Lapetek online store customer register
Updated: 09.3.2026

1. Data controller

Oy Lapetek Ab
Business ID: 0488840-6
Hermannin Rantatie 2b B9
00580 Helsinki
Telephone: +358 9 2511 030
www.lapetek.fi

2. Contact person for data protection matters

Lapetek Customer Service
Email: sales@lapetek.fi
Telephone: +358 9 2511 030

3. Name of the register

Lapetek online store customer and marketing register

4. Purpose of processing personal data

Personal data is processed for the following purposes:

  • Processing and delivering online store orders
  • Processing payments and invoicing
  • Managing customer relationships and customer service
  • Processing warranty, return and complaint matters
  • Fulfilling statutory obligations (e.g. the Accounting Act)
  • Direct marketing and newsletters (if the customer has given consent or the processing is based on legitimate interest)
  • Development of online services, analytics and statistics
  • Prevention of misuse and ensuring data security

5. Legal basis for processing (Article 6 GDPR)

The processing of personal data is based on one or more of the following legal bases:

  • Contract: processing orders and managing the customer relationship
  • Legal obligation: accounting and consumer protection legislation
  • Legitimate interest: maintaining the customer relationship, customer communications and marketing to existing customers
  • Consent: newsletters and electronic direct marketing where consent is required

The data subject has the right to object to processing based on legitimate interest.

6. Contents of the register

The register may contain the following data:

  • First and last name
  • Company and Business ID (business customers)
  • Postal address
  • Email address
  • Phone number
  • Order and delivery details
  • Payment details (information transmitted by the payment service provider)
  • Customer feedback and contacts
  • Marketing consents and prohibitions
  • IP address and technical data related to the use of the online service
  • Data collected by cookies and analytics tools

Additional information on company representatives:

  • title and/or job description in current and previous duties related to the Data Controller’s operations
  • start and end time and method of the customer relationship or similar relationship
  • customer transaction history
  • campaigns and offers directed to the customer and their use
  • the customer’s declared interests and other information
  • content of feedback and complaints, related correspondence and follow-up measures
  • information related to financing, maintenance and other ancillary agreements

Lapetek does not store payment card information in its own systems.

7. Regular sources of information

Personal data is obtained from:

  • From the customer themselves in connection with an online store order, registration or contact
  • From the payment service provider in connection with the payment transaction
  • From the transport service provider in connection with delivery
  • From the credit information company in connection with a credit decision (if necessary)
  • Through cookies and analytics tools in connection with website use

8. Disclosures of personal data and processors

Data may be disclosed or transferred to the following parties:

  • Payment service providers
  • Transport and logistics companies
  • IT and system service providers
  • Debt collection and invoicing services
  • Authorities in situations required by law

Service providers process personal data on behalf of Lapetek in accordance with written data processing agreements.
Data is not sold to external parties.

9. Transfer of data outside the EU/EEA

Personal data may be transferred outside the EU/EEA if the service providers used are located outside the EU/EEA.
In such cases, transfers are carried out in accordance with the GDPR, for example on the basis of:

  • Standard Contractual Clauses (SCC) approved by the European Commission
  • Other lawful transfer mechanisms

10. Retention period of personal data

Personal data is retained only for as long as necessary to fulfil the purposes of processing or to comply with statutory obligations.

  • Order and accounting data: in accordance with the Accounting Act (6–10 years)
  • Customer data: for the duration of the customer relationship and for a reasonable period after its end
  • Marketing data: until consent is withdrawn or the right to object is exercised
  • Complaint and warranty data: in accordance with the applicable liability period

11. Rights of the data subject

The data subject has the following rights:

  • Right to access their own data
  • Right to rectification of data
  • Right to erasure of data
  • Right to restriction of processing
  • Right to object to processing
  • Right to data portability
  • Right to withdraw consent at any time
  • Right to lodge a complaint with the supervisory authority

Requests concerning data must be submitted in writing to the data controller.
Supervisory authority in Finland: Office of the Data Protection Ombudsman, www.tietosuoja.fi

12. Automated decision-making and profiling

Personal data may be used for customer segmentation and targeted marketing.
Lapetek does not make decisions producing legal effects concerning the data subject based solely on automated processing.

13. Data security

Personal data is protected by appropriate technical and organisational measures, including:

  • Access control and user-specific credentials
  • Password-protected systems
  • Firewalls and information security software
  • Data processing agreements with subcontractors
  • Data protection guidance for personnel

14. Cookies and analytics

Lapetek’s website uses cookies and similar technologies to implement the functionality, analytics and marketing of the online service. The use of these technologies is generally based on the data subject’s consent, which is given via the cookie banner. Consent may be withdrawn at any time through the cookie settings. More information on cookies is available in a separate cookie policy.

Google Analytics 4
Lapetek uses the Google Analytics 4 analytics tool on its website, provided by Google LLC.

Google Analytics collects information such as:

  • website usage
  • page visits
  • devices and browsers used
  • time spent on the website
  • users’ interaction with the website

The collected data is used for:

  • developing the online service
  • improving the user experience
  • analysing the use of the website

Google Analytics uses cookies and similar technologies. IP addresses are anonymised before storage where possible. Google may also process data outside the EU/EEA. In such cases, data transfers are based on GDPR-compliant safeguards, such as Standard Contractual Clauses (SCC) approved by the European Commission.
More information on Google’s privacy practices: https://policies.google.com/privacy

Meta and Google Ads remarketing
Lapetek uses remarketing technologies provided by Meta Platforms Inc. (Facebook and Instagram) and Google Ads.
With these technologies, Lapetek may show targeted advertisements to users who have visited the website, for example on:

  • Facebook
  • Instagram
  • Google’s advertising network
  • YouTube
  • other websites

Remarketing is based on cookies and similar identifiers that make it possible to identify users who have previously visited the website.
Lapetek does not receive personally identifiable information about individual users from these services; instead, the data is generally processed in pseudonymised form.
Meta and Google may also process data outside the EU/EEA using GDPR-compliant safeguards.
More information:
Google Ads: https://policies.google.com/privacy
Meta: https://www.facebook.com/privacy/policy

Preventing remarketing
The user may prevent targeted advertising, for example, in the following ways:

  • by changing cookie settings on the website
  • through Google ad settings at https://adssettings.google.com
  • through Meta ad settings at https://www.facebook.com/adpreferences