Privacy Policy
Data Processing
The responsible data controller for the website www.artlab.ee is Artlab OÜ (registration code 12905674), located at J.Vilmsi 53J, Tallinn, 10126, phone +372 58667027, email: artlabestonia@gmail.com.
Types of Personal Data Processed
Name, phone number, and email address;
Delivery address of goods;
Bank account number;
Cost of goods and services and payment-related data (purchase history);
Customer support data.
Purpose of Data Processing
Personal data is used for managing customer orders and delivering goods. Purchase history data (purchase date, product, quantity, customer data) is used to generate an overview of purchased goods and services and to analyze customer preferences. The bank account number is used for refunding payments to the customer. Personal data such as email, phone number, and customer name is processed to resolve issues related to the provision of goods and services (customer support). The IP address or other network identifiers of the online store user are processed to provide the online store service and generate usage statistics.
Legal Basis
The processing of personal data is carried out for the performance of a contract with the customer. Personal data processing is also carried out to fulfill legal obligations (e.g., accounting and resolving consumer disputes).
Recipients to Whom Personal Data is Transferred
Personal data is transferred to the customer support team of the online store for managing orders and purchase history, as well as resolving customer issues. Name, phone number, and email address are transferred to the transport service provider chosen by the customer. If the product is delivered by a courier, the customer’s address is also transferred along with the contact details. If the online store’s accounting is handled by a service provider, personal data is transferred to this service provider for accounting purposes. Personal data may be transferred to IT service providers if necessary to ensure the functionality of the online store or data hosting services.
Security and Data Access
Personal data is stored on servers hosted by zone.ee, located within the territory of an EU member state or a country that is part of the European Economic Area. Data may be transferred to countries deemed by the European Commission to have adequate data protection, as well as to U.S. companies that are part of the Privacy Shield framework. Access to personal data is granted to online store employees who can review the data in order to resolve technical issues related to the use of the online store and provide customer support. The online store implements appropriate physical, organizational, and technical security measures to protect personal data from accidental or unlawful destruction, loss, alteration, or unauthorized access and disclosure. The transfer of personal data to authorized processors (e.g., transport service providers and data hosting) is based on agreements between the online store and authorized processors. Authorized processors are required to ensure appropriate protection measures when processing personal data.
Access to and Correction of Personal Data
Personal data can be reviewed and corrected through the user profile on the online store.
Withdrawal of Consent
If personal data processing is based on the customer’s consent, the customer has the right to withdraw their consent by notifying customer support via email.
Retention
When a customer account is closed, personal data will be deleted, unless such data needs to be retained for accounting purposes or resolving consumer disputes. In case of payment-related and consumer dispute issues, personal data will be retained until the claim is fulfilled or until the expiration of the statute of limitations. Personal data required for accounting purposes will be retained for seven years.
Deletion
To request the deletion of personal data, customers should contact customer support via email. A response to the deletion request will be provided within one month, specifying the period for data deletion.
Data Portability
Requests for the transfer of personal data via email will be addressed within one month. Customer support will verify identity and inform about the data to be transferred.
Direct Marketing Communications
Email addresses and phone numbers may be used to send direct marketing communications if the customer has given consent. If the customer no longer wishes to receive such communications, they should select the corresponding option at the bottom of the email or contact customer support. If personal data is processed for direct marketing purposes (including profiling), the customer has the right to object to the processing of their personal data, including profiling, at any time by notifying customer support via email.
Dispute Resolution
Disputes related to personal data processing will be resolved through customer support (artlabestonia@gmail.ee).