The entity responsible for processing personal data of the online store kondoomid24.ee is PAVIUS Baltic OÜ (registration number 12408019).
- What personal data we process
- Name and email address;
- Bank account number;
- Cost of goods and services, as well as payment-related data (purchase history);
- IP address;
- Cookies;
- Purpose of personal data processing
- Personal data is used to manage customer orders.
- Purchase history data (purchase date, product, quantity, customer data) is used to create an overview of purchased goods and services, analyze customer preferences, and for resolving consumer disputes.
- The bank account number is used for refunding payments to the customer.
- Personal data such as email address and customer name is processed to address issues related to goods and services (customer support). Email is also used for sending invoices.
- IP addresses or other network identifiers of the online store user are processed to provide online store services as information society services, as well as for site usage statistics.
- Legal basis
- Personal data processing is carried out for the purpose of fulfilling the contract with the customer (managing customer orders, refunding payments).
- Personal data processing is carried out to fulfill a legal obligation (accounting).
- Personal data processing is necessary due to the legitimate interest of the data controller, which consists of collecting purchase history data for potential consumer dispute resolution.
- Recipients of personal data
- Personal data is provided to the online store's customer support to manage purchases and purchase history, as well as to resolve customer issues.
- If the online store’s accounting is handled by a service provider, personal data is provided to them to carry out accounting operations.
- Personal data may be shared with IT service providers if necessary to ensure the functionality of the online store or data storage.
- Data security and access
- Personal data is stored on Zone Media OÜ servers located within the European Union or countries of the European Economic Area.
- Access to personal data is granted to online store employees who may access it to resolve technical issues related to the use of the online store and provide customer support.
- The online store implements appropriate physical, organizational, and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized access, and disclosure.
- Transfer of personal data from authorized processors of the online store to the receiving party (e.g., shipping providers and web hosting) is carried out based on agreements between the online store and the authorized processors. Authorized processors are required to guarantee appropriate protection measures in accordance with Article 28 of the General Data Protection Regulation (GDPR).
- Access to and correction of personal data
- You can access and correct your personal data in the online store user profile or through customer support.
- Withdrawal of consent
- If personal data is processed based on customer consent, the customer has the right to withdraw it in their account settings or by notifying customer support via email.
- Data retention
- When a customer account is closed, personal data is deleted, except for personal data (purchase history) that must be retained for accounting or dispute resolution purposes.
- In case of disputes related to payments and consumer issues, personal data is retained until the requirement is fulfilled or until the end of the statute of limitations.
- Personal data contained in primary accounting documents is retained for seven years.
- Restriction
- The customer may request the restriction of processing of their personal data if the data is inaccurate or incomplete, or if their personal data is processed unlawfully.
- Objections
- The customer may object to the processing of their personal data if they have reason to believe that there is no legal basis for such processing.
- Deletion
- To delete personal data, contact customer support by email. A response will be provided within one month specifying the period of deletion. The response will also indicate which personal data will not be deleted and provide the legal basis and reason.
- Data portability
- The response to a data portability request submitted by email will be provided within one month. Customer support will verify the requester’s identity and provide information on which personal data will be transferred.
- Direct marketing
- Email addresses are used for sending direct marketing messages if the customer has given consent. If the customer does not wish to receive such messages, they should follow the link at the bottom of the email or contact customer support.
- Dispute resolution
- Disputes related to personal data processing are resolved through customer support. The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).