Privacy and Cookie Policy

Privacy and Cookie Policy

Last updated: 31 August 2026

This privacy and cookie policy explains how Versatile Idea Oy processes personal data in its online shop, physical sales, courses, customer service and other business activities.

1. Controller and contact details

Versatile Idea Oy
Business ID: 2454349-9
Jokiniementie 46 B 96
00650 Helsinki
Finland
Email: info@versatile.fi

Please use the email address above for questions or requests concerning your personal data.

2. Whose personal data we process

We may process personal data relating to:

  • online-shop and physical-store customers;
  • people who create an account, wishlist, product alert or product review;
  • course participants and people enquiring about our products or services;
  • recipients of deliveries, where someone orders a product for another person;
  • business customers, suppliers and their contact persons; and
  • visitors to our website.

3. Personal data we process

Depending on how you interact with us, we may process:

  • identification and contact details, such as your name, postal address, email address and telephone number;
  • account information, login credentials in protected form, language preferences, wishlists and product alerts;
  • order, payment, invoicing, delivery, return, withdrawal, refund and transaction information;
  • course registrations and information needed to arrange the course;
  • communications, form submissions, feedback, product reviews and other information you provide to us;
  • marketing choices and records of consent or objection;
  • technical information, such as IP address, browser and device type, timestamps, referring page and security logs; and
  • consent-based website usage statistics described below.

We do not receive or store complete payment-card details from Visma Pay or Zettle by PayPal.

4. Purposes and legal bases

Purpose Legal basis
Processing orders, payments, deliveries, returns, withdrawals, refunds, course bookings and other requested services Performance of a contract or steps taken at your request before entering into a contract
Creating and maintaining customer accounts, wishlists and product alerts Performance of the requested service; consent where required
Customer service, enquiries, feedback and management of the customer relationship Contract and our legitimate interest in providing customer service and managing our business relationships
Accounting, taxation, payment records and compliance with official requests Compliance with legal obligations
Preventing fraud, protecting accounts, maintaining website security, troubleshooting and establishing or defending legal claims Our legitimate interests in protecting our customers, systems, rights and business
Publishing a product review submitted for publication Our legitimate interest in presenting genuine customer feedback; consent where required
Electronic direct marketing and non-essential website analytics Consent, except where applicable law permits communication to an existing customer and an easy right to object is provided

Where processing is based on our legitimate interests, we balance those interests against your rights and reasonable expectations. You may object to such processing as explained in section 10.

5. Where the data come from

We normally receive personal data directly from you when you place an order, use our website, make a payment, register for a course, complete a form, visit our shop or contact us. We may also receive data from:

  • a person who names you as the recipient of a delivery;
  • payment providers, to confirm the status of a payment;
  • Shipit and transport companies, to provide delivery and tracking information;
  • public authorities or publicly available business registers where necessary; and
  • our systems when they generate transaction, consent and security records.

6. Recipients and service providers

We disclose personal data only where necessary for the purposes described in this policy. Recipients and service providers may include:

  • Visma Payments Oy (Visma Pay) and the payment method selected by the customer, for online payment processing;
  • Zettle by PayPal / PayPal Point of Sale, for payments made at our physical point of sale;
  • Shipit and the selected transport company, for delivery, customs requirements where applicable, and shipment communications;
  • Finago Procountor and our accounting service providers, for financial management, invoicing, accounting and statutory reporting;
  • Zoho Forms, for information submitted through our online forms;
  • Zoho Mail, for email and transactional messages sent through our SMTP service;
  • UpCloud Oy, which provides the server infrastructure used for our online shop and self-hosted analytics;
  • IT maintenance and professional advisers where access is necessary and appropriately protected; and
  • public authorities where disclosure is required by law.

Some recipients, particularly payment providers and transport companies, also process personal data as independent controllers for their own statutory and operational purposes. Their own privacy notices provide further information about that processing.

7. Transfers outside the European Economic Area

Our online shop currently accepts deliveries only to European Union countries. Nevertheless, some service providers or their subcontractors may process personal data outside the European Economic Area.

Where personal data are transferred outside the European Economic Area, the transfer must be protected by a lawful transfer mechanism. Depending on the provider and destination, this may be an adequacy decision adopted by the European Commission, the European Commission's standard contractual clauses, or another safeguard permitted by data protection law. Further information about applicable safeguards is available from us on request.

