Processing of personal data
The controller of personal data of the online store malestuskivi.ee is Mälestuskivid LLC (registration code 17146251) with address Ülgase tee 15, Kallavere village, Jõelähtme parish, Harju County, 74121 Estonia
phone +372 5333 5054 and e-mail info@malestuskivid.ee
Malestuskivid LLC forwards the personal data necessary for making payments to the authorized processor Swedbank.
What personal data is processed
- name, telephone number and e-mail address;
- delivery address of goods;
- bank account number;
- cost of goods and services and payment-related data (purchase history);
- customer support data.
For what purpose is personal data processed
Personal data is used to manage customer orders and deliver goods.
Purchase history data (purchase date, goods, quantity, customer data) is used to compile an overview of purchased goods and services and to analyze customer preferences.
The bank account number is used to refund payments to the customer.
Personal data such as e-mail, telephone number, customer name are processed in order to resolve issues related to the provision of goods and services (customer support).
The IP address or other network identifiers of the online store user are processed to provide the online store as an information society service and to produce website usage statistics.
Legal basis
he processing of personal data is carried out for the purpose of fulfilling the contract concluded with the customer.
he processing of personal data is carried out to fulfill a legal obligation (e.g. accounting and resolving consumer disputes).
Recipients to whom personal data is transferred
Personal data is transferred to the online store customer support to manage purchases and purchase history and to resolve customer problems.
The name, telephone number and e-mail address are transferred to the transport service provider chosen by the customer. If the goods are delivered by courier, then in addition to the contact details, the customer's address is also transferred. If the online store's accounting is carried out by a service provider, then personal data is transferred to the service provider for accounting operations. Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality of the online store or data hosting.
Security and access to data
Personal data is stored on web hosting.ee servers located in a member state of the European Union or a country that has joined the European Economic Area. Data may be transferred to countries whose level of data protection has been assessed by the European Commission as adequate and to US companies that have joined the Privacy Shield framework. Access to personal data is available to online store employees who can access personal data in order to resolve technical issues related to the use of the online store and to provide customer support services.
The online store implements appropriate physical, organizational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorized access and disclosure.
Personal data is transferred to online store authorized processors (e.g. transportation service provider and data hosting) based on agreements concluded with the online store and authorized processors. Authorized processors are required to ensure appropriate safeguards when processing personal data.
Withdrawal of consent
If the processing of personal data is based on the client's consent, the client has the right to withdraw the consent by notifying customer support by e-mail.
Storage
If a purchase is made in the online store without a customer account, the purchase history is stored for three years.
In the case of disputes related to payments and consumer disputes, personal data is stored until the claim is satisfied or the statute of limitations expires.
Personal data necessary for accounting is stored for seven years.
Deletion
To delete personal data, you must contact customer support by e-mail. The deletion request will be responded to no later than within a month and the period for data deletion will be specified.
Transfer
A request for the transfer of personal data submitted by e-mail will be responded to no later than within a month.
Customer support will verify the identity of the person and inform you about the personal data that is subject to transfer.
Direct marketing communications
The email address and phone number are used to send direct marketing communications if the customer has given their consent. If the customer does not wish to receive direct marketing communications, they must select the appropriate link in the footer of the email or contact customer support.
If personal data is processed for the purpose of direct marketing (profiling), the customer has the right to object at any time to both the initial and further processing of their personal data, including profiling related to direct marketing, by informing customer support by e-mail at info@malestuskivid.ee.
Dispute resolution
Disputes related to the processing of personal data are resolved through customer support by tel. +372 5333 5054, e-mail: info@malestuskivid.ee.
The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).