Data and Privacy
Mää e-store (Villatoode OÜ), hereinafter “e-store”, has undertaken to protect the privacy of its customers and e-store users, and has drawn up privacy policy principles regarding the collection, use, transfer and storage of customer data.
Processing of personal data
The chief process or of the personal data of the e-store is Villatoode OÜ (registration code16310754) located at Töökoja, Meelva village, Räpina parish, Põlva county. Contact: sander@maa.garden.
Which personal data are processed: name, phone number, e-mail address, delivery address, price of goods.
Why are personal data processed?
Personal data are used to manage customer orders and deliver goods. Purchase history data (purchase date, goods, quantity, customer data) are used to create an overview of purchased goods and services, as well as to analyze customer preferences. Personal data such as e-mail, phone number, customer name, are processed to resolve issues related to the provision of goods and services (Customer Support). The e-store user’s IP address or other network identifiers are processed for the provision of the e-store as an information society service, and for online usage statistics.
Legal basis
Personal data are processed for the purpose of fulfilling the contract concluded with the customer. Personal data are processed to fulfil a legal obligation.
Recipients to whom personal data are transferred
Personal data are transferred to the Customer Support of the e-store to manage purchases and purchase history and to solve customer problems. If the e-store's accounting is done by the service provider, personal data are transferred to the service provider for accounting operations. Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality of the e-store or data hosting. Villatoode OÜ is the chief processor of personal data, the company transfers the personal data necessary for making payments to the authorized processor Stripe Payment Centre.
Security and data access
Personal data is stored on Webflow.com servers. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission, and to US companies that are complying with the Privacy Shield framework. Employees of the e-store have access to personal data, they can access personal data in order to solve technical issues related to the use of the e-store, and to provide Customer Support services. The e-store uses appropriate physical, organizational and IT security measures to protect personal data from accidental or illegal destruction, loss, alteration or unauthorized access, and disclosure. Transfer of personal data to authorized processors of the e-store (e.g. transport service provider and data hosting) takes place on the basis of contracts concluded with the e-store and authorized processors. The authorized processors are obliged to ensure appropriate protection measures when processing personal data.
Viewing and amending personal data
Personal data can be viewed and amended through the user profile of the e-store. If the purchase has been made without a user account, the personal data can be viewed via the Customer Support.
Withdrawal of consent
If the processing of personal data takes place on the basis of the customer's consent, the customer has the right to withdraw the consent by notifying the Customer Support by e-mail.
Storage of personal data Upon closing the customer account of the e-store, personal data will be deleted, except in cases where it is necessary to keep such data for accounting purposes or to resolve consumer disputes. If a purchase is made in the e-store without a customer account, the purchase history is stored for three years. In the case of disputes related to payments and consumer disputes, personal data will be stored until the claim is fulfilled or the expiry period ends. Personal data necessary for accounting are stored for seven years.
Erasure of personal data
To erase personal data, you must contact the Customer Support by e-mail. A request for erasure will be responded after no more than a month, and the data erasure period will be specified.
Transfer of personal date
A request for transferring personal data submitted by e-mail will be responded after no more than a month. The Customer Support identifies the identification, and informs about the personal data that is subject to transfer.
Direct marketing messages
The e-mail address and phone number are used to send direct marketing messages if the customer has given their consent. If the customer does not wish to receive direct marketing messages, they must select the corresponding reference in the footer of the e-mail, or contact the Customer Support. If personal data is processed for the purpose of direct marketing (profiling), the customer has the right to object at any time to both the initial and further processing of their personal data, including profile analysis related to direct marketing, by notifying the Customer Support by e-mail.
Resolving disputes
Disputes related to the processing of personal data are resolved through the Customer Support (e-mail: sander@maa.garden). The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).