[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"owner-doc:gdpr":3},"\u003Ch1>\u003Cstrong>GDPR\u003C\u002Fstrong>\u003C\u002Fh1>\n\u003Cp>Version 1.0 · 23 August 2026\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>What we store\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>We collect only what is needed to process and deliver your order — your e-mail address and delivery address (and name and phone number for the carrier) — plus the technical records the law and security require (order history for bookkeeping retention, login security events, and payment references held by the payment provider; we never see card numbers).\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>We do not store financial information\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>We do not store any financial information — no credit or debit card numbers, bank details or wallet credentials. That data is collected, stored and handled only by the payment processors we use. Today that is Stripe, which is PCI-DSS certified. PayPal, Paytrail, Klarna and MobilePay may be offered when enabled; each of those processors is PCI-DSS certified. The shop receives only a payment reference and a payment status.\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>Sign-in\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>You can create an account with e-mail and password, or use the standard Google and Facebook sign-in buttons. We request the smallest permission set those buttons need. From them we receive only your name and e-mail address, never your contacts, posts or friends. We also store the provider's user identifier so we can recognise you the next time you sign in. Scopes (quoted exactly): Google: openid email profile. Facebook: email,public_profile.\u003C\u002Fp>\n\u003Ch2 id=\"ai-assistant\">\u003Cstrong>Shopping assistant (AI)\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>The store offers an optional AI shopping assistant. It runs only if you open it and write something; every other part of the store works without it. What you write, and the answer you get back, is sent to Google, the provider of the Gemini model that generates the reply, for the sole purpose of answering your question. That call goes to the Gemini model on Google Cloud Vertex AI in the EU region europe-north1 — the same region the store itself runs in — so your text stays inside the EEA; see the section on international transfers.\u003C\u002Fp>\n\u003Cp>Assistant messages are used only to answer you. We do not use them for advertising, for profiling or for automated decision-making, and we never sell them. We use the model provider on a paid plan, whose terms do not allow your messages to be used to train its models. The assistant cannot take a payment or change an order; a person handles anything that does. Please do not write card numbers, passwords or health information into it — a dietary or allergy detail you mention is sent with your message.\u003C\u002Fp>\n\u003Cp>A conversation is kept with your chat session so the assistant can follow the thread, and is deleted automatically after 90 days at the latest. If you would rather your text was not processed this way, do not use the assistant: it is optional, and the catalogue, your account and checkout all work fully without it.\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>No marketing e-mail\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>We will never send you marketing e-mail unless you explicitly subscribe. The default is not to send any e-mail beyond the transactional messages your order requires (order confirmation, shipping, password reset and e-mail confirmation). Any subscription can be withdrawn at any time.\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>Controller and processor\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>The controller is the Seller named in the store footer (legal name, Finnish business ID \u002F Y-tunnus, and registered address). The Seller decides why and how your personal data is processed.\u003C\u002Fp>\n\u003Cp>The processor is Csitea Oy, the platform operator. Csitea hosts the store and processes personal data only on the Seller's instructions, under a data-processing agreement (GDPR Article 28).\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>Data we collect and why\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>Depending on how you use the store, we may process:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>E-mail address — to run your account, send order and delivery messages, and answer support requests.\u003C\u002Fli>\n\u003Cli>Delivery name, address and phone — so the carrier can deliver the goods.\u003C\u002Fli>\n\u003Cli>Billing address — for the invoice required by Finnish bookkeeping law.\u003C\u002Fli>\n\u003Cli>Order contents, amounts and status — to fulfil the contract and keep accounts.