Privacy Policy
Last updated:
1. Introduction
Craxyloneph ("we", "us", or "our") operates the website https://craxyloneph.world (the "Website"). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our Website and purchase our products, in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Finnish Data Protection Act (1050/2018), and other applicable data protection legislation.
By using our Website, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with the terms described herein, please discontinue use of our Website.
2. Data Controller
The data controller responsible for your personal data is:
- Company Name: Craxyloneph
- Address: Keskuskatu 5, 00100 Helsinki, Finland
- Email: notify-us@craxyloneph.world
- Website: https://craxyloneph.world
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Data You Provide Directly
- Contact Information: Full name, email address, and phone number (optional) when you submit an order form or contact us.
- Order Information: Messages and special requests included with your order submission.
- Consent Records: Your consent to our Privacy Policy and data processing, including the date and time of consent.
3.2 Data Collected Automatically
- Technical Data: IP address, browser type and version, operating system, device type, screen resolution, and language preferences.
- Usage Data: Pages visited, time spent on pages, referral URLs, click patterns, and navigation paths.
- Cookie Data: Information collected through cookies and similar technologies as described in our Cookie Policy.
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): When you provide explicit consent for specific processing activities, such as subscribing to communications or accepting analytics cookies.
- Contract Performance (Art. 6(1)(b)): When processing is necessary to fulfill an order or respond to your inquiries.
- Legitimate Interests (Art. 6(1)(f)): When processing is necessary for our legitimate business interests, such as improving our Website, provided these interests do not override your rights and freedoms.
- Legal Obligation (Art. 6(1)(c)): When processing is necessary to comply with applicable legal obligations, such as tax and accounting requirements.
5. Purposes of Data Processing
We process your personal data for the following purposes:
- Processing and fulfilling your orders for CoreVitality Plus.
- Communicating with you regarding your orders, inquiries, or requests.
- Improving and optimizing our Website functionality and user experience.
- Analyzing Website usage patterns and trends through anonymized or aggregated data.
- Ensuring the security and integrity of our Website.
- Complying with legal and regulatory obligations.
- Managing cookie preferences and consent records.
6. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Order Data: Retained for 5 years from the date of the order to comply with Finnish accounting and tax regulations.
- Contact Form Data: Retained for 12 months from the date of submission, unless a longer retention period is required for legal purposes.
- Consent Records: Retained for 5 years from the date of consent to demonstrate compliance with GDPR.
- Cookie Data: Retained in accordance with the durations specified in our Cookie Policy.
- Technical and Usage Data: Retained for up to 26 months in anonymized or aggregated form.
After the applicable retention period expires, personal data is securely deleted or anonymized.
7. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data. We may share your data with the following categories of recipients:
- Service Providers: Trusted third-party service providers who assist us with website hosting, order processing, email delivery, and analytics. These providers are contractually bound to process data only on our instructions and in compliance with GDPR.
- Legal Authorities: When required by law, regulation, or legal process, or to protect our rights, safety, or property.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred as part of the transaction, subject to the same privacy protections.
8. International Data Transfers
Your personal data is primarily stored and processed within the European Economic Area (EEA). If data is transferred outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs) approved by the European Commission.
- Adequacy decisions by the European Commission for the recipient country.
- Other appropriate safeguards as required under Chapter V of the GDPR.
9. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of Access (Art. 15): You have the right to request a copy of your personal data that we hold.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You have the right to request deletion of your personal data, subject to legal retention requirements.
- Right to Restrict Processing (Art. 18): You have the right to request limitation of processing in certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), Lintulahdenkuja 4, 00530 Helsinki, Finland, or online at https://tietosuoja.fi/en.
To exercise any of these rights, please contact us at: notify-us@craxyloneph.world. We will respond to your request within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS/SSL protocols (HTTPS).
- Access controls and authentication mechanisms for systems containing personal data.
- Regular security assessments and updates to our infrastructure.
- Employee training on data protection and confidentiality obligations.
- Secure data storage with appropriate backup and recovery procedures.
While we strive to protect your personal data, no method of transmission over the Internet or electronic storage is completely secure. We cannot guarantee absolute security but commit to taking all reasonable measures to safeguard your data.
11. Children's Privacy
Our Website and products are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child under 18, we will take steps to delete such data promptly.
12. Third-Party Links
Our Website may contain links to third-party websites or services. We are not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party services you access through our Website.
13. Changes to This Privacy Policy
We reserve the right to update or modify this Privacy Policy at any time. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- Email: notify-us@craxyloneph.world
- Address: Keskuskatu 5, 00100 Helsinki, Finland
- Website: https://craxyloneph.world