Stakeholder privacy policy

Updated October 26, 2020

We at Fiskars Group are committed to protecting the privacy of our stakeholders’ personal data. By “stakeholder” we mean you as a representative of our vendor, supplier, customer or any other co-operation partner (also, “your company”) of Fiskars. This Privacy Policy informs you how Fiskars Corporation and its EU/EEA group companies (hereinafter “Fiskars”, “we”, “us” and “our”) process your personal data as a Fiskars stakeholder. For the purposes of this Policy, Fiskars is the controller. This Privacy Policy concerns all processing of stakeholders’ personal data, in connection to which this Privacy Policy is visible.

We recommend that you read this Privacy Policy carefully as it provides important information about personal data and other information that we collect.

These definitions have the following meaning in this Privacy Policy:

  • controller” means the entity that decides how and why personal data are processed.
  • personal data” means any information relating to an identified or identifiable natural person; an identifiable person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that person.
  • process”, “processing” or “processed” means anything that is done with any personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
  • “processor” means any person or entity that processes personal data on behalf of the Controller (other than employees of the Controller).

1. Lawful basis of processing

We collect your personal data based on one or many of the following legal bases:

  • we have a legal obligation which obliges us to process your data;
  • we have a legitimate interest in carrying out the processing for the purpose of managing, operating or promoting our business, and that legitimate interest is not overridden by your interests, fundamental rights, or freedoms (“legitimate interests”); or
  • where you have given your consent to processing of your personal data
  • the processing is necessary in connection with any contract between Fiskars and you (“contractual necessity”).

2. Personal data we collect

We may collect personal data either directly from you, indirectly from your company or its representatives, indirectly from your or your company’s stakeholders, automatically from your devices that interact with our services, or from third party sources as described below.

Information collected directly from you:

  • Contact details: your name, email address(es), telephone number, postal address;
  • Demographic information: gender, date of birth or age, language, title or degree;
  • Any consents, communications and feedback that you provide to us;
  • Work-related information provided by you: company/employer’s name and contact details;
  • Social media profiles.

Information collected when our websites or other services are used:

  • Your user account identity and registration date (if you are logged in);
  • Your browser, operating system, device model, IP-address, time of access and duration of access;
  • Cookies and other identification tags; and
  • Other information collected based on your consent.

Information collected from other sources:

  • If you or your company have connected to any Fiskars website, service or social media channel using your social media profile(s), we may collect the public information available on your social media profile(s);
  • We may collect your data from public websites, business cards, electronic communication footer information;
  • We may collect information from public registers, if such registers are available in your country, or purchase similar information collected by third parties;
  • Updated delivery and contact information from delivery agents.

3. How Fiskars uses your personal data

As you are in a position of our stakeholder, we use your personal data to establish and maintain business relationship between you, your company and us. In this respect, we may use your personal data for the following purposes:

  • Offering, selling and delivering products as well as planning, supporting and maintaining marketing activities
  • Invoice processing, sourcing, purchasing and contract management activities
  • Other activities we may deem reasonable for creating or nurturing a business relationship between you, your company and Fiskars
  • Product and services development and anonymized reporting
  • Detection, investigation and prevention of unlawful activities
  • Identifying users, for example any external persons visiting our premises

4. How long is your data stored

Your data is stored as long as it is necessary for the purposes of processing it i.e. as long as there is a valid contract or consent between you or your company and Fiskars (unless your employment at the company ends, in which case we may delete your data as soon as we receive information on your departure and the processing of your data is no longer necessary); or we have otherwise a meaningful business relationship or business prospects with your company; plus, the applicable period for limitation of legal claims, and any additional periods required or permitted under applicable law.

5. How we disclose your personal data to other parties

We disclose your personal data only to the parties indicated below and for the following reasons only:

  • Affiliates and third party processors. We may disclose your personal data to Fiskars group companies and authorized third party vendors who process the data for us. All such processing is based on our prior instructions set out in a binding contract that is compliant with the requirements of applicable law, and is conducted in accordance with this Privacy Policy. These authorized third parties are not permitted to use your personal data for any other purposes than those described in this Privacy Policy and they are required to keep your personal data strictly confidential.
  • International transfers. Our services may be provided using resources and servers located in various countries, partly located outside of EU/EEA. In the event that your personal data are transferred outside of EU/EEA, we will ensure that any such transfer is covered by appropriate contractual measures (e.g., using European Commissions Standard Contractual Clauses), that the transfer has an appropriate legal basis, and that the data processing and confidentiality fulfills the requirements in relevant laws. You may obtain a copy of the relevant Standard Contractual Clauses (where applicable) by contacting our Customer Service Team.
  • Lawful requests. We may be required by the binding requirements of applicable law, or for the purposes of responding to legal proceedings or other lawful requests to disclose your personal data to authorities or third parties.
  • Protection of our interests and combating fraud. We may also disclose or otherwise process your personal data, in accordance with applicable law, to defend our legitimate interests (for example, in civil or criminal legal proceedings) and when combating fraud.
  • Mergers and acquisitions. In the event of any sale, consolidation or reorganization of our businesses (for example mergers and acquisitions), we may disclose your personal data to prospective or actual purchasers or their advisers, where appropriate.

