Privacy policy

The controller of the personal data of the online shop is purenature.ee (registry code 114102997), with a registered location at Tulbi tee 20, Rae küla, Harjumaa, phone +372 5884 8748 and e-mail info@elusvali.ee.

Which personal data are processed?

– name, phone number and e-mail address;

– delivery address;

– bank account number;

– cost of goods and services and data related to payments (purchase history);

– customer support data;

– IP address.

For which purposes are personal data processed?

Personal data is used to manage the customer’s orders and to deliver goods.

Purchase history data (date of purchase, goods, quantity, customer data) are used to put together an overview of the goods and services purchased, to analyse customer preferences and, among other things, for the purposes of resolving consumer disputes.

The bank account number is used to reimburse payments to the customer.

Personal data such as the e-mail address, telephone number and name of the customer are processed to handle any issues relating to the provision of goods and services (customer support). E-mail is also used in order to forward invoices and the telephone number is used to notify the customer about their goods arriving in the parcel locker.

The IP address of the customer  is used to collect website usage statistics, to improve the user experience or to display targeted advertisements. The customer gives his consent to this by accepting cookies on the website.

Legal basis

The purpose of processing personal data is to fulfill the agreement entered into with the customer (managing the customer’s orders, delivery, returning goods and reimbursing payments).

Personal data are processed in order to fulfill legal obligations (e.g. for accounting).

The processing of personal data, i.e. the collection of purchase history data for the purposes of resolving potential consumer disputes, is necessary due to the controller’s legitimate interest.

The data are processed with the consent of the customer for the following purposes: newsletters via email.

Recipients of personal data

Name, telephone number and e-mail address are forwarded to the transport service provider selected by the customer. If the goods are delivered by a courier, the customer’s contact details, as well as their address, are forwarded to the courier.

If an outside service provider handles the accounting for the online shop, the personal data is forwarded to that service provider to perform the accounting operations.

Personal data may be forwarded to IT service providers if this is needed to ensure the functionality of the online shop or to host data.

Security and access to data

Personal data are stored in the servers of the online shop and IT service providers , which are located on the territory of Estonia.

Personal data can be accessed by the staff of the online shop in order to resolve technical issues related to the use of the online shop and to provide customer support.

The online shop applies the relevant physical, organisational and IT security measures in order to protect personal data from accidental or unlawful destruction, loss, amendment or unauthorised access and disclosure. These measures are:

− data exchange with the e-shop takes place via an encrypted connection (TSL);

− customer passwords are kept encrypted (hash);

− standard encryption is used when sending e-mails;

− a firewall and appropriate anti-virus protection have been implemented to protect the e-shop’s servers;

– regular backups are created, which are kept separately from the e-shop server.

Personal data are forwarded to processors (e.g. the transport service provider and data hosts) on the basis of contracts between the online shop and processors.

Upon processing data, the processors are obliged to ensure the relevant safeguards in accordance with article 28 of the GDPR.

Access to and rectification of personal data

Personal data can be accessed and rectified via the online shop’s user profile or customer support. If a purchase is made without a user account, personal data can be accessed via customer support. If the request to access personal data has been submitted electronically, the information will also be provided via commonly used electronic means.

Withdrawal of consent

If personal data are processed with the customer’s consent, the customer has the right to withdraw their consent by notifying customer support via email.

Storage

Personal data are erased upon deleting the online shop’s customer account, except for the personal data (purchase history) which are necessary for accounting or to resolve consumer disputes.

In the event of disputes regarding payments and consumer disputes, personal data are stored until the claim is settled or the limitation period expires. The personal data in original accounting documents is stored for seven years.

Restriction

If the data are incorrect, incomplete or processed unlawfully, the customer has the right to request the restriction of the processing of their personal data.

Objections

The customer has the right to submit objections regarding the processing of their personal data if they have a reason to believe that there is no legal basis to process their personal data.

Erasure

For the erasure of personal data, customer support should be contacted by email. Requests for erasure are responded to within one month and the period of erasure is specified. The response to the request will also indicate which personal data will not be erased, on which legal basis and why.

Transfer

Requests to transfer personal data submitted via e-mail are responded to within one month.

Customer support identifies the person and indicates which personal data is to be transferred.

Direct marketing messages

The email address is used to send direct marketing messages only if the customer has given consent to receive newsletters. Otherwise, no direct marketing messages will be sent to the customer. If the customer does not wish to receive direct marketing messages to which he has previously given his consent, he must select the corresponding reference in the footer of the email or contact customer support.

Resolution of disputes

Disputes concerning the processing of personal data are settled through customer support (email info@elusvali.ee or telephone +372 5884 8748).