Privacy policy
1. General Provisions
1.1. This Privacy Policy governs the principles of collection, processing, and storage of personal data. Personal data is collected, processed, and stored by the data controller OÜ Britlyn (hereinafter the Data Controller).
1.2. A data subject within the meaning of this Privacy Policy is a customer or any other natural person whose personal data is processed by the Data Controller.
1.3. A customer within the meaning of this Privacy Policy is anyone who purchases goods or services from the Data Controller’s website.
1.4. The Data Controller complies with the data processing principles set out in applicable legislation, including processing personal data lawfully, fairly, and securely. The Data Controller is able to confirm that personal data is processed in accordance with legal requirements.
2. Collection, Processing, and Storage of Personal Data
2.1. Personal data collected, processed, and stored by the Data Controller is gathered electronically, mainly via the website and email.
2.2. By sharing their personal data, the data subject grants the Data Controller the right to collect, organize, use, and manage the personal data for the purposes defined in this Privacy Policy, which the data subject provides directly or indirectly when purchasing goods or services via the website.
2.3. The data subject is responsible for ensuring that the data provided is accurate, correct, and complete. Knowingly providing false data is considered a violation of this Privacy Policy. The data subject is obliged to immediately inform the Data Controller of any changes to the provided data.
2.4. The Data Controller is not responsible for any damage caused to the data subject or third parties due to the submission of incorrect data by the data subject.
3. Processing of Customers’ Personal Data
3.1. The Data Controller may process the following personal data of the data subject:
3.1.1. First and last name;
3.1.2. Phone number;
3.1.3. Email address;
3.1.4. Delivery address;
3.1.5. Bank account number;
3.1.6. Payment card details.
3.2. In addition to the above, the Data Controller has the right to collect data about the customer available in public registers.
3.3. The legal basis for processing personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation:
a) the data subject has given consent to the processing of their personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is a party or in order to take steps prior to entering into a contract at the request of the data subject;
c) processing is necessary for compliance with a legal obligation of the Data Controller;
f) processing is necessary for the purposes of the legitimate interests pursued by the Data Controller or a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject, particularly where the data subject is a child.
3.4. Processing purposes and retention periods:
3.4.1. Purpose – security and safety
Maximum retention period – according to statutory requirements
3.4.2. Purpose – order processing
Maximum retention period – until the end of the customer relationship + 3 years
3.4.3. Purpose – ensuring the functioning of the e-shop services
Maximum retention period – up to 1 year
3.4.4. Purpose – customer management
Maximum retention period – until the end of the customer relationship + 3 years
3.4.5. Purpose – financial activities, accounting
Maximum retention period – according to statutory requirements
3.4.6. Purpose – marketing
Maximum retention period – until consent is withdrawn
3.5. The Data Controller has the right to share customers’ personal data with third parties such as authorized processors, accountants, transport and courier companies, and payment service providers. The Data Controller is the responsible data controller. For payment processing, the Data Controller transfers necessary personal data to authorized processors.
3.6. When processing and storing personal data, the Data Controller applies organizational and technical measures to protect personal data against accidental or unlawful destruction, alteration, disclosure, or any other unlawful processing.
3.7. The Data Controller stores personal data depending on the purpose of processing, but not longer than 7 years.
4. Rights of the Data Subject
4.1. The data subject has the right to access and review their personal data.
4.2. The data subject has the right to receive information about the processing of their personal data.
4.3. The data subject has the right to complete or correct inaccurate data.
4.4. If personal data is processed based on consent, the data subject has the right to withdraw consent at any time.
4.5. The data subject may exercise their rights by contacting customer support at the e-shop at: info@arrakdesign.com.
4.6. The data subject has the right to file a complaint with the Data Protection Inspectorate to protect their rights.
5. Final Provisions
5.1. These data protection terms have been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the Estonian Personal Data Protection Act, and other legislation of the Republic of Estonia and the European Union.
5.2. The Data Controller has the right to partially or fully amend these data protection terms by notifying data subjects of the changes via the website arrakdesign.com.
Updated: 18.04.2025
OÜ Britlyn
Registration Code: 17283829