Processing of personal data
The controller and holder of the personal data of the online shop Santa.ee is CoomorLander OÜ (registration number 10521585), located at Kassi 14, 12618, Tallinn, with phone +372 6563517 and e-mail firstname.lastname@example.org.
Which personal data are processed
- personal and contact details (name, phone number, e-mail address)
- delivery address
- bank account number
- value of goods and services and payment data (buy history and post-payment data)
- customer support details
The purpose for which personal data are processed
Personal data is used to manage customer orders and deliver goods.
Data from the purchase history (date of purchase, commodity, quantity, customer data) are used to compile an overview of the goods and services purchased and to analyse customer preferences.
The bank account number is used to return payments to the customer.
Personal data such as e-mail, telephone number, customer name is processed to resolve issues related to the provision of goods and services (customer support).
The online shop user’s IP address or other online identifiers are processed for the provision of the online shop as an information society service and for the production of web usage statistics.
The processing of personal data is carried out for the purpose of performing a contract with a customer.
The processing of personal data is carried out in order to comply with a legal obligation (e.g. accounting and consumer dispute resolution).
Recipients to whom personal data are transferred
Personal data is transferred to the online shop customer support for managing purchases and shopping history and resolving customer problems.
Customer`s name, telephone number and e-mail address shall be communicated to the transport service provider chosen by the customer.
In the case of goods delivered by courier, the customer’s address shall be communicated in addition to the contact details.
If the online shop is kept by the service provider, the personal data are transferred to the service provider for accounting purposes.
Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality or hosting of the online shop.
The transfer of personal data to Santa.ee’s processors (e.g. Maksekeskus, hire-purchase provider) takes place on the basis of contracts concluded with CoomorLander OÜ and the processors. Processors are obliged to ensure appropriate safeguards for the processing of personal data.
Security and access to data
Personal data are stored on servers located in the territory of a Member State of the European Union or a country which is part of an economic area of the European Union. Data may be transferred to countries whose level of data protection has been assessed as adequate by the European Commission and to U.S. companies that are members of the Privacy Shield framework.
Access to personal data is provided to Santa.ee’s staff who can access personal data for the purpose of resolving customer or technical issues related to the use of an e-shop.
Santa.ee shall implement appropriate physical, organisational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.
Access and rectification of personal data
Personal data can be accessed and corrected in the user profile of the online shop. If the purchase has been made without a user account, the personal data can be accessed via the customer support.
Withdrawal of consent
If the processing of personal data is carried out on the basis of the customer’s consent, the customer has the right to withdraw consent by notifying the client support by e-mail.
When closing an online shop account, Roller Äritarkvara OÜ deletes all personal data 1 month after the online shop account is closed, unless it is necessary to store such data for accounting purposes or for the resolution of consumer disputes.
If an online shop has been purchased without a customer account, the purchase history is retained for three years.
In the case of disputes concerning payments and consumer disputes, personal data shall be retained until the enforcement of the claim or the expiry of the limitation period.
The personal data required for accounting purposes shall be kept for seven years.
To delete your personal data, you need to log in to your own e-shop account and select “My account” from the menu or contact your client support by e-mail. The request for deletion shall be answered within a period of not more than one month and the period of deletion shall be specified.
Access to data
The data collected can be accessed by login to the e-shop. Both in the ‘My account’ menu and in the order history.
Requests for the transfer of personal data submitted by e-mail shall be answered within a month at the latest. The customer support shall establish the identity and inform about the personal data to be transferred.
Direct marketing communications
The e-mail address and telephone number shall be used to send direct marketing communications with the customer’s consent. If the customer does not wish to receive direct marketing messages, contact the customer support team.
Where personal data are processed for direct marketing purposes (profiling), the customer has the right to object at any time to the processing of his or her personal data, including profiling related to direct marketing, both initially and further. To do so, customer should send application to CoomorLander OÜ, Kassi 14, 12618, Tallinn or by e-mail email@example.com. The application will be answered within 30 days at the latest.
Settlement of disputes
The data controller is CoomorLander OÜ. For any questions, please contact firstname.lastname@example.org. The supervisory authority is the Estonian Data Protection Inspectorate (email@example.com).