1. General Terms.
1.2 Personal Data means any information relating to an identified or identifiable natural person, i.e. the Data Subject. Processing means any operation relating to Personal Data, such as obtaining, recording, modifying, using, viewing, erasing or destroying it.
1.3 The Data Controller complies with the principles of data processing as set out in the legislation and is able to confirm that personal data is processed in accordance with the applicable legislation.
2. Acquisition, processing and storage of personal data.
2.1 The Data Controller obtains, processes and stores personally identifiable information primarily through the online shop website and email. (NB: To be completed if personal data is also collected in another way, e.g. in paper form).
2.4 The Data Controller shall not be liable for any damages suffered by the Data Subject or third parties as a result of incorrectly submitted personal data.
3. Processing of Customer Personal Data
3.1. The Data Controller may process the following personal data:
3.1.1. Name and surname
3.1.2. Date of birth
3.1.3. Contact details (e-mail address and/or telephone number)
3.1.4. Transaction data (goods purchased, delivery address, price, payment details, etc.).
3.1.5. Any other information provided to us during the purchase of the services and goods offered by the Site or when contacting us.
3.2. In addition to the foregoing, the Data Controller shall have the right to verify the accuracy of the data submitted using publicly accessible registers.
3.3. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c) and (f) of the General Data Protection Regulation:
(a) The data subject has given his or her consent to the processing of his or her personal data for one or more specified purposes;
(b) The processing is necessary for the performance of a contract to which the data subject is a party or for the performance of measures at the request of the data subject prior to entering into the contract;
(c) Processing is necessary for compliance with a legal obligation to which the controller is subject;
(f) processing is necessary for the pursuit of the legitimate interests of the controller or of a third party, except where the interests or fundamental rights and freedoms of the data subject which require the protection of personal data override such interests, in particular where the data subject is a child.
3.4. The Data Controller shall store and process the Data Subject's personal data for as long as at least one of the following criteria applies:
3.4.1. The Personal Data is necessary for the purposes for which it was received;
3.4.2. As long as the Data Controller and/or the Data Subject can exercise their legitimate interests, such as lodging an objection or bringing or pursuing a legal action, in accordance with the procedures established by external laws and regulations;
3.4.3. As long as there is a legal obligation to retain the data, such as under the Accountancy Act;
3.4.4. As long as the Data Subject's consent to the processing of the personal data concerned is valid, unless there is another lawful basis for processing the personal data.
Upon expiry of the circumstances referred to in this paragraph, the Data Subject's retention period shall also expire and all relevant personal data shall be permanently erased from the computer systems and electronic and/or paper documents that contained the relevant personal data or such documents shall be anonymised.
3.5. In order to fulfil its obligations towards you, the Data Controller shall have the right to transfer your personal data to business partners, data processors who carry out the necessary data processing on our behalf, such as accountants, courier services, etc. The Data Processor is the controller of the personal data.
3.6. When processing and storing personal data, the Data Controller shall implement organisational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure or any other unlawful processing.
4. Rights of the data subject
4.1. In accordance with the General Data Protection Regulation and the legislation of the Republic of Latvia, you have the right to:
4.1.1. to access your personal data, to receive information about its processing, as well as to request a copy of your personal data in electronic format and the right to transfer this data to another controller (data portability);
4.1.2. to request the rectification of personal data that is incorrect, inaccurate or incomplete;
4.1.3. to erase their personal data ("to be forgotten"), except where required by law to retain the data;
4.1.4. withdraw their prior consent to the processing of personal data;
4.1.5 Restrict the processing of your data – the right to request that we temporarily cease processing all your personal data altogether;
4.1.6. to apply to the Data Inspectorate
You can submit a request to exercise your rights by filling in the form in person at 31 Mazā Nometņu iela 31, Riga, or by sending your request electronically to the Customer Support Service at firstname.lastname@example.org.
5. Final provisions