We at Threads of Hope Hellas are committed to protecting the privacy of our customers, website visitors and newsletter subscribers. We feel that it's important that you know what personal data we are collecting, your rights related to the data collected and how you can influence the way your data is processed.
1. WHAT PERSONAL DATA DO WE COLLECT?
We collect personal data when you join our newsletter when you visit our website (threadsofhopehellas.org) or when you contact our customer service by email, phone or chat.
We collect following information from our customers:
- Customer data: Name, address, email address, phone number, order – and purchasing history.
- Registration: Data related to user account and registration date.
- Online behaviour: Your actions on our website such as browsing the product pages, adding products to shopping cart, selections and searches and information on how and from where did you arrive on our website.
- Device information: Used browser and its settings, IP-address, language settings and device’s geographical information.
- Email marketing: If you have given us a consent for email marketing as a newsletter subscriber or as a member of a customer loyalty program, we will collect related information such as delivery, opening and clicking or other actions of the emails.
- Orders: We collect information about your orders, deliveries, payment- and delivery addresses and your contacts to our customer services.
2. WHY DO WE COLLECT PERSONAL DATA?
We process your personal data for the following purposes:
- Orders: We use your personal data for order processing and delivery.
- Customer service: our customer service uses your personal data for order processing and delivery and for handling potential reclamations.
- User account: We use personal data you have given for account management so that you can browse your order history, save your delivery addresses and to manage your personal settings such as newsletter subscription.
- Marketing: We use your personal data for marketing purposes. Purposes for processing are amongst other things:
- In case you have accepted email marketing, we use your personal data for sending newsletters. You can unsubscribe our newsletter by using an unsubscribe link in the newsletter.
- If you have added products into a shopping cart, we can send an email reminding you of your incomplete order so you can easily continue shopping where you left.
- Questionnaires and surveys: If you have accepted email marketing, we can send you invitations to customer questionnaires or surveys, which aim in developing our services and products.
- Product reviews: When you have ordered products from our website, we can ask you to review the products you ordered. Review can be published with your first name and the first letter of your last name in our website with the product you ordered. By writing a review, you accept that the review can be published in our website and that it will be used in our marketing communication. The purpose of the product reviews is to offer information of our products to other customers by showing other customer’s reviews.
- Business reporting: We process personal data for analyzing and developing our business. Individual persons cannot be identified from our reports.
- Legal obligations: We process personal data in order to fulfill our legal obligations, for example in accounting.
3. LEGAL BASIS FOR PROCESSING YOUR PERSONAL DATA
Processing of your personal data is based on contract when we process your personal data to fulfill our customer relationship related obligations, when you join our newsletter or when shop on our website. Legal basis for processing your personal data is legitimate interest when we process your personal data for customer service, marketing and product review purposes. Legal basis to process your personal data is consent in cases where we process your personal data for electronic direct marketing and customer surveys. Legal basis is legal obligation when we process your personal data to fulfill our legal obligations.
4. HOW LONG DO WE STORE YOUR PERSONAL DATA?
Your personal data is processed only as long as needed for pre-defined purposes, for example to fulfill an order. If you have created an account on our website, your personal data will be stored until you close your account or ask for your data to be erased.
When Threads of Hope Hellas processes your personal data for other purpose than our contractual obligations, for example to fulfill accounting – or consumer law related obligations, Threads of Hope Hellas processes data only as long as it is necessary to fulfill each obligation.
5. WHO CAN PROCESS YOUR PERSONAL DATA?
At Threads of Hope Hellas, only persons who are allowed to process your personal data based on their duties can process your personal data. Third parties are processing your personal information in following circumstances:
- We use external service provider for example when sending email marketing, showing personalized offers and to enable product reviews. Transferring and processing personal data to third parties is managed on an agreement.
Personal data disclosures:
- If you have placed your order on our online store, we can disclose personal data like your name, address and phone number to the logistics company for them to be able to make the delivery to you.
- Based on your payment selection on our online store, we can use external service provider and you will be directed to their website when processing the payment. In these cases the terms and conditions of third party’s website shall be followed. Threads of Hope Hellas does not store payment information such as credit card information.
- We might be obligated to disclose your personal data to authorities based on law or regulations.
Threads of Hope Hellas providers and cooperation partners process your personal data in general in EU/ EEA area. Transferring your data outside EU / EEA area shall be handled by appropriate safeguards. In case personal data is processed outside EU / EEA, there is an EU Commission’s decision that the third country provides equal level of protection or appropriate safeguards are in place to ensure an adequate level of protection of your personal data. Examples for appropriate safeguards are acceptable code of conduct in the receiving country, model clauses, binding corporate rules or Privacy Shield.
6. PROTECTION OF PERSONAL DATA
We ensure your personal data protection by adequate safeguards. We have implemented technical and organisational safeguards to ensure that your personal data shall not be altered, lost or destroyed or that there’s no unauthorised access to your personal data.
7. USING COOKIES
User experience can be improved for example with following means:
- Site personalization based on customer’s preferences
- To improve site’s security and speed
- Easy log-in due to the saved log-in information
- More interesting and personalized marketing
Cookies referred in this article mean actual cookies and similar techniques.
8. DATA SUBJECT’S RIGHTS
As a data subject you have a right to influence on how your personal data is processed and get information about the processing. Below you can find information about your rights as a data subject. In case you want to use one of the rights shown below, please kindly contact our customer service via email: firstname.lastname@example.org
You have a right to get a confirmation whether your personal data is processed or not and to inspect what data we have collected about you.
Incorrect data rectification
You have a right to ask us to complete or rectify your incorrect, inaccurate or deficient personal data.
Right to erase personal data
You have a right to get your personal data erased. In this case we will erase all your personal data unless we have a legal obligation to keep them.
Restriction of the processing
In certain cases, you have a right to request to restrict the processing. You can use your right for example when your data is partially inaccurate. In this case you have a right to request that the processing will be temporarily restricted until the accuracy of your data has been confirmed
Right to data portability
You can ask your data to be transferred to another system if we process data that you have provided based on an agreement we have with you. In this case we will provide your personal data in machine-readable format so you can store them by yourself or transfer those to another controller.
Right to object
In certain situations you have, with justified reason, a right to object processing of your personal data. You have a right to object for example in cases when we process your personal data based on our legitimate interest. In this case we will assess if there still exist some compelling and justified reason to still process personal data.
Right to notification to the supervisory authority
If you feel that we have processed your data unlawfully, you have a right to make a complaint about your data processing to local supervisory authority.
Right to withdraw consent
In cases where processing of your personal data is based on your consent, you can at any time withdraw your consent. If you want to cancel your consent to receive the newsletter, you can use the link in the newsletter or contact our customer service by email: email@example.com
9. CHANGES TO PRIVACY NOTICE
When we publish changes to this privacy notice, we will update the date at the top of this privacy notice. If the changes on privacy practices are essential, we will inform those at the beginning of this privacy notice, at our website and by email.
10. CONTACT DETAILS
If you have questions regarding the processing of your personal data, please contact us at firstname.lastname@example.org