Privacy policy

PRIVACY POLICY

Last updated: 18.02.2026

1. Data Controller

Company: Chroma Objects Oy
Business ID: 3597097-1
Email: chromaobjects@gmail.com
Registered office: Finland

Chroma Objects Oy is responsible for processing personal data in accordance with the EU General Data Protection Regulation (GDPR).


2. Personal Data We Collect

We collect only the personal data necessary to operate our business, including:

  • name

  • email address

  • postal address

  • phone number

  • order details and purchase history

  • payment-related information (processed by payment service providers)

  • IP address and cookie-related technical data

We do not collect sensitive personal data.


3. Purpose of Processing

Personal data is processed for the following purposes:

  • processing and delivering orders

  • customer service and communication

  • payment processing and invoicing

  • fulfilling legal obligations

  • developing and improving our webshop and services

  • marketing communications (with consent only)


4. Legal Basis for Processing

The processing of personal data is based on:

  • performance of a contract (online purchases)

  • compliance with legal obligations

  • consent of the data subject (e.g. email subscriptions)

  • legitimate interest (ensuring functionality and security of the webshop)


5. Data Retention

Personal data is retained only as long as necessary:

  • order and accounting data: as required by accounting legislation

  • customer data: for the duration of the customer relationship

  • marketing data: until consent is withdrawn


6. Disclosure and Data Transfers

Personal data may be disclosed only when necessary to:

  • payment service providers (e.g. Klarna)

  • logistics partners (e.g. Shipit)

  • e-commerce platform providers (Shopify)

  • accounting services and authorities as required by law

We do not sell or rent personal data to third parties.

Data may be transferred outside the EU/EEA only when adequate data protection safeguards are in place (e.g. Shopify).

Shopify acts as our e-commerce platform and processes personal data on our behalf.


7. Cookies

We use cookies to improve the functionality and user experience of our website. Cookies collect information about how the site is used.

You can manage cookie settings through your browser.


8. Your Rights

You have the right to:

  • access your personal data

  • request correction or deletion of data

  • restrict or object to processing

  • withdraw consent at any time

  • lodge a complaint with a data protection authority

Requests can be submitted by contacting the data controller via email.


9. Data Security

Personal data is protected using appropriate technical and organizational measures. Access is limited to authorized persons only.


10. Changes to This Policy

We reserve the right to update this Privacy Policy. The most current version will always be available on our website.