PROCESSING OF PERSONAL DATA
Fitness Trading OU is the data processor of the online shop www.criticalpump.com. Personal data necessary for making payments shall be forwarded to the authorized processor Maksekeskus AS.
What personal data are processed?
- Name, phone number, personal identification code and e-mail address;
- delivery address;
- Bank account number;
- cost of goods and services and payment related information (purchase history);
- customer support information.
For what purpose is personal data processed?
Personal information is used to manage customer orders and deliver goods.
Purchase history data (date of purchase, item, quantity, customer information) is used to compile an overview of the goods and services purchased and to analyze customer preferences.
The bank account number is used to refund customer payments.
Personal data such as e-mail, telephone number, customer name is processed to resolve issues related to the provision of goods and services (customer support).
The web store user IP address or other network identifiers are processed to provide the web store as an information society service and to compile statistics on web usage.
Personal data are processed for the purpose of executing the contract with the client.
The processing of personal data takes place in order to fulfill a legal obligation (eg accounting and settlement of consumer disputes).
Recipients to whom personal data are transmitted
Personal information is passed to online store customer support to manage purchases and purchase history, and to resolve customer issues.
The name, phone number and e-mail address will be forwarded to the transport service provider of your choice.
In the case of goods delivered by courier, the address of the customer shall be provided in addition to the contact details.
If the online store is accounted for by a service provider, personal data will be transferred to the service provider for accounting purposes.
Personal information may be transferred to information technology service providers if this is necessary to ensure the functionality of the web store or data hosting.
The online store transmits personal data necessary for making payments to the authorized processor Maksekeskus AS.
Data security access
Personal data is stored on www.shopify.com servers located in the territory of a Member State of the European Union or countries that have joined the European Economic Area.
Access to personal information is available to online store staff who can access personal information to resolve technical issues related to the use of the online store and to provide customer support.
The Web Store implements appropriate physical, organizational and IT security measures to protect personal information from accidental or unlawful destruction, loss, alteration or unauthorized access and disclosure.
The transfer of personal data to authorized processors of the web store (eg transport service provider and data hosting) is subject to agreements with the web store and the authorized processors.
Controllers are required to provide appropriate safeguards for the processing of personal data.
Access of personal data
If the purchase is made without a user account, personal information can be accessed through contacting customer service.
Withdrawal of consent
If personal data is processed with the customer's consent, the customer has the right to withdraw the consent by notifying customer support via email.
If a purchase is made without a client account in the online store, the purchase history is kept for three years.
In the case of disputes concerning payments and consumer disputes, personal data shall be retained until the claim has been complied with or until the limitation period has expired.
The personal data necessary for accounting purposes shall be kept for seven years.
You must contact customer support via email to delete your personal information.
The request for erasure shall be replied to within not more than one month and the period for erasure shall be specified.
Requests for the transfer of personal data by e-mail shall be replied to within a maximum of one month.
The customer support will identify the person and inform you of the personal data that are to be transferred.
Direct marketing messages
The email address and phone number will be used to send direct marketing communications, subject to customer consent.
If the customer does not wish to receive direct marketing notices, either select the appropriate reference in the footer of the email or contact customer support.
If personal data are processed for direct marketing purposes (profiling), the customer has the right to object at any time to the initial and further processing of their personal data, including profiling analysis for direct marketing purposes, by notifying customer support via email (email@example.com).
Disputes related to the processing of personal data are solved through customer support, possible ways of contacting are firstname.lastname@example.org.
The supervisory authority is the Estonian Data Protection Inspectorate (email@example.com).