Aalto University is committed to protecting the privacy of our site visitors and customers.
If you log in using an Aalto account, some information is automatically recorded in the Aalto Shop customer register. This information includes your name, email address, phone number and customer group (staff/student).
In addition, the site collects analytics data from its visitors. This includes IP address, date and time of visit, approximate location, language and other browser information and other system information.
The legal basis for processing your personal information is that it is necessary for the performance of a contract or for processing prior to entering into a contract. Personal information may also be processed on the basis of compliance with a legal obligation to which Aalto Shop is subject.
We use your information…
● To provide you with a service
● To improve our website
● To improve customer service
We will not sell your name, address, email address or other personal information to any third party without your permission. We may release your information when it is necessary in order to comply with our legal obligations or to protect ours or others’ rights. However, site analytical information may be gathered by other parties, including parties in third countries, for marketing, advertising or other uses. In any other cases, we will ascertain your explicit permission to disclose your data and will not transfer it to any third (non-EU/ETA countries) without your prior consent.
Should you choose to opt into Aalto Shop marketing in conjunction with your purchase, Aalto Shop may send you updates and other information about Aalto Shop. You can opt out of these emails at any time by clicking the link sent in conjunction with each marketing email or by accessing your user information on the Aalto Shop.
The General Data Protection Regulation grants the data subject a number of rights with which the data subject can govern the processing of their personal data. The data subject may use the following rights in relation to Aalto insofar as Aalto acts as the controller for the data subject’s personal data:
Right of access and right to rectification
You have the right to receive confirmation on whether we process personal data relating to you and the right to access any such personal data. Aalto may ask you to specify your request where necessary, for example with regard to the details of the provision of information. In addition, you have the right to request the rectification of incorrect personal data relating to you, or to supplement incomplete personal data that Aalto is processing.
Right to data erasure
You have the right to request erasure of your personal data from our data systems. Aalto will comply with your request, provided that there is no legitimate reason to retain the data, such as a statutory obligation to continue processing the personal data. Personal data may not be deleted instantly from backup copies and other such data systems, but will be deleted through regular database retention practices.
Right to object
You also have the right to object to the processing of your personal data if your personal data is processed for other purposes than the fulfillment of legal responsibilities or the provision of services. You may object to the processing of your personal data for purposes of direct marketing, even if the basis for such processing is consent given by you in the past. Objecting to the processing of your personal data may lead to limitation of the usage of the Aalto website. You have the right to prohibit direct marketing by following the instructions contained in all of our marketing messages.
Right to restriction of processing
If you contest the correctness of the data which we have registered about you or the lawfulness of processing, or if you have objected to the processing of the data in accordance with your right to object, you may request us to restrict the processing of these data to only storage. The processing will only be restricted to storage, until the correctness of the data can be established, or until it is assured that our legitimate interests override your interests.
If you are not entitled to erasure of the data which we have registered about you, you may instead request that we restrict the processing of these data to only storage. If the processing of the data which we have registered about you is solely necessary to assert a legal claim, you may also demand that other processing of these data be restricted to storage. We may process your data for other purposes if this is necessary to assert a legal claim or if you have granted your consent to this.
Right to data portability
You have the right to receive your personal data from us in a structured, commonly used format so that you may transfer your personal data to another controller, provided that the processing of your personal data is based on consent or a contract between you and Aalto.
Who is the controller and who can I contact?
You can use your rights by contacting Aalto's data protection officer at firstname.lastname@example.org. The extent of your rights is subject to the legal basis for processing, and exercising your rights requires identification.
Aalto-korkeakoulusäätiö sr, which functions as Aalto University
Mailing address: PO BOX 11000, FI-00076 AALTO
Phone number: +358 (9) 47001
Visiting address: Otakaari 24, 02150 Espoo
Data protection officer: email@example.com
Right to lodge a complaint
If the processing of your personal data is in breach of applicable legislation, you have the right to lodge a complaint with the national supervisory authority. You can lodge the complaint with a competent supervisory authority. In Finland, this is the Data Protection Ombudsman, and the complaint must be lodged in accordance with instructions provided by the Office of the Data Protection Ombudsman. Please see https://tietosuoja.fi/en/homefor more information.