PROCESSING OF PERSONAL DATA

The controller of personal data of online store eesti-mesi.ee (hereinafter the Online Store) is OÜ SP Kaubandus (registry code 16039033), located in Hundinuia tee 8, Rae parish, Harjumaa, 75316, e-mail sptooted@gmail.com, phone +372 5138007

What personal data are processed

  • − name, telephone number and e-mail address;
  • − the delivery address of the goods;
  • − bank account number;
  • − cost of goods and services and payment data (purchase history);
  • − customer support data.

For what purpose is personal data processed

Personal data is used to manage customer orders and deliver goods.

Purchase history data (purchase date, item, quantity, customer data) is used to create an overview of purchased goods and services and to analyze customer preferences.

The bank account number is used to return payments to the customer.

Personal data such as e-mail, phone number, customer name, are processed in order to resolve issues related to the provision of goods and services (customer support).

The IP address or other online identifiers of the user of the online store are processed for the provision of the online store as an information society service and for the production of web usage statistics.

Legal basis

The processing of personal data is carried out for the purpose of performance of the contract entered into with the client.

The processing of personal data is carried out in order to fulfil a legal obligation (e.g. accounting and consumer dispute resolution).

Recipients to whom personal data are transmitted

Personal data is transferred to the customer support of the online store to manage purchases and purchase history and to solve customer problems.

The name, telephone number and e-mail address shall be forwarded to the transport service provider chosen by the customer. If the goods delivered by courier are delivered by courier, the customer’s address will be sent in addition to the contact details.

If the online store’s accounting is passed by the service provider, the personal data will be forwarded to the service provider for accounting operations.

Personal data may be transferred to IT service providers if this is necessary to ensure the functionality of the online store or data hosting.

SP Kaubandus OÜ transfers the personal data necessary for making payments to the authorised processor Maksekeskus AS.

Security and access to data

Personal data shall be stored veebimajutus.ee servers located in the territory of a Member State of the European Union or of countries which are members of the European Union Economic Area. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to US companies that have joinedthe Privacy Shieldframework.

The employees of the online store have access to personal data in order to resolve technical issues related to the use of the online store and to provide customer support services.

The online store shall implement appropriate physical, organisational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.

The transfer of personal data to the authorised processors of the online store (e.g. transport provider and data hosting) is carried out on the basis of contracts concluded with the online store and the authorised processors. Processors are obliged to provide appropriate safeguards for the processing of personal data.

Access and rectification of personal data

Personal data can be consulted and made corrections to the user profile of the online store. If the purchase has been made without a user account, you can consult the personal data via klint support.

Withdrawal of consent

If the processing of personal data is carried out on the basis of the client’s consent, the client

by notifying the customer support by e-mail.

Preservation

Personal data will be deleted when the online store’s customer account is closed, unless such data needs to be stored for accounting ly or in the resolution of consumer disputes.

If an online store has made a purchase without a customer account, the purchase history is kept for three years.

In the case of disputes relating to payments and consumer disputes, personal data shall be stored until the fulfilment of the claim or until the expiry date.

The personal data necessary for the accounting lys shall be kept for seven years.

Delete

To delete personal data, you must contact customer support by e-mail. The request for deletion shall be answered no later than one month and the period for erasing the data shall be selected.

Transfer

A request for the transfer of personal data submitted by e-mail shall be answered within a month at the latest. Customer Support identifies and notifies you of the personal data that are subject to transfer.

Direct marketing reports

The e-mail address and phone number are used to send direct marketing messages if the customer has given consent. If the customer does not wish to receive direct marketing messages, you must select a reference in the e-mail footer or contact customer support.

If personal data are processed for direct marketing purposes (profiling), the customer has the right to process both the original and the further processing of their personal data, including

profiling at any time by notifying the Commission of the results of the

Settlement of disputes

Disputes related to the processing of personal data are resolved through customer support (CONTACT DETAILS). The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).