Privacy Policy

1. General Provisions

1.1. This Privacy Policy sets out the principles governing the collection, processing, use, and storage of personal data in the online store www.leniro.ee. The controller of personal data is Vilcar OÜ, registry code 14735873, e-mail info@leniro.ee (hereinafter referred to as the Data Controller).

1.2. For the purposes of this Privacy Policy, a data subject is a customer or any other natural person whose personal data is processed by the Data Controller.

1.3. For the purposes of this Privacy Policy, a customer is a person who purchases or intends to purchase goods from the Data Controller’s online store.

1.4. The Data Controller processes personal data lawfully, fairly, transparently, and securely, and only to the extent necessary for the operation of the online store, fulfilment of orders, customer communication, and compliance with obligations arising from applicable law.

2. Collection, Processing, and Storage of Personal Data

2.1. Personal data collected, processed, and stored by the Data Controller is collected electronically, primarily through the website and by e-mail.

2.2. By providing personal data, the data subject confirms that the information provided is correct, accurate, and complete.

2.3. The data subject is required to inform the Data Controller of any changes to the information provided where such changes are necessary for the fulfilment of an order or the provision of another service.

2.4. The Data Controller shall not be liable for any damage caused by incorrect or incomplete information provided by the data subject.

2.5. The Data Controller shall retain personal data only for as long as necessary to fulfil the purpose of the processing or to comply with obligations arising from applicable law.

2.6. The Data Controller may process the following personal data of the data subject:

2.6.1. first name and surname;

2.6.2. telephone number;

2.6.3. e-mail address;

2.6.4. delivery address;

2.6.5. billing information;

2.6.6. order information;

2.6.7. customer communication data;

2.6.8. technical data related to the use of the website, including the IP address.

2.7. If the customer purchases goods as a legal entity, the Data Controller may also process the company name, registry code, and information necessary for issuing invoices.

2.8. The Data Controller does not store the customer’s full payment card details. Payments are processed in the secure environment of the payment service provider.

2.9. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation (GDPR):

a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;

c) processing is necessary for compliance with a legal obligation to which the controller is subject;

f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

2.10. Personal data is processed primarily for the following purposes:

2.10.1. receiving and fulfilling orders;

2.10.2. enabling payment for goods;

2.10.3. delivery of goods;

2.10.4. communication with the customer;

2.10.5. handling returns and complaints;

2.10.6. accounting and compliance with obligations arising from applicable law;

2.10.7. ensuring the operation, development, and security of the online store;

2.10.8. sending newsletters and promotional offers where the customer has given consent.

2.11. The Data Controller has the right to transfer personal data to third parties to the extent necessary for the fulfilment of an order, provision of a service, or compliance with an obligation arising from applicable law. Such third parties may include payment service providers, transport and courier companies, parcel locker service providers, accounting service providers, and technical service providers of the online store.

2.12. When processing and storing the personal data of the data subject, the Data Controller applies appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, disclosure, unauthorised access, and any other unlawful processing.

3. Rights of the Data Subject

3.1. The data subject has the right to access and review his or her personal data.

3.2. The data subject has the right to receive information regarding the processing of his or her personal data.

3.3. The data subject has the right to request the correction of incorrect or inaccurate personal data.

3.4. Where personal data is processed on the basis of the data subject’s consent, the data subject has the right to withdraw such consent at any time.

3.5. To exercise his or her rights, the data subject may contact the Data Controller by e-mail at info@leniro.ee.

3.6. The data subject has the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) in order to protect his or her rights.

Ostukorv
Kerige üles