This privacy policy concerns the processing of personal data carried out by Zoner Oy, 1985221-1 (“Zoner”, “we”, or “us”) when you use our services, websites, or other digital channels. This privacy policy also covers the processing of personal data that we carry out in connection with marketing and customer communications.
This privacy policy does not apply to the processing of customers’ personal data that we carry out in the role of a processor on behalf of our customers, for example when delivering Zoner’s server solutions to our corporate customers. This privacy policy does not apply either when we process the personal data of domain name users in connection with the registration and management of domain names, which we carry out in the role of a processor on behalf of and in accordance with the instructions of the Finnish Transport and Communications Agency.
In this privacy policy, we describe how we collect, process, and share your personal data when acting as a data controller. Personal data means any information that can be used to identify you.
It is important to us that you feel safe about how we handle your personal data. We take all necessary measures to ensure that your personal data is protected and that the processing of your personal data is carried out in accordance with applicable data protection legislation and our internal policies.
Who is this privacy policy aimed at?
This privacy policy covers the following groups of data subjects:
- Users who use our websites and digital channels, such as Zoner’s social media channels.
- Private individuals, including sole traders, who order and use our services.
- Contact persons who act as a contact person or representative of a corporate customer.
- Partners who participate in Zoner’s affiliate programme.
How do we collect your personal data?
We collect your personal data in the following ways:
- Personal data that you provide to us yourself, for example when you provide your personal data when contacting us by email or phone, or when submitting information to us via surveys or forms on our website.
- Through automated means, for example when you use our services or visit our website, we automatically collect your online identifier data.
- From social media platform providers, for example when you visit our social media channels (e.g. Facebook or LinkedIn), we collect personal data that you provide in those channels.
- From third parties, for example data obtained from advertising networks and search data providers.
Why do we process your personal data?
In simplified terms, we process your personal data for the following purposes:
- Customer relationship management and service delivery.
- Marketing and communications.
- Management of websites and digital channels.
The purposes, circumstances, categories of personal data, and applicable legal bases for processing are set out in more detail below.
Customer relationship management and service delivery
| Purpose of processing | Context of processing | Categories of personal data | Legal basis |
| Customer relationship management. | Receiving orders, storing order and customer data, and managing contracts. | Basic and identification data, contact details, billing information, order data, additional information provided in communications. | Contract (private individuals): Processing is necessary for entering into or performing a contract between Zoner and the private individual. Legitimate interest (contact persons): Processing is necessary to pursue our legitimate interests related to customer relationship management. |
| Carrying out billing, debt collection, and receivables management. | Maintaining accounts receivable, including sending invoices and monitoring payments, and using a debt collection service when necessary. | Basic and identification data, contact details, order data, billing information, other financial data. | Contract (private individuals). Legitimate interest (contact persons): Processing is necessary to pursue our legitimate interests related to receivables management. |
| Providing and handling customer support. | Receiving customer support contacts, creating customer tickets, and communicating with the customer. | Basic and identification data, contact details, order data, service-specific customer data, additional information provided in communications. | Contract (private individuals). Legitimate interest (contact persons): Processing is necessary to pursue our legitimate interests related to providing and handling customer support. |
| Handling feedback, cancellations, and complaints. | Receiving feedback, cancellations, and complaints, creating customer tickets, investigating and resolving complaints, and communicating with the customer. | Basic and identification data, contact details, service-specific customer data, additional information provided in communications, billing information, other financial data. | Contract (private individuals). Legitimate interest (contact persons): Processing is necessary to pursue our legitimate interests related to handling feedback, cancellations, and complaints. |
| Maintaining the Zoner Home service and managing user accounts. | Processing personal data related to maintaining and ensuring the security of the Zoner Home service. | Basic and identification data, log data, online identifier data. | Contract (private individuals). Legitimate interest (contact persons): Processing is necessary to pursue our legitimate interests related to maintaining the Zoner Home service and managing user accounts. |
| Offering and operating the affiliate programme. | Receiving and storing partner applications, verifying that commission requirements are met, paying commissions. | Basic and identification data, contact details, order data, billing information, payment data. | Contract (private individuals). Legitimate interest (contact persons): Processing is necessary to pursue our legitimate interests related to offering and operating the affiliate programme. |
