Skip to content

PROCESSING OF PERSONAL DATA

The controller of personal data of the online store sivona.ee is OÜ EtnoArt (registry code 11909374) located at Reiu kooli tee, Reiu küla, 86508 Häädemeeste municipality, Pärnu county, Estonia,
tel +3725177789 and e-mail info@etnoart.eu.

OÜ EtnoArt transfers personal data necessary for executing payments to the authorised processor Montonio OÜ.

What personal data is processed

• name, phone number and e-mail address;
• delivery address of the goods;
• bank account number;
• cost of goods and services and payment-related data (purchase history);
• customer support data.

Purpose of processing personal data

Personal data is used to manage customer orders and deliver goods.

Purchase history data (purchase date, product, quantity, customer data) is used to compile an overview of purchased goods and services and to analyse customer preferences.

The bank account number is used to return payments to the customer.

Personal data such as e-mail, phone number and customer name are processed in order to resolve issues related to the provision of goods and services (customer support).

The IP address of the online store user or other network identifiers are processed for providing the online store as an information society service and for compiling web usage statistics.

Legal basis

Personal data is processed for the performance of a contract concluded with the customer.

Personal data is processed to fulfil legal obligations (e.g. accounting and resolution of consumer disputes).

Recipients of personal data

Personal data is transferred to the online store customer support for managing purchases and purchase history and resolving customer issues.

Name, phone number and e-mail address are forwarded to the transport service provider chosen by the customer. If the goods are delivered by courier, the customer’s address will also be transmitted.

If the accounting of the online store is carried out by a service provider, personal data is transferred to the service provider for accounting purposes.

Personal data may also be transferred to IT service providers if necessary to ensure the functionality or hosting of the online store.

Security and access to data

Personal data is stored on zone.ee servers located in the territory of a Member State of the European Union or in countries that have joined the European Economic Area. Data may be transferred to countries whose data protection level has been assessed as adequate by the European Commission and to companies in the United States that have joined the Privacy Shield framework.

Access to personal data is granted to employees of the online store who need it to resolve technical issues related to the use of the online store and to provide customer support services.

The online store implements appropriate physical, organisational and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.

Transfer of personal data to authorised processors of the online store (e.g. transport service providers and data hosting providers) takes place on the basis of contracts concluded between the online store and authorised processors. Authorised processors are required to ensure appropriate safeguards for personal data processing.

Access and correction of personal data

Personal data can be accessed and corrected in the online store user profile. If the purchase has been made without a user account, personal data can be accessed via customer support.

Withdrawal of consent

If the processing of personal data is based on the customer’s consent, the customer has the right to withdraw the consent by notifying customer support via e-mail.

Storage

When the online store customer account is closed, personal data will be deleted unless the data must be retained for accounting purposes or for resolving consumer disputes.

If a purchase has been made without a customer account, purchase history will be stored for three years.

In the event of disputes related to payments or consumer disputes, personal data will be stored until the claim is fulfilled or the limitation period expires.

Personal data necessary for accounting purposes will be stored for seven years.

Deletion

To delete personal data, customer support must be contacted via e-mail. The deletion request will be answered no later than within one month and the data deletion period will be specified.

Transfer

Requests for the transfer of personal data submitted by e-mail will be answered within one month.

Customer support will verify the identity of the person and inform which personal data will be transferred.

Direct marketing messages

The e-mail address and phone number are used for sending direct marketing messages if the customer has given consent. If the customer does not wish to receive such messages, they must select the respective link in the e-mail footer or contact customer support.

If personal data is processed for direct marketing purposes (profiling), the customer has the right to object at any time to both the initial and further processing of personal data, including profiling related to direct marketing, by notifying customer support via e-mail at info@etnoart.eu.

Dispute resolution

Disputes related to the processing of personal data will be resolved via customer support (OÜ EtnoArt, registry code 11909374, Reiu kooli tee, Reiu küla, 86508 Häädemeeste municipality, Pärnu county, tel +3725177789, e-mail info@etnoart.eu).

The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).