Privacy policy
1. General provisions
1.1. This Privacy Policy describes how ____COMPANY NAME, REG. NO., LEGAL ADDRESS__ (hereinafter also referred to as the “Data Controller”) obtains, processes and stores personal data that ___WEB STORE NAME__ obtains from its customers and persons visiting the website (hereinafter referred to as the “Data Subject” or “You”).
1.2. Personal data is any information relating to an identified or identifiable natural person, i.e. Data Subject. Processing is any operation related to personal data, such as obtaining, recording, modification, use, consultation, deletion or destruction.
1.3. The Data Controller complies with the data processing principles provided for by law and is able to confirm that personal data are processed in accordance with applicable law.
2. Obtaining, processing and storing personal data
2.1. The Data Controller obtains, processes and stores personally identifiable information mainly using the online store website and e-mail. (NB! It is necessary to supplement if personal data is also collected in another way, for example, in paper form).
2.2. By visiting and using the services provided in the online store, you agree that any information provided is used and managed in accordance with the purposes set out in the Privacy Policy.
2.3. The Data Subject is responsible for ensuring that the personal data submitted is correct, accurate and complete. Deliberate provision of false information is considered a violation of our Privacy Policy. The Data Subject is obliged to immediately notify the Data Controller of any changes to the submitted personal data.
2.4. The Data Controller is not liable for losses caused to the Data Subject or third parties if they arise due to falsely submitted personal data.
3. Processing of Customer Personal Data
3.1. The Data Controller may process the following personal data:
3.1.1. Name, surname
3.1.2. Date of birth
3.1.3. Contact information (email address and/or phone number)
3.1.4. Transaction data (purchased goods, delivery address, price, payment information, etc.).
3.1.5. Any other information submitted to us during the purchase of services and goods offered by the site or when contacting us.
3.2. In addition to the above, the Data Controller has the right to verify the accuracy of the submitted data using publicly available registers.
3.3. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c) and (f) of the General Data Protection Regulation:
a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
b) the processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the data subject’s request prior to entering into a contract;
c) the processing is necessary for compliance with a legal obligation to which the controller is subject;
f) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.
3.4. The data controller shall store and process the personal data of the data subject for as long as at least one of the following criteria applies:
3.4.1. The personal data are necessary for the purposes for which they were obtained;
3.4.2. As long as the Data Controller and/or the Data Subject can exercise their legitimate interests, such as filing objections or bringing or bringing legal action in court, in accordance with the procedure specified in external regulatory enactments;
3.4.3. As long as there is a legal obligation to store the data, such as in accordance with the Accounting Law;
3.4.4. As long as the Data Subject’s consent to the relevant processing of personal data is valid, if there is no other legal basis for the processing of personal data.
Upon the expiry of the circumstances referred to in this paragraph, the period for storing the Data Subject’s personal data also expires and all relevant personal data are irreversibly deleted from computer systems and electronic and/or paper documents containing the relevant personal data or these documents are anonymized.
3.5. In order to fulfill its obligations towards you, the Data Controller has the right to transfer your personal data to cooperation partners, data processors who perform the necessary data processing on our behalf, such as accountants, courier services, etc. The Data Processor is the personal data controller. Payment processing is provided by the payment platform makecommerce.lv, therefore our company transfers the personal data necessary for payment processing to the platform owner Maksekeskus AS.
Upon request, we may transfer your personal data to state and law enforcement authorities in order to defend our legal interests, if necessary, by drawing up, submitting and defending legal claims.
3.6. When processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure and any other unlawful processing.
4. Data subject rights
4.1. In accordance with the General Data Protection Regulation and the legislation of the Republic of Latvia, you have the right to:
4.1.1. Access your personal data, receive information about their processing, as well as request a copy of your personal data in electronic format and the right to transfer this data to another controller (data portability);
4.1.2. Request the correction of incorrect, inaccurate or incomplete personal data;
4.1.3. Delete your personal data (“be forgotten”), except in cases where the law requires the data to be retained;
4.1.4. Withdraw your previously given consent to the processing of personal data;
4.1.5. Restrict the processing of your data – the right to request that we temporarily stop processing all of your personal data;
4.1.6. Contact the State Data Inspectorate
You can submit a request to exercise your rights by filling out the form in person at ___COMPANY ADDRESS___, or by sending a request electronically by writing to the customer support service at ___INSERT COMPANY EMAIL ADDRESS__.
5. Final provisions
5.1. This Privacy Policy has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as well as the applicable laws of the Republic of Latvia and the European Union.
5.2. The Data Controller has the right to make changes or additions to the Privacy Policy at any time and without prior notice. Amendments shall enter into force upon their publication on the website __INSERT ONLINE STORE DOMAIN ADDRESS__.