Privacy Policy – Sophia Christ Holding Oy Effective date: 29.8.2025 This Privacy Policy describes how Sophia Christ Holding Oy (“we”, “us”, “our”) collects, uses, and protects personal data when you interact with our online store hosted on the Holvi platform. We are committed to protecting your privacy and ensuring that your personal data is processed in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR). 1. Data Controller Sophia Christ Holding Oy Business ID: FI34390617 Address: Vuolahdentie 324, 21620 Kuusisto, Finland Email: sophiachristholding@gmail.com 2. What Personal Data We Collect We may collect and process the following personal data when you interact with our online store: Contact information: Name, email address, phone number Delivery details: Shipping address Purchase information: Ordered products, payment details, delivery method Communication data: Messages or feedback you provide We do not store payment card information. All payment transactions are securely handled through Holvi’s payment platform. 3. Purpose and Legal Basis for Processing We process personal data for the following purposes: To fulfill and deliver your orders (contractual obligation) To provide customer service and respond to inquiries (legitimate interest) To comply with accounting and legal obligations (legal obligation) With your consent, for optional email communication or updates (consent) 4. How Your Data Is Stored and Protected We store your data securely using trusted service providers, including Holvi. Your data is only accessible to persons who need it to process your order or provide support. We do not transfer personal data outside the EU/EEA unless necessary for delivery (e.g., international shipping) or based on appropriate safeguards. 5. How Long We Keep Your Data We retain your data only as long as necessary for: fulfilling your order meeting legal obligations (e.g., accounting regulations) handling customer service cases Typically, your data is retained for 6 years for accounting purposes unless longer retention is legally required. 6. Your Rights You have the right to: Access your personal data Request correction or deletion of your data Object to or restrict processing Withdraw your consent (if processing is based on consent) Lodge a complaint with the Finnish Data Protection Ombudsman Contact us at [your email address] if you wish to exercise any of these rights. 7. Cookies Holvi’s online store platform may use cookies to ensure the technical functionality of the service and to improve user experience. See Holvi’s own Cookie Policy for more information. 8. Third Parties We do not sell or rent your data. Personal data may be shared only with: Holvi (online store and payment provider) Shipping partners (for delivery) Accounting providers (for financial reporting, if needed) All third parties are GDPR-compliant and bound by confidentiality agreements. 9. Changes to This Policy We may update this Privacy Policy from time to time. The most recent version is always available on our website. By continuing to use our store, you agree to the latest version. Contact Us If you have any questions about this Privacy Policy or how we handle your personal data, please contact: sophiachristholding@gmail.com Sophia Christ Holding Oy Business ID: FI34390617