{"id":226,"date":"2025-01-10T13:36:04","date_gmt":"2025-01-10T11:36:04","guid":{"rendered":"https:\/\/epayment.helsinki.fi\/luomus\/?page_id=226"},"modified":"2025-09-29T12:36:32","modified_gmt":"2025-09-29T09:36:32","slug":"privacy-policy","status":"publish","type":"page","link":"https:\/\/epayment.helsinki.fi\/luomus\/privacy-policy\/?lang=en","title":{"rendered":"PRIVACY POLICY FOR THE CUSTOMER REGISTER OF THE WEBSHOP OF THE FINNISH MUSEUM OF NATURAL HISTORY \u2013LUOMUS (UNIVERSITY OF HELSINKI)"},"content":{"rendered":"\n<p class=\"MsoNormal\"><span lang=\"FI\">Updated 26.9.2025<\/span><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">1. Data Controller<\/h2>\n\n\n\n<p>Finnish Museum of Natural History<br>University of Helsinki, Business ID 0313471\u20137<br>Finnish Museum of Natural History<br>P.O. Box 17 (Pohjoinen Rautatiekatu 13)<br>00014 University of Helsinki<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">2. Contact regarding the register<\/h2>\n\n\n\n<p>For matters related to the register, you may contact Luomus Webshop:<br>luomus-shop@helsinki.fi (Responsible persons: Laura Sandholm, Janna Virtanen and Sari<br>Siipola)<br>The Data Protection Officer of the University of Helsinki can be reached at:<br>tietosuoja@helsinki.fi<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">3. Purpose and legal basis for the processing ofpersonal data<\/h2>\n\n\n\n<p>Processing of orders and invoicing, as well as customer relationship management. Use of<br>the Webshop does not require registration.<br>The processing of personal data is based on the agreement between the controller and the<br>customer, as well as statutory obligations (accounting and consumer protection).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">4. Data content of the register<\/h2>\n\n\n\n<p>For the purpose of managing customer relationships and processing orders, the following<br>data are stored in the Webshop register: customer\u2019s IP address, first and last name, email<br>address, postal address, and the language used when conducting transactions.<br>In addition, order details provided by the customer when placing an order are stored, such<br>as payment method, date and time of purchase, price of purchased services, as well as<br>the services ordered (e.g. tickets) and any related additional information (such as<br>participant details).<br>For accounting purposes, the necessary data are transferred from the Webshop to the<br>University of Helsinki\u2019s virtual server, where they are stored for 7 years. The stored data<br>consist of the order receipt, pdf ticket, and accounting report.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5. Regular sources of data<\/h2>\n\n\n\n<p>The data are obtained from customers when they order services or other products and<br>when they make online payments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">6. Retention period of personal data<\/h2>\n\n\n\n<p>Data stored in the Webshop register are retained for two years for the management of<br>customer relationships, after which the data are anonymised.<br>If a customer registers and creates a user account in the Webshop, the account remains<br>valid for two years, after which it will be deactivated if it has not been used.<br>The retention period for personal data is based on the retention time required by the<br>Accounting Act for accounting materials and receipts. According to the Accounting Act,<br>receipts must be stored for at least six years after the end of the financial year. Accounting<br>material is stored on the University of Helsinki\u2019s designated server for 7 years.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">7. Regular disclosures of data and transfers<br>outside the EU or EEA<\/h2>\n\n\n\n<p>Data are not disclosed or transferred outside the EU\/EEA.<br>The Finnish Museum of Natural History does not disclose data stored in the Luomus<br>Webshop to external parties.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">8. Parties connected to the register<\/h2>\n\n\n\n<p>The data contained in the register are stored in the databases of the following companies,<br>with restricted access rights granted only to certain individuals:<br>CPU \u2013 Computer Program Unit Oy \/ Verifone Finland Oy \/ University Services of the<br>University of Helsinki<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">9. Your rights and exceptions to rights<\/h2>\n\n\n\n<p>The contact address for matters concerning the rights of the data subject is the contact<br>information provided in section 2 of this notice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">10. Right of access<\/h2>\n\n\n\n<p>You have the right to know whether your personal data are being processed and which of<br>your personal data are being processed. You may also request a copy of the personal data<br>being processed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">11. Right to rectification<\/h2>\n\n\n\n<p>If your personal data are inaccurate or incorrect, you have the right to request that they be<br>rectified or completed.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">12. Right to erasure<\/h2>\n\n\n\n<p>You have the right to request that your personal data be erased if the personal data are no<br>longer necessary for the purposes for which they were collected, or if the personal data<br>have been processed unlawfully.<br>However, the right to erasure does not apply if the processing of personal data is<br>necessary for compliance with a statutory obligation.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">13. Right to restriction of processing<\/h2>\n\n\n\n<p>You have the right to request the restriction of processing of your personal data. This<br>means that we will store your data but will not otherwise process them.<br>You have this right in the following cases:<br>a) you contest the accuracy of the personal data, in which case processing will be<br>restricted for the period during which the university can verify their accuracy<br>b) the processing is unlawful and you oppose the erasure of the personal data and request<br>restriction of their use instead<br>c) the university no longer needs the personal data for the purposes of processing, but you<br>need them for the establishment, exercise, or defence of legal claims<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">14. Right to lodge a complaint<\/h2>\n\n\n\n<p>If you have questions or concerns about the processing of your personal data, you may<br>always contact us. You also have the right to lodge a complaint with the Office of the Data<br>Protection Ombudsman if you consider that the processing of your personal data has<br>infringed applicable data protection legislation.<br>Contact details:<br>Office of the Data Protection Ombudsman<br>Tietosuoja.fi\/en<br>Switchboard: +358 29 56 66700<br>Registry: +358 29 566 6768<br>Email: tietosuoja@om.fi<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Updated 26.9.2025 1. Data Controller Finnish Museum of Natural HistoryUniversity of Helsinki, Business ID 0313471\u20137Finnish Museum of Natural HistoryP.O. Box 17 (Pohjoinen Rautatiekatu 13)00014 University of Helsinki 2. Contact regarding the register For matters related to the register, you may contact Luomus Webshop:luomus-shop@helsinki.fi (Responsible persons: Laura Sandholm, Janna Virtanen and SariSiipola)The Data Protection Officer of [&hellip;]<\/p>\n","protected":false},"author":178,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"footnotes":""},"class_list":["post-226","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/pages\/226","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/users\/178"}],"replies":[{"embeddable":true,"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/comments?post=226"}],"version-history":[{"count":5,"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/pages\/226\/revisions"}],"predecessor-version":[{"id":998,"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/pages\/226\/revisions\/998"}],"wp:attachment":[{"href":"https:\/\/epayment.helsinki.fi\/luomus\/wp-json\/wp\/v2\/media?parent=226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}