Last updated: 2022.06.29
BASIC PROVISIONS
We care about your privacy and the security of the personal data that you entrust to us, so we have prepared this privacy policy (hereinafter referred to as the “Privacy Policy”), which explains how we process and protect your personal data, what your rights are, as well as other information about the processing of your personal data.
The manager of your personal data is CJSC “Barbara plius”, a private limited liability company registered in the Republic of Lithuania, the legal entity code is 302746051, the registration address is Fermentu g. 4, LT-02244 Vilnius, Lithuania, the location of the enterprise is Polocko str. 26, Vilnius, Lithuania, LT-01205 (hereinafter referred to as the “Company” or “we”). You can contact the company by email [email protected] or by phone +370 617 77 113 , and also come to our pick-up point at Polocko str. 26, Vilnius, Lithuania.
This Privacy Policy sets out the terms and conditions of confidentiality regarding your use of our site doro-boutique.com (The “Site”) through which, among other things, you can access the e-store doro-boutique.com, managed by us.
As used in this Privacy Policy, “Personal data” (“Personal Data”) means any information or set of information on the basis of which we can directly or indirectly identify you, for example, your first name, last name, email address, phone number, etc.
This Privacy Policy applies when you visit our website, register as a registered user, view and order products offered by us, subscribe to our newsletters, participate in games, promotions, contests, contact us by phone or other communication channels, visit our physical stores, provide us with goods or services or otherwise communicate with us.
Some services on the Website may be provided by third parties, or you may be redirected to the websites of such third parties (for example, to make payments for goods that you want to purchase, etc.). When you use these services, the third-party data protection policy applies along with this Privacy Policy. Please read them and make sure that the conditions for processing your personal data set out in them are acceptable to you.
We have the right to unilaterally change the terms of this Privacy Policy. We will notify you of the changes by posting the updated Privacy Policy on the Website or using other usual means of communication. Any additions or changes to this Privacy Policy will take effect from the date of posting specified in the Privacy Policy, unless another effective date is specified. If you continue to use the Website after changing the terms of the Privacy Policy, we will assume that you have accepted the terms of the Privacy Policy as amended.
WHAT PERSONAL DATA DO WE STORE ABOUT YOU?
We process the Personal Data you receive in the following ways:
– When you provide us with Personal Data;
– When we collect your Personal Data ourselves as a result of your use of the Website, social accounts that we administer, when you contact us by phone or email, or when you visit our collection point;
– To the extent permitted by applicable law, we may also receive information about you from other sources, such as publicly available registries, databases, marketing partners and other third parties.
Depending on your social network settings, if you decide to link your social network account to your account on our Website, we will be able to see certain data from your social network account, including your personal account data, such as your first name, last name or alias in your account, your profile picture and your email address.
You have the right to change and update the information that you provide to us. In some cases (for example, when we sell or deliver goods to you, etc.), we need to have accurate and up-to-date information about you in order to provide you with quality services, so we may ask you to periodically confirm the correctness of the information we have about you.
By providing us with Personal Data, you are responsible for the accuracy, completeness and timeliness of this Personal Data.
We process your Personal Data under the following conditions:
Purpose of personal data processing |
Processed personal data |
Terms of personal data processing |
Legal basis for the processing of personal data |
Registering on the Website, logging in to your account, maintaining your account |
Username, password, email address, IP address, date of registration and consent to receive newsletters, date of last visit. |
Personal data is stored for the entire period of active use of the account and for 5 years after the last login to the account after the termination of its use. |
Processing is necessary for the conclusion and execution of the contract (Article 6(1)(b) GDPR) |
E-commerce |
First name, last name, personal identification number, if it is voluntarily provided by the buyer, for example, when making a payment order, phone number, email address, IP address, purchase history, delivery address, payment details, history of actions during order-delivery, history of refunds, communication with the customer |
Personal data is stored for 10 years from the date of purchase on the Website Accounting documents are kept within the time limits established by law |
Processing is necessary for the conclusion and execution of the contract (Article 6(1)(b) GDPR) Data processing is required by law (Article 6(1)(c) GDPR) Processing is necessary to comply with the legitimate interests of the company or a third party (Article 6(1)(f) GDPR) |
In order to improve the quality of customer service of the company (telephone records) |
Phone number, voice recording of the interlocutor, date of the call, the content of the call, the start and end time of the conversation |
Personal data is stored for 90 days from the date of sound recording |
Data processing is necessary to comply with the legitimate interests of the company or a third party (Article 6(1)(f) GDPR) |
Direct Marketing |
First name, last name, email address, date of consent to receive newsletters, date of last visit. |
Personal data is stored for 5 years after the last login to the account, unless consent to the processing of Personal Data was revoked earlier |
Consent of the data subject to such processing (Article 6(1)(a) GDPR) |
Improving the company’s website, updating marketing communications |
IP addresses of visitors’ computers, data about visits, data about the browser used by the device, the date and time of login, the manufacturer and model of the mobile device, the operating system of the mobile device, visit statistics, other information collected using cookies |
Personal data collected through cookies or similar tracking technologies are stored for the periods specified below in this Privacy Policy |
Consent of the data subject to such processing (Article 6(1)(a) GDPR) Processing is necessary to comply with the legitimate interests of the company or a third party (Article 6(1)(f) GDPR) |
Communication with persons interested in the Company’s services, visitors to the Company’s social media accounts |
