Privacy Policy and Security

Processed personal data:

Name and surname;

Telephone number;

E-mail;

Address;

Cost of goods and services;

Bank account number.

Purpose of processing personal data

Personal data are used for the handling of customer orders and delivery of goods.

Purchase history data (date of purchase, goods, quantity, customer information) are used for preparing an overview of purchased goods and services and analysing customer preferences.

The bank account number is used for the return of payments to customers. Personal data such as e-mail, telephone number and customer’s name are processed for resolving issues related with the purchase of goods and services (customer support). The IP addresses of e-shop users or other network indicators are processed for the provision of e-shop service as an information society service and preparation of web usage statistics.

Legal basis

The processing of personal data takes place with the objective of performing the contract entered into with the customer. The processing of personal data takes place for the performance of a legal obligation (e.g accounting and resolving consumer disputes).

Recipients of information

Personal data are transmitted to the e-shop customer support for the management of purchases and purchase history and resolving customers’ problems.

The name, telephone number and e-mail address are transmitted to the provider of transport service chosen by the customer. If the goods are delivered by courier service, the customer’s address is also transmitted in addition to the contact details.

The personal data are transmitted to the accountant specified by the service provider.

Personal data may be transmitted to IT service providers if it is necessary for ensuring the functionality of the e-shop or data storage.

Security and access to data

Personal data are preserved in zone.ee servers, which are located on the territory of a European Union Member State or a state having joined the economic area of the European Union.

The employees of the e-shop have access to the personal data. The employees may examine the personal data in order to resolve the technical issues related with the use of the e-shop and to provide the customer support service.

The e-shop applies relevant physical, organisational and IT security measures to protect the personal data against accidental or illegal loss, damage, alteration or unauthorised access and disclosure.

Transmission of personal data to the processors of the e-shop (e.g provider of transport service and data storage) takes place on the basis of contracts entered into with the processors of the e-shop. The processors are obliged to ensure the application of appropriate protection measures upon processing personal data.

Withdrawal of consent

If the processing of personal data takes place with the customer’s consent, the customer has the right to withdraw the consent by notifying the customer support thereof by e-mail.

Preservation

Upon closing the e-shop customer account, the personal data shall be deleted, unless such data need to be preserved for accounting or resolving customer disputes.

Where a purchase has been made in the e-shop without customer account, the purchase history shall be preserved for three years. In case of disputes concerning payments and consumer disputes, personal data are preserved until the performance of the claim or the expiry of the limitation period.

Personal data necessary for accounting shall be preserved for seven years.

Deletion

For the deletion of personal data please contact the e-shop by e-mail.

The deletion application is replied to within a month and the period for the deletion of data is specified.

Boss Trading LTD is the controller of personal data.