Asia/Pacific

Europe

North America

South America

Global

Register and repair tools

Keep your tools in excellent shape on myMirka where you can register, manage and order repair for your tools.

Login to myMirka

Mirka partners

Replenish your stock, access marketing materials, view sales guides and read about upcoming product launches.

Login to Partner Portal

Privacy Statement

This privacy statement (“Statement”) explains how the personal data of actual or potential clients of Mirka Ltd (“Mirka”), website visitors at Mirka.com, and users of various Mirka services is processed. It is intended to cover all personal data processing by Mirka, except for purely internal processing (such as for internal HR, production or other internal purposes), and processing in relation to Mirka’s Partner Program and Partner Portal, which is covered by a different privacy statement, accessible here: Partner Portal Privacy Statement

This Statement was originally written in English. In case of any discrepancy between the English version and any translation, the English version shall prevail.

The information presented below covering data processors, and what data is processed (section 2) is divided into sections for ease of use/clarity, which you can click open for more detailed information.

Further sections on data processing may be added or existing ones amended from time to time, and this Statement will then be updated as needed.

This document contains the following information:

  1. Overall description of our data processing practices
  2. Who processes personal data, what data is processed, for what purpose, and how long is it stored
  3. Data transfers
  4. What are your rights
  5. Changes to the Statement
  6. Use of non-personal data

     Appendix: Glossary

1. Overall description of our data processing practices

Mirka as the data controller, collects and processes personal data under this Privacy Statement and in accordance with applicable national legislation, including the EU General Data Protection Regulation. The term “personal data” refers to personal identifiable information that directly or indirectly identifies you, such as your name, physical address, e-mail address, IP number or other contact details. Personal data processing refers to any action that we or a third party that we have engaged takes with the personal data, such as collection, registration and storage. We process personal data that is adequate, relevant and not excessive in relation to the purpose for which it has been collected. We only collect and process personal data where we have lawful grounds to do so.  

2. Who processes personal data, what data is processed, for what purpose, and how long is it stored

Responsible data controller and data processors

For all of the fields of processing listed below, the data controller for personal data collected and processed is Mirka. Mirka also transfers data, and provides access to data to other Mirka Group companies, in particular local subsidiaries, in order to fulfil orders, to fulfil warranty obligations, to provide local support, and to manage clients and partners. These Mirka Group companies act as processors on the basis of a written data processing agreement. For inquiries relating to personal data at Mirka, please contact: privacy@mirka.com

For detailed information on data processors, and processing of data related to specific fields of data processing, please click open the relevant sections below.

myMirka users

Mirka processes personal data of persons (“User(s)”) using the myMirka service, including e.g. tool warranty registration service and other functionalities, either through an app or web portal (“myMirka”). In addition, myMirka may collect non-personal, power tool related data of some users of myMirka. For more information on this, see Section 6 Use of non-personal data.

Who processes the personal data?

In addition to processing by group companies, Mirka uses external data processors to provide myMirka, in particular:

  • A cloud service provider, currently Microsoft Azure
  • A content management system (CMS) and webform provider and processor, currently Optimizely
  • An email service provider, currently Twilio SendGrid
  • Maintenance and development providers, currently KPS and Solita
  • A payment service provider, currently Adyen
  • Shipping providers for product returns, currently Posti, UPS and FedEx
  • Analytics providers, currently Fullstory, Plausible and Alphabet (Google Analytics)

Data is processed by these processors subject to a written data processing agreement with Mirka, consistent with article 28 of GDPR. For information about the processing of personal data when purchasing Mirka goods or services, see ecommerce below.

