Metsvintage website personal data processing policy
The controller of personal data on the Metsvintage website ( Metsvintage.com ) is E-asy OÜ (registration code 11987239), located at Undioru mill, Ülde village, Põhja-Sakala parish, 70411, Viljandi mk, e-mail.
What personal data is processed
- First and last name, telephone number and e-mail address;
- Bank account number;
- the cost of goods and services and payment details (purchase history);
- customer support details.
Purposes for which personal data is processed
Personal data is used for the management of customer orders and delivery of goods.
The bank account number is used to return payments to the customer.
Purchase history data (date of purchase, goods, quantity, cost, customer details) is used to compile an overview of goods and services purchased and to analyse customer preferences.
Personal data, such as e-mail, telephone number, customer name, are processed in order to resolve issues related to the provision of goods and services (customer support).
The IP address or other network identifiers of the user of the Metsvintage website are processed for the purpose of providing the Metsvintage website as an information society service and for the purpose of web usage statistics.
The legal basis for the processing of personal data is the sales contract concluded with the customer.
Processing of personal data is carried out for the performance of a contract and for the fulfilment of a legal obligation (e.g. accounting and settlement of consumer disputes).
Recipients to whom personal data are disclosed
Personal data will be transferred to Metsvintage’s website customer support for the purpose of managing purchases and purchase history and resolving customer issues.
The name, telephone number and e-mail address will be forwarded to the transport service provider chosen by the customer.
E-asy OÜ is the data controller, which forwards the personal data necessary for the execution of payments to the processor AS LHV Pank and Inbank AS. AS LHV Pank and Inbank AS will transfer personal data to E-asy OÜ for the purpose of accounting transactions.
Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality of the website or to ensure data availability.
Security and data access
Personal data is stored on servers of Zone Media OÜ located in the territory of a Member State of the European Union or in the territory of countries that are members of the European Economic Area. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to US companies that have signed up to the Privacy Shield framework.
Access to personal data is granted to the website’s employees who can access personal data in order to resolve technical issues related to the use of the website and to provide customer support services.
The Website implements appropriate physical, organisational and information technology security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.
The transfer of personal data to the website’s processors (e.g. the transport service provider and the data aggregator) is based on agreements between the website and the processors. Data controllers are required to ensure appropriate safeguards when processing personal data.
Accessing and correcting personal data
Personal data can be accessed and corrected in the user profile on the website. If the purchase has been made without a user account, you can access your personal data via customer support.
Receiving and unsubscribing from the newsletter
To receive the newsletter, the customer gives their consent. The customer may withdraw the aforementioned consent at any time by informing Customer Support by e-mail.
When a customer account is closed, the personal data is deleted, unless such data needs to be stored for accounting purposes or to resolve consumer disputes.
If the purchase is made without a customer account, the purchase history is kept for three years.
In the case of disputes relating to payments and consumer disputes, personal data will be kept until the claim is settled or the limitation period expires (three years).
Personal data necessary for accounting purposes are kept for seven years.
To have your personal data deleted, you must contact customer support by e-mail(firstname.lastname@example.org). A reply to the erasure request will be given within one month at the latest, specifying the period of erasure. Deletion of personal data is possible for personal data that, by law, no longer need to be kept for a longer period.
In order to transfer personal data, you must contact customer support by e-mail(email@example.com). Requests for the transfer of personal data made by e-mail will be answered within one month at the latest. Customer Support will verify the identity and inform you of the personal data to be transferred.
Direct marketing communications
The email address and telephone number will be used to send direct marketing messages if the customer has given their consent. If the customer does not wish to receive direct marketing communications, he/she should select the appropriate reference in the footer of the e-mail or contact customer support.
Where personal data is processed for the purposes of direct marketing (profiling), the customer has the right to object at any time to both the initial and further processing of his or her personal data, including profiling in relation to direct marketing, by informing Customer Support by e-mail (this information must be provided clearly and separately from any other information).
The following cookies are used on the website:
- Cookies necessary for the basic purposes of the website. These cookies are indispensable to ensure the user’s access to the customer-oriented services offered on this website and to use some features, such as access to secure areas. Without these cookies, desired services such as payment methods, secure account login and other bonuses that come with having a customer account would not be possible.
- Functionality and performance cookies. These cookies support the performance and functionality of our website, but are not strictly necessary for the functioning of the site. These cookies allow the website to identify the user and (if desired) remember the customer’s login details, store products added to the shopping cart for a certain period of time, etc.
- Analytics. The Metsvintage website uses the widely used Google analytics software to measure website traffic and map behavioural patterns. This data helps us to better understand the behaviour of visitors to our online shop and enables us to provide the best technical solutions for the user. These cookies are used for statistical purposes only and do not identify individual visitors.
- Third parties / advertising and social media. The Metsvintage website uses a number of trusted third party cookies. This allows users to share pages on social networks and display personalised and relevant advertising. Thus, these cookies enable the display of ads, for example, on various Google and Google partner platforms. The use of these cookies does not involve the processing of personal data.
Customers can delete and/or block cookies stored on their devices by changing the settings on their browser. If cookies are not used, the Metsvintage website may not function as intended and/or some functionalities may not be available to the customer.
Disputes relating to the processing of personal data will be resolved through customer support.
For any questions regarding data protection, please contact Metsvintage’s website customer support at firstname.lastname@example.org.
The supervisory authority is the Estonian Data Protection Inspectorate (email@example.com).