Privacy Policy

Last updated: 5.6.2026

1. Data Controller

Ateljee Piccolo
Business ID: 3465221-8 / FI34652218
Address: Palokunnankatu 9, 13100 Hämeenlinna
Email: ateljeepiccolo@gmail.com

For any questions regarding this Privacy Policy or the processing of your personal data, please contact us using the details above.

2. What Personal Data We Collect

When you visit our website, place an order, subscribe to our newsletter, or contact us, we may collect the following personal data:

  • Name

  • Email address

  • Phone number

  • Billing address

  • Shipping address

  • Order and transaction information

  • Customer service communications

  • Newsletter subscription information

  • Technical information such as IP address, browser type, device information, and website usage data collected through cookies and similar technologies

We do not store or process payment card details directly. Payment information is handled securely by our payment service provider, Stripe.

3. How We Use Your Personal Data

We process personal data for the following purposes:

  • Processing and fulfilling orders

  • Delivering purchased products

  • Providing customer support

  • Managing payments and invoicing

  • Complying with legal obligations

  • Improving the functionality, security, and performance of our website

  • Sending newsletters and marketing communications where you have provided consent

4. Legal Basis for Processing

We process personal data based on one or more of the following legal grounds:

  • Performance of a contract when fulfilling orders and providing services

  • Compliance with legal obligations, including accounting and tax requirements

  • Legitimate interests, such as maintaining customer relationships and improving our business operations

  • Consent, where required, for example when subscribing to our newsletter

You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.

5. Newsletter and Marketing Communications

If you subscribe to our newsletter, we will use your email address to send updates, promotions, and other marketing content related to our products and services.

You can unsubscribe at any time by clicking the unsubscribe link included in our emails or by contacting us directly.

6. Sharing of Personal Data

We only share personal data when necessary for operating our business and fulfilling customer orders.

Squarespace

Our website and online store are hosted on Squarespace. Squarespace may process personal data on our behalf to provide website hosting, e-commerce functionality, and related services.

Stripe

Payments are processed through Stripe. Stripe receives and processes payment-related information in accordance with its own privacy practices and security standards.

Shipit

To arrange deliveries, we provide the necessary shipping information to Shipit. This may include your name, address, email address, and phone number. Shipit may share this information with the selected carrier solely for the purpose of delivering your order.

Service Providers

We may use additional service providers for website analytics, email communications, accounting, or business operations. These providers only process personal data as necessary to perform services on our behalf.

7. International Data Transfers

Some of our service providers, including Squarespace, Stripe, and email marketing providers, may process personal data outside the European Economic Area (EEA).

Where personal data is transferred internationally, appropriate safeguards are implemented in accordance with applicable data protection laws, including the use of Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms.

8. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy or as required by applicable law.

Information related to orders and accounting records may be retained for the period required under applicable accounting and tax legislation.

Newsletter subscription data is retained until you unsubscribe or request deletion.

9. Cookies

Our website uses cookies and similar technologies to ensure proper functionality, improve user experience, analyze website traffic, and support marketing activities.

You can control or disable cookies through your browser settings. Please note that some features of the website may not function properly if cookies are disabled.

10. Your Rights

Subject to applicable data protection laws, you have the right to:

  • Access your personal data

  • Request correction of inaccurate or incomplete data

  • Request deletion of your personal data

  • Request restriction of processing

  • Object to processing based on legitimate interests

  • Withdraw consent where processing is based on consent

  • Request a copy of your personal data in a portable format

  • Lodge a complaint with a supervisory authority

To exercise any of these rights, please contact us using the contact details provided above.

11. Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, misuse, alteration, or disclosure.

However, no method of transmission over the internet or electronic storage can be guaranteed to be completely secure.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements, business practices, or services.

Any updates will be posted on this page with the revised "Last updated" date.