Processing of personal data
The data controller for the cabinmax.ee online shop is CrystalShine OÜ, registry code: 11397733, address: Harjumaa, Tallinn, Narva mnt. 7, 10117, telephone: +372 6861777 and e-mail: firstname.lastname@example.org (hereinafter the merchant).
What personal data are processed
• contact information such as a telephone number and an e-mail address;
• payer’s address and delivery address;
• bank account number;
• costs of goods and services and data related to payments (purchase history);
• customer support details;
• other information related to customer surveys and/or offers.
For what purpose personal data are processed
Personal data are processed for the purposes of the performance of the contract concluded with the customer. Personal data are processed for the performance of legal obligations (for example, accounting and the resolution of consumer disputes).
Personal data are used for managing the customer’s orders and delivering the goods.
Purchase history data (purchase date, goods, quantity, customer data) are used for preparing an overview of goods and services purchased and for analysing customer preferences.
The bank account number is used to refund payments to the customer.
Personal data such as e-mail address, telephone number and customer name are processed in order to resolve any issues related to the provision of goods or services (customer support).
The IP address or other online identifiers of the user of the online shop are processed for the provision of the online shop as an information society service and for the compilation of Internet use statistics.
Transmission of personal data to authorised processors
The merchant keeps secret the customer’s personal data that have become known to it in the course of the registration and use of the user account and publishes them to third parties only with the customer’s consent, except where the obligation or entitlement to publish the data results from legislation. The user of the online shop accepts that, in order to provide the customer with suitable services, the merchant is entitled to process their data, including the transmission of the customer’s data to parties related to the provision of a service for the customer by the merchant. List of authorised processors:
• Maksekeskus - https://maksekeskus.ee/wp-content/uploads/2016/11/Maksekeskuse-privaatsuspoliitika-alates-25.05.2018.pdf (Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.)
• Omniva - Personal data (name, telephone number and e-mail address) will be forwarded to the transport service provider chosen by the customer. In the case of goods delivered by courier, in addition to the contact details, the customer's address will also be provided.
• LHV - Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.
• Swedbank - Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.
• SEB - Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.
• Luminor - Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.
• Coop Pank - Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.
• Pocopay - Personal data is transferred to the payment solution provider selected by the customer in connection with the storage of information necessary for transactions.
Cookies are text files placed on your computer to collect standard Internet log information and visitor behavior information. When you visit our websites, we may collect information from you automatically through cookies or similar technology
For further information, visit allaboutcookies.org.
• Keeping you signed in
• Understanding how you use our website
What types of cookies do we use?
There are a number of different types of cookies, however, our website uses:
• Functionality – Our Company uses these cookies so that we recognize you on our website and remember your previously selected preferences. These could include what language you prefer and location you are in. A mix of first-party and third-party cookies are used.
• Advertising – Our Company uses these cookies to collect information about your visit to our website, the content you viewed, the links you followed and information about your browser, device, and your IP address. Our Company sometimes shares some limited aspects of this data with third parties for advertising purposes. We may also share online data collected through cookies with our advertising partners. This means that when you visit another website, you may be shown advertising based on your browsing patterns on our website.
How to manage cookies
You can set your browser not to accept cookies, and the above website tells you how to remove cookies from your browser. However, in a few cases, some of our website features may not function as a result.
Security and access to data
Personal data are stored on the servers of Radicenter OÜ located within the territory of a Member State of the European Union or of a country that has acceded to the European Economic Area. Data may be transmitted to countries where the European Commission has estimated the level of data protection to be sufficient or to companies in the United States that have signed up for the Privacy Shield framework.
The online shop takes appropriate physical, organisational and information technology security measures in order to protect personal data against accidental or unlawful destruction, loss, modification or unauthorised access or disclosure.
Transmission of personal data to the authorised processors of the online shop – personal data are processed under the contract concluded between the online shop and the authorised processor. The authorised processors are required to ensure appropriate safeguards during the processing of personal data.
Inspection and amendment of personal data
Personal data can be accessed through customer support.
Revocation of consent
If the processing of personal data takes place on the basis of the customer's consent, the customer has the right to withdraw the consent by notifying the customer support by e-mail.
If a purchase has been made in the online shop in the capacity of a visitor (without a user account), the individual purchase history will be retained for three years.
In the event of disputes related to payments or consumer disputes, personal data are retained until the settlement of the claim or until the expiry of the limitation period (three years).
Personal data needed for accounting are retained for seven years.
To delete personal information, contact customer support via email. Requests for erasure shall be answered no later than one month and the period for erasure shall be specified.
A transfer request submitted by e-mail will be answered within a month at the latest. Customer support will identify you and provide you with personal information applicable to the transfer.
Direct marketing messages
An e-mail address or a telephone number is used for the transmission of direct marketing messages if the customer has provided the relevant consent. If the customer does not wish to receive direct marketing messages, the relevant link has to be selected in the e-mail header or customer support has to be contacted.
If personal data are processed for the purposes of direct marketing (profiling), the customer is entitled to submit objections in relation to the initial or subsequent processing of their personal data, including the preparation of a profile analysis related to direct marketing, at any time by notifying customer support thereof via e-mail.
Resolution of disputes
Disputes related to the processing of personal data are resolved through customer support (email@example.com). The supervisory authority is the Estonian Data Protection Inspectorate (firstname.lastname@example.org).