Skip to content

Privacy policy

Last updated: 9 April 2026

Who we are

Wiberg's (T:mi Wiberg Härri Johannes Kustaa, business ID Y-3501400-7) is the data controller responsible for the personal data collected through this website. We are a sole proprietorship (toiminimi) and regenerative farm based in Kuusjoki, Salo, Finland.

Registered address: Ylikulmantie 467, 25330 Kuusjoki, Finland

Contact for privacy matters: privacy@wibergs.fi

We have not appointed a Data Protection Officer, as our core business activities do not involve large-scale processing of personal data. For any privacy-related questions, contact us at the address above.

What personal data we collect

We collect personal data only when you actively provide it or when it is technically necessary to operate the website. We do not use advertising trackers, behavioural analytics, or third-party profiling tools.

Newsletter signup

When you subscribe to our newsletter, we collect your email address. We use this solely to send you seasonal updates about the farm.

Order request form

When you submit an order request for egg subscriptions, we collect the information you provide in the form: your name, email address, phone number (optional), organisation name (optional), type of customer, estimated order volume, preferred collection method (optional), and any message you include.

Contact via phone, WhatsApp, or email

When you contact us directly via phone, WhatsApp, or email, we receive whatever information you choose to share in your message.

Server logs

When you visit the website, our hosting provider automatically collects technical data required to serve the pages: your IP address, browser type, referring URL, and the date and time of your visit. This data is collected in server logs and is not linked to any other personal data we hold.

Why we process your data

We process personal data for the following purposes:

  • Newsletter: To send you seasonal updates about the farm, its products, and events. We send a few emails per season, not per week.
  • Order requests: To review your inquiry, respond to you, and manage potential business relationships.
  • Contact messages: To reply to your questions or requests.
  • Server logs: To keep the website running, secure, and to diagnose technical issues.

We do not sell, rent, or share your personal data for marketing purposes.

Legal basis for processing

Under the GDPR, every use of personal data requires a legal basis. Ours are:

DataLegal basisGDPR article
Newsletter emailYour consent (opt-in)Art. 6(1)(a)
Order request formPre-contractual steps (responding to your request to order)Art. 6(1)(b)
Contact messagesLegitimate interest (responding to your message)Art. 6(1)(f)
Server logsLegitimate interest (website security and operation)Art. 6(1)(f)

You can withdraw your newsletter consent at any time by clicking the unsubscribe link in any email or by contacting us at privacy@wibergs.fi. Withdrawing consent is as easy as giving it. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

Who processes your data

We use the following service providers to operate the website and communicate with you. Each acts as a data processor under a data processing agreement.

Service providerPurposeLocation
Vercel Inc.Website hosting and server logsUSA (serverless functions configured to execute in EU, Stockholm). Static content served from a global CDN. Vercel's Data Processing Addendum with EU Standard Contractual Clauses applies.
MailerLiteNewsletter deliveryLithuania (EU)
Supabase Inc.Database for order request submissions and admin email notificationsEU (eu-west-1, Ireland)

We do not share your data with any other third parties.

Commerce

When you click a "Shop" or "Subscribe" link on this website, you are redirected to Yosis, an external commerce platform. Any personal data you provide during a purchase is processed by Yosis under their own privacy policy and terms of service. We do not send your personal data to Yosis through these links. Wiberg's is not the data controller for transactions on that platform.

International data transfers

Some of our service providers are based outside the European Economic Area (EEA). Where personal data is transferred outside the EEA, we ensure adequate safeguards are in place:

  • Vercel (USA): Transfers are governed by EU Standard Contractual Clauses (SCCs) included in their data processing agreement.
  • MailerLite (Lithuania) and Supabase (Ireland): Data remains within the EEA. No international transfer occurs.

IP addresses are processed by Vercel's global network for DDoS protection and traffic routing. This is a technical necessity of operating a website on a content delivery network.

How long we keep your data

DataRetention period
Newsletter emailUntil you unsubscribe. Your email is deleted from our mailing list when you opt out.
Order request submissionsFor the duration of the business relationship, then retained for six years as required by Finnish bookkeeping law (kirjanpitolaki).
Contact messagesAs long as needed to resolve your inquiry, then deleted within 12 months.
Server logsAutomatically deleted after 30 days.

Security

We protect personal data with appropriate technical and organisational measures to prevent unauthorised access, alteration, disclosure, and destruction. The website uses encrypted HTTPS connections. Access to systems containing personal data is restricted to those who need the data to perform their duties.

Your rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can ask us to correct inaccurate data.
  • Right to erasure: You can ask us to delete your data, unless we are legally required to retain it.
  • Right to restriction: You can ask us to limit how we process your data.
  • Right to data portability: You can request your data in a structured, machine-readable format.
  • Right to object: You can object to processing based on legitimate interest. We will stop processing unless we have compelling grounds.
  • Right to withdraw consent: For newsletter subscriptions, you can withdraw consent at any time.

To exercise any of these rights, contact us at privacy@wibergs.fi. We will respond within one month.

Is providing your data required?

Providing your email address for the newsletter is voluntary. You can use the website without subscribing. Providing your name and email in the order request form is necessary to process your inquiry. If you choose not to provide this information, we cannot respond to your request. Server log data is collected automatically and cannot be opted out of while using the website.

Automated decision-making

We do not use automated decision-making or profiling based on your personal data.

Supervisory authority

If you believe we have not handled your personal data correctly, you have the right to lodge a complaint with the Finnish Data Protection Ombudsman:

Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto) PO Box 800, 00531 Helsinki tietosuoja@tietosuoja.fi www.tietosuoja.fi

Dispute resolution

If you have a consumer dispute with us that we cannot resolve directly, you may refer the matter to the Finnish Consumer Disputes Board (Kuluttajariitalautakunta):

Consumer Disputes Board PO Box 306, 00531 Helsinki www.kuluttajariita.fi

The Consumer Disputes Board provides free, impartial resolution of consumer disputes. You must first contact our customer service before filing a complaint.

Children

We do not knowingly collect personal data from children under 13 years of age. If you believe a child has provided us with personal data, please contact us at privacy@wibergs.fi and we will delete it.

Cookies

This website uses only strictly necessary cookies required for the site to function, such as locale preference and session management. We do not use analytics cookies, advertising cookies, or third-party tracking cookies. No cookie consent banner is required under Finnish law for strictly necessary cookies, but we disclose their use here for transparency.

Changes to this policy

We may update this privacy policy to reflect changes in our data processing practices or legal requirements. The "last updated" date at the top of this page shows when the policy was most recently revised. We encourage you to review this page periodically.