PRIVACY POLICY
(For the online store Naturasugar OÜ)
1. General Provisions
1.1. This Privacy Policy regulates the principles of collection, processing, and storage of personal data. The data controller is Naturasugar OÜ (registry code 14389094, address: Katusepapi 4/2, Tallinn, Estonia) (hereinafter referred to as the Data Controller).
1.2. For the purposes of this Privacy Policy, a data subject means a customer or any other natural person whose personal data is processed by the Data Controller.
1.3. A customer is any person who purchases goods or services from the Data Controller’s online store.
1.4. The Data Controller observes all applicable legislation on personal data processing and ensures that personal data is processed lawfully, fairly, and securely.
2. Collection, Processing, and Storage of Personal Data
2.1. Personal data is collected and processed primarily electronically via the online store and e-mail.
2.2. By providing their personal data, the data subject grants the Data Controller the right to collect, organize, use, and manage the personal data for the purposes defined in this Privacy Policy.
2.3. The data subject is responsible for the accuracy and completeness of the submitted data. Deliberately providing false information is considered a violation of this Privacy Policy.
2.4. The Data Controller is not liable for any damage caused to the data subject or third parties due to the submission of false information.
3. Processing of Customers’ Personal Data
3.1. The Data Controller may process the following personal data:
First and last name
Date of birth
Phone number
Email address
Delivery address
Bank account information
Payment card information
3.2. The Data Controller also has the right to collect publicly available information about customers.
3.3. Legal grounds for processing personal data in accordance with Article 6(1) GDPR:
a) Consent of the data subject
b) Performance of a contract
c) Compliance with a legal obligation
f) Legitimate interests of the Data Controller, unless overridden by the interests or fundamental rights of the data subject
3.4. Purposes of Processing and Retention Periods
3.4.1 Security and safety
Data is retained according to legal requirements.
3.4.2 Processing orders
Data is retained up to 3 years after the last purchase.
3.4.3 Ensuring online store services
Data is retained up to 3 years.
3.4.4 Customer management
Data is retained up to 3 years after the end of the customer relationship.
3.4.5 Financial and accounting purposes
Data is retained in accordance with legislation (7 years).
3.4.6 Marketing
Data is retained until consent is withdrawn or for a maximum of 3 years after last interaction.
3.5. The Data Controller may share personal data with third parties such as:
Accounting companies
Transport and courier companies
Payment service providers
For payment processing, necessary personal data is transmitted to the payment processor Maksekeskus AS.
3.6. The Data Controller implements technical and organizational measures to protect personal data from unlawful access, alteration, destruction, or disclosure.
3.7. Personal data is stored according to the purpose of processing, but no longer than 7 years.
4. Rights of the Data Subject
4.1. The data subject has the right to access their personal data.
4.2. The data subject has the right to obtain information on the processing of their data.
4.3. The data subject has the right to rectify inaccurate data.
4.4. If personal data is processed based on consent, the data subject has the right to withdraw their consent at any time.
4.5. To exercise their rights, the data subject can contact customer support:
4.6. The data subject has the right to file a complaint with the Data Protection Inspectorate.
5. Final Provisions
5.1. This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation), the Personal Data Protection Act of the Republic of Estonia, and other applicable legislation of the European Union.
5.2. The Data Controller reserves the right to amend this Privacy Policy, with updates published on the website: