E-shop rosaya.ee responsible processor of personal data is Rosaya OÜ registry code 14574615 location Arulaane, Kalita küla, Saarde vald, Pärnumaa 86206, phone nr +372 5359 4334 and email firstname.lastname@example.org
WHICH PERSONAL DATA WILL BE PROCESSED
-name, phone number and email address
-bank account number
-cost of goods and services and information relative to payments(shopping history)
-customer support data
ON WHAT PURPOSE PERSONAL DATA WILL BE PROCESSED
Personal data is used to manage clients orders and deliver goods. Data of shopping history (date of the purchase, items, amounts, clients data) will used to put together overview of bought items and services and to analyze clients preferences. Bank account number will be used to return payments to client. Personal data such as email, phone nr, clients name, will be processed in order to solve issues about bought products or services (customer support). E-shop users IP-address or other web identifiers will be processed for e-shop as info society to provide service and to put together web usage statistics.
Processing of personal data will be performed in order to fulfill the goal set when signing a contract with the client. Processing of personal data will be performed in order to fulfill legal obligations (for example accounting and consumer dispute solution).
RECIEVERS, TO WHOM PERSONAL DATA WILL BE GIVEN
Personal data will be given to e-shop customer support to manage purchases and shoppin history and to resolve client problems. Name, phone nr and email address will be given to transport services selected by the client. If selected is home delivery then additional to contact information also clients address will be given. If e-shop accounting is performed by accounting services then personal data needed to perform accounting will be given to accounting services. Personal data nay be given to infotechology services provider if it is necessary to guarantee the functionality of the e-shop or data housing.
SAFETY AND ACCESS TO DATA
Personal data is kept is servers, that are located in European Union country or in the territory of a country that has joined European Union economy area. Data may be given to countries whos personal data protection level is judged to be enough by the European Comission and to USA companies who have joined the Privacy Shield. Access to personal data have e-shop workers who can see personal data in order to resolve technical issues relevant to using the e-shop and provide service to customer. E-shop uses necessary physical, organizational and infotechincal safety measures to protect personal data from random or illegal destruction, being lost, being changed or unallowed access or publication. Forwarding personal data to authorized employess (for example provider of transport services or data hosting) will be performed under contract signed between e-shop and authorize emplyees. Authorized employees are obligated to guarantee necessary measurements when processing personal data.
LOOKING INTO PERSONAL DATA AND CORRECTING THEM
Looking at personal data and correcting them can be done in e-shop users profile. If the purchase has been done without users account then you can look at personal data through customer support.
If personal data processing is done on the grounds of clients agreement, then client has the right to decline the agreement or let customer services know about this via email email@example.com
When clients account in e-shop is closed then personal data will be deleted, unless the data is needed for accounting or resolving consumers disputes. If purchase in e-shop has been done without clients account then shopping history will be preserved for three years. Disputes about payments or consumer arguments personal data will be preserved until claim has been fulfilled or expiration date. Personal data needed for accounting will be preserved for seven years.
In order to delete Personal data client must contact customer support via email firstname.lastname@example.org. Application for deleting will be answered not later then within a one month and the period of deleting personal data will be specified.
Application for transferring personal data presented via email will be replied within one month. Customer support will identify person and let know of personal data to be transferred.
DIRECT MARKETING NOTIFICATIONS
Email address and phone nr are used to send direct marketing notifications, when client has given agreement to this. If client does not want to receive direct marketing notifications then client must choose required reference from bottom of email or contact customer support. If personal data is processed for direct marketing (profiling) then client has the right to present objections to personal data processing and profiling. Then customer support must be let know of this via email.
Resolving of disputes concerning processing personal data will be performed via customer support mailto: email@example.com
Authority is Eesti Andmekaitse Inspektsioon (firstname.lastname@example.org).