PROCESSING OF PERSONAL DATA
The controller of the personal data is www.mgdisain.com MG Disain OÜ (registration code 14835346 ) with its registered office at Pärnu mnt 24, Viljandi. The data controller has appointed a Data Protection Officer whose contact details are: tel 55582575 and email mgdisain@mgdisain.com (applicable to those who have appointed a Data Protection Officer).
What personal data is processed
– name, telephone number and e-mail address;
– delivery address;
– bank account number;
– cost of goods and services and payment details (purchase history);
– customer support details.
Purposes for which personal data is processed
Personal data is used for the management of customer orders and the delivery of goods.
Purchase history data (date of purchase, goods, quantity, customer details) is used to compile an overview of goods and services purchased and to analyse customer preferences.
The bank account number is used to refund payments to the customer.
Personal data such as e-mail, telephone number, customer name, are processed in order to resolve issues related to the provision of goods and services (customer support).
The IP address or other network identifiers of the user of the webshop are processed for the purpose of providing the webshop as an information society service and for the purpose of web usage statistics.
Legal basis
The processing of personal data is carried out for the purposes of the performance of a contract with the customer.
The processing of personal data is carried out for the performance of a legal obligation (e.g. accounting and consumer dispute resolution).
The processing of data is carried out with the customer’s consent for the following activities: the production of parcel labels for customer orders (applicable to those who process personal data outside the terms of use, e.g. profiling.). For processing of personal data (e.g. for personal data processing for purposes other than those covered by the “personal data processing” policy), the customer must be informed in advance of the processing and consent must be obtained separately).
Recipients to whom personal data are disclosed
Personal data will be transferred to the online shop’s customer support for the purpose of managing purchases and purchase history and resolving customer issues.
Name, telephone number and e-mail address will be transferred to the transport service provider of the customer’s choice. In the case of goods to be delivered by courier, the customer’s address will be provided in addition to the contact details.
If the accounting of the online shop is carried out by the service provider, the personal data will be transferred to the service provider for the purpose of carrying out accounting operations.
Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality or data availability of the online shop.
Security and data access
Personal data is stored on webimajutus.ee servers located in the territory of a Member State of the European Union or in the territory of countries that have joined the European Economic Area. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to companies in the United States that have signed up to the Privacy Shield framework.
Access to personal data is provided to the employees of the online shop who can access personal data in order to resolve technical issues related to the use of the online shop and to provide customer support services.
The online shop implements appropriate physical, organisational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.
The transfer of personal data to the online shop’s processors (e.g. transport service providers and data aggregators) is subject to agreements between the online shop and the processors. Data controllers are required to ensure appropriate safeguards when processing personal data.
Accessing and correcting personal data
Personal data can be accessed and corrected in the online shop’s user profile. If the purchase has been made without a user account, the personal data can be accessed via the login.
Withdrawal of consent
If the processing of personal data is based on the consent of the customer, the customer has the right to withdraw the consent by informing Customer Support by e-mail.
Storage
When you close your online shop customer account, your personal data will be deleted, unless such data needs to be kept for accounting purposes or to resolve consumer disputes.
If a purchase is made in the online shop without a customer account, the purchase history will be kept for three years.
In the case of disputes relating to payments and consumer disputes, personal data will be kept until the claim is settled or until the expiry of the limitation period.
Personal data necessary for accounting purposes will be kept for seven years.
Deletion
In order to delete personal data, you must contact customer support by e-mail. A reply to the deletion request will be given within one month at the latest, specifying the period of deletion.
Transfer to
Requests for the transfer of personal data made by e-mail will be answered within one month at the latest. Customer Support will verify the identity and inform you of the personal data to be transferred.
Direct marketing communications
The email address and telephone number will be used to send direct marketing messages if the customer has given their consent. If the customer does not wish to receive direct marketing communications, he/she should select the appropriate reference in the footer of the e-mail or contact customer support.
Where personal data is processed for the purposes of direct marketing (profiling), the customer has the right to object at any time to both the initial and further processing of his or her personal data, including profiling in relation to direct marketing, by informing Customer Support by e-mail (this information must be provided clearly and separately from any other information).
Dispute resolution
Disputes relating to the processing of personal data will be resolved through customer support (CONTACT US). The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).