Privacy Policy

Privacy Policy

 

Last modified: 28.04.2020

 

  1. General

1.1. This document is the privacy policy (“Privacy Policy“) of the company LapaDuu OÜ (hereinafter “LapaDuu“), describing how LapaDuu processes the personal data of its clients and other data subjects.

1.2. In the context of this Privacy Policy, personal data means any information related to a data subject that can be used directly or indirectly to identify the individual, such as name, email address, or residential address.

1.3. Customer satisfaction is LapaDuu’s highest priority. To ensure better customer service and to fulfill all contractual and legal obligations, LapaDuu processes the personal data of its clients in accordance with the principles set forth in this Privacy Policy and the applicable data protection laws. In particular, LapaDuu complies with the obligations set out in Regulation (EU) 2016/679 of the European Parliament and of the Council (“GDPR“).

1.4. This Privacy Policy does not apply to, nor does it protect, the processing of anonymous data or the data of legal entities.

2. Responsible Controller

2.1. The responsible controller of the data subject’s personal data is LapaDuu OÜ, registry code 14842122, address Pärnu mnt 129b-14, 11314 Tallinn, Estonia.

2.2. LapaDuu OÜ is the responsible controller of personal data. LapaDuu OÜ transfers the necessary personal data for payment processing to the authorized processor Maksekeskus AS.

2.3.  Contact information for reaching the responsible controller: phone 53702287, email: lapaduu kontakt

3. Authorized data processors

3.1. In order to successfully serve clients, LapaDuu engages authorized data processors in certain cases. The authorized data processors include our consultants and companies that provide various services to support LapaDuu’s business activities (such as companies providing IT services), as well as other partners (including Maksekeskus AS, to whom the necessary personal data for payment processing is transmitted) who process personal data to achieve the objectives set by us, based on instructions received from LapaDuu.

4. Recipients of personal data

4.1. In certain cases, particularly when required by applicable laws, LapaDuu must disclose the data subject’s personal data to authorities, including tax and social security authorities. LapaDuu discloses the data subject’s personal data to recipients, while adhering to the general principles of personal data processing set out in the GDPR. LapaDuu also complies with all obligations set forth in the GDPR and other data protection laws when disclosing personal data to recipients.

5. Types of processed personal data

5.1. LapaDuu processes the following types of personal data:

5.1.1. name and surname;

5.1.2. address, telephone number, email address, and other contact details;

5.1.3. credit card details;

5.1.4. IP address of the user of the LapaDuu website;

5.1.5. data regarding purchases made by the client;

5.1.6. other data voluntarily disclosed by data subjects to LapaDuu (e.g., personal data provided by customers in customer feedback questionnaires).

6. Processing of personal data

6.1. LapaDuu processes personal data for the following purposes:

6.1.1. Selling products to customers. The legal basis for processing personal data is GDPR Article 6(1)(b) or (f) (the legitimate interest of the data controller in responding to data subject inquiries);

6.1.2. For marketing activities, including direct marketing. The legal basis for processing personal data is GDPR Article 6(1)(f) (preparation of direct marketing, the legitimate interest of the data controller in promoting its sales activities), Article 6(1)(a) (sending direct marketing), or another legal basis provided by law;

6.1.3. Communicating with customers and potential customers, including billing and complaint resolution. The legal basis for processing personal data is GDPR Article 6(1)(b) or, in relevant cases, Article 6(1)(f) (the legitimate interest of the data controller in responding to data subject inquiries);

6.1.4. To fulfill legal obligations imposed on LapaDuu by law. The legal basis for processing personal data is GDPR Article 6(1)(c);

6.1.5. Conducting surveys with customers to obtain feedback and improve services. The legal basis for processing personal data is GDPR Article 6(1)(f) (the legitimate interest of the data controller in improving its products);

6.1.6. Obtaining feedback from customers and analyzing it. The legal basis for processing personal data is GDPR Article 6(1)(f) (the legitimate interest of the data controller in improving its products).

7. Use of Cookies

7.1. Cookies are used on the LapaDuu website to ensure user convenience, including remembering the contents of the user’s shopping cart. Before installing cookies in the visitor’s browser, the website visitor must consent to the use of cookies.

7.2. The website user can always change the cookie settings in their browser.

7.3. If the user does not agree to the installation of cookies in their browser, the convenience of using the website may be disrupted.

8. Data Subject Rights

8.1. Data subjects have the following rights, subject to the limitations arising from applicable data protection laws:

8.1.1. The right to access their personal data;

8.1.2. The right to rectify personal data;

8.1.3. The right to erase personal data;

8.1.4. The right to data portability;

8.1.5. The right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning the data subject or similarly significantly affects them;

8.1.6. The right to withdraw consent to the processing of personal data by LapaDuu (where the legal basis for processing personal data is the data subject’s consent).

8.2. If LapaDuu processes personal data for direct marketing purposes, data subjects have the right to object at any time to the processing of their personal data for such marketing, which includes profiling to the extent that it is related to such direct marketing.

8.3. If a data subject objects to the processing of personal data for direct marketing purposes, LapaDuu will no longer process the data subject’s personal data for such purposes. In such a case, LapaDuu will cease the processing of your personal data for marketing purposes but may not cease processing for other purposes if LapaDuu has a legal basis for doing so.

8.4. All data subjects have the right to lodge a complaint with a supervisory authority, in particular in the Member State of their habitual residence, place of work, or place of the alleged infringement if the data subject considers that the processing of personal data relating to them infringes applicable data protection laws.

8.5. If the processing of personal data is based on the data subject’s consent, the data subject has the right to withdraw consent at any time. The withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal. The data subject is informed of this before giving consent. LapaDuu will cease the processing of personal data if the sole legal basis for the processing is consent. If there is another legal basis (e.g., a contract with the data subject, legitimate interest), processing may continue on a different legal basis.

9. Security of Personal Data

9.1. LapaDuu keeps all personal data provided to it strictly confidential and protects personal data from unauthorized access by third parties.

9.2. LapaDuu implements appropriate technical and organizational measures to protect personal data, taking into account the nature, scope, context, and purposes of processing, as well as the risk to the rights and freedoms of individuals.

10. Other

10.1. LapaDuu regularly reviews this Privacy Policy, and changes are made as necessary. The latest version of the Privacy Policy is always available on the LapaDuu website. LapaDuu informs data subjects of updates to the Privacy Policy and asks whether the data subject agrees to the changes.

10.2. If a data subject has any questions about how LapaDuu processes their personal data, they can contact LapaDuu using the contact information provided in section 2.