Information about the protection of personal data

INFORMATION ON THE PROTECTION OF OUR CUSTOMERS’ PERSONAL DATA

(INFORMATION OBLIGATION OF THE GDPR)

 

This document provides you with information in accordance with our information obligation under the Regulation of the European Parliament and of the Council (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing the Directive 95/46/EC (GDPR).

The information provided relates to your personal data, which we process in order to be able to provide you with our products and services, to effectively manage relationships and contacts with us and you and our personal data intermediaries, to answer your questions, to deal with your requests, etc., and to send you selected marketing/commercial communications and invitations in accordance with legal regulations.

 

 

Who is the controller of your personal data?

 

The controller of your personal data is:

 

ProfiVN shop, s. r. o.., CIN: 55 547 858, registered office: Špitálska 10, 811 08 Bratislava, Slovakia, registered in the Commercial Register maintained by Municipal Court Bratislava III, Section Sro, Insert N. 170874/B

 

 

What personal data do we process?

We process the following categories of personal data:

  • name, surname and form of addressing (Mrs, Mr),
  • contact details (postal address, e-mail address, telephone contact),
  • data necessary for your basic identification and delivery of goods,
  • Information relating to the IP address of the device from which you log in to our website,
  • Information about interactions between you and us, such as history of your relationships and transactions with us, including your visits, purchases, saved product configurations, visits for repair and modification purposes, contacts with us, your questions, requests, applications and complaints addressed to us, and history of their assessment;
  • information about the goods you purchased (e.g. date of order creation, date of delivery, method of delivery, information concerning repair, service, claimed product defects,
  • information about your interests and preferences,
  • information about the consents you have given us and our management of those consents (for example, including keeping a register of revoked consents).

In case your purchase will be subject to our legal obligations to prevent money laundering and the prevention of terrorist financing under the Act (AML), we will process, in addition to the above, other categories of personal data:

  • Date of Birth,
  • Address of permanent residence or other residence,
  • Nationality,
  • Type and number of identity document,
  • for a minor who does not have an identity card, identification of the name, surname and birth registration number or date of birth, permanent residence or other residence, the nationality of the minor and his or her legal representative,

However, at most to the extent established by valid legal regulations in the area of protection against the legalization of income from criminal activity and in the area of preventing the financing of terrorism.

 

 

 

Who are the processors of personal data and how we transfer them

The processor of your personal data will be entities that can provide services, supply goods or participate in the processing of data for the above purposes, companies cooperating in the field of it services, marketing services, accounting and archiving services, market research, telephone centre, companies supporting the organization and implementation of events.

 

Your data may be transferred outside the Slovak Republic, within the EEA countries, where appropriate (i) to achieve any of the purposes set out in this information obligation, or (ii) to transfer your data to data recipients in accordance with this information obligation. If your personal data is transferred outside the Slovak Republic, we will ensure that your personal data is protected by the following security measures:

  • The laws of the country to which your information is transmitted ensure an adequate level of data protection (Article 45 GDPR) or
  • The transfer is subject to standard data protection clauses approved by the European Commission (Article 46(2) of the GDPR) or to binding corporate rules (Article 47 of the GDPR).

Retention period of your personal data

Your personal data is stored:

  1. for the period necessary for the performance of the contract/service or guarantee and for the assertion or defence of related claims, i.e. for a period of 10 years from the end of the year in which the contract was concluded or until the claims expire;
  2. in the case of data processing on the basis of law - for the period that is bindingly determined by the relevant law;
  3. in the case of data processing for direct marketing purposes – until your consent has been revoked (if there is no other legal basis for the processing). In addition, we will keep evidence of the consent given for 10 years for evidentiary purposes - to prove the facts in the event of any claims related to improper processing of personal data;
  4. to carry out our obligations related to product safety, if any - for a period of 10 years from the end of the year in which the contract was concluded;
  5. in the case of data processing for the purposes of our legitimate interest – for a period until you object, subject to the necessity of processing the data until the end of the period necessary to establish, exercise or defend claims.

