Privacy policy
Last updated: 9 April 2026
Who we are
Wiberg's (T:mi Wiberg Härri Johannes Kustaa, business ID Y-3501400-7) is the data controller responsible for the personal data collected through this website. We are a sole proprietorship (toiminimi) and regenerative farm based in Kuusjoki, Salo, Finland.
Registered address: Ylikulmantie 467, 25330 Kuusjoki, Finland
Contact for privacy matters: privacy@wibergs.fi
We have not appointed a Data Protection Officer, as our core business activities do not involve large-scale processing of personal data. For any privacy-related questions, contact us at the address above.
What personal data we collect
We collect personal data only when you actively provide it or when it is technically necessary to operate the website. We do not use advertising trackers, behavioural analytics, or third-party profiling tools.
Newsletter signup
When you subscribe to our newsletter, we collect your email address. We use this solely to send you seasonal updates about the farm.
Order request form
When you submit an order request for egg subscriptions, we collect the information you provide in the form: your name, email address, phone number (optional), organisation name (optional), type of customer, estimated order volume, preferred collection method (optional), and any message you include.
Contact via phone, WhatsApp, or email
When you contact us directly via phone, WhatsApp, or email, we receive whatever information you choose to share in your message.
Server logs
When you visit the website, our hosting provider automatically collects technical data required to serve the pages: your IP address, browser type, referring URL, and the date and time of your visit. This data is collected in server logs and is not linked to any other personal data we hold.
Why we process your data
We process personal data for the following purposes:
- Newsletter: To send you seasonal updates about the farm, its products, and events. We send a few emails per season, not per week.
- Order requests: To review your inquiry, respond to you, and manage potential business relationships.
- Contact messages: To reply to your questions or requests.
- Server logs: To keep the website running, secure, and to diagnose technical issues.
We do not sell, rent, or share your personal data for marketing purposes.
Legal basis for processing
Under the GDPR, every use of personal data requires a legal basis. Ours are:
| Data | Legal basis | GDPR article |
|---|---|---|
| Newsletter email | Your consent (opt-in) | Art. 6(1)(a) |
| Order request form | Pre-contractual steps (responding to your request to order) | Art. 6(1)(b) |
| Contact messages | Legitimate interest (responding to your message) | Art. 6(1)(f) |
| Server logs | Legitimate interest (website security and operation) | Art. 6(1)(f) |
You can withdraw your newsletter consent at any time by clicking the unsubscribe link in any email or by contacting us at privacy@wibergs.fi. Withdrawing consent is as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Who processes your data
We use the following service providers to operate the website and communicate with you. Each acts as a data processor under a data processing agreement.
| Service provider | Purpose | Location |
|---|---|---|
| Vercel Inc. | Website hosting and server logs | USA (serverless functions configured to execute in EU, Stockholm). Static content served from a global CDN. Vercel's Data Processing Addendum with EU Standard Contractual Clauses applies. |
| MailerLite | Newsletter delivery | Lithuania (EU) |
| Supabase Inc. | Database for order request submissions and admin email notifications | EU (eu-west-1, Ireland) |
We do not share your data with any other third parties.
Commerce
When you click a "Shop" or "Subscribe" link on this website, you are redirected to Yosis, an external commerce platform. Any personal data you provide during a purchase is processed by Yosis under their own privacy policy and terms of service. We do not send your personal data to Yosis through these links. Wiberg's is not the data controller for transactions on that platform.
International data transfers
Some of our service providers are based outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure adequate safeguards are in place:
- Vercel (USA): Transfers are governed by EU Standard Contractual Clauses (SCCs) included in their data processing agreement.
- MailerLite (Lithuania) and Supabase (Ireland): Data remains within the EEA. No international transfer occurs.
IP addresses are processed by Vercel's global network for DDoS protection and traffic routing. This is a technical necessity of operating a website on a content delivery network.
How long we keep your data
| Data | Retention period |
|---|---|
| Newsletter email | Until you unsubscribe. Your email is deleted from our mailing list when you opt out. |
| Order request submissions | For the duration of the business relationship, then retained for six years as required by Finnish bookkeeping law (kirjanpitolaki). |
| Contact messages | As long as needed to resolve your inquiry, then deleted within 12 months. |
| Server logs | Automatically deleted after 30 days. |
Security
We protect personal data with appropriate technical and organisational measures to prevent unauthorised access, alteration, disclosure, and destruction. The website uses encrypted HTTPS connections. Access to systems containing personal data is restricted to those who need the data to perform their duties.
Your rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate data.
- Right to erasure: You can ask us to delete your data, unless we are legally required to retain it.
- Right to restriction: You can ask us to limit how we process your data.
- Right to data portability: You can request your data in a structured, machine-readable format.
- Right to object: You can object to processing based on legitimate interest. We will stop processing unless we have compelling grounds.
- Right to withdraw consent: For newsletter subscriptions, you can withdraw consent at any time.
To exercise any of these rights, contact us at privacy@wibergs.fi. We will respond within one month.
Is providing your data required?
Providing your email address for the newsletter is voluntary. You can use the website without subscribing. Providing your name and email in the order request form is necessary to process your inquiry. If you choose not to provide this information, we cannot respond to your request. Server log data is collected automatically and cannot be opted out of while using the website.
Automated decision-making
We do not use automated decision-making or profiling based on your personal data.
Supervisory authority
If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman:
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) PO Box 800, 00531 Helsinki tietosuoja@tietosuoja.fi www.tietosuoja.fi
Dispute resolution
If you have a consumer dispute with us that we cannot resolve directly, you may refer the matter to the Finnish Consumer Disputes Board (Kuluttajariitalautakunta):
Consumer Disputes Board PO Box 306, 00531 Helsinki www.kuluttajariita.fi
The Consumer Disputes Board provides free, impartial resolution of consumer disputes. You must first contact our customer service before filing a complaint.
Children
We do not knowingly collect personal data from children under 13 years of age. If you believe a child has provided us with personal data, please contact us at privacy@wibergs.fi and we will delete it.
Cookies
This website uses only strictly necessary cookies required for the site to function, such as locale preference and session management. We do not use analytics cookies, advertising cookies, or third-party tracking cookies. No cookie consent banner is required under Finnish law for strictly necessary cookies, but we disclose their use here for transparency.
Changes to this policy
We may update this privacy policy to reflect changes in our data processing practices or legal requirements. The "last updated" date at the top of this page shows when the policy was most recently revised. We encourage you to review this page periodically.