What data is processed in myMirka, for what purpose, and how long is it stored

Category of personal data

Legal basis

Purpose of processing

Duration of processing

Name of User

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Verifying the identity of the User

Within 12 months of the removal of the User’s account, or of the account otherwise becoming inactive

 

Unique numeric identifier for the User

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Identifying the User in order to use all the different functionalities of myMirka even when other identifying information (such as email) changes; collecting usage information in the myMirka app and providing suggestions for preventative maintenance of tools

Email address of User

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Logging into the User’s account, receiving communications from Mirka, handling support requests, handling returns of products, sending status information concerning myMirka

Consent of the User (GDPR Article 6(1)(a)

Sending marketing and information concerning relevant Mirka goods or services

Postal address of User

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Shipping of products, product returns

Phone number of User

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Secondary means of contacting the user concerning their myMirka related orders and support tickets or other relevant issues

Tool serial number entered into myMirka

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Handling warranty/repair claims relating to User’s tools, tracking User’s stolen/misplaced tools at User’s request

User’s IP address

Legitimate interests of Mirka (GDPR Article 6(1)(f)

Error detection and repair in order to ensure the Service can be used as intended, detecting and preventing fraud or misuse of myMirka

Various personal data entered in support requests, in chatbot discussions

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Fulfilling the User’s support requests, helping with the User’s questions entered in the chatbot

Tool usage data collected through the myMirka app

Consent of the User (GDPR Article 6(1)(a)

General analytics of tool usage and tool user profiles, used e.g. for targeted advertising/marketing of relevant goods or services

myMirka website analytics data collected by Google Analytics 4 (GA4):

· User pseudonymous identifiers

· Session data

· IP address (anonymized)

· Approximate geolocation

· Browser and device information

· Event data (page views, downloads, clicks)

Consent of the User (GDPR Article 6(1)(a)

·      Analysing website usage patterns and user journeys to improve website functionality and user experience

·      Measuring effectiveness of our online services

·      Understanding geographic distribution of visitors

·      Identifying technical issues and performance bottlenecks

·      Creating aggregated statistics about site usage

Data is automatically deleted after 2 months (default GA4 setting for user-level and event-level data). IP addresses are anonymized before storage.

 

Website analytics data collected by Plausible:

·      Session statistics

·      Approximate geolocation

·      Browser and device information

Consent of the User (GDPR Article 6(1)(a)

Tracking and analysing aggregated visitor behaviour on website, developing a better user experience

Data is anonymized at collection; no personal data is stored

Recording of User’s activities when using myMirka online– may contain personal data like name and contact information if user enters them during the browsing session

Consent of the User (GDPR Article 6(1)(a)

Tracking and analysing Visitor behaviour on myMirka, developing myMirka online for a better user experience

Information removed 30 days after the User’s Fullstory session

Performance of contract between User and Mirka (GDPR Article 6(1)(b))

Assisting with User support requests by going over records of User activities

IP address collected when using myMirka online

Consent of the User (GDPR Article 6(1)(a)

Getting location data on the Visitor

Individual user ID number generated by Fullstory when using myMirka online

Consent of the User (GDPR Article 6(1)(a)

Connecting activities on website during several sessions to a single browser/user

Data is collected mainly from the User through a registration form, although some data may also be collected through use of myMirka. Access to myMirka requires providing personal data, in particular the User’s name and contact information.

Sales and marketing contacts

Mirka processes personal data of contact persons (“Contact(s)”) of current or potential customers in connection with its business-to-business (B2B) sales and marketing activities.

Who processes the personal data?

In addition to processing by group companies, Mirka uses external data processors in connection with sales and marketing related processing, in particular:

  • Cloud service and CRM system provider, currently SAP
  • Email service provider, currently Sinch
  • Sales support service provider, currently SnapADDY and ABBYY Cloud
  • Maintenance and development providers, currently KPS and Vincit

Data is processed by these processors subject to a written data processing agreement with Mirka, consistent with article 28 of GDPR.

What data is processed in relation to Marketing, for what purpose, and how long is it stored?

