Nicotine Finland Oy processes personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Finnish Data Protection Act. This policy describes what data we collect, for what purposes and how long the data is retained.
1. Data controller
Nicotine Finland Oy
Y-tunnus: 3404949-4
Postiosoite: C/O Suomen Tuontiliike Oy, PL 11, 65101 Vaasa
Sähköposti tietosuoja-asioissa: tietosuoja@nicotine.store
The company does not have a separately designated Data Protection Officer, as this is not required by legislation. For data protection matters you can contact the email address above.
2. Data processed
We process personal data in the following situations:
Contacts and customer service
When you contact us via the form or by email, we process the information you provide: name, email address, phone number, organization and message content.
Job applicants
For applicants who have submitted an open application we process: name, contact details, age group, interests, preferred working time, start date and free-form introduction.
We do not accept CVs or other attachments via the form. We request them separately from the applicant when needed.
Commercial space providers
In connection with commercial space offers we process: name, organization, email, phone number and details of the offered space.
Website use
Anonymized visitor data is collected on the website using Google Analytics 4: page loads, device and browser used, and referral source. IP addresses are anonymized and individual users cannot be identified.
3. Purpose and legal basis for processing
We process personal data for the following purposes:
- Customer service — responding to contacts and feedback (basis: legitimate interest)
- Recruitment — processing job applications and communicating with applicants (basis: consent)
- Commercial space scouting — processing offers related to expansion plans (basis: legitimate interest)
- Operations development — anonymized analysis of website use (basis: consent, collected via cookie consent)
- Compliance with legislation — accounting and other regulatory requirements (basis: legal obligation)
4. Retention period
We retain personal data only as long as necessary for the purpose of processing:
- Contacts — generally 12 months after the contact
- Applicant data — 12 months from when the application was submitted, unless the applicant has separately requested earlier deletion. Outdated data is removed automatically.
- Commercial space offers — for the duration of processing and one month after the offer has been processed
- Accounting data — for the period required by the Accounting Act (generally 6 years)
- Anonymized visitor data — 14 months by default in Google Analytics, and the data cannot be linked to an individual user
5. Data disclosures and service providers
We do not disclose personal data to third parties for marketing purposes and do not sell data to anyone.
We use the following trusted service providers who process data on our behalf:
- Zapier, Inc. (USA) — form forwarding service from the website to Airtable. Data is transferred outside the EU protected by the GDPR standard contractual clauses (SCC).
- Airtable, Inc. (USA) — lomakevastausten ja työnhakijatietojen tallennus. Tietojen siirto perustuu EU-USA -tietosuojakehykseen ja standardisopimuslausekkeisiin.
- Google LLC (USA) — Google Workspace sähköpostien käsittelyyn ja Google Analytics 4 anonymisoituun kävijämittaukseen. Tietojen siirto perustuu EU-USA -tietosuojakehykseen.
All partners are obligated to comply with data protection legislation and to process data only on our behalf. We have signed the required data processing agreements with each service provider.
6. Cookies
Our website uses cookies, i.e. small text files stored in your browser during your visit. You can manage your cookie consent in the site's cookie settings.
Necessary cookies
Cookies necessary for the site's operation and for remembering your cookie consent. These cannot be disabled.
nicotine_cookie_consent— Stores your cookie consent (Nicotine Finland Oy). Retention: 12 months.
Analytics cookies
We use Google Analytics 4 for anonymized measurement of visitor traffic. IP addresses are anonymized and individual users cannot be identified. Analytics cookies are only set if you have accepted them in the cookie settings.
_ga— Distinguishes individual visitors with an anonymous identifier (Google). Retention: 2 years._ga_*— Maintains session state for Google Analytics 4 (Google). Retention: 2 years.
You can change your cookie consent at any time via the site's cookie settings or by deleting cookies in your browser settings.
7. Data subject rights
Under data protection legislation you have the following rights regarding your personal data:
- Right of access — you can request information about which of your personal data we process
- Right to rectification — you can request the correction of inaccurate data
- Right to be forgotten — you can request the deletion of your data, unless legislation requires us to retain it
- Right to restrict processing — in certain situations you can request the restriction of processing your data
- Right to data portability — you can request your data in a machine-readable format
- Right to object — you can object to processing based on legitimate interest
- Right to withdraw consent — if processing is based on your consent, you can withdraw it at any time
Requests to exercise rights can be sent by email to tietosuoja@nicotine.store. We will respond to your request within one month at the latest.
If you feel that we have not processed your data appropriately, you have the right to file a complaint with the Data Protection Ombudsman's office. Contact details for the Data Protection Ombudsman's office: tietosuoja.fi.
8. Information security
We use appropriate technical and organizational measures to protect personal data from unauthorized access, alteration, disclosure and destruction. All data traffic between the website and our service providers is encrypted.
Personal data is only processed by people whose job tasks require processing. They are bound by a duty of confidentiality.
9. Changes to this policy
We may update this privacy policy as our operations, legislation or technology change. We will announce significant changes on our website. We recommend reviewing the policy regularly.
10. Contact information
For questions related to data protection you can contact:
Nicotine Finland Oy
Y-tunnus: 3404949-4
Postiosoite: C/O Suomen Tuontiliike Oy, PL 11, 65101 Vaasa
Sähköposti: tietosuoja@nicotine.store