Privacy policy

Privacy Policy of Re-One Oy. This is the register and privacy policy for Re-One Oy's online store, in accordance with the EU General Data Protection Regulation (GDPR). Last updated: 26 of August 2026. 

1. Data Controller

Company name: Re-One Oy

Business ID: 3174729-7

Address: Nuijamäki 2 A 6, 02630 Espoo

Email: info@re1.fi

Phone number: 040 544 7018

2. Contact person for data protection matters

Name: Risto Timonen

Email: info@re1.fi

3. Name of the register:

Online store customer and order register.

4. Purpose and legal basis for the processing of personal data. We process your personal data for the following purposes:

Order processing: Product delivery, invoicing, and customer service. (Basis: Performance of a contract).

Maintaining the customer relationship: Communication and potential complaints. (Basis: Legitimate interest).

Marketing: Newsletters and targeted advertising, if you have given your consent. (Basis: Consent or legitimate interest).

5. Data content of the register. The following customer data may be stored in the register:

Basic information: First name and surname.

Contact details: Delivery and billing address, email address, phone number.

Order information: Purchase history, ordered products, selected payment method, and delivery method.

Technical data: IP address and cookie information regarding browsing the online store.

6. Regular sources of information.

Information is primarily collected from the customer themselves when placing an order, creating a customer account, or subscribing to the newsletter. Technical data regarding the use of the online store is collected using cookies.

7. Regular disclosures of data and transfers outside the EU or EEA.

Data is shared only with partners essential to the operation of the online store:

Logistics companies: Posti (for parcel delivery).

Payment service providers: Paytrail, Klarna (for payment processing).

IT partners: Webnode (maintenance of the online store platform).

Data is not disclosed to third parties for marketing purposes. If data is transferred outside the EU/EEA (for example, due to US-based system providers), we ensure protection through Standard Contractual Clauses (SCCs) in accordance with the GDPR. 

8. Principles of register protection.

Your data is handled confidentially. There is no physical (paper) material, or it is stored in a locked area. Digital systems are protected by SSL encryption, firewalls, and personal user accounts. Access to the data is restricted to employees who require it for their work duties.

9. Data retention period.

We retain your personal data only for as long as is necessary to fulfill the purposes defined in this notice.

Order information: Retained for the period required by the Finnish Accounting Act (6 years from the end of the financial year).

Marketing information: Retained until you withdraw your consent (e.g., by unsubscribing from the newsletter list).

10. Rights of the data subject. Under the GDPR, you have the following rights:

Right to access data: You may request a copy of the data stored about you

Right to correct data: You may request the correction of incorrect or incomplete data.

Right to delete data: You may request the deletion of your data if there is no longer a legal basis for processing (e.g., the Accounting Act).

Right to withdraw consent: You may withdraw your marketing consent at any time.

You can exercise your rights by sending a written request to: info@re1.fi. You also have the right to lodge a complaint with the Data Protection Ombudsman if you believe that we are violating data protection legislation.