Category of personal data

Legal basis

Purpose of processing

Duration of processing

Name, contact details of Contacts, title/position in company

Legitimate interests of Mirka (GDPR Article 6(1)(f)

Identifying interesting business leads and contacting them about Mirka goods and services

Within 24 months of the last contact with the business lead, after which the data will be either deleted or archived in accordance with legal obligations

Performance of contract between Mirka and potential business client (GDPR Article 6(1)(b)

Providing information as requested by potential business client about Mirka goods and services

Individual ID number associated with lead

Legitimate interests of Mirka (GDPR Article 6(1)(f)

 

Performance of contract between Mirka and potential business client (GDPR Article 6(1)(b)

Ensuring that data in Mirka systems is associated with the correct lead

 

Transferring data from marketing system to sales system when lead matures to become a potential or actual business client

Behaviour of Contact on Mirka websites

Consent of the Contact (GDPR Article 6(1)(a)

Segmentation of target groups for Mirka goods/services

Contact’s IP address

Legitimate interests of Mirka (GDPR Article 6(1)(f)

Detecting and fixing errors, preventing malicious behaviour/DDoS attacks

What data is processed in relation to Sales, for what purpose, and how long is it stored

Category of personal data

Legal basis

Purpose of processing

Duration of processing

Name, contact details of Contact, title/position in company

Performance of contract between Mirka and potential business client (GDPR Article 6(1)(b)

Providing quotes to potential business client and other correspondence, customer relationship management

Within 24 months of the business the Contact is associated with ceasing to become a potential or actual business client of Mirka

Individual ID number associated with business lead/customer

Performance of contract between Mirka and potential business client (GDPR Article 6(1)(b)

Ensuring that data in Mirka systems is associated with the correct business lead/customer

Possible personal data entered into customer complaints or support tickets

Performance of contract between Mirka and potential business client (GDPR Article 6(1)(b)

Handling customer complaints/providing support to the business lead/customer

Possible personal data entered into notes about business leads / customers, such as notes concerning meetings or discussions with leads/customers

Performance of contract between Mirka and potential business client (GDPR Article 6(1)(b)

Customer relationship management

Behaviour of Contact on Mirka websites

Legitimate interests of Mirka (GDPR Article 6(1)(f)

Segmentation of target groups for Mirka goods/services

Contact’s IP address

Legitimate interests of Mirka (GDPR Article 6(1)(f)

Detecting and fixing errors, preventing malicious behaviour/DDoS attacks

Data is collected into the marketing/sales systems directly from Contacts using, e.g., webforms. The provision of personal data is necessary for those potential clients that wish to procure Mirka goods or services.  

Mirka.com website visitors

Mirka processes personal data of visitors (“Visitor(s)”) to its website based on their browsing activities as well as on various contact forms they may use on the website. In addition, Mirka may collect non-personal analytics data of visitors. For more information on this, see Section 6 Use of non-personal data.

Note! The Visitor may also browse or purchase products while visiting the Mirka website. For personal data processing relating to e-commerce, see below.

Who processes the personal data?

In addition to processing by group companies, Mirka uses external data processors to provide its website and related services, in particular:

  • Cloud service provider, currently Microsoft Azure
  • CMS and webform provider and processor, currently Optimizely
  • CRM system provider, currently SAP
  • Analytics service providers, currently Alphabet (Google Analytics), Plausible and Fullstory
What data of Visitors is processed, for what purpose, and how long is it stored

Category of personal data

Legal basis

Purpose of processing

Duration of processing

Contact forms: Name, e-mail address, phone number of Visitor

Performance of contract between Mirka and Visitor (GDPR Article 6(1)(b)

Answering contact forms, handling support and warranty requests

Information removed within two weeks after contact request has been answered, unless Visitor orders newsletter (see Sales and Marketing above)

Contact forms: assorted personal data that may be entered by Visitor into free subject and message fields of contact form

Performance of contract between Mirka and Visitor (GDPR Article 6(1)(b)

Answering contact forms, handling support and warranty requests

IP address of Visitor

Performance of contract between Mirka and Visitor (GDPR Article 6(1)(b)

