Privacy Policy
Last updated: 22.01.2026
1) Controller
- Controller: TWOMUCH
- Business ID: 2458561-3
- Address: Hankasuontie 10, 00390 Helsinki, Finland
- Email: auto@thomastatoimeen.fi
For questions related to data protection, please contact the email address above.
2) What personal data do we collect?
We collect and process only the necessary information depending on how you use the website:
-
A) Contact form / email
- name
- email address
- phone number (if you provide it)
- message content
- technical data (e.g. IP address and timestamp) for spam prevention and security
-
B) Appointment booking (Bookly)
- name and contact details
- booking details (service, time and possible location)
- any additional information you provide yourself (e.g. related to the car or your wishes)
-
C) Online store (WooCommerce) – digital and physical products
- name
- email and phone number
- billing address
- shipping address (for physical deliveries)
- order details (products/services, amount, VAT, status changes, refunds)
- delivery-related information (e.g. delivery method and tracking information, if used)
-
D) Payments (WooPayments – credit/debit)
- information required for payment processing (e.g. amount, currency, payment status and transaction identifiers)
- billing details and other information related to payment verification
- Note: we do not store full card details in our own system.
-
E) Website use (cookies)
- necessary cookies and technical data to ensure website functionality (e.g. cart/session)
- Analytics: we do not currently use separate visitor analytics. If we enable analytics, we will request the necessary consent in the cookie settings.
3) For what purposes do we use the data?
- customer service and responding to contact requests
- processing appointments and delivering the service
- processing orders, delivery and payment verification
- delivering digital products (e.g. download links and order confirmations)
- legal obligations (e.g. accounting)
- security and prevention of misuse (e.g. logs and spam protection)
- developing the website’s functionality at a general level
4) Legal basis for processing
We process personal data on the following GDPR-compliant bases:
- Contract: when we deliver a service, process a booking/order or handle customer service.
- Legal obligation: for example obligations related to accounting.
- Legitimate interest: security, prevention of misuse and basic website functionality.
- Consent: if we introduce non-essential cookies (e.g. analytics), they are used only with your consent and consent can be withdrawn in the cookie settings.
5) How long do we retain data?
- Contact requests: usually 12–24 months, unless handling the matter requires longer retention.
- Appointment bookings (Bookly): usually 24 months or as needed (e.g. in complaint situations).
- Orders and accounting material: retained in accordance with the Accounting Act and other applicable rules (often receipts for at least 6 years and some material for 10 years depending on the type of material).
- Technical logs/security: for a reasonable time to ensure security.
6) To whom is data disclosed?
We do not sell personal data. We disclose data only when it is necessary to provide the service:
- Web hosting / technical maintenance / backups
- Appointment booking system: Bookly
- Online store platform: WooCommerce
-
Payment service: WooPayments (WooCommerce Payments / Automattic)
- Payment processing in WooPayments is based on Stripe infrastructure (the Stripe Express model as part of the WooPayments service).
- Information necessary for the payment may be transferred for payment processing (e.g. amount, currency, billing details and payment status).
7) Transfer of data outside the EU/EEA
Some service providers may process data outside the EU/EEA. In such cases, we use safeguards required by the GDPR (e.g. EU Standard Contractual Clauses and other appropriate arrangements).
8) Cookies
- Necessary cookies: website functionality (e.g. cart, session, security).
- Optional cookies: if we introduce analytics or other non-essential functions in the future, they will be used only with your consent through the cookie settings.
You can manage cookies through your browser settings and/or the website’s cookie settings (cookie banner).
9) Data subject rights
You have the right to:
- access your data and receive a copy of it
- request correction of data
- request deletion of data in certain situations
- request restriction of processing in certain situations
- object to processing when the basis is legitimate interest
- transfer data from one system to another when the basis is contract or consent (under certain conditions)
- withdraw consent at any time (if processing is based on consent)
Requests: auto@thomastatoimeen.fi
10) Right to lodge a complaint
If you believe that your personal data is being processed unlawfully, you can lodge a complaint with the Office of the Data Protection Ombudsman.
11) Security
We protect data using technical and organisational measures (access rights, updates, backups, logs and spam protection). Nevertheless, no system is completely risk-free.
12) Embedded content and third-party links
The website may contain embedded content (e.g. YouTube) and links to external services. The privacy policies of those services apply to them.