Marketing and communications
| Purpose of processing | Context of processing | Categories of personal data | Legal basis |
| Electronic marketing communications to customers regarding services in the same product category as the products they have ordered. | Sending newsletters or other electronic marketing communications to customers regarding services in the same product category. | Basic and identification data, contact details, data related to opening communications, opt-out consent data. | Legitimate interest: Processing is necessary to pursue our legitimate interests related to marketing. |
| General marketing communications. | Sending newsletters or other electronic marketing communications to customers regarding services in different product categories. | Basic and identification data, contact details, data related to opening communications, opt-out consent data. | Consent: We process your data for this purpose only if you have given us your explicit consent. |
| Telephone marketing to promote sales. | Contacting customers and potential customers by phone to promote sales. | Basic and identification data, contact details, order data, opt-out consent data. | Legitimate interest: Processing is necessary to pursue our legitimate interests related to marketing. |
| Conducting customer surveys. | Sending surveys, receiving and evaluating survey results. | Basic and identification data, information provided in communications, contact details. | Legitimate interest: Processing is necessary to pursue our legitimate interests related to organising competitions and prize draws, and promoting the Zoner brand. |
Websites and digital channels
| Purpose of processing | Context of processing | Categories of personal data | Legal basis |
| Maintaining social media channels and communicating on social media to promote the Zoner brand. | Maintaining social media channels and communicating with followers. | Basic and identification data, information provided in communications, social media profile and activity. | Legitimate interest: Processing is necessary to pursue our legitimate interests related to maintaining social media channels, communications, and promoting the Zoner brand. |
| Ensuring the functioning and security of the website and fulfilling requests made by users. | Ensuring the basic security of the website and fulfilling user requests, including placing necessary cookies on the user’s device. | Online identifier data, log data. | Legitimate interest: Processing is necessary to pursue our legitimate interests related to ensuring the functioning and security of the website. |
| Measuring and developing the use of the website. | Placing analytical and statistical cookies on the user’s device. Cookies are used to measure and develop the use of the website. | Online identifier data. | Consent: Placing analytical and statistical cookies is based on the user’s consent. |
| Providing enhanced functionality and personalised content on the website. | Placing preference cookies on the user’s device. Cookies are used to tailor the website for a specific user. | Online identifier data. | Consent: Placing preference cookies is based on the user’s consent. |
| Providing relevant advertising on the website and elsewhere online. | Placing marketing cookies on the user’s device. Cookies are used to track users so that advertising partners can target their marketing with relevant and interesting advertisements. | Online identifier data. | Consent: Placing marketing cookies on the user’s device is based on the user’s consent. |
Recipients with whom we share your personal data
Where necessary, we also share your personal data with other parties. We distinguish between recipients of your personal data within the One.com group, service providers, and other recipients. Service providers are processors who process personal data on Zoner’s behalf for the purposes set out in this privacy policy. Other recipients who may receive your personal data are controllers and process personal data for their own purposes.
We may share your personal data with the following recipients:
One.com group
We may share your personal data with other entities within the One.com group where necessary, in which case those entities will process your personal data on our behalf. This includes (i) our support centres located in the Philippines, Sweden, Norway, the Netherlands, and Denmark, (ii) our server facilities located in Denmark and Norway, and (iii) system operations in Denmark and India. Our support centres process your customer data if your support request is directed to one of these centres. Our data centres are the locations where website data is stored.
Service providers
We use various service providers to fulfil the processing purposes set out in this privacy policy. Service providers process your personal data on our behalf and we are responsible for the actions of the service providers we use when processing personal data. These service providers may vary but include marketing, communications, information security, infrastructure, and IT services. Service providers may only process personal data in accordance with the instructions we have given them and for the purposes set out in this privacy policy.
Other recipients
Where necessary, we also share your personal data with other recipients who act as controllers in their own right when processing your personal data. Examples of other recipients include social media platforms, external advisors (e.g. auditors and law firms), authorities, courts, and buyers or sellers in connection with possible corporate transactions.
Where do we process your personal data?