Searching for closest reseller upon request by the Visitor

Information removed immediately after search has been completed

Legitimate interests of Mirka (GDPR Article 6(1)(f)

Logging IP address to direct website traffic, to detect and remedy errors, and to detect and prevent malicious activity like DDoS attacks

Retained for 30 days

Website analytics data collected by Google Analytics 4 (GA4):

· User pseudonymous identifiers

· Session data

· IP address (anonymized)

· Approximate geolocation

· Browser and device information

· Event data (page views, downloads, clicks)

Consent of the Visitor (GDPR Article 6(1)(a)

·      Analysing website usage patterns and user journeys to improve website functionality and user experience

·      Measuring effectiveness of our online services

·      Understanding geographic distribution of visitors

·      Identifying technical issues and performance bottlenecks

·      Creating aggregated statistics about site usage

Data is automatically deleted after 2 months (default GA4 setting for user-level and event-level data). IP addresses are anonymized before storage.

 

Website analytics data collected by Plausible:

·      Session statistics

·      Approximate geolocation

·         Browser and device information

Consent of the Visitor (GDPR Article 6(1)(a)

Tracking and analysing aggregated visitor behaviour on website, developing a better user experience

Data is anonymized at collection; no personal data is stored

Recording of User’s activities on the website from Fullstory analytics application – may contain personal data like name and contact information if user enters them during the browsing session

Consent of the Visitor (GDPR Article 6(1)(a)

Tracking and analysing Visitor behaviour on the website, developing the website for a better user experience

Data is automatically deleted 30 days after the User’s Fullstory session

IP address collected by Fullstory

Consent of the Visitor (GDPR Article 6(1)(a)

Getting location data on the Visitor

Individual user ID number generated by Fullstory

Consent of the Visitor (GDPR Article 6(1)(a)

Connecting activities on website during several sessions to a single browser/user

Data collected through contact forms is collected directly from the Visitor, whereas some data is collected simply through visiting and browsing the Mirka website if the Visitor has allowed cookies. Use of contact forms requires providing personal data, in particular the Visitor’s name and contact information.

eCommerce customers

Mirka processes personal data of customers (“Customer(s)”) buying from its online shop based on their shopping activities as well as on the purchase orders they make. The data collected slightly varies depending on whether the Customer is shopping on their own behalf (“B2C”) or on behalf of a company (“B2B”). In addition, Mirka may collect non-personal analytics data of Customers. For more information on this, see Section 6 Use of non-personal data.

Note! Using the online shop requires browsing the Mirka website. For personal data processing relating to browsing the website as a Visitor, see above.

Who processes the personal data?

In addition to processing by group companies, Mirka uses external data processors to provide its online shop and related services, in particular:

  • Cloud service provider, currently Microsoft Azure
  • CMS and webform provider and processer, currently Optimizely
  • CRM and Marketing automation system provider, currently SAP
  • eCommerce platform provider, currently SAP
  • Email service provider, currently Sinch and Twilio SendGrid
  • Analytics service providers, currently Alphabet (Google Analytics), Plausible and Fullstory

In addition, Mirka uses Adyen NV as a payment processing provider. When processing payments, Adyen acts as a data controller. For more information about how Adyen processes information when processing payments, see their privacy notice: https://www.adyen.com/privacy-policy

What data of Customers is processed, for what purpose, and how long is it stored

Category of personal data

Legal basis

Purpose of processing

Duration of processing

Webform data collected from Customer when making a purchase: name, address, phone number, email, company name (only B2B Customers), company VAT code (only B2B Customers)

Performance of contract between Mirka and Customer (GDPR Article 6(1)(b)

Registering and fulfilling order for Mirka products

10 years from the end of the accounting year in which the transaction occurred (to comply with tax and accounting requirements across operating jurisdictions)

Webform data collected from Customer when requesting to return a product: name, address, phone number, email, (only B2B Customers), company VAT code (only B2B Customers), order number, assorted personal data that may be entered by Customer into free subject and message fields of return form

