The chief processor of personal data of the online store hiiuõllekoda.ee is Kassariotsa OÜ (10819576) located in Tammetalu, Kassari village, Hiiumaa parish, 92111; info@hiiuõllekoda.ee.
What personal data is processed
– name, telephone number and e-mail address;
– delivery address;
– bank account number;
– cost of goods and services and data related to payments (purchase history);
– customer support information.
For what purpose is personal data processed?
Personal data is used to manage customer orders and deliver goods. Purchase history data (purchase date, goods, quantity, customer data) is used to compile an overview of purchased goods and services and to analyze customer preferences. The bank account number is used to return payments to the customer. Personal data, such as e-mail, telephone number, customer name, is processed to resolve issues related to the provision of goods and services (customer support). The IP address or other network identifiers of the online store user are processed to provide the online store as an information society service and to compile online usage statistics.
The processing of personal data takes place for the purpose of fulfilling the contract entered into with the customer. The processing of personal data is carried out in order to fulfill a legal obligation (eg accounting and settlement of consumer disputes).
Recipients to whom personal data are transmitted
Kassariotsa Osaühing is the chief processor of personal data, the company forwards the personal data necessary for making payments to the authorized processor Maksekeskus AS. Personal information is passed on to the online store’s customer support to manage purchases and purchase history and to resolve customer issues. The name, telephone number and e-mail address will be forwarded to the transport service provider chosen by the customer. In the case of goods delivered by courier, the customer’s address will be provided in addition to the contact details.
Security and access to data
Personal data is stored on the servers of Zone Media OÜ, which are located in the territory of a Member State of the European Union or countries that have joined the European Economic Area. The data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to US companies that are affiliated to the Privacy Shield framework service.
The Online Store implements appropriate physical, organizational and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration or unauthorized access and disclosure.
The transfer of personal data to the authorized processors of the online store (eg transport service provider and data hosting) takes place on the basis of agreements concluded with the online store and the authorized processors. Authorized processors are required to ensure appropriate safeguards for the processing of personal data.
Access to and correction of personal data
Personal data can be accessed and corrections made to the user profile of the online store. If the purchase has been made without a user account, personal data can be accessed via klint support.
Withdrawal of consent
If the processing of personal data takes place on the basis of the customer’s consent, the customer has the right to withdraw the consent by notifying the customer support by e-mail.
Upon closing the customer account of the online store, personal data will be deleted, unless such data needs to be kept for accounting or resolving consumer disputes. The personal data required for accounting purposes shall be kept for seven years.
To delete personal information, contact customer support via email. A request for erasure shall be answered within a month at the latest and the period for erasure shall be specified.
A request for the transfer of personal data submitted by e-mail will be answered within a month at the latest. Customer support identifies and notifies you of personal information that is subject to transfer.
Direct marketing announcements
The e-mail address and telephone number will be used to send direct marketing communications if the customer has given their consent. If the customer does not wish to receive direct marketing communications, please select the appropriate link in the email footer or contact customer support.
If personal data is processed for direct marketing purposes (profiling), the customer has the right to object at any time to the initial and further processing of his personal data, including profiling related to direct marketing, by notifying customer support by e-mail.
Disputes related to the processing of personal data are resolved through customer support info@hiiuõllekoda.ee. The supervisory authority is the Estonian Data Protection Inspectorate (email@example.com).