Privacy Notice
This Privacy Notice describes exclusively the customer register of the Alvar Aalto Foundation’s Johku-based online shop and the principles governing the processing of personal data contained therein.
We may update our data protection practices and this Privacy Notice from time to time. We therefore recommend reviewing our Privacy Policy regularly.
1. Data Controller
Alvar Aalto Foundation
Tiilimäki 20
FI-00330 Helsinki
shop@alvaraalto.fi
Business ID: 0714145-5
2. Person Responsible for the Register and/or Contact Person
Anna Salomaa
Alvar Aalto Foundation
+358 40 160 3147
shop@alvaraalto.fi
3. Name of the Register
Customer Register of the Alvar Aalto Foundation’s Johku Shop
4. Legal Basis and Purpose of Processing Personal Data / Purpose of the Register
The legal basis for the processing of personal data in accordance with the EU General Data Protection Regulation (GDPR) is a contractthat is concluded when a User orders products and/or services from the Merchant’s Johku-based online shop.
The purpose of this register is to enable online transactions through the Alvar Aalto Foundation’s Johku shop, such as the transmission of order data, invoicing data, payment confirmation data, and order processing data between the Merchant and the User.
In addition, the register is used to enable customer service contacts, to maintain customer relationships, and for electronic marketing communications where the User has given explicit consent.
The Alvar Aalto Foundation does not store, in any way, orders placed for products of other merchants or any data relating to such orders.
Personal data is not used for automated decision-making. The datamay be used for profiling.
5. Data Content of the Register
First and last name
Address
Postcode and city
Country
Telephone number
Email address
Order source page
In addition, the additional process information field allows the User to voluntarily provide other information they consider relevant.
Data Retention Period
Personal data is stored for as long as the User and the Alvar Aalto Foundation have a valid contractual relationship and/or consent.
Data may be retained longer where necessary to fulfil or demonstrate compliance with obligations imposed by applicable legislation, such as accounting and consumer protection laws.
6. Regular Sources of Data
Data is collected via electronic forms in the Johku service. Users enter their data personally when ordering from the Alvar Aalto Foundation’s Johku-based online shop.
7. Regular Disclosure of Data and Transfer Outside the EU or EEA
Personal data is not disclosed to third parties and remains solely with the Data Controller. Data may be technically processed outside the European Union or the European Economic Area.
8. Principles of Data Security
Due care is exercised in the processing of personal data, and all data processed through information systems is adequately protected. When personal data is stored on internet servers, appropriate physical and digital security measures are applied.
Access to stored data and server environments is restricted and granted only to authorised persons whose tasks require such access.
Electronically Stored Data
The register is hosted within the Johku service, and the Data Processor is Aptual Commerce Oy.
Full access to register data is limited to the Data Controller and authorised technical maintenance personnel of Aptual Commerce Oy.
More information about Johku’s Privacy Policy:
https://johku.fi/fi/tietosuoja
Manual Records
As a rule, personal data is not printed. If manual records are exceptionally created, they are stored securely in locked premises and accessible only to the Data Controller.
9. Right of Access and Implementation of the Right
Users have the right to access their personal data and to request correction of inaccurate or incomplete information.
These rights are implemented via the My Johku service, which makes the processing of personal data transparent to the User.
The My Johku service allows Users to:
review stored personal data
correct data
download data in a structured format for data portability
My Johku is available at:
https://johku.com/customer
If the User terminates their My Johku agreement, automated personal data management functions cease. After termination, all GDPR-related requests must be submitted in writing directly to the Alvar Aalto Foundation.
Requests are handled within the timeframe set out in the GDPR (generally within one month).
Use of the My Johku service is free of charge.
10. Other Rights Related to Personal Data Processing
Users have the right to request deletion of their personal data (“right to be forgotten”) and other rights provided under the GDPR, including restriction of processing.
Please note that customer data is created in connection with purchases. In such cases, statutory retention obligations under accounting and tax legislation apply.
11. Cookies
This website uses cookies. Cookies are small text files stored on the User’s device.
Both session cookies and persistent cookies are used to improve usability and manage login sessions for registered Users. Cookies may be used to analyse User interests and improve service functionality.
Disabling cookies may limit certain site features.
Third-party providers, including Google, may use cookies or web beacons to optimise advertising. Data collected via cookies does not contain personal data and cannot be linked to an identified individual.
Prepared: 31.3.2026