Privacy policy
Under the General Data Protection Regulation, the controller is obliged to inform data subjects in a clear manner. This policy fulfils that duty to inform.
1. Controller
Legal name: SKY NV Oy
Business ID (Y-tunnus): 3593369-5
Visiting address: Topparoikka 3 C 35, 02400 Kirkkonummi
Email: kristina.vasileva8785@gmail.com
Contact details in matters concerning the register
Legal name: Csitea Oy Ab
Business ID (Y-tunnus): 3173350-6
Responsible contact person: Yordan Georgiev
Visiting address: Läksyrinne 27-29 I 3, 00760 Helsinki
Postal address: Läksyrinne 27 I 3, 00760 Helsinki
Phone: 044 530 1464
Email: yordan.georgiev@csitea.net
Where applicable, the contact details of the data protection officer:
Data protection officer
Legal name: Csitea Oy Ab
Business ID (Y-tunnus): 3173350-6
Responsible contact person: Yordan Georgiev
Visiting address: Läksyrinne 27-29 I 3, 00760 Helsinki
Postal address: Läksyrinne 27 I 3, 00760 Helsinki
Phone: 044 530 1464
Email: yordan.georgiev@csitea.net
2. Data subjects
The register covers the following people:
- Customers who order with an account — the account holder, and the person named as the recipient of the delivery where that is somebody else.
- Customers who order without an account, identified only by the e-mail address and the delivery details given at checkout.
- People who have created an account but not ordered, including anyone who signed in with a Google or Facebook account.
- People who write to us through the feedback form.
- People who use the optional AI shopping assistant.
- The shop's own back-office users, whose sign-ins and whose changes to orders, products and prices are recorded.
3. Purpose of processing personal data
The register is kept on the following legal bases:
- The personal data is processed on the basis of the customer relationship — performance of the sales contract you enter into at checkout (GDPR Article 6(1)(b)). This covers the order, the delivery and the account you place it from.
- The personal data is processed to meet a legal obligation (Article 6(1)(c)) — the retention of orders and invoices required by Finnish bookkeeping law.
- The personal data is processed on the basis of legitimate interest (Article 6(1)(f)) — keeping accounts secure, preventing fraud and misuse, answering the messages you send us, and answering the questions you put to the shopping assistant.
- The personal data is processed on the basis of consent (Article 6(1)(a)) — non-essential cookies, the page-performance measurement they allow, and marketing e-mail. Each of these can be withdrawn at any time.
Purpose of processing personal data and of the register
The purposes of the processing are:
- Taking, charging, delivering and where necessary refunding your order, and keeping you informed about it.
- Maintaining the customer relationship — running your account, letting you sign in, and showing you your own order history.
- Answering the messages and questions you send us, through the feedback form or the shopping assistant.
- Keeping accounts and the shop secure — detecting and investigating unauthorised sign-ins, fraud and misuse.
- Keeping the accounts and issuing the invoices that Finnish bookkeeping law requires.
- Informing you about the shop's products, only if you have expressly subscribed. Nothing is sent by default and a subscription can be withdrawn at any time.
4. Personal data stored in the register
The customer register contains the following data, as the application actually stores it:
- Account: e-mail address; first and last name; telephone number; the password, kept only as an irreversible hash and never in readable form; your chosen shop language; your account role; the time the account was created; the time your e-mail address was confirmed; the time you last signed in; whether you have subscribed to marketing e-mail, and when and from where; and a profile picture, if you upload one.
- Order: the order number; the delivery address and the billing address exactly as given at checkout — recipient name, street, postal code, town, country and telephone number; the e-mail address given for an order placed without an account; the products, quantities and prices ordered; the amounts, tax and delivery cost; the currency; the language checkout was completed in; the order's status and the history of its status changes; the carrier, the tracking code and the tracking link; any refunds; and the invoice number with its issue and due dates.
- Payment: the name of the payment provider used; the payment reference it returns; the payment method type; and the two-letter country of the card issuer, which the payment provider reports and which decides the payment methods the shop may offer you. The shop stores no card numbers, bank details or wallet credentials — those stay with the payment provider.
- Social sign-in: if you sign in with Google or Facebook, the provider's name, the user identifier it gives us, and the e-mail address it returns.
