Processing of personal data
Responsibility for processing personal data in pood.regio.ee/en lies with Regio OÜ (Reg. No. 12971967), address Riia 35, Tartu linn, 50410, phone +372 731 0122, email email@example.com. We forward the personal data needed for payment to authorized processor Maksekeskus AS.
Regio provides the necessary personal data to the postal service company to the extent necessary for the delivery of the order.
What personal data is processed:
- name, telephone number and e-mail address;
- delivery address of the goods;
- bank account number;
- cost of goods and services and data related to payments (purchase history);
- Customer support information.
Purpose for processing personal data
Personal data will be used for order management and delivery.
Purchase history (order date, goods, amount, Customer information) will be used for analyzing Customer preferences and for getting an overview of purchased goods and services.
Bank account number will be used for refunding payments.
Personal data such as e-mail, phone number, Customer’s name will be processed to solve goods- and services-related questions (Customer support).
The IP-address and other network identifiers of the Customer of the online store will be processed for monitoring web usage statistics and for providing the online shop service as one of the information society services.
The processing of personal data is used for fulfilling the contract concluded with the Customer.
The processing of personal data is used for fulfilling the legal obligations (for example accounting, consumer dispute resolution).
Recipients to whom the personal data is forwarded
Personal data will be transferred to online shop customer support for managing the purchases and purchase history and in order to solve customer problems.
Name, phone number and e-mail are transferred to the transport service provider chosen by the Customer. The delivery address will also be forwarded in case of delivery by courier.
When the accounting service comes from a service provider, the personal data will be transferred to the service provider for accounting operations.
Personal data may be transferred to information technology service providers, when it is necessary for the assurance of the functionality or data hosting of the online store.
Security and access to data
Personal data is stored in the servers of OÜ Elkdata. These are located in the territory of a Member State of the European Union or in countries that have joined the European Economic Area. Data may be sent to countries, whose level of data protection has been assessed as adequate by the European Commission and to US companies that have joined the framework of the Privacy Shield.
Access to the personal data has been granted to the workers of the online shop, who need to see the data to solve technical issues related to the use of the online shop and provide customer support service.
The online store implements appropriate physical, organizational and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration or unauthorized access and disclosure.
The transfer of personal data to the authorized processors of the online store (e.g. transport service provider and data hosting) takes place on the basis of agreements concluded with the online store and the authorized processors. Authorized processors are obliged to ensure appropriate protective measures for the processing of personal data.
Access to and correction of personal data
Personal data can be accessed and corrections can be made in the user profile of the online store. If the purchase has been made without a user account, personal data can be accessed through the customer support.
Withdrawal of consent
If the processing of personal data takes place on the basis of the Customer’s consent, the Customer has the right to withdraw the consent by notifying the customer support by e-mail.
When closing the Customer account in the online store, personal data will be deleted, unless the data have to be retained for accounting purposes or for resolving consumer disputes.
If the purchase in the online store has been made without a customer account, the purchase history will be stored for three years. In the case of disputes related to payments and consumer disputes, personal data will be kept until the claim is fulfilled or the limitation period expires.
Personal data required for accounting purposes are kept for seven years.
In order to delete personal data, customer service must be informed by e-mail. The request for erasure will be answered no later than within one month and the period for erasure of data is will be specified.
A request for the transfer of personal data submitted by e-mail will be answered within a month at the latest.
Customer support will identify the person and will notify them of the personal data to be transferred.
Direct marketing notifications
E-mail and phone number will be used for direct marketing notifications only if the customer has given his/her consent. When the Customer wants to unsubscribe from direct marketing notification, the reference at the end of the letter must be selected or the customer service contacted.
When personal data is used for direct marketing, the Customer is entitled to object at any time to the processing of personal data, including the profile analysis related to direct marketing, by notifying customer support via e-mail.
Settlement of disputes related to the processing of personal data
The settlement of disputes related to the processing of personal data is resolved through customer support – Leida Lepik, Regio OÜ (Registration code 12971967) address Riia 35, Tartu, 50410, phone +372 731 0122, e-mail firstname.lastname@example.org.
The supervisory authority is the Data Protection Inspectorate (email@example.com).