8. Retention periods

We retain personal data only for as long as necessary for the relevant purpose or legal obligation. Our normal retention periods are:

  • Orders and associated customer, payment, delivery, return and refund records: six years from the end of the year in which the relevant financial year ended.
  • Accounting vouchers and transaction correspondence: at least six years from the end of the year in which the financial year ended.
  • Financial statements, accounting records, chart of accounts and lists of accounting materials: at least ten years from the end of the financial year.
  • Customer accounts without orders: normally deleted or anonymised after three years of inactivity.
  • Customer accounts connected with orders: account access may be removed earlier, while information required for order history, accounting or legal claims is retained for the applicable six-year period.
  • Enquiries, Zoho Forms submissions and ordinary correspondence: normally two years after the matter has concluded. Information connected with a contract, accounting obligation or dispute may be retained for the corresponding longer period.
  • Course registrations: normally two years after the course; transaction and accounting information is retained for six years.
  • Wishlists and product alerts: until deleted or unsubscribed, or after three years of inactivity.
  • Product reviews: for as long as the review remains relevant and published, or until a justified deletion request is made. Information needed to investigate misuse or a dispute may be retained for longer.
  • Marketing information: until consent is withdrawn or you object. We may retain a minimal suppression record to ensure that the objection continues to be respected.
  • Apache website access and error logs: normally 14 days. Relevant extracts may be retained longer where necessary to investigate a security incident or establish, exercise or defend legal claims.
  • Matomo raw visitor data: 180 days.
  • Matomo aggregated reports: 12 months.

A longer retention period may apply where required by law, an authority, an unresolved complaint or the establishment, exercise or defence of legal claims. Data are deleted or anonymised when there is no longer a lawful reason to retain them.

9. Cookies, analytics and external content

Necessary cookies

Necessary cookies support functions requested by the user, including navigation, language selection, account login, shopping cart, checkout, security and storage of cookie choices. These cookies do not require consent when they are used only for a function explicitly requested by the user.

Matomo analytics

We use a self-hosted installation of Matomo to understand how the website is used and to improve its content and performance. Matomo analytics run only after you consent to statistics cookies. The analytics service is hosted on infrastructure controlled by us, and analytics data are not disclosed to the developer of Matomo merely because we use its software.

Matomo may process information such as a shortened or otherwise privacy-protected IP address, approximate location, browser and device type, referring page, pages visited and visit times. We configure Matomo to minimise the collection of identifying information. Raw visitor data are deleted after 180 days and aggregated reports after 12 months.

YouTube and interactive maps

Pages containing a YouTube video or an interactive map display a placeholder before external content is loaded. Data are sent to the external provider only after you choose to load that content. The provider may then receive information such as your IP address, browser information, the page visited and any information its cookies or account session make available.

Our interactive map uses OpenStreetMap map data. Map tiles may be supplied by the OpenStreetMap Foundation or another map-tile provider identified when the map is loaded. The map displays the attribution required by the map-data and tile provider.

Managing consent

You can accept or reject non-essential cookies separately in the cookie settings. You can also reopen those settings and withdraw consent at any time. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal. Blocking necessary cookies may prevent requested shop functions from working correctly.

The cookie settings show the current cookie names, providers, purposes and lifetimes used on this website.

10. Your data protection rights

Subject to the conditions and limitations in data protection law, you have the right to:

  • obtain confirmation of whether we process your personal data and receive a copy of those data;
  • have inaccurate or incomplete personal data corrected;
  • request deletion of personal data that we no longer have a lawful reason to retain;
  • request restriction of processing in the circumstances provided by law;
  • receive personal data you provided to us in a structured, commonly used and machine-readable format where the right to data portability applies;
  • object to processing based on legitimate interests, including objecting at any time to direct marketing;
  • withdraw consent at any time where processing is based on consent; and
  • lodge a complaint with a supervisory authority.

In Finland, the supervisory authority is the Office of the Data Protection Ombudsman: tietosuoja.fi.

To exercise your rights, email info@versatile.fi. We may ask for information necessary to verify your identity. We normally respond within one month, subject to the extensions permitted by law.

11. Required information and consequences of not providing it

Information marked as required during checkout, registration or another transaction is needed to provide the requested service or comply with law. If you do not provide it, we may be unable to create an account, enter into or perform a contract, process payment, deliver an order or respond to the request. Optional information can be left blank.

12. Automated decision-making

We do not use personal data to make decisions based solely on automated processing that produce legal or similarly significant effects. We do not use personal data for automated profiling.

13. Security

We protect personal data using appropriate technical and organisational measures. These include encrypted connections, access controls, user-specific credentials, software updates, backups, server and network protections, limited staff access and contractual safeguards with service providers. No online service can guarantee absolute security.

14. Changes to this policy

We may update this policy when our processing, service providers or legal obligations change. The current version and its update date are published on this page. Material changes will be highlighted where appropriate.

Cookie consent