- Security: sign-in events — time, e-mail address, sign-in method, IP address and browser identification; the single-use password-reset and e-mail-confirmation tokens, kept only as a hash; and, for back-office users, a record of the changes made to orders, products and prices, with the time, the person and the IP address.
- Feedback: the name, e-mail address, subject and message you send; the page you sent it from; your language and your browser identification; and the handling status and the shop's internal notes on your message.
- Shopping assistant: the chat session and its language, the messages you write and the replies you are given.
- Page-performance measurement: if you accept the analytics cookie category, the shop's own measurements of how quickly pages load — a page path, a metric and a value, with your browser identification — sent to the shop's own server and to no third party.
- Error diagnostics: if you accept the analytics cookie category, a note of technical failures your browser met on the shop's pages — the request method, the page address without its query part, the response code or the error name, the shop's own error code, and a reference number that identifies the record and not you — sent to the shop's own server and to no third party. The text of the error, the contents of requests and answers, and any passwords, tokens, e-mail addresses or card numbers are never collected.
- Cookie choice: kept in your own browser, not on the shop's servers.
No other personal data is held in the register. The shop neither asks for nor stores an identity number, a date of birth, health data or any other special category of personal data. When you delete your account from the account page, the details above are erased or replaced with an anonymous marker, your social sign-in links and your unused tokens are deleted and your assistant conversations are redacted; the orders and invoices that bookkeeping law obliges the shop to keep remain; a feedback message you sent is emptied of your name, your address and its text, leaving only an anonymous record that the ticket existed; and a sign-in event keeps its time, method and network address as a security record, with your e-mail address replaced by the same anonymous marker as the account.
This register covers the customer register. The shop also processes one telephone number for a purpose that has nothing to do with customers: the operator's own business number, already published on the contact and feedback pages, is set up to receive an automated message when the shop is down or unreachable, so that an outage is noticed within minutes instead of hours. Those messages are dispatched by Google Cloud Monitoring and delivered onward by a mobile carrier we cannot identify; each one carries only the service name, the condition and a timestamp, never customer or order data, and we keep no record of the messages sent. No customer's personal data is involved.
5. Rights of the data subject
You may request access, rectification, erasure, restriction, portability, and objection. You may withdraw consent for cookies or marketing at any time. Send the request using the contact e-mail on the contact page. We may need to verify your identity.
Right of access
The data subject may check the personal data we have stored.
Right to rectification
The data subject may request that incorrect or incomplete data concerning them be rectified.
Right to object
The data subject may object to the processing of personal data if they consider that the personal data has been processed unlawfully.
Prohibition of direct marketing
The data subject has the right to prohibit the use of their data for direct marketing.
Right to erasure
The data subject has the right to request the erasure of their data if the processing of the data is not necessary. We will process the erasure request, after which we will either erase the data or state a justified reason why the data cannot be erased.
Please note that the controller may have a statutory or other right not to erase the requested data. The controller is obliged to retain accounting records for the period (10 years) specified in the Accounting Act (chapter 2, section 10). For this reason, material relating to accounting cannot be erased before the expiry of that period.
Withdrawal of consent
If the processing of personal data concerning the data subject is based solely on consent, and not e.g. on a customer relationship or membership, the data subject may withdraw their consent.
The data subject may appeal against the decision to the Data Protection Ombudsman
The data subject has the right to demand that we restrict the processing of disputed data until the matter has been resolved.
Right to lodge a complaint
The data subject has the right to lodge a complaint with the Data Protection Ombudsman if they consider that we are breaching the data protection legislation in force when processing personal data.
Contact details of the Data Protection Ombudsman: www.tietosuoja.fi/fi/index/yhteystiedot.html
6. Regular sources of data
All personal data in the register comes from you, or is created by the shop itself as it carries out your order. We do not buy personal data and we do not collect it from public or commercial data sources, inside or outside the EU.
- From you — what you type when you register, when you place an order, in the feedback form or in the shopping assistant; and, if you sign in with Google or Facebook, the name, e-mail address and user identifier that provider returns to us.
- From the shop's own systems — the order and its status, the payment reference the payment provider returns, the carrier's tracking code, and the sign-in security events recorded when you use your account.
7. Regular disclosures of data
We have ensured that all our service providers comply with data protection legislation. We regularly use the following service providers:
- Payment processors enabled at checkout (Stripe today; others when enabled) — to take payment.
