PRIVACY POLICY

The personal data controller of the online store www.karvaeemalduskivi.ee is Depositum OÜ (registry code 16268213), located in Harju county, Tallinn, Haabersti district, Õismäe tee 173-5, 13517.

The online store www.netiriiul.ee collects and processes personal data in accordance with the legislation of the EU and the Republic of Estonia regulating the protection of personal data.

Types of processed personal data:

  1. Name, phone number, and email address
  2. Delivery address
  3. Bank account number
  4. Cost of goods and services, and payment-related data (purchase history)
  5. Customer support data.

Purposes for the processing of personal data:

  • Submitted personal data are used for managing the customer’s orders and delivering the goods.
  • Purchase history data (date of the purchase, goods, quantity, customer details) are used for preparing an overview of the purchased goods and services and for analysing customer preferences.
  • The bank account number is used to process customer payments.
  • Personal data such as email, phone number, customer name, are processed for the purpose of providing services.
  • The IP address and other network identifiers of a user of the online store are processed for providing the online store service as an information society service as well as for producing web usage statistics.


Legal basis:

Submitted personal data are processed for the performance of the agreement concluded with the customer.

Submitted personal data are processed for compliance with legal obligations (for example, accounting and settlement of consumer disputes).

Recipients of transmitted personal data:

  1. Submitted personal data are transmitted to the customer support team of the online store for managing purchases and purchase histories as well as resolving any customer issues.
  2. The customer’s name, phone number and email address are transmitted to the selected delivery service provider.
  3. To carry out accounting operations.
  4. Personal data may be transmitted to information technology service providers if it is necessary for the functionality or data hosting of the online store.
  5. The company transmits personal data which is necessary for making payments to the data processor Maksekeskus AS.

 

Security and access to data:

Any personal information that you provide to us and on the basis of which you can be identified will be stored securely and confidentially and will be processed fairly and lawfully.

Access to submitted personal data is granted to the employees of the online store for resolving technical issues related to the use of the online store and for providing customer support.

The online store shall implement the appropriate physical, organisational and information technology security measures to protect the personal data against accidental or unlawful destruction, loss and alteration as well as unauthorised access and disclosure.

Personal data are transmitted to the online store’s data processors (for example, transport and data hosting service providers) under agreements concluded between the online store and the data processors. Data processors are required to ensure that appropriate security measures are taken when processing the personal data.

 

Accessing and amendment of personal data:

If the purchase has been made without a user account, personal data can be accessed via customer support by email depositumou@gmail.com


Withdrawal of consent:

In cases where the processing of personal data is carried out on the basis of the consent of the customer, the customer has the right to withdraw their consent by notifying customer support by e-mail.

Retention:

Upon closure of a customer account in the online store, any personal data shall be deleted, unless the retention of the data is required for accounting purposes or for the resolution of consumer disputes.

Histories of purchases made without a customer account shall be retained for 3 years.

In the event of disputes relating to payments or consumer disputes, related personal data shall be retained until the settlement of the claim or the end of the validity period.

Personal data which are necessary for accounting shall be retained for 7 years.

Deletion:

If you wish to have your personal data deleted, please contact our customer support team by e-mail. Requests for deletion shall be answered no later than within 1 (one) month and shall include a specification of the data deletion period.

Transfer:

Requests submitted by e-mail for the transfer of personal data shall be answered no later than within 1 (one) month. In such cases, customer support shall verify the requester’s identity and notify the requester about the personal data to be transferred.

Direct marketing messages:

The customer’s e-mail address and phone number may be used for sending direct marketing messages, if the customer has given their consent. If the customer does not wish to receive direct marketing messages, they may opt out by using the link in the footer for such e-mails or by contacting customer support.

Settlement of disputes

Disputes relating to the processing of personal data may be resolved via customer support depositumou@gmail.com.  

The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).

 

NB! The data controller has the right to partially or completely change the data protection conditions by notifying the data subjects of the changes via the website www.netiriiul.ee

Visitors to the online store understand that by using the website after the privacy policy has been updated, they agree to the changes made.