Performance of contract between Mirka and Customer (GDPR Article 6(1)(b)

Registering and fulfilling return request relating to Mirka products

Retained as part of the original purchase record for 10 years from the end of the accounting year in which the transaction occurred, as returns form part of the complete transaction record required for tax and accounting purposes

Website analytics data collected by Google Analytics 4 (GA4):

· User pseudonymous identifiers

· Session data

· IP address (anonymized)

· Approximate geolocation

· Browser and device information

·         Event data (page views, downloads, clicks)

Consent of the Customer (GDPR Article 6(1)(a)

·      Analysing website usage patterns and user journeys to improve website functionality and user experience

·      Measuring effectiveness of our online services

·      Understanding geographic distribution of visitors

·      Identifying technical issues and performance bottlenecks

Creating aggregated statistics about site usage

Data is automatically deleted after 2 months (default GA4 setting for user-level and event-level data). IP addresses are anonymized before storage.

 

Website analytics data collected by Plausible:

·      Session statistics

·      Approximate geolocation

Browser and device information

Consent of the Customer (GDPR Article 6(1)(a)

Tracking and analysing aggregated visitor behaviour on website, developing a better user experience

Data is anonymized at collection; no personal data is stored

General usage data concerning Mirka.com ecommerce use

Consent of the Customer (GDPR Article 6(1)(a)

Creating user profiles / personalising content to offer targeted advertising of relevant goods/services to the Customer

12 months from last activity

Recording of Customer’s activities on the website from Fullstory analytics application – may contain personal data like name and contact information if user enters them during the browsing session

Consent of the Customer (GDPR Article 6(1)(a)

Tracking and analysing Customer behaviour on the website, developing the website for a better user experience

Data is automatically deleted 30 days after the User’s Fullstory session

IP address collected by Fullstory

Consent of the Customer (GDPR Article 6(1)(a)

Getting location data on the Customer

Individual user ID number generated by Fullstory

Consent of the Customer (GDPR Article 6(1)(a)

Connecting activities on website during several sessions to a single browser/user

Data collected in connection with purchases and returns is collected directly from the Customer, whereas some data is collected simply through visiting and browsing the Mirka online shop if the Customer has allowed cookies. Making a purchase requires providing personal data, in particular the Customer’s name and contact information.  

3. Data transfers

For data subjects in the EU/EEA/UK, the servers will be hosted in the EU. However, personal data may be accessed (and therefore processed) from outside the EU/EEA/UK or in some cases transferred outside the EU/EEA/UK, by local Mirka subsidiaries in order to:

  • provide support or repair
  • fulfil orders
  • investigate suspected or actual illegal activity
  • prevent physical harm or financial loss
  • support the sale or transfer of all or a portion of our business or assets

All transfers/processing of personal data outside the EU/EEA are carried out on the basis of an adequacy decision by the EU commission (GDPR Article 45), or subject to standard contractual clauses (GDPR Article 46), complemented by sufficient supplementary safeguards in order to ensure that the rights of data subjects can be fulfilled. You can request a copy of the standard contractual clauses, including a description of the transferred data, by using the contact details provided for Mirka above.

4. What are your rights

Since we process your personal data, you can exercise certain rights during specific circumstances under the applicable data protection legislation as follows:

