Privacy policy

Data Controller
Name: Linssikauppa / IXI Optics Oy
Business ID: 3538196-6
Address: Keilaranta 16 A 2, 02150 Espoo, Finland
Email: info@linssikauppa.fi
Phone: +358 2 6510 5999
Contact person for registry matters: Henna Mäkinen, henna.makinen@ixieyewear.com

Name of the Register
Linssikauppa Customer Register

Legal Basis for Processing
The processing of personal data is based on the following grounds under the EU General Data Protection Regulation (GDPR):

  1. The data subject has given consent for the processing of personal data for one or more specific purposes (GDPR Art. 6(1)(a));
  2. Processing is necessary for the performance of a contract to which the data subject is party, or to take steps at the request of the data subject prior to entering into a contract (GDPR Art. 6(1)(b));
  3. Processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party (GDPR Art. 6(1)(f)).

The above-mentioned legitimate interest is based on a relevant and appropriate relationship between the data subject and the controller, which results from the data subject being a customer of the controller, and when the processing occurs for purposes that the data subject can reasonably expect at the time of data collection.

Purpose of Processing Personal Data
We process personal data for the following purposes and based on the legal grounds listed below:

PurposeExamplesLegal Basis
Customer relationship managementOrder processing, customer service, communicationContract (6(1)(b))
Marketing and communicationNewsletters, campaignsConsent or legitimate interest (6(1)(a), 6(1)(f))
Website monitoring and analyticsWebsite development, visitor trackingConsent (6(1)(a))
Legal obligationsAccounting, authority requestsLegal obligation (6(1)(c))

The register is used for product deliveries, marketing, as well as for conducting surveys, campaigns, and competitions. The basis for data processing may be an assignment from an optician or another legitimate relationship, in which case the data is used for identifying, delivering, and invoicing a custom-made product. The data may also be used to maintain customer relationships, inform and remind customers of services, and for direct marketing if the customer has given consent. Data may also be used in recruitment if expressly permitted by the data subject.

Data Content of the Register
The content may vary depending on the user. The following types of user data may be recorded:

Data subject groups:

  • Website visitors
  • Online store customers
  • Contact form users
  • Job applicants

Data types may include:

  • Name, address, email address, phone number, delivery address
  • Contact history (phone, email, social media, etc.)
  • IP address, device identifiers
  • Purchase data and order history
  • Form submissions (e.g., contact or job application)
  • Cookie and analytics data
  • Additional information provided by the customer (e.g., hobbies, use of eyeglasses or contact lenses)
  • Eyeglass prescription data
  • Opt-out information related to the disclosure or use of data for direct marketing

Regular Sources of Information
Information is obtained from:

  • The data subject themselves (via orders, forms, or email)
  • Cookies and tracking tools (see EU Cookie Policy)
  • Public registers (e.g., Finnish Business Information System)

The sources include data provided by the customer or their legal representative, and information given to customer service during product orders. Data may also be collected via competitions and marketing campaigns. Separate consent is requested for electronic direct marketing (email and/or mobile). Additionally, data may be collected as reference information from B2B product orders, and from education and career data provided for recruitment purposes.

Data Retention Period
We retain personal data only as long as necessary for the purposes stated or as required by law:

  • Customer data: 5 years from last interaction
  • Accounting records: 6 years
  • Marketing lists: until consent is withdrawn
  • Job applications: up to 12 months

Recipients and Subcontractors
We may disclose data to the following parties only to the extent necessary to provide the service:

  • Payment processors (e.g., Paytrail, Klarna)
  • Delivery services (e.g., Posti, Matkahuolto)
  • Newsletter services (e.g., MailerLite)
  • Technology providers (e.g., analytics and cookie services)

Customer Reviews and Marketing Use
When a customer leaves a review on the Linssikauppa.fi online store, they consent to the use of that review—including text, images, and videos—for Linssikauppa.fi’s marketing purposes. Reviews may appear on our website, in newsletters, on social media, or other marketing materials.
Linssikauppa.fi reserves the right to edit reviews for language or clarity without altering their content or meaning. Customers may request the removal of their review from marketing materials by contacting customer service.

Regular Disclosures and Transfers Outside the EU or EEA
Customer data may be processed by Finnsusp Oy and its partners, including software companies, as described in this policy. Data will only be disclosed to third parties with the consent of the data subject or based on specific legal provisions. Servers and technical systems used in processing may be owned and operated by third-party service providers.
As a rule, data is not transferred outside the EU or EEA. If service providers (e.g., cloud services) process data outside the EU, we ensure compliance with data protection regulations.

Principles of Register Protection
Customer, supplier, and applicant data may be processed by representatives of Finnsusp Oy and its partners, including software vendors in exceptional cases. All parties must adhere to data handling protocols. Access to the customer register is granted only as required by job duties. Eyeglass prescriptions are processed as medical data.

All customer data is confidential and subject to non-disclosure. The customer register resides in Finnsusp Oy’s information system, accessible only with personal credentials. The system is protected by a firewall against external access. Data is regularly backed up to prevent loss during disruptions. Data is disclosed only in cases required by law, customer request, or official authority requests.

Right of Access
Data subjects have the following rights:

  • Right to access their data
  • Right to rectify incorrect data
  • Right to erasure (“right to be forgotten”)
  • Right to restrict processing
  • Right to object (e.g., to direct marketing or processing based on legitimate interest)
  • Right to data portability (when applicable)
  • Right to withdraw consent at any time

You can exercise these rights by contacting us using the details provided in Section 1.

Right to Object
Customers may provide or withdraw consent for direct marketing by notifying the data controller in writing. Job applicant data will not be used for direct marketing, advertising, research, campaigns, or competitions.

Updated: 1 August 2025