Updated 26.9.2025
1. Data Controller
Finnish Museum of Natural History
University of Helsinki, Business ID 0313471–7
Finnish Museum of Natural History
P.O. Box 17 (Pohjoinen Rautatiekatu 13)
00014 University of Helsinki
2. Contact regarding the register
For matters related to the register, you may contact Luomus Webshop:
luomus-shop@helsinki.fi (Responsible persons: Laura Sandholm, Janna Virtanen and Sari
Siipola)
The Data Protection Officer of the University of Helsinki can be reached at:
tietosuoja@helsinki.fi
3. Purpose and legal basis for the processing ofpersonal data
Processing of orders and invoicing, as well as customer relationship management. Use of
the Webshop does not require registration.
The processing of personal data is based on the agreement between the controller and the
customer, as well as statutory obligations (accounting and consumer protection).
4. Data content of the register
For the purpose of managing customer relationships and processing orders, the following
data are stored in the Webshop register: customer’s IP address, first and last name, email
address, postal address, and the language used when conducting transactions.
In addition, order details provided by the customer when placing an order are stored, such
as payment method, date and time of purchase, price of purchased services, as well as
the services ordered (e.g. tickets) and any related additional information (such as
participant details).
For accounting purposes, the necessary data are transferred from the Webshop to the
University of Helsinki’s virtual server, where they are stored for 7 years. The stored data
consist of the order receipt, pdf ticket, and accounting report.
5. Regular sources of data
The data are obtained from customers when they order services or other products and
when they make online payments.
6. Retention period of personal data
Data stored in the Webshop register are retained for two years for the management of
customer relationships, after which the data are anonymised.
If a customer registers and creates a user account in the Webshop, the account remains
valid for two years, after which it will be deactivated if it has not been used.
The retention period for personal data is based on the retention time required by the
Accounting Act for accounting materials and receipts. According to the Accounting Act,
receipts must be stored for at least six years after the end of the financial year. Accounting
material is stored on the University of Helsinki’s designated server for 7 years.
7. Regular disclosures of data and transfers
outside the EU or EEA
Data are not disclosed or transferred outside the EU/EEA.
The Finnish Museum of Natural History does not disclose data stored in the Luomus
Webshop to external parties.
8. Parties connected to the register
The data contained in the register are stored in the databases of the following companies,
with restricted access rights granted only to certain individuals:
CPU – Computer Program Unit Oy / Verifone Finland Oy / University Services of the
University of Helsinki
9. Your rights and exceptions to rights
The contact address for matters concerning the rights of the data subject is the contact
information provided in section 2 of this notice.
10. Right of access
You have the right to know whether your personal data are being processed and which of
your personal data are being processed. You may also request a copy of the personal data
being processed.
11. Right to rectification
If your personal data are inaccurate or incorrect, you have the right to request that they be
rectified or completed.
12. Right to erasure
You have the right to request that your personal data be erased if the personal data are no
longer necessary for the purposes for which they were collected, or if the personal data
have been processed unlawfully.
However, the right to erasure does not apply if the processing of personal data is
necessary for compliance with a statutory obligation.
13. Right to restriction of processing
You have the right to request the restriction of processing of your personal data. This
means that we will store your data but will not otherwise process them.
You have this right in the following cases:
a) you contest the accuracy of the personal data, in which case processing will be
restricted for the period during which the university can verify their accuracy
b) the processing is unlawful and you oppose the erasure of the personal data and request
restriction of their use instead
c) the university no longer needs the personal data for the purposes of processing, but you
need them for the establishment, exercise, or defence of legal claims
14. Right to lodge a complaint
If you have questions or concerns about the processing of your personal data, you may
always contact us. You also have the right to lodge a complaint with the Office of the Data
Protection Ombudsman if you consider that the processing of your personal data has
infringed applicable data protection legislation.
Contact details:
Office of the Data Protection Ombudsman
Tietosuoja.fi/en
Switchboard: +358 29 56 66700
Registry: +358 29 566 6768
Email: tietosuoja@om.fi

