Privacy policy
1. General provisions
1.1. This privacy policy regulates the principles of collecting, processing and preserving of personal data. The controller collecting, processing and preserving the personal data is Vincent Holding OÜ (Loveby online store) (hereinafter the data processor).
1.2. In the meaning of this privacy policy, a data subject is a client or another physical person whose personal data the data processor processes.
1.3. In the meaning of this privacy policy, a client is anyone who purchases goods or services from the data processor’s website.
1.4. The data processor shall follow the data processing principles provided in the legislation, among else, the data processor processes the personal data in a lawful, fair and secure manner. The data processor is able to confirm that the personal data has been processed according to the provisions of the legal acts.
2. Collecting, processing and preserving personal data
2.1. The personal data the data processor collects, processes and preserves is collected electronically, mainly via the website and e-mail.
2.2. By sharing one’s personal data, the data subject grants the data processor the right to collect, organise, use and administer the personal data, which the data subject shares with the data processor either directly or indirectly by purchasing goods or services from the website, with the purpose provided in the privacy policy.
2.3. The data subject shall be responsible for ensuring that the data submitted by them is correct, precise and whole. Knowingly providing false data is considered a breach of privacy policy. The data subject is obligated to immediately inform the data processor if the submitted data changes.
2.4. The data processor shall not be liable for damages caused to the data subject or third parties by the data subject providing false data.
3. Processing the clients’ personal data
3.1. The data processor may process the following personal data of the data subject:
3.1.1. First name and last name;
3.1.2. Date of birth;
3.1.3. Telephone number;
3.1.4. E-mail address;
3.1.5. Delivery address;
3.1.6. Bank account number;
3.1.7. Payment card information;
3.2. In addition to the aforementioned, the data processor shall have the right to collect the data on the client which is available in public registers.
3.3. The legal basis of the processing of personal data are clauses 6 (1) a), b), c) and f) of the General Data Protection Regulation:
a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation to which the controller is subject;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
3.4. Processing of personal data according to the purpose of processing:
3.4.1. Purpose of processing – security and safety
Maximum period of preserving personal data – according to the deadlines provided in the law
3.4.2. Purpose of processing – processing the order
Maximum period of preserving personal data – 5 years
3.4.3. Purpose of processing – ensuring the functioning of the online store services
Maximum period of preserving personal data – 5 years
3.4.4. Purpose of processing – client management
Maximum period of preserving personal data – 5 years
3.4.5. Purpose of processing – financial activities, accounting
Maximum period of preserving personal data – according to the deadlines provided in the law
3.4.6. Purpose of processing – marketing
Maximum period of preserving personal data – 5 years
3.5. The data processor shall have the right to share the data with third persons who are data processors, accountants, transport and courier companies, companies providing transaction services. Data processor is the controller of personal data. The data processor shall forward the personal data necessary for making a payment to the processor Montonia Finance OÜ, registry code 14557628 (Estonia).
3.6. When processing and preserving the personal data of a data subject, the data processor shall implement organisational and technical measures to ensure that the personal data is protected from accidental or illegal destruction, changing, disclosure and any other illegal processing.
3.7. The data processor shall preserve the information of the data subjects depending on the aim of processing but not longer than 5 years.
4. Rights of the data subject
4.1. The data subject shall have the right to have access to their personal data and to read it.
4.2. The data subject shall have the right to receive information about the processing of their personal data.
4.3. The data subject shall have the right to supplement or correct incorrect data.
4.4. If the data processor processes the personal data of the data subject based on the data subject’s consent, then the data subject shall have the right to withdraw their consent at any time.
4.5. To execute one’s rights, the data subject may contact the customer support of the online store at hi@loveby.eu.
4.6. To protect one’s rights, the data subject shall have the right to contact the Data Protection Inspectorate.
5. Final provisions
5.1. These data protection terms and conditions are prepared according to the regulation (EU) 2016/679 of the European parliament and of the council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the Personal Data Protection Act of the Republic of Estonia and legal acts of the Republic of Estonia and the European Union.
5.2. The data processors shall have the right to amend these data protection terms and conditions partially or completely informing the data subjects of the changes via the website www.loveby.eu.