• FREE shipping to a parcel locker on orders from 890 SEK

  • 0

    Privacy policy

    1. General provisions

    1.1. This privacy policy regulates the principles of collecting, processing, and storing personal data. Personal data is collected, processed, and stored by the data controller.

    1.2. The data controller of the website https://www.lysgarden.se is Põhjala Teetalu OÜ, registration code 12575243, address: Põhjala, Jõksi küla, Kanepi vald, Põlvamaa 63110, phone (+372) 566 642 80, and email: info@lysgarden.se (hereinafter referred to as the data controller).

    1.3. The data subject within the meaning of the privacy policy is the client or any other natural person whose personal data is processed by the data controller.

    1.4. A client within the meaning of the privacy policy is anyone who purchases goods from the data controller’s website.

    1.5. The data controller adheres to the principles of data processing established by law, including processing personal data lawfully, fairly, and securely. The data controller can confirm that personal data has been processed in accordance with the applicable laws.

    2. Collection, processing, and storage of personal data  

    2.1. Personal data collected, processed, and stored by the data controller is primarily collected electronically, mainly through the website and email.

    2.2. By sharing their personal data, the data subject grants the data controller the right to collect, organize, use, and manage personal data for the purposes defined in the privacy policy, which the data subject directly or indirectly shares with the data controller when purchasing goods or services on the website.

    2.3. The data subject is responsible for ensuring that the data they provide is accurate, correct, and complete. Knowingly providing false information is considered a breach of the privacy policy. The data subject must immediately notify the data controller of any changes to the data provided.

    2.4. The data controller is not responsible for any damage caused to the data subject or third parties due to the data subject providing incorrect data.

    3. Types of personal data processed 

    3.1. The data controller may process the following personal data of the data subject:

    • First and last name, phone number, and email address;
    • Customer support data;
    • Bank account number;
    • Cost of goods and services and payment-related data (purchase history);
    • Technical data (IP address, device type, browser type and version, time zone, cookies);
    • Other information related to customer surveys and/or offers, including consent to receive marketing materials.

    3.2. In addition to the above, the data controller has the right to collect data about the customer from publicly available registers.

    4. Legal basis

    4.1 The processing of personal data is carried out for the purpose of fulfilling the sales contract with the customer (managing the customer’s orders, delivering goods, returning goods, and payments).

    4.2. The processing of personal data is carried out to fulfill legal obligations (accounting, responding to inquiries from public authorities in cases and to the extent permitted by law, resolving consumer disputes).

    4.3. The processing of personal data is based on the consent of the data subject for one or more specific purposes (e.g., direct marketing).

    5. Purposes of processing personal data 

    5.1 Personal data is used for managing customer orders and delivering goods.

    5.2. Personal data such as email, phone number, and customer name is processed for resolving issues related to the provision of goods and services (customer support).

    5.3. The email address is also used for sending invoices, including order confirmations, and the phone number is used for notifying about goods delivered to a parcel machine.

    5.4. Purchase history data (purchase date, goods, quantity, customer information) is used to compile an overview of purchased goods and services, for sales statistics, and for analyzing purchase preferences and consumer habits.

    5.5. The user’s IP address or other network identifiers are processed to provide the website as an information society service and to create website usage statistics.

    5.6. Personal data is processed for legal claims (resolving consumer disputes) and fulfilling legal obligations.

    5.7. Personal data is used (with the data subject’s consent) to prepare direct marketing offers and to send newsletters.

    5.8. The data controller follows the principle of data minimization, meaning that only the data necessary to achieve the specific purpose is processed. If the data controller intends to process the collected personal data for purposes not specified above, the data controller will provide information about the new purpose and other relevant additional information before further processing.

    6. Transmission of personal aata to Authorized processors 

    6.1. The online store may use third-party service providers as authorized processors of personal data when processing customer personal data, providing the necessary services to the online store (software development, payment, and postal services, collecting statistics, etc.). Authorized processors have the right to process personal data only according to the instructions received from the data controller, and agreements have been signed with authorized processors regarding the confidentiality of personal data. In addition to the above, the online store has the right to transmit personal data to supervisory, investigative, and law enforcement authorities and third parties if such an obligation arises from the law.

    6.2. List of authorized processors

    6.2.1 IT service providers (ensuring the functionality and data hosting of the online store)

    • Anyweb OÜ
    • VVUNK Digital Agency OÜ

    6.2.2 Accounting software provider (performing accounting tasks)

    • Merit Software

    6.2.3 Statistics collection (improving the user experience of the online store)

    • Google Analytics
    • Meta
    • Hotjar

    6.2.4 Payment service providers (prder payment processing)

    • Trustly Group AB
    • Apple Pay
    • Google Pay

    6.2.6 Postal service providers (order delivery to customers)

    • Itella Estonia AS
    • Posten Bring AS

    7. Data retention period

    7.1. The data controller stores personal data as long as necessary to achieve the purpose for which the data was collected, but no longer than two years, or until the data subject withdraws their consent for data processing, or until the expiration of statutory limitation periods, or until the expiration of the statutory document retention period (according to the VAT Act and the Accounting Act, 7 years).

    7.2. In the processing and storage of personal data, the data controller applies organizational and technical measures that ensure the protection of personal data from accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing. Only authorized persons have access to modify and process personal data.

    8. Rights of the data subject

    8.1. The data subject has the right to access and review their personal data.

    8.2. The data subject has the right to obtain information about the processing of their personal data.

    8.3. The data subject has the right to supplement or correct inaccurate data.

    8.4. If the data controller processes personal data based on the consent of the data subject, the data subject has the right to withdraw their consent at any time.

    8.5. The data subject can exercise their rights by contacting the online store’s customer support at info@lysgarden.se. To ensure the security of personal data processing, the request must be digitally signed.

    9. Direct marketing communications 

    9.1. The online store sends newsletters and offers to the customer’s email address only if the customer has given the appropriate consent. If the customer does not wish to receive direct marketing communications, they should select the appropriate link at the bottom of the email or contact customer support via email (info@lysgarden.se).

    9.2. The customer can unsubscribe from offers and newsletters sent to their email at any time by following the instructions in the marketing email or by contacting customer support via email.

    9.3. The online store may process personal data for direct marketing purposes (profiling) to better understand the customer’s preferences and, as a result, offer better goods and services. In such cases, the customer has the right to object to the processing of their personal data, including profiling related to direct marketing, at any time by notifying customer support via email.

    10. Use of cookies 

    A cookie is a small text file that the browser automatically saves on the user’s device. Cookies are used to collect information about how the user uses the website to provide the user with a better browsing experience. You can read more about the use and storage of cookies here.  

    11. Final Provisions

    11.1. These data protection terms have been drawn up in accordance with Regulation (EU) No 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the Estonian Personal Data Protection Act, and the laws of the Republic of Estonia and the European Union.

    11.2. The data controller has the right to change and supplement the privacy policy at any time. The current privacy policy is always available on the website www.lysgarden.se.

    0
      0
      A tea basket
      The tea basket is emptyBack to the store