Legal
Privacy policy
Last updated: 14 August 2026
1. Who is responsible for your data
Totus Ceramics (Simply Resolve, Y-tunnus: 3110121-8) is the data controller for the personal data described below. Contact: hello@totus.fi.
2. What we collect, and why
| Data | Collected when | Why (legal basis) |
|---|---|---|
| Name, email, phone | Booking a course, contacting us, requesting a quote or commission | To fulfil a contract with you / respond to your enquiry |
| Postal address, city, country | Shop purchases, shipping quote requests | To fulfil a contract with you (deliver your order) |
| Booking details (course, date, headcount) | Course bookings | To fulfil a contract with you |
| Payment information | Purchases and bookings | Processed entirely by Stripe — we never see or store full card details ourselves |
| Marketing consent status | If you tick the newsletter/updates checkbox | Your explicit consent, which you can withdraw at any time |
| Commission details (description, reference images if provided) | Commission requests | To fulfil a contract with you |
| Gift voucher details (recipient name/email/message, if provided) | Gift voucher purchases | To fulfil a contract with you (deliver the voucher as instructed) |
| Basic website usage data | Browsing the site | Our legitimate interest in understanding how the site is used, and in preventing abuse of our contact/booking forms (e.g. automated spam) |
We only collect what's actually needed for the purpose above — we don't ask for more than we need.
3. Who we share data with
We use a small number of trusted service providers to run this business. Each only receives the data it needs to do its specific job:
- Stripe — payment processing
- Cal.com — course booking and scheduling
- Cloudflare — website hosting, security, and basic analytics
- Google (Gmail) — business email and automated booking/order confirmations
- Make.com — connects the above services together (for example, triggering a confirmation email after a booking)
Some of these providers are based outside the EU/EEA (notably in the United States). Where that's the case, they operate under the EU-US Data Privacy Framework or Standard Contractual Clauses, which are the recognized legal mechanisms for transferring personal data outside the EEA safely. We don't sell or share your data with anyone for advertising purposes.
4. How long we keep your data
- Enquiries that don't lead to a booking or purchase: kept for a reasonable period to allow follow-up, then deleted if no relationship develops.
- Booking, purchase, and payment records: kept for at least 6 years, as required under Finnish accounting law (kirjanpitolaki), even after your relationship with us ends.
- Marketing consent and contact details for our mailing list: kept until you unsubscribe or ask us to remove you.
5. Cookies and tracking
This website uses Cloudflare's website analytics, which is designed to work without cookies and without tracking individual visitors personally — so no cookie consent banner is currently needed for this. If we start using advertising tools that do use tracking cookies (for example, running ads on Instagram/Meta), we'll update this policy and add a proper cookie consent banner before doing so — that hasn't happened yet as of the date above.
6. Your rights
Under GDPR, you have the right to:
- Access the personal data we hold about you
- Correct it if it's inaccurate
- Delete it, in most circumstances
- Restrict or object to certain processing
- Receive a copy of your data in a portable format
- Withdraw consent at any time, where we rely on consent (for example, marketing emails — every marketing email includes an easy way to unsubscribe)
To exercise any of these, email hello@totus.fi. We'll respond within a reasonable time, in line with GDPR requirements.
If you believe we haven't handled your data properly, you also have the right to complain to Finland's data protection authority:
Tietosuojavaltuutetun toimisto (Office of the Data Protection Ombudsman)
tietosuoja.fi
7. Children's data
Our services are aimed at adults. Minors may attend a course only when accompanied by a supervising adult, and we don't knowingly collect personal data directly from children without a parent or guardian's involvement.
8. Security
We rely on the built-in security of our service providers (Stripe for payments, Cloudflare for hosting) rather than storing sensitive data ourselves. We don't store full payment card details anywhere in our own systems.
9. Changes to this policy
We may update this policy as the business grows or as our tools and processes change. The current version is always the one published here, with the date at the top.
10. Contact
Questions or requests about your data: hello@totus.fi