 

Source of your data

We process data provided by you, data provided by controllers, document-based data, website data (cookies), in relation to business entities and public registers.

What are your fundamental rights?

You have the following rights:

  • Right to information: You have the right to have clear, transparent and easily understandable information about how we use your personal data and your related rights. This is partly the reason why we provide you with information in the form of this document.
  • Right of access to data: You have the right to access your personal data. You may also request access to your personal data to verify that we use it in accordance with applicable data protection laws.
  • Right to rectification: You have the right to have your personal data corrected if it is inaccurate or incomplete.
  • Right to erasure: Also known as the “right to be forgotten”. In simple terms, this means that you can request the erasure or removal of your personal data if there is no other legal basis for the processing in order for us to continue using it. Please note that this is not an absolute right and is subject to exceptions. We are obliged to delete personal data without undue delay, if you exercise the right to erasure or even without it, and if: personal data are no longer necessary for the purpose for which they were obtained or otherwise processed and there is a legal title to continue processing, if you revoke the consent on the basis of which the processing of personal data is carried out, and there is no other legal basis for the processing of personal data, if you object to the processing of personal data and no legitimate reasons for the processing of personal data prevail, if personal data is processed illegally, if the reason for the deletion is meeting of an obligation under an act, a special regulation or an international agreement to which the Slovak Republic is bound, or if the personal data was obtained in connection with the offer of information society services.
  • Right to restriction of processing: You have the right to block or prevent the further use of your personal data. In the event of restriction of processing, we may continue to store your personal data, but their use by us will be limited.
  • Right to data transfer: You have the right to obtain and reuse your personal data for your own purposes within the various services. For example, if you terminate your relationship with us, this right allows you to easily transfer, copy or transfer your personal data within our IT systems and the systems of other entities without thereby reducing their usability. Please note that this is not an absolute right and is subject to limitations. You may exercise this right only if it does not adversely affect the rights of others (for example, you may exercise it in connection with personal data you have provided to us and which we have processed for the purpose of performing our contract with you).
  • Right to file a complaint: You have the right to file a complaint about the way we handle or process your personal data, both with us and at any time with a national data protection authority. In the Slovak Republic it is the Office for the Protection of Personal Data (Úrad na ochranu osobných údajov Slovenskej republiky), Hraničná 12, 820 07 Bratislava, Slovak Republic; https://dataprotection.gov.sk/uoou/; statny.dozor@pdp.gov.sk; +421 /2/ 3231 3214.
  • The right not to be subject to automated decision-making: You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
  • In the event of direct marketing, you have the right to object at any time to the processing of your data for direct marketing purposes. If you exercise this right, we will stop processing your data for this purpose. You have the right to object at any time to the processing of your data on the basis of the legitimate interest mentioned above, as well as for other purposes of processing. We will no longer process your data for these purposes unless we can demonstrate that there are valid legal reasons in relation to these data that outweigh your interests, rights and freedoms, or the data will be necessary for us to establish, investigate or defend claims.
  • The right to withdraw consent to the processing of personal data. You have the right to withdraw your consent at any time by sending an e-mail and in case of difficulties also by means of a regular letter to the following addresses: e-mail: store24@gmail.com, address: Špitálska 10, 811 08 Bratislava, Slovakia.
  • Your personal data will be profiled based on your consent to receive tailored information. Sending customized marketing and business communications may affect your purchasing decisions by displaying or offering certain of our products and providing special discounts. The provision of your personal data is voluntary, but failure to provide it will result in the inability to conclude and perform the contract/provide services.

 

Contact:

In matters relating to the protection of personal data in the Slovak Republic, you can contact our contact point for the protection of personal data at the following e-mail address: vnbeauty.store24@gmail.com .

 

 

 

What are the purposes and legal basis for the processing of your data?

