Last update: 19/11/2018
1. ABOUT THIS POLICY
Nucu develops well-being solutions.
At Nucu Oy (“Nucu”), we take data protection seriously. We collect and process personal
data for customer relationship management and Nucu website visitor analysis.
(“Customers” or “you”) with transparent information about the privacy policies of Nucu.
• What personal data we collect when you browse on Nucu.fi site or otherwise are in
contact with us
• Why we collect data
• How we may use and share your personal data
• Your legal rights and how to exercise them
2. OUR CONTACT INFORMATION
Business ID: 2785473-5
Address: Aapistie 1, 90220 Oulu, Finland
E-mail address: email@example.com
Contact: Juha Hannula, firstname.lastname@example.org
3. WHAT PERSONAL DATA DO WE PROCESS?
The data we collect can be categorized into two groups: Customer data and Analytics
data. Analytics data is automatically collected when you visit the site.
Although we do not normally use Analytics data to identify individuals, sometimes
individuals can be recognized from it, either alone or when combined or linked with
Customer data. In such situations, Analytics data shall also be considered as personal
data under applicable laws and we will treat the combined data as personal data.
Nucu may collect and process the following Customer data:
• Your name and contact details
• Phone number
• E-mail address
• Possible communication with us
• Invoicing and billing information
• Possible claims or refunds
• Delivery information (if different from contact information)
• Your purchase information (service and value)
Analytics data may include for example the following data:
• IP address
• Device type
• Operating system
• Time of visit
• Browser type and version
• Language settings
4. DATA SOURCES
Your Customer data is primarily received directly from you when you purchase a service
from Nucu or contact us with a question, complaint or support request. In business to
business contacts we may get information also from your employer.
Analytics data is automatically collected when you visit the site.
5. PURPOSES AND LEGITIMATE GROUNDS FOR
Purposes of processing
Processing and delivering your service
We process personal data to process and handle your service.
We may process personal data for the purpose of communicating with Customers. If you
contact our customer service, we will use the provided information to answer your
questions and for solving any issues you may have.
Analytics and service improvements
We may process information regarding the use of our site to improve our service quality.
This may involve the use of analytics or the assessment of any trends on our website.
When possible, we will do this using only aggregated, non-personally identifiable data.
With your consent we may send you marketing material, such as newsletters or offers.
Legal grounds for processing
We process personal data to perform our contractual obligations towards Customers or
to facilitate their entry into a contract at their request. We also process certain
information to comply with legal obligations, such as accounting legislation.
Furthermore, we process personal data to pursue our legitimate interest to run, maintain
and develop our business, for analytics and trend detection, direct marketing and to
create and maintain customer relationships. We may also process data for responding to
consumer claims, cases regarding product warranty and similar situations. When
choosing to use your data on the basis of our legitimate interests, we carefully weigh our
own interests against your right to privacy.
6. COOKIES AND ANALYTICS
We use various technologies to collect and store Analytics data and other information
when Customers use our site, including third party cookies.
Cookies are small text files sent and saved on your device that allows us to identify
visitors of our websites and facilitate the use of our site and to create aggregate
information of our visitors. This helps us to improve our service and better serve our
site and the information we provide in accordance with the individual interests of our
Web analytics services
We use Google Analytics services to compile Analytics Data and reports on visitor usage
and to help us improve the Services. Please visit their privacy policies for more
7. DATA TRANSFERS TO COUNTRIES OUTSIDE EEA
Nucu stores the Customers’ personal data primarily within the European Economic Area.
8. SHARING YOUR PERSONAL DATA
We do not share personal data with third parties outside of our organization unless one
of the following circumstances applies:
For legal reasons
We may share personal data with third parties outside Nucu’s organization if we have a
good-faith belief that access to and use of the personal data is reasonably necessary to:
(i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or
otherwise address fraud, security or technical issues; and/or (iii) protect the interests or
safety of Nucu or our Customers in accordance with the law. Where possible, we will
inform Customers about such transfer and processing.
To our authorized service providers
We may share personal data to authorized service providers who perform services for us
(including data storage, sales, marketing and Customer support).
For other legitimate reasons
If Nucu is involved in a merger, acquisition or asset sale, we may transfer personal data
to the third party involved. However, we will continue to ensure the confidentiality of all
personal data. We will give notice to all Customers concerned when the personal data
With your explicit consent
We may share personal data with third parties outside Nucu’s organization for other
reasons than the ones mentioned before, when we have the Customer’s explicit consent
to do so. You have the right to withdraw this consent at all times.
9. HOW LONG DO WE KEEP YOUR DATA?
Nucu does not store personal data longer than is legally permitted and necessary for the
purposes specified above. The storage period depends on the nature of the information
and the purposes of processing. The maximum period may therefore vary per use.
Storage periods are determined by contracts, consent and law.
10. YOUR RIGHTS
Right to access
You have the right to access your personal data processed by us. You may contact us to
email@example.com and we will inform you what personal data we have collected and
processed regarding you.
Right to withdraw consent
In case the processing is based on your consent, you may withdraw the consent at any
time. Withdrawing a consent may lead to fewer possibilities to use our site. The
withdrawal of consent does not affect the lawfulness of processing based on consent
before its withdrawal.
Right to correct
Customers have the right to have incorrect or incomplete personal data we have stored
about the Customer corrected or completed. You may contact us to firstname.lastname@example.org and
we will correct your personal data.
Right to erasure
Customers may also ask us to erase the Customer’s personal data from our systems.
We will comply with such request unless we have a legitimate ground to not delete the
data. You may contact us to email@example.com and we will erase your personal data when
Right to object
Customers may object to the processing of personal data if such data are processed for
other purposes than processing and delivering the service, customer communication or
Nucu.fi site analytics. In case we do not have legitimate grounds to continue processing
such personal data, we shall no longer process the personal data after your objection.
Right to restriction of processing
Customers may request us to restrict processing of personal data for example when
your data erasure, rectification or objection requests are pending and/or when we do not
have legitimate grounds to process your data. This may however lead to fewer
possibilities to use our site or service.
Right to data portability
Customers have the right to receive their personal data from us in a structured and
commonly used, machine-readable format and to independently transmit those data to a
How to use the rights
The above mentioned rights may be used by sending a letter or an e-mail to us on the
addresses set out above, including the following information: the full name, company
name, address, e-mail address and a phone number. We may request the provision of
additional information necessary to confirm the identity of the Customer. We may reject
requests that are unreasonably repetitive, excessive or manifestly unfounded.
11. DIRECT MARKETING
Notwithstanding any consent granted beforehand for the purposes of direct marketing,
you have the right to prohibit us from using your personal data for direct marketing
purposes by contacting us to firstname.lastname@example.org
12. SAFEGUARDING YOUR DATA
We do our best to keep your data safe and secure. We use administrative,
organizational, technical, and physical safeguards to protect the personal data we collect
and process. Measures may include, for example, where appropriate, encryption,
pseudonymization and access right systems.
Our security controls are designed to
maintain an appropriate level of data confidentiality, integrity, availability, resilience and
ability restore the data. We regularly test our systems, and other assets for security
Should despite of the security measures, a security breach occur that is likely to have
negative effects to your privacy, we will inform you and relevant authorities as required
by applicable data protection laws.
13. LODGING A COMPLAINT
In case you consider our processing of personal data to be inconsistent with the
applicable data protection laws please contact us to email@example.com. Complaint may also be
lodged with the data protection supervisory authority.