- The carrier — name, phone and delivery address only.
- The e-mail delivery provider — to send transactional mail.
- Google Cloud in the EU (europe-north1, Finland) — to host the application and database.
- Google, as the provider of the Gemini model behind the shopping assistant — the messages you send it; processed in the same EU region as the store (europe-north1, Finland).
- Csitea Oy as processor.
We do not sell your data. We do not profile you for advertising, and nothing you write to the shopping assistant is used for advertising.
8. Duration of processing
- Orders and invoices: at least six years, as required by Finnish bookkeeping law; some accounting records may be kept for ten years.
- Account data: until you ask us to delete the account, except records we must keep.
- Login security events: a short period needed for security investigation.
- Cookie choice: in your browser, typically up to 12 months.
- Shopping-assistant conversations: at most 90 days, then deleted automatically.
9. Processors of personal data
The controller is the Seller named in the store footer (legal name, Finnish business ID / Y-tunnus, and registered address). The Seller decides why and how your personal data is processed.
The processor is Csitea Oy, the platform operator. Csitea hosts the store and processes personal data only on the Seller's instructions, under a data-processing agreement (GDPR Article 28).
The controller and its employees process personal data. We may also partially outsource the processing of personal data to a third party, in which case we guarantee by contractual arrangements that personal data is processed in accordance with the data protection legislation in force and otherwise appropriately.
10. Transfer of data outside the EU
The store and database run in the EU/EEA (Google Cloud europe-north1). The Gemini model behind the shopping assistant runs in that same EU region (Google Cloud Vertex AI, europe-north1), with Google as a sub-processor, so what you write to the assistant is not transferred outside the EEA. The payment provider does process data outside the EEA; that transfer relies on the European Commission's Standard Contractual Clauses and the provider's GDPR terms. We do not transfer your data outside the EEA for any other purpose.
11. Automated decision-making and profiling
We do not use the data for automated decision-making or profiling.
12. AI shopping assistant
The store offers an optional AI shopping assistant. It runs only if you open it and write something; every other part of the store works without it. What you write, and the answer you get back, is sent to Google, the provider of the Gemini model that generates the reply, for the sole purpose of answering your question. That call goes to the Gemini model on Google Cloud Vertex AI in the EU region europe-north1 — the same region the store itself runs in — so your text stays inside the EEA; see the section on international transfers.
Assistant messages are used only to answer you. We do not use them for advertising, for profiling or for automated decision-making, and we never sell them. We use the model provider on a paid plan, whose terms do not allow your messages to be used to train its models. The assistant cannot take a payment or change an order; a person handles anything that does. Please do not write card numbers, passwords or health information into it — a dietary or allergy detail you mention is sent with your message.
A conversation is kept with your chat session so the assistant can follow the thread, and is deleted automatically after 90 days at the latest. If you would rather your text was not processed this way, do not use the assistant: it is optional, and the catalogue, your account and checkout all work fully without it.
Additional information about this shop
Personal details are not required
You do not need to write or submit personal details to browse the catalogue or use the storefront in general. Viewing products is not conditioned on registration or a profile.
Personal data is processed only when you choose to register, sign in, place an order, or contact support — not merely for browsing. Cookie consent is about optional technical storage, not a requirement to fill in personal forms.
Payments — handled by payment providers
Bank and payment card details are handled by the respective payment provider(s). We do not enter or store full card numbers, CVV, or card secrets in our shop systems or databases.
At checkout, you pay through the payment provider’s secure flow. We only receive non-sensitive outcomes such as payment status (paid or failed) and a provider reference (for example a payment-intent or transaction id). We do not keep cards on file for reuse in this store.
Who is responsible
This notice is for customers of this online shop. Personal data is processed to run the storefront, your account, orders, delivery and support. The seller named on the contact page handles orders, deliveries and returns. The platform operator named on the data-protection page is the data controller for the site.
The platform operator (data controller) is Csitea Oy Ab.
Google and Facebook sign-in
If you choose to continue with Google or Facebook, that provider authenticates you and may share a verified email and a provider user id so we can create or link your shop account. We do not post to your social profile. Disconnecting Facebook is described on the Facebook data-deletion page linked from that provider.