  • Right to access and rectification: You have the right to request access to the personal data relating to you. This includes e.g. the right to be informed whether or not personal data about you is being processed, what personal data is being processed, and the purpose of the processing. You also have the right to request that inaccurate or incomplete personal data be corrected.
  • Right to restriction of processing: You are entitled to restrict the processing of personal data in certain situations.
  • Right to object: You have the right to object at any time to the processing of your personal data based on legitimate interests. This includes the right to object to processing for direct marketing purposes. If you object, we will no longer process your personal data for such purposes.
  • Right to be forgotten: You may also request that your personal data be erased if e.g. the personal data is no longer necessary for the purposes for which it was collected, the processing is unlawful, or the personal data has to be erased to enable us to comply with a legal requirement.
  • Right to Data Portability: If personal data about you that you yourself have provided is being processed automatically with your consent or in accordance with a contract between you and Mirka, you may request that the data is provided in a structured, commonly used and machine-readable format and you may also request that the personal data is transmitted to another controller, if this is technically feasible.
  • Opt-out from marketing: We will give you the opportunity to opt out of future marketing whenever we send you marketing material, you can also opt out at any time by contacting us.
  • If you wish to exercise your rights or have any other questions regarding your personal data, please contact us at: privacy@mirka.com. You are also entitled, at any time, to lodge a complaint with the relevant supervisory authority if you consider that your personal data has been processed in contravention of applicable data protection legislation. The supervisory authority for Mirka’s domicile is the Finnish Data Protection Ombudsman: https://tietosuoja.fi/en/home

 

5. Changes to the Statement

Mirka reserves the right to amend this Statement from time to time. We will post any changes on this page and, where appropriate, notify you by e-mail. Please check back regularly to see any updates or changes to our Privacy Statement.

6. Use of non-personal data

Mirka also collects and processes data that does not directly or indirectly identify individual Visitors. Furthermore, certain data is anonymised or collected into general statistics containing no personal data, which may then be used for developing Mirka goods or services, or analysing usage of Mirka goods or services.

Cookies and website analytics data

When you enter this website, we may collect information about your computer, IP address, operating system and browser type, for example, for statistical purposes or for the purposes of system administration. This information generally comprises data which does not allow individual identification of information related to a specific user. If a Visitor gives consent and allows cookies via the Cookiebot banner, Mirka uses cookies from Google Analytics and Google Tag Manager as well as Plausible and Fullstory in order to further analyse web usage and traffic. More information concerning cookie practices by Mirka can be found in our Cookiebot banner, which you can access again by clicking the "Cookie preferences" link in the footer.

For Google Analytics 4 (GA4), we have implemented the following measures to protect user privacy:

  • IP address anonymization is enabled
  • Data sharing with Google products and services is disabled
  • Advertising features are disabled
  • User-ID tracking is disabled
  • Maximum data retention period is set to the shortest possible, currently 2 months
  • We process the data within the EU where possible through Google's EU servers

The data collected by GA4 is transferred to Google servers, which may be located outside the EU/EEA. Such transfers are safeguarded by the EU Standard Contractual Clauses and additional technical and organizational measures. For more information about how Google processes data, please see Google's Privacy Policy: https://policies.google.com/privacy

Power Tools analytics data

In addition, Mirka collects and processes non-personal data collected for persons who have connected their power tools to myMirka. In particular, Mirka collects and processes data relating to speed, usage time, vibration, accumulated vibration dose, battery capacity, battery charge, battery charge level, battery full charge cycles, battery health, tool settings and malfunction alerts. This data may be used to provide analytics and reports to the user or to develop Mirka products or services.

 

Revised: 16.1.2025

Appendix

Glossary

Analytics data: Information collected about how users interact with websites or applications, including page views, clicks, and navigation patterns.

Cookie: A small text file stored on your device that helps websites remember your preferences and track your browsing behaviour.

DDoS Attack: Distributed Denial of Service - an attempt to disrupt normal website traffic by overwhelming the system.

IP Address: A unique numerical label assigned to each device connected to a computer network.

Pseudonymous Identifier: A processed version of personal data where the most identifying fields are replaced with artificial identifiers.

Server: A computer or system that provides resources, data, or services to other computers over a network.

Session: A period of time during which a user interacts with a website or application.

Standard Contractual Clauses (SCCs): Legal tools approved by the European Commission for international data transfers.

User ID: A unique identifier assigned to track individual user activity across sessions.

For inquiries relating to personal data at Mirka, please contact: privacy@mirka.com