Privacy Policy
Pehmö Online Shop Data Processing Terms
The data controller for the Pehmö online shop (pehmoshop.com) is Pehmö OÜ (registration code 16629779), located at Keskuse tee 4, Kõima village, Pärnu city, Pärnu county, 88309. Phone: +372 5043660, Email: info@pehmoshop.com
Pehmö OÜ transmits personal data necessary for processing payments to the authorized processor Montonio Finance OÜ.
Personal Data Processed
- Name, phone number, and email address.
- Delivery address for goods.
- Bank account number.
- Cost of goods and services, and payment-related data (purchase history).
- Customer support data.
- IP address.
Purpose of Processing Personal Data
- Personal data is used for managing customer orders and delivering goods.
- Purchase history data (purchase date, goods, quantity, customer details) are used for compiling an overview of purchased goods and services, analyzing customer preferences, and resolving consumer disputes.
- Bank account numbers are used to refund payments to customers.
- Personal data like email, phone number, and customer name are processed to resolve issues related to the provision of goods and services (customer support). Email is also used for sending invoices, and the phone number is used for notifying about goods arriving at parcel terminals.
- The IP address of the online shop user or other network identifiers are processed for the provision of the online shop as an information society service and for making web usage statistics.
Legal Basis
- Processing of personal data occurs for the purpose of fulfilling the contract with the customer (managing orders, delivery, and refund of goods and payments).
- Processing of personal data takes place to fulfill a legal obligation (e.g., accounting and resolving consumer disputes).
- The processing of personal data is necessary due to the legitimate interest of the responsible processor, which consists of collecting purchase history data for resolving potential consumer disputes.
Recipients to Whom Personal Data is Transmitted
- Name, phone number, and email address are transmitted to the transportation service provider selected by the customer. If the delivery is made by courier, the customer’s address is also transmitted along with the contact details.
- If the online shop’s accounting is managed by a service provider, personal data is transmitted to the service provider for accounting operations.
- Personal data may be transmitted to IT service providers if necessary for the functionality or data hosting of the online shop.
- The partner to whom data is transmitted is Smaily (Sendsmaily OÜ) Paldiski mnt 29, 10612, Tallinn, Harju County, Estonia.
Security and Access to Data
- Personal data is stored on servers of Zone Media OÜ, located in the territory of the European Union member state or states associated with the European Economic Area. Data may be transmitted to countries whose level of data protection has been deemed adequate by the European Commission or to a third-country company for which protection measures specified in Article 46 have been applied.
- Access to personal data is available to employees of the online shop, who can access personal data in order to resolve technical issues related to the use of the online shop and provide customer support.
- The online shop implements appropriate physical, organizational, and information technology security measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorized access and disclosure.
- The transfer of personal data to authorized processors of the online shop (e.g., transportation service provider and data hosting) is based on contracts concluded between the online shop and the authorized processors. Authorized processors are required to ensure appropriate protection measures in processing personal data.
Accessing and Correcting Personal Data
- Personal data can be accessed and corrected in the online shop’s user profile. If a purchase is made without a user account, personal data can be accessed through customer support. If a request to access personal data is submitted electronically, information is also provided through commonly used electronic means.
Withdrawal of Consent
- If the processing of personal data occurs based on the customer’s consent, the customer has the right to withdraw consent by notifying customer support via email.
Retention
- Upon closing the online shop customer account, personal data is deleted, except for personal data (purchase history data) that needs to be retained for accounting purposes or resolving consumer disputes. In the case of disputes related to payments and consumer disputes, personal data is retained until the fulfillment of the claim or the expiry of the limitation period. Personal data contained in accounting source documents are retained for seven years.
Restriction
- The customer has the right to request the restriction of their personal data processing if the data is incorrect or incomplete, or if their personal data is processed unlawfully.
Objections
- The customer has the right to object to the processing of their personal data if they believe there is no legal basis for the processing of their personal data.
Disputes
- The resolution of disputes related to the processing of personal data is handled through customer support by sending an email to info@pehmoshop.com or by calling the phone number: +372 5043660. The supervisory authority is the Estonian Data Protection Inspection (info@aki.ee).
Cookie policy
- A cookie is a small text file that is sent to a user’s browser. most of the web browsers are initially configured to accept cookies, which are designed to hold a modest amount of data and keep track of your settings in order to improve your shopping experience. you have right to request access to your data or disable cookies on your device by changing your browser settings.