Your information
Privacy, explained clearly
This policy explains what personal data the Agafia website and online sales service use, why it is needed, who may receive it and which choices remain yours.
Last updated: 19 July 202601 · Who is responsible
Controller
The controller is Mariia Karnaukh, a Finnish sole trader who operates the Agafia website and provides online sales through it. “Agafia”, “we”, “us” and “our” in this policy refer to that activity.
- Official name
- Mariia Karnaukh
- Business ID
- 3592242-7
- Address
- Minivägen 3 A 3, 66950 Munsala, Finland
- agafiagrace@gmail.com
- +358 40 708 5885
02 · Information
Personal data we collect
Depending on how you use the website, we may process:
- identity and contact data, such as name, email address and phone number;
- account data and securely protected authentication information;
- billing, delivery and saved-address information;
- order requests, selected products, colour variants, monograms, measurements and other custom instructions;
- order chat, customer-service messages and complaint correspondence;
- payment status and transaction identifiers received from Stripe, but not full payment-card details;
- delivery carrier, tracking and fulfilment information;
- newsletter email and consent, if you choose to subscribe;
- technical and security data, such as IP address, browser information, timestamps, session identifiers and error logs.
Most information comes directly from you. We may also receive payment status from Stripe and delivery updates from a carrier.
03 · Why it is used
Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Create and secure an account | Identity, contact and authentication data | Contract and steps requested before a contract |
| Prepare and fulfil an order | Order, customisation, address and communication data | Contract and pre-contractual steps |
| Process and document payment | Amount, status and payment identifiers | Contract and legal obligations |
| Customer care, defects and disputes | Messages, order history and evidence | Contract, legal obligations and legitimate interests |
| Prevent fraud and protect the service | Technical, session and security data | Legitimate interests in service and information security |
| Send optional newsletters | Email and consent record | Consent |
| Accounting and official requests | Order, payment and identity records | Legal obligations |
We do not use your data for solely automated decisions that produce legal or similarly significant effects for you.
04 · Service providers
Sharing and international transfers
Data is shared only when needed with categories of recipients such as:
- website, database, file-storage and security providers;
- Stripe and other payment infrastructure used to complete a payment;
- email providers used for account and order notifications;
- postal and parcel carriers used to deliver an order;
- accountants, professional advisers, insurers or public authorities where legally necessary.
Some providers may process data outside the European Economic Area. Where this occurs, we use a lawful transfer mechanism, such as an adequacy decision or approved contractual safeguards, as applicable. Each independent provider also applies its own privacy terms.
We do not sell personal data.
05 · How long
Retention
We retain data according to the following criteria:
- account data while the account remains active and for a limited period afterwards where needed for legal claims;
- order, payment and accounting records for the periods required by Finnish accounting, tax and consumer law;
- order chats and customer-service records while needed to fulfil the order, handle defects or establish legal claims;
- newsletter data until consent is withdrawn or the mailing list is discontinued;
- technical and security logs only for the period reasonably needed to secure and troubleshoot the service.
Data may be retained longer if required by law, an authority, an unresolved complaint or a legal claim. When data is no longer needed, it is deleted or anonymised.
06 · Your device
Cookies and local storage
The website uses essential cookies and browser storage for functions such as sign-in, session renewal, cart identification, security and interface state. These technologies are required to provide the service requested by you.
The current website does not use advertising cookies or behavioural advertising. If non-essential analytics or marketing technologies are introduced later, this policy and the consent controls will be updated before they are activated.
07 · Your choices
Your data-protection rights
Subject to the conditions and limits in data-protection law, you may:
- request access to your personal data;
- request correction of inaccurate or incomplete data;
- request deletion or restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time, without affecting earlier lawful processing;
- object to direct marketing at any time.
Send a request to agafiagrace@gmail.com. We may need to verify your identity. Some records cannot be deleted immediately where retention is required by law.
You may lodge a complaint with the Finnish Office of the Data Protection Ombudsman at tietosuoja.fi, or with the competent supervisory authority in your country of residence or work.
08 · Protection
Security
We use access controls, protected authentication, encrypted transport, restricted administrative access, backups and service-provider safeguards appropriate to the nature of the data. No internet service can guarantee absolute security, but suspected incidents are investigated and handled under applicable notification requirements.
09 · Questions
Changes and contact
We may update this policy when the website, providers or legal requirements change. The current version and update date will remain available on this page.
Minivägen 3 A 3, 66950 Munsala, Finland
agafiagrace@gmail.com