\u003C\u002Fli>\n\u003Cli>Payment references (never card numbers) — the payment provider holds the payment; we keep only their reference.\u003C\u002Fli>\n\u003Cli>Login security events (time, method, IP address, browser) — to protect accounts.\u003C\u002Fli>\n\u003Cli>Social-login identifiers if you choose to sign in with Google or Facebook.\u003C\u002Fli>\n\u003Cli>Feedback you send us, if you use that form.\u003C\u002Fli>\n\u003Cli>Your cookie choice, stored in your browser, not on our servers.\u003C\u002Fli>\n\u003Cli>Messages you write to the shopping assistant, and its replies, if you choose to use it.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>\u003Cstrong>Legal bases\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Contract (GDPR Article 6(1)(b)) — taking and delivering your order.\u003C\u002Fli>\n\u003Cli>Legal obligation (Article 6(1)(c)) — Finnish bookkeeping retention of orders and invoices.\u003C\u002Fli>\n\u003Cli>Legitimate interest (Article 6(1)(f)) — login security events and fraud prevention.\u003C\u002Fli>\n\u003Cli>Consent (Article 6(1)(a)) — non-essential cookies and any marketing e-mail you opt into.\u003C\u002Fli>\n\u003Cli>Legitimate interest (Article 6(1)(f)) — answering your questions in the optional shopping assistant, which you start yourself.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>\u003Cstrong>Who receives the data\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Payment processors enabled at checkout (Stripe today; others when enabled) — to take payment.\u003C\u002Fli>\n\u003Cli>The carrier — name, phone and delivery address only.\u003C\u002Fli>\n\u003Cli>The e-mail delivery provider — to send transactional mail.\u003C\u002Fli>\n\u003Cli>Google Cloud in the EU (europe-north1, Finland) — to host the application and database.\u003C\u002Fli>\n\u003Cli>Google, as the provider of the Gemini model behind the shopping assistant — the messages you send it; processed in the same EU region as the store (europe-north1, Finland).\u003C\u002Fli>\n\u003Cli>Csitea Oy as processor.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>We do not sell your data. We do not profile you for advertising, and nothing you write to the shopping assistant is used for advertising.\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>How long we keep it\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>Orders and invoices: at least six years, as required by Finnish bookkeeping law; some accounting records may be kept for ten years.\u003C\u002Fli>\n\u003Cli>Account data: until you ask us to delete the account, except records we must keep.\u003C\u002Fli>\n\u003Cli>Login security events: a short period needed for security investigation.\u003C\u002Fli>\n\u003Cli>Cookie choice: in your browser, typically up to 12 months.\u003C\u002Fli>\n\u003Cli>Shopping-assistant conversations: at most 90 days, then deleted automatically.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>\u003Cstrong>Your rights\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>You may request access, rectification, erasure, restriction, portability, and objection. You may withdraw consent for cookies or marketing at any time. Send the request using the contact e-mail on the contact page. We may need to verify your identity.\u003C\u002Fp>\n\u003Cp>You may lodge a complaint with the Finnish Data Protection Ombudsman (Tietosuojavaltuutettu): \u003Ca href=\"https:\u002F\u002Ftietosuoja.fi\" rel=\"noopener noreferrer\">tietosuoja.fi\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>International transfers\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>The store and database run in the EU\u002FEEA (Google Cloud europe-north1). The Gemini model behind the shopping assistant runs in that same EU region (Google Cloud Vertex AI, europe-north1), with Google as a sub-processor, so what you write to the assistant is not transferred outside the EEA. The payment provider does process data outside the EEA; that transfer relies on the European Commission's Standard Contractual Clauses and the provider's GDPR terms. We do not transfer your data outside the EEA for any other purpose.\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>Contact\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>Questions about this notice: use the contact e-mail published on the contact page. The Seller is the controller; Csitea Oy is the processor.\u003C\u002Fp>\n\u003Ch2>\u003Cstrong>Data Protection Officer (DPO) — Длъжностно лице по защита на данните\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>The platform operator names a Data Protection Officer (DPO). Send data-protection requests using the company facts on this page. Public Finnish business registry: \u003Ca href=\"https:\u002F\u002Fwww.finder.fi\u002FIT-konsultointi+IT-palvelut\u002FCsitea+Oy+Ab\u002FHelsinki\u002Fyhteystiedot\u002F3544432\" rel=\"noopener noreferrer\">finder.fi\u003C\u002Fa>\u003C\u002Fp>\n\u003Ch2 id=\"art30-register\">\u003Cstrong>Register of processing activities (GDPR Article 30)\u003C\u002Fstrong>\u003C\u002Fh2>\n\u003Cp>GDPR Article 30 requires the controller to keep a record of its processing activities. This is that record for the one activity this store carries out — running its customer register — and it is published here so you can read it without having to ask for it.