1. General Provisions
1.1. This privacy policy governs the principles of collection, processing and storage of personal data. Personal data is processed and stored by Aniri Flowers OÜ, reg. code: 14102075, which is the controller of personal data (hereinafter referred to as the controller).
1.2. For the purposes of this privacy policy, data subject means the customer or other natural person whose personal data is processed by the controller.
1.3. For the purposes of this privacy policy, customer means any person purchasing goods or services on the website of the controller.
1.4. The controller complies with the principles for processing personal data provided by law and, among other things, processes personal data in a lawful, fair and secure manner. The controller may declare that personal data has been processed in accordance with legal provisions.
2. Collection, processing and storage of personal data
2.1. The personal data collected, processed and stored by the controller is collected electronically, mainly through the website and email.
2.2. By providing personal data, the data subject grants the controller the right to collect, organize, use and administer, for the purposes specified in the privacy policy, the personal data that the data subject shares with the controller directly or indirectly when purchasing goods. or services on the site.
2.3. The data subject is responsible for the accuracy, correctness and integrity of the data provided by him. Providing knowingly false information is considered a violation of the privacy policy. The data subject must immediately notify the controller of any changes to the data provided.
2.4. The controller is not liable for any damage or loss caused to the data subject or a third party as a result of the data subject providing false data.
3. Processing of clients’ personal data
3.1. The controller may process the following personal data of the data subject:
3.1.1. First and last name;
3.1.2. Date of Birth;
3.1.3. Phone number;
3.1.4. E-mail address;
3.1.5. Delivery adress;
3.1.6. Bank account number;
3.1.7. Payment card details;
3.2. In addition to the above, the controller has the right to collect customer data that is available in public registers.
3.3. Legal basis for the processing of points (a), (b), (c) and (f) of personal data of Article 6 (1) GDPR:
(a) the data subject has consented to the processing of his personal data for one or more specific purposes;
(b) the processing is necessary for the performance of a contract to which the data subject is party or to take steps at the data subject’s request prior to entering into a contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is subject;
(f) the processing is necessary for the purposes of the legitimate interests pursued by the controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.
3.4. Processing of personal data in accordance with the purpose of processing:
3.4.1. The purpose of processing is safety and security
The maximum storage period for personal data is in accordance with the periods established by law.
3.4.2. The purpose of processing is order processing.
The maximum storage period for personal data is 1 year.
3.4.3. The purpose of processing is to ensure the operation of online store services
The maximum storage period for personal data is 1 year.
3.4.4. Purpose of processing - customer management
The maximum storage period for personal data is 1 year.
3.4.5. The purpose of processing is financial activities, accounting.
The maximum period for storing personal data is in accordance with the conditions established by law.
3.4.6. The purpose of processing is marketing. The maximum storage period for personal data is 2 years.
3.5. The controller has the right to transfer personal data of clients to third parties, such as processors, accountants, transport and courier companies, companies providing translation services. The controller is responsible for the processing of personal data. The controller transmits the personal data necessary for making payments to the processor, Montonio Finance.
3.6. The controller processes and stores the personal data of the data subject, applying organizational and technical measures to ensure the protection of personal data against any accidental or unlawful destruction, alteration, disclosure and any other unlawful processing.
3.7. The controller stores data of data subjects depending on the purpose of processing, but for no longer than 2 years.
4. Rights of the data subject
4.1. The data subject has the right to access and verify his personal data.
4.2. The data subject has the right to receive information about the processing of his personal data.
4.3. The data subject has the right to change or correct inaccurate data.