Last update: May 16, 2019
1. ABOUT THIS POLICY
At Oura Health Oy (“Oura”), we take data protection seriously.
• What personal data we collect when you browse or make purchases on this site
• How we may use and share your personal data
• Your legal rights and how to exercise them
2. OUR CONTACT INFORMATION
Oura Health Oy
Business ID: 25427764
Address: Elektroniikkatie 10 90590 Oulu Finland
E-mail address: firstname.lastname@example.org
Data Protection Officer: Markku Koskela, email@example.com
3. WHAT PERSONAL DATA DO WE PROCESS?
The data collected on this site can be categorized into two groups: Customer data and Analytics data.
Although we do not normally use Analytics data to identify individuals, sometimes individuals can be recognized from it, either alone or when combined or linked with Customer data. In such situations, Analytics data shall also be considered to be personal data under applicable laws and we will treat the combined data as personal data.
Please note that payment information is processed by a third party payment service provider.
Oura may collect and process the following Customer data:
• Your name and contact details
• Phone number
• E-mail address
• Possible communication with us
• Invoicing and billing information
• Possible claims or refunds
• Delivery information and delivery status
• Your purchases on this site (item and value)
• Chosen payment method
• Possible use of discount or campaign codes;
• Direct marketing opt-outs and opt-ins
We may also process details about your interaction with our emails (such as whether the email is opened and which links are clicked in the email).
Analytics data may include for example the following data:
• IP address
• Device type
• Operating system
• Firmware version of the ring
• Bluetooth ID of the ring
• Time of visit
• Search terms used to reach our websites
• Browser type and version • Browsing patterns on the site • Unique cookie identifiers • Language settings
4. DATA SOURCES
Your Customer data is primarily received directly from you in connection with your registration or in connection with completing a purchase in our online store. We may also receive data directly from you if you contact us with a question or complaint.
Analytics data is automatically collected when you visit the site. We may also track transactions data as well as details of your browsing patterns on the site.
5. PURPOSES AND LEGITIMATE GROUNDS FOR PROCESSING
Purposes of processing
Processing and delivering your orders
We process personal data in the first place to process, handle and send your orders and to facilitate your shopping.
We may process personal data for the purpose of communicating with Customers. If you contact our customer service, we will use the provided information to answer your questions and for solving any issues you may have.
Analytics and service improvements
We may process information regarding the use of our site to improve our service quality. This may involve the use of analytics or the assessment of any trends on our website and in our online store. When possible, we will do this using only aggregated, non-personally identifiable data.
With your consent we may send you marketing material, such as newsletters or offers.
Legal grounds for processing
We process personal data to perform our contractual obligations towards Customers or to facilitate their entry into a contract at their request. We also process certain information to comply with legal obligations, such as accounting legislation.
Furthermore, we process personal data to pursue our legitimate interest to run, maintain and develop our business, for analytics and trend detection, direct marketing and to create and maintain customer relationships. We may also process data for responding to consumer claims, cases regarding product warranty and similar situations. When choosing to use your data on the basis of our legitimate interests, we carefully weigh our own interests against your right to privacy.
6. COOKIES AND ANALYTICS
The cookies we use include both first party and third party cookies.
Web analytics services and other online tools
Hotjar is used on the site for tracking the cursor movements and keypresses of website visitors and for the collection of associated visitor analytics.
Klaviyo is used for ecommerce targeting, tracking of email interactions and online marketing. Klaviyo can, for example, be used to follow up on emails and for enabling us to see whether an email has been opened by the recipient or not.
For more information and directions for opting out, please see the privacy policies of the service providers linked above.
7. DATA TRANSFERS TO COUNTRIES OUTSIDE EEA
Oura stores the Customers’ personal data primarily within the European Economic Area.
However, we have service providers in several geographical locations. As such, we or our service providers may transfer personal data to, or access it in, jurisdictions outside the European Economic Area or the Customer’s domicile.
We will take steps to ensure that the Customers’ personal data receives an adequate level of protection in the jurisdictions in which it is processed. We provide adequate protection for the transfers of personal data to countries outside of the European Economic Area through a series of agreements with our service providers based on the Standard Contractual Clauses or other similar arrangements.
8. SHARING YOUR PERSONAL DATA
For legal reasons
We may share personal data with third parties outside Oura’s organization if we have a good-faith belief that access to and use of the personal data is reasonably necessary to: (i) meet any applicable law, regulation, and/or court order; (ii) detect, prevent, or otherwise address fraud, security or technical issues; and/or (iii) protect the interests or safety of Oura or our Customers in accordance with the law. Where possible, we will inform Customers about such transfer and processing.
To our authorized service providers
For other legitimate reasons
With your explicit consent
We may share personal data with third parties outside Oura’s organization for other reasons than the ones mentioned before, when we have the Customer’s explicit consent to do so. You have the right to withdraw this consent at all times.
9. HOW LONG DO WE KEEP YOUR DATA?
Oura does not store personal data longer than is legally permitted and necessary for the purposes specified above. The storage period depends on the nature of the information and the purposes of processing. The maximum period may therefore vary per use.
Storage periods reflect the time frames we may need data for accounting, claims handling, internal reporting or reconciliation purposes.
10. YOUR RIGHTS
Right to access
You have the right to access your personal data processed by us. You may contact us and we will inform you what personal data we have collected and processed regarding you.
Right to withdraw consent
In case the processing is based on your consent, you may withdraw the consent at any time. Withdrawing a consent may lead to fewer possibilities to use our site and online store. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
Right to correct
Customers have the right to have incorrect or incomplete personal data we have stored about the Customer corrected or completed. You can correct or update some of your personal data through your account.
Right to erasure
Customers may also ask us to erase the Customer’s personal data from our systems. We will comply with such request unless we have a legitimate ground to not delete the data.
Right to object
Customers may object to the processing of personal data if such data are processed for other purposes than purposes necessary for the provision of the site and online store to the Customer or for compliance with a legal obligation. In case we do not have legitimate grounds to continue processing such personal data, we shall no longer process the personal data after your objection.
Right to restriction of processing
Customers may request us to restrict processing of personal data for example when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. This may however lead to fewer possibilities to use our site.
Right to data portability
Customers have the right to receive their personal data from us in a structured and commonly used format and to independently transmit those data to a third party.
How to use the rights
The above mentioned rights may be used by sending a letter or an e-mail to us on the addresses set out above, including the following information: the full name, company name, address, e-mail address and a phone number. We may request the provision of additional information necessary to confirm the identity of the Customer. We may reject requests that are unreasonably repetitive, excessive or manifestly unfounded.
11. DIRECT MARKETING
Notwithstanding any consent granted beforehand for the purposes of direct marketing, you have the right to prohibit us from using your personal data for direct marketing purposes by contacting us or by using the unsubscribe possibility offered in connection with our newsletter.
12. SAFEGUARDING YOUR DATA
We do our best to keep your data safe and secure. We use administrative, organizational, technical, and physical safeguards to protect the personal data we collect and process. Measures may include, for example, where appropriate, encryption, pseudonymization and access right systems. Our security controls are designed to maintain an appropriate level of data confidentiality, integrity, availability, resilience and ability restore the data. We regularly test our systems, and other assets for security vulnerabilities.
Should despite of the security measures, a security breach occur that is likely to have negative effects to your privacy, we will inform you and relevant authorities as required by applicable data protection laws.
13. LODGING A COMPLAINT
In case you consider our processing of personal data to be inconsistent with the applicable data protection laws, a complaint may be lodged with the data protection supervisory authority.