 

Depending on our obligations and rights you grant us or which result from applicable law, we process your personal data for this purpose and on this legal basis:

 

 

 

Purpose of processing

Legal basis

Marketing communication and market research:

-     sending notices that may contain commercial content relating to the goods and services offered;

-     our direct offer of products and services (including offers of jewellery models, accessories, investment options and other products and services,

-     invitations to events organized by us (direct marketing),

-     sending questionnaires about marketing surveys, surveys about our products and services, and surveys containing marketing, advertising or promotional content relating to you or our products and services, including their adaptation to your needs and expectations, data collection from different sources and profile creation (profiling for marketing purposes).

We want to ensure that we do not send you unnecessary information. We will make every effort to ensure that what we send you is relevant and useful to you. Based on the information collected, such as purchase history, visits to our website, opening our e-mail correspondence, etc., we create a customer profile so that we can provide you with personalized offers, notifications and invitations.

Your consent under the Article 6(1)(a) GDPR.

 

Taking pre-contractual actions based on your interest in the offer

For example arranging a date for the presentation of selected goods, responding to your request for a meeting, or information about our products and services or any other request for information, granting and processing the right to a discount or special offer.

Acts preceding and aimed at concluding the contract under the Article 6(1)(b) GDPR

Performance of the concluded contract

For the purposes of performance and under a contract concluded relating to purchased products or services.

Contract concluded under the Article 6(1)(b) GDPR

Compliance with legal obligations

Documentation of the service or contract performed for accounting and tax compliance purposes.

Legal obligation of the controller under the Article 6(1)(c) GDPR

In relation to the provisions in the field of accounting and tax obligations

Evaluation and improvement of the quality of our products, services and customer experience

Better choice of services according to customer needs, overall optimization of our products and services, building knowledge about our customers.

For the purposes of evaluating and improving the quality of our products and services, as well as for research and development purposes, your personal data may be anonymised and, as such, used by other entities we will cooperate with in the area.

Our legitimate interest under the Article 6(1)(f) GDPR.

Optimization of our internal processes and offered products and services.

Management, maintenance and development of IT systems and data security

Our legitimate interest under the Article 6(1)(f) GDPR.

Maintenance and correct use of our IT systems.

Protection against claims

Enabling possible investigation, defence against third-party claims and for evidentiary purposes, securing information in the event of a legal need to prove certain facts.

Our legitimate interest pursuant to Article 6(1)(f) GDPR.

The need for evidence.

Management of your personal data

Keeping customers’ personal data up to date, correcting and maintaining it in order, as well as contacting customers in case of problems with customer requests and centralizing, combining, sharing, updating and correcting your personal information that you have provided to us or that has already been available to us. Managing your consent, such as verifying that you have agreed to receive marketing materials.

Your personal data is stored in protected repositories electronically in order to:

-     manage your personal data effectively (e.g. ensuring that your questions are up to date, solving your questions, their accuracy, enabling them to be shared in accordance with the law, etc.);

-     provide you with the best possible customer service,

-     support and facilitate certain activities described in other processing purposes.

Our legitimate interest pursuant to Article 6(1)(f) GDPR.

Processing of rights and obligations of customers

Maintaining relationships and solving your queries

Conducting customer satisfaction surveys with our products and services.

Our legitimate interest under the Article 6(1)(f) GDPR

After-sales service

Processing for the purposes of compliance with a legal obligation of protection against the legalization of proceeds of crime and the prevention of terrorist financing

In those cases where we are obliged under applicable law to comply with legal obligations in the field of protection against legalization of proceeds of crime and in preventing terrorist financing, we must process a larger range of personal data. For these purposes, we have an obligation and we are entitled to request from you further information necessary for your identification, otherwise we cannot sell our goods or provide our services to you.

Legal obligation of the controller under the Article 6(1)(c) GDPR

In the field of protection against the legalization of proceeds of crime and the prevention of terrorist financing.