and digital data security of their hardware is ensured appropriately. The controller ensures that stored data, as well as server access rights and other information critical to the security of personal data, are handled confidentially and only by those employees whose job description it includes.

 

9. Right of access and right to request correction

Every person in the register has the right to check their data stored in the register and to demand the correction of any inaccurate information or the completion of incomplete information. If a person wishes to check their stored data or demand a correction, the request must be sent to the controller by email. The controller may, if necessary, ask the requester to prove their identity. The controller will respond to the customer within the timeframe set by the EU Data Protection Regulation (generally within one month).

 

10. Other rights related to the processing of personal data

A person in the register has the right to request the deletion of their personal data from the register ("right to be forgotten"). Likewise, data subjects have other rights under the EU General Data Protection Regulation, such as the restriction of personal data processing in certain situations. Requests must be sent to the controller by email. The controller may, if necessary, ask the requester to prove their identity. The controller will respond to the customer within the timeframe set by the EU Data Protection Regulation (generally within one month).

Data subjects have the right to withdraw their consent to analytics cookies at any time, for example through the cookie settings available on our website.

 

X