6. Steps taken to safeguard the personal data

We have implemented appropriate technical and organizational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, unauthorized access, and other unlawful or unauthorized forms of processing, in accordance with applicable law.

We maintain a variety of physical, electronic, and procedural safeguards to guard your personally identifiable information. Specifically, we use commercially accepted procedures and systems to protect against unauthorized access to our systems. Only our appointed personnel and third party companies operating on behalf of us or on our assignment (referred to as “Authorized Third Parties”) are entitled to access or process your personal data.

All persons processing such data must receive individual accreditation. Different levels of access have been created based on the type of data a person needs to access or process according to his/her job description. Our systems are fire-wall protected. Manually stored and processed documents which may contain your personal data are stored in locked and fireproof premises. Only specifically authorized personnel of ours or Authorized Third Parties are entitled to access such premises or process such data. All Fiskars personnel or personnel from Authorized Third Parties who are granted access to your personal data are required to keep such data confidential.

Unfortunately, the transmission of information via the internet is never completely secure. Although we will implement all reasonable measures to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.

7. Actions you can take in regard to the processing

We hope to ensure that the personal data we possess are accurate at all times and therefore we encourage you to update your information in your own account in case any changes have occurred. We have listed below the rights that you may be able to exercise in respect of the processing of your personal data, subject to applicable law. We take every reasonable step to ensure that the personal data that we process are limited to the personal data that are reasonably required in connection with the purposes set out in this Privacy Policy.

Please note that upon exercising any of the rights listed below, you may be requested to provide additional information for identification purposes. Such additional information shall not be used for any other purpose and will be removed after successful identification.

  • Providing your data: You may choose not to provide your personal data to us. It should be noted that some features of our websites and other services may not be fully available to you if you choose not to provide us with your personal data (e.g., we may not be able to process your orders without the necessary details).
  • Right of access: You may have the right to request access to, or copies of, your personal data, together with information regarding the nature, processing and disclosure of those data.
  • Unsubscribing: We include an unsubscribe link in all electronic marketing messages we send to you. You may withdraw your consent to direct marketing at any time. If you do so, we will promptly update our databases, and will not send you further direct marketing, but we may continue to contact you to the extent necessary for the purposes of any products or services you have requested.
  • Checking and editing your personal data: Should you have an online user account, you may edit and complete your personal data directly yourself. If you do not have an online user account, you may contact our Customer Service team using the details provided in Section 9 below, who will upon your request as soon as possible rectify, remove or complete the information which is incorrect, unnecessary, lacking or outdated.
  • Blocking and deleting cookies: You may block the cookies using your browser settings. Please note that blocking the cookies may affect the usability of our websites. You may also delete the cookies from your browser via its settings, in which case the information collected by the previous cookie will not affect the account created based on the information collected after such deletion.
  • Allowing use of location data: You may give your consent to the use of location data in the options of the device or the application. You may also withdraw such consent at any time from the options menu in your account, or by contacting our Customer Service team.
  • Erasure, or restriction of our processing, of your data: Should you believe that we process your data which is not accurate; the processing is illegal; we are not processing your data in accordance with the processing purpose or you want to oppose the processing, you may contact our Customer Service team to request the erasure, or restrictions on the processing, of your data. Please note that we will investigate your request reasonably promptly, before deciding what action to take.
  • Right to object: You may have the right to object, on legitimate grounds, to the processing of your personal data.
  • Withdrawing your consent. You may at any time decide to withdraw your consent to the processing of your personal data. If your consent is withdrawn, it does not prevent us from processing your personal data based on other legal bases, such as fulfilling your orders and storing your order data as required by applicable law. However, it should be noted that your account(s) on our web store(s) will be removed, and advantages granted to you via your account will be reset. Please note that withdrawal of consent does not affect the lawfulness of any processing performed prior to the date on which we receive notice of such withdrawal.
  • Right to data portability: You may have the right to have your personal data transferred to another controller, in a structured, commonly used and machine-readable format, to the extent applicable.
  • Lodging a claim with a supervisory authority: Should you believe that our processing of your personal data infringes your legal rights, you may lodge a claim with your local supervisory authority. Please do see a list for supervisory authorities’ websites here.

8. Changes to this Privacy Policy

Fiskars reserves the right to change and modify this Privacy Policy from time to time. When we post changes to this Privacy Policy we will modify the “Effective Date” at the top of this Privacy Policy to indicate when such changes have come into effect.

If the changes are material and affect you in an adverse way, Fiskars will inform you with an email and prominently post a notice advising of such change at the beginning of this Privacy Policy and on our websites home page.

9. Our contact point

n general privacy issues, in issues relating to your account or to opt out from marketing messages, please contact our customer service.