\u003C\u002Fp>\n\u003Ch3>\u003Cstrong>1. Controller\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cp>The controller is the Seller, the merchant of record for your order. Its legal name, business identity code, company form, domicile and street and postal address (street, postal code and town) are listed in the Controller section further down this page. They are read from the store's configuration when the page is built, so the page always shows the identity currently on record instead of a copy that can quietly fall out of date.\u003C\u002Fp>\n\u003Cp>Contact for questions concerning this register: the Seller has not published a telephone number or a separate e-mail address for data-protection matters. Until it does, use the platform operator's data-protection contact — company name, contact person, street address, postal code and town, telephone number and e-mail address — given in the Processor and Data Protection Officer sections further down this page. Requests received there are passed on to the Seller.\u003C\u002Fp>\n\u003Cp>Data protection officer, where applicable: the store's records name no data protection officer for the Seller, and Article 30(1)(a) asks for that contact only where such a person has been designated. The platform operator does name a data-protection contact person; that person's name, address, postal code and town, telephone number and e-mail address are in the Data Protection Officer section further down this page.\u003C\u002Fp>\n\u003Ch3>\u003Cstrong>2. Data subjects\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cp>The register covers the following people:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Customers who order with an account — the account holder, and the person named as the recipient of the delivery where that is somebody else.\u003C\u002Fli>\n\u003Cli>Customers who order without an account, identified only by the e-mail address and the delivery details given at checkout.\u003C\u002Fli>\n\u003Cli>People who have created an account but not ordered, including anyone who signed in with a Google or Facebook account.\u003C\u002Fli>\n\u003Cli>People who write to us through the feedback form.\u003C\u002Fli>\n\u003Cli>People who use the optional AI shopping assistant.\u003C\u002Fli>\n\u003Cli>The shop's own back-office users, whose sign-ins and whose changes to orders, products and prices are recorded.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>3. Purpose of using the personal data\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cp>The register is kept on the following legal bases:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>The personal data is processed on the basis of the customer relationship — performance of the sales contract you enter into at checkout (GDPR Article 6(1)(b)). This covers the order, the delivery and the account you place it from.\u003C\u002Fli>\n\u003Cli>The personal data is processed to meet a legal obligation (Article 6(1)(c)) — the retention of orders and invoices required by Finnish bookkeeping law.\u003C\u002Fli>\n\u003Cli>The personal data is processed on the basis of legitimate interest (Article 6(1)(f)) — keeping accounts secure, preventing fraud and misuse, answering the messages you send us, and answering the questions you put to the shopping assistant.\u003C\u002Fli>\n\u003Cli>The personal data is processed on the basis of consent (Article 6(1)(a)) — non-essential cookies, the page-performance measurement they allow, and marketing e-mail. Each of these can be withdrawn at any time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>The purposes of the processing are:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Taking, charging, delivering and where necessary refunding your order, and keeping you informed about it.\u003C\u002Fli>\n\u003Cli>Maintaining the customer relationship — running your account, letting you sign in, and showing you your own order history.\u003C\u002Fli>\n\u003Cli>Answering the messages and questions you send us, through the feedback form or the shopping assistant.\u003C\u002Fli>\n\u003Cli>Keeping accounts and the shop secure — detecting and investigating unauthorised sign-ins, fraud and misuse.\u003C\u002Fli>\n\u003Cli>Keeping the accounts and issuing the invoices that Finnish bookkeeping law requires.\u003C\u002Fli>\n\u003Cli>Informing you about the shop's products, only if you have expressly subscribed. Nothing is sent by default and a subscription can be withdrawn at any time.