Privacy Policy

Privacy Policy

The controller of personal data for the online store accademiaboutique.ee is Italmoda OÜ (registry code 12394518), located at Rataskaevu tn 4, Tallinn, Harju County, 10123, Estonia.

Tel: +372 645 0098

Email: info@accademiaboutique.ee

What personal data is processed

− Name, phone number, and email address; − Delivery address for goods; − Bank account number; − Cost of goods and services and data related to payments (purchase history); − Customer support data.

Purpose of processing personal data

Personal data is used to manage customer orders and deliver goods. Purchase history data (date of purchase, goods, quantity, customer details) is used to compile overviews of purchased goods and services and to analyze customer preferences. The bank account number is used to issue refunds to the customer. Personal data such as email, phone number, and customer name are processed to resolve issues related to the provision of goods and services (customer support). The IP address or other network identifiers of the online store user are processed for the provision of the online store as an information society service and for web usage statistics.

Legal basis

The processing of personal data is carried out for the purpose of fulfilling the contract concluded with the customer. The processing of personal data is carried out to fulfill a legal obligation (e.g., accounting and resolution of consumer disputes).

Recipients to whom personal data is transferred

Personal data is transferred to the online store’s customer support for managing purchases and purchase history and for resolving customer issues. The name, phone number, and email address are transferred to the transport service provider selected by the customer. In the case of goods delivered by courier, the customer’s address is also provided in addition to contact details. If the online store’s accounting is performed by a service provider, personal data is transferred to the service provider for accounting operations. Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality of the online store or for data hosting.

Security and access to data

Personal data is stored on servers provided by Veebimajutus, located in the territory of a Member State of the European Union or countries that have joined the European Economic Area. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to US companies that have joined the Privacy Shield framework. Access to personal data is restricted to online store employees who may access the data to resolve technical issues related to the use of the online store and to provide customer support services. The online store implements appropriate physical, organizational, and information technology security measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorized access and disclosure. The transfer of personal data to authorized processors of the online store (e.g., transport service provider and data hosting) takes place on the basis of contracts concluded between the online store and the processors. Processors are obliged to ensure appropriate safeguards when processing personal data.

 

Accessing and rectifying personal data

Personal data can be accessed and rectified in the user profile of the online store. If a purchase was made without a user account, personal data can be accessed through customer support.

Withdrawal of consent

If the processing of personal data is based on the customer’s consent, the customer has the right to withdraw their consent by notifying customer support via email.

Retention of data

Upon closing a customer account in the online store, personal data is deleted, unless such data needs to be retained for accounting purposes or for the resolution of consumer disputes. If a purchase in the online store was made without a customer account, the purchase history is stored for three years. In the event of disputes related to payments and consumer disputes, personal data is stored until the claim is satisfied or the limitation period expires. Personal data required for accounting purposes is stored for seven years.

Deletion of data

To delete personal data, customer support must be contacted via email. A response to the deletion request will be provided no later than within one month, specifying the period for deleting the data.

Data Portability

A request for data portability submitted via email will be answered within one month at the latest. Customer support verifies the person’s identity and notifies them of the personal data subject to transfer.

Direct marketing messages

The email address and phone number are used for sending direct marketing messages if the customer has given their consent. If the customer does not wish to receive direct marketing messages, they must select the corresponding link in the footer of the email or contact customer support.

Dispute resolution

Disputes related to the processing of personal data are resolved through customer support. The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).

Shopping Cart