Privacy Policy
USE OF COOKIES
The Online Store uses cookies. A cookie is a small text file that the browser automatically saves to the client’s device. Cookies are used to collect information about how the client uses the Online Store to improve the client’s user experience.
The following types of cookies are used in the Online Store:
- Session cookies – to enable the use of the Online Store;
- Persistent cookies – to remember the client’s choices in the Online Store;
- First- and/or third-party cookies – to display relevant advertisements and offers to the client;
- Third-party analytics cookies – to optimize marketing communication.
The client can delete and/or block cookies saved on their device by adjusting their browser settings. Without cookies, the Online Store may not function as intended, and some features may not be available to the client.
In addition to analytics cookies, the Online Store also uses pixel tags (web beacons) to track the seller’s website usage. No personal data that could identify individuals is processed in this manner.
PROCESSING OF PERSONAL DATA
The responsible processor of personal data in the Online Store proaora.eu is Magusaekspert OÜ (registration code [company registration code]), located at Väike-Kaare tee 35, Viimsi, email info@proaora.eu.
WHAT PERSONAL DATA IS PROCESSED
- Name, phone number, and email address;
- Delivery address;
- Bank account number;
- Cost of goods and services and related payment information (purchase history);
- Customer support data.
PURPOSE OF PROCESSING PERSONAL DATA
Personal data is used to manage client orders and deliver goods.
Purchase history data (date of purchase, product, quantity, client information) is used to compile an overview of purchased goods and services and analyze client preferences.
The bank account number is used to refund payments to the client.
Personal data such as email, phone number, and client name are processed to resolve issues related to the provision of goods and services (customer support).
The IP address or other network identifiers of the Online Store user are processed to provide the Online Store service and compile website usage statistics.
LEGAL BASIS
Personal data is processed to fulfill the agreement concluded with the client.
Personal data is processed to fulfill a legal obligation (e.g., accounting and resolution of consumer disputes).
RECIPIENTS TO WHOM PERSONAL DATA IS DISCLOSED
Personal data is disclosed to the Online Store’s customer support for managing purchases and purchase history and for resolving customer issues.
The client’s name, phone number, and email address are provided to the chosen transport service provider. If a courier service is used for delivery, the client’s address is also shared with the courier service provider.
The Online Store’s accounting is handled by a service provider, and personal data is provided to this service provider for accounting purposes.
Personal data may be disclosed to IT service providers as necessary to ensure the Online Store's functionality or data hosting.
SECURITY AND ACCESS TO DATA
Personal data is stored on ShopRoller.com servers located within a European Union member state or a country that has joined the European Economic Area. Data may be transferred to countries that the European Commission has deemed to have adequate data protection levels, as well as to U.S. companies that adhere to the Privacy Shield framework.
Access to personal data is granted to Online Store employees who need it to resolve technical issues related to the Online Store and to provide customer support.
The Online Store implements appropriate physical, organizational, and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized access, or disclosure.
The transmission of personal data to authorized processors (e.g., transport service providers and data hosting providers) occurs under agreements between the Online Store and authorized processors, who are obligated to apply adequate protective measures when processing personal data.
ACCESS TO AND CORRECTION OF PERSONAL DATA
Personal data can be accessed and corrected via the user profile in the Online Store. If a purchase is made without a user account, personal data can be accessed through customer support.
WITHDRAWAL OF CONSENT
If personal data processing is based on the client’s consent, the client has the right to withdraw consent by notifying customer support by email.
RETENTIONUpon closing an Online Store client account, personal data is deleted unless retention is required for accounting or resolving consumer disputes.
If a purchase is made without a client account, purchase history is retained for three years.
Personal data related to payments and consumer disputes is retained until the claim is fulfilled or the expiration period is reached.
Personal data required for accounting purposes is retained for seven years.
DELETION
To delete personal data, contact customer support by email. Requests for deletion will be responded to within one month, specifying the period for data deletion.
DATA PORTABILITY
Requests for data portability submitted via email will be responded to within one month. Customer support will verify the individual’s identity and provide information on the personal data that can be transferred.
DIRECT MARKETING NOTICES
The email address and phone number are used to send direct marketing notices if the client has given prior consent. If the client no longer wishes to receive direct marketing notices, they can unsubscribe using the link in the email footer or by contacting customer support.
If personal data is processed for direct marketing purposes (profiling), the client has the right to object to the initial and further processing of personal data, including profiling related to direct marketing, by notifying customer support via email (this information must be presented clearly and separately from any other information).
DISPUTE RESOLUTION
Disputes related to the processing of personal data are resolved through customer support at info@proaora.eu. The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).