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch3>\u003Cstrong>4. Personal data stored in the register\u003C\u002Fstrong>\u003C\u002Fh3>\n\u003Cp>The customer register contains the following data, as the application actually stores it:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Account: e-mail address; first and last name; telephone number; the password, kept only as an irreversible hash and never in readable form; your chosen shop language; your account role; the time the account was created; the time your e-mail address was confirmed; the time you last signed in; whether you have subscribed to marketing e-mail, and when and from where; and a profile picture, if you upload one.\u003C\u002Fli>\n\u003Cli>Order: the order number; the delivery address and the billing address exactly as given at checkout — recipient name, street, postal code, town, country and telephone number; the e-mail address given for an order placed without an account; the products, quantities and prices ordered; the amounts, tax and delivery cost; the currency; the language checkout was completed in; the order's status and the history of its status changes; the carrier, the tracking code and the tracking link; any refunds; and the invoice number with its issue and due dates.\u003C\u002Fli>\n\u003Cli>Payment: the name of the payment provider used; the payment reference it returns; the payment method type; and the two-letter country of the card issuer, which the payment provider reports and which decides the payment methods the shop may offer you. The shop stores no card numbers, bank details or wallet credentials — those stay with the payment provider.\u003C\u002Fli>\n\u003Cli>Social sign-in: if you sign in with Google or Facebook, the provider's name, the user identifier it gives us, and the e-mail address it returns.\u003C\u002Fli>\n\u003Cli>Security: sign-in events — time, e-mail address, sign-in method, IP address and browser identification; the single-use password-reset and e-mail-confirmation tokens, kept only as a hash; and, for back-office users, a record of the changes made to orders, products and prices, with the time, the person and the IP address.\u003C\u002Fli>\n\u003Cli>Feedback: the name, e-mail address, subject and message you send; the page you sent it from; your language and your browser identification; and the handling status and the shop's internal notes on your message.\u003C\u002Fli>\n\u003Cli>Shopping assistant: the chat session and its language, the messages you write and the replies you are given.\u003C\u002Fli>\n\u003Cli>Page-performance measurement: if you accept the analytics cookie category, the shop's own measurements of how quickly pages load — a page path, a metric and a value, with your browser identification — sent to the shop's own server and to no third party.\u003C\u002Fli>\n\u003Cli>Error diagnostics: if you accept the analytics cookie category, a note of technical failures your browser met on the shop's pages — the request method, the page address without its query part, the response code or the error name, the shop's own error code, and a reference number that identifies the record and not you — sent to the shop's own server and to no third party. The text of the error, the contents of requests and answers, and any passwords, tokens, e-mail addresses or card numbers are never collected.\u003C\u002Fli>\n\u003Cli>Cookie choice: kept in your own browser, not on the shop's servers.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>No other personal data is held in the register. The shop neither asks for nor stores an identity number, a date of birth, health data or any other special category of personal data. When you delete your account from the account page, the details above are erased or replaced with an anonymous marker, your social sign-in links and your unused tokens are deleted and your assistant conversations are redacted; the orders and invoices that bookkeeping law obliges the shop to keep remain; a feedback message you sent is emptied of your name, your address and its text, leaving only an anonymous record that the ticket existed; and a sign-in event keeps its time, method and network address as a security record, with your e-mail address replaced by the same anonymous marker as the account.\u003C\u002Fp>\n\u003Cp>This register covers the customer register. The shop also processes one telephone number for a purpose that has nothing to do with customers: the operator's own business number, already published on the contact and feedback pages, is set up to receive an automated message when the shop is down or unreachable, so that an outage is noticed within minutes instead of hours. Those messages are dispatched by Google Cloud Monitoring and delivered onward by a mobile carrier we cannot identify; each one carries only the service name, the condition and a timestamp, never customer or order data, and we keep no record of the messages sent. No customer's personal data is involved.\u003C\u002Fp>\n",1789102102286]