Some service providers and other recipients of personal data may store data outside the EU or the European Economic Area. To ensure the adequate protection of your personal data, we ensure that appropriate safeguards are in place for those recipients who process your personal data outside the European Union/European Economic Area. Such safeguards include in particular the European Commission’s standard contractual clauses and adequacy decisions. If you have questions about the countries to which your personal data is transferred and the safeguards we use to protect your personal data, please contact us at tietosuoja@zoner.fi.
How long do we process your personal data?
Based on applicable statutory obligations, Zoner is required to retain certain personal data for the minimum period required. For example, data belonging to the accounting voucher material must be retained for the minimum period required by the Accounting Act (the current year and the following 6 years). In other respects, we retain personal data only for as long as is necessary for the purpose of each processing activity set out in this privacy policy. After this point, we delete the personal data unless we need to retain it for the establishment, exercise, or defence of legal claims. For more detailed information about personal data retention periods, please contact us at tietosuoja@zoner.fi.
Automated decision-making and profiling
We may use automated decision-making, including profiling, for example to target marketing online or to develop the user experience of our services. Based on your online browsing behaviour or orders you have made as a customer, we may classify you into a certain group based on what types of products or services we consider you to be interested in. We consider that the automated decision-making and profiling we carry out does not produce legal effects or otherwise significantly affect you within the meaning of data protection legislation.
Please read our cookie policy.
Your rights
Under data protection legislation, you have certain rights in relation to the processing of your personal data. To exercise your rights, please contact us at tietosuoja@zoner.fi. You have the right to:
Access your personal data
You have the right to access the personal data relating to you that we process. We will provide you with this information unless we have a legal reason not to share the data, or if sharing the data would adversely affect the rights and freedoms of third parties.
Update your personal data
You have the right to request the correction or completion of inaccurate or incomplete personal data.
Withdraw your consent
To the extent that we process personal data based on your consent, you have the right to withdraw your consent at any time.
You can withdraw your consent to marketing communications via the unsubscribe link in our messages or on the My details page in the Zoner Home control panel.
You can withdraw your consent to the use of cookies in Zoner’s Cookie settings, which can be opened by clicking the icon visible in the bottom left corner of the page.
Object to the processing of personal data
You have the right to object to the processing of personal data processed on the basis of legitimate interest on grounds relating to your particular personal situation. In this case, we will stop processing the personal data unless we can demonstrate that our legitimate interest overrides your data protection interests, rights, and freedoms, or that the use of your personal data is necessary for the establishment, exercise, or defence of a legal claim.
In addition, if we process your personal data for direct marketing purposes, you have the right to object at any time to the processing of personal data relating to you for such marketing purposes, including profiling.
Have your personal data deleted
In certain circumstances, you have the right to request the deletion of your personal data. However, we cannot delete your personal data if, for example, the law requires us to retain the data or if we need the data for the establishment, exercise, or defence of a legal claim.
Restrict the processing of your personal data
In certain circumstances, you have the right to request that the processing of your personal data be restricted. If the processing of your personal data is restricted, we may, in addition to storing the personal data, only process it on the basis of your consent, for the establishment, exercise, or defence of a legal claim, or to protect the rights of a third party.
Data portability
You have the right to request a copy of the personal data we hold about you in a structured, commonly used, and machine-readable format (data portability). Unlike the right to access, the right to data portability only covers personal data that you have provided to us yourself or that we process on the basis of certain legal grounds, such as your consent.
Lodge a complaint with a supervisory authority
If you consider that we are processing your personal data in violation of data protection legislation, or if you are not satisfied with how we respond to a request to exercise your rights, you may lodge a complaint with the competent supervisory authority in Finland. The contact details of the competent supervisory authority can be found here.
We may update this privacy policy
We may periodically update the information provided in this privacy policy if, for example, we process personal data for new purposes or share personal data with new recipients. In such cases, we will inform you of the update in an appropriate manner. The most recent version of this privacy policy or its contents will always be published on Zoner’s website.
Contact us
If you have any questions about the processing of your personal data, please contact us. You will find our contact details below.
Zoner Oy
Pakkalankuja 6
01510 Vantaa
tietosuoja@zoner.fi