First name, last name, email address, phone number, contact time, contact content, any other information that you have decided to freely share with the Company: reviews, opinions, comments, ratings, information contained in documents that you provide to the Company, photos, etc. |
Personal data is stored for the entire duration of the message and for 1 year after its termination |
Data processing is necessary to comply with the legitimate interests of the company (Article 6(1)(f) GDPR) Consent of the data subject to such data processing (Article 6(1)(a) GDPR) |
Communication with clients and/or potential targets (complaints, appeals, requests, etc.) |
Facebook account data (profile photo, first name, last name, pseudonym), any other information that you have decided to freely share with the Company, first name, last name, email address, phone number, time of the request, content of the complaint, contact, request, account number, if applicable, when contacting via Facebook |
Personal data is stored for the entire period of the message and for 2 years after its termination |
Data processing is necessary for the conclusion and execution of the contract (Article 6(1)(b) GDPR) Data processing is required by law (Article 6(1)(c) GDPR) Consent of the data subject to such processing (Article 6(1)(a) GDPR) Data processing is necessary to comply with the legitimate interests of the company or a third party (Article 6(1)(f) GDPR) |
To ensure the safety of property and people (video surveillance) |
Video data about persons entering the observation field |
Personal data is stored for 30 days from the moment of video recording |
Processing is necessary to comply with the legitimate interests of the company or a third party (Article 6(1)(f) GDPR) |
Ensuring the continuity and continuity of the company’s activities, conclusion and execution of contracts |
Data of suppliers (individuals): first name, last name, personal identification number, date of birth, address, phone number, email address, bank account details, date, amount, currency of monetary transaction, details of the certificate of entrepreneurial activity, number of the certificate of individual activity, VAT registration number, other data |
Personal data is stored for the entire duration of the contractual relationship and for 10 years after the end of the contractual relationship Accounting documents are kept within the time limits established by law |
Data processing is necessary for the performance of the contract (Article 6(1)(b) GDPR) Data processing is required by law (Article 6(1)(c) GDPR) Data processing is necessary to comply with the legitimate interests of the company or a third party (Article 6(1)(f) GDPR)) |
HOW DO WE USE YOUR PERSONAL DATA AND WHAT PRINCIPLES DO WE FOLLOW?
We collect and process only those personal data that are necessary to fulfill the purposes for which they were collected. We do not collect or store Personal Data that does not relate to the conduct of our business and the sale of goods to you.
When processing your personal data, we:
We comply with current and applicable legislation, including REGULATION BDAR (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL. April 27 on the protection of individuals with regard to the processing of personal data and on the free movement of such data and on the repeal of Directive 95/46/EC (General Data Protection Regulation, hereinafter referred to as the “Data Protection Regulation”);
– We process your Personal Data in a lawful, fair and transparent manner;
– We collect your Personal Data for specific, clearly defined and legitimate purposes and do not process them in a manner incompatible with these purposes, except as permitted by law;
– We take all reasonable measures to ensure that Personal Data that is not accurate or complete with respect to the purposes for which they are processed is corrected, supplemented, suspended or destroyed in a timely manner;
– We store Personal Data in a form that allows us to establish your identity for no longer than is necessary for the purposes for which Personal Data is processed;
– We will not disclose Personal Data to third parties or make them publicly available, except as provided for in this Privacy Policy or applicable law;
– We guarantee that your Personal Data is processed in such a way as to ensure, through appropriate technical or organizational measures, adequate security of Personal Data, including protection against unauthorized or illegal processing, as well as against accidental loss, destruction or damage.
WHO DO WE SHARE YOUR PERSONAL DATA WITH?
We may share your personal data if:
– If you have consented to the disclosure of your Personal Data;
– Our partners or trusted third parties who help us sell goods and/or provide services, for example, customer service companies in Europe, transport companies, financial institutions, etc. We will provide our partners with Personal Data only to the extent necessary to provide a specific service;
– Our partners or trusted third parties who help us in our activities, for example, auditors, consultants, insurance companies, etc;
– State bodies and institutions, law enforcement agencies, courts, other persons performing the functions assigned by law, in accordance with the procedure provided for by the legislation of the Republic of Lithuania. We provide these organizations with information required by law or specified by the organizations themselves;
– personal Data processors engaged by the Company (for example, companies providing IT, server services, website administration, accounting companies, call processing companies, analytical companies, advertising companies, payment intermediaries, etc.). We require that handlers store, process and process Personal Data as responsibly as we do, and only according to our instructions;
– If necessary, companies that could buy or acquire the Company’s business;
– Debt collection companies that are assigned the rights to claim the client’s debts, courts, out-of-court dispute resolution bodies and insolvency administrators.
Your personal data may be transferred outside the European Union or the European Economic Area only if the following conditions are met:
– This data is transmitted only to our reliable partners who ensure the provision of our services to you;
– Such partners have data processing agreements that ensure the security of your Personal Data in accordance with the law;
– The European Commission has decided on the suitability of the country in which our partner is located, i.e. a sufficient level of security is provided;
– Partners provide a level of Personal Data security in accordance with the EU-USA Privacy Shield;
– You have consented to the transfer of your personal data outside the European Union or the European Economic Area.
If you would like us to name specific individuals with whom we share your data, please contact our Data protection officer at [email protected]
RIGHTS OF THE DATA SUBJECT
As a data subject, you have the following rights with respect to your personal data:
– To know (be informed) about the processing of your Personal Data (the right to know);
– Know your personal data and how they are processed (access rights);
– To demand correction or, taking into account the purposes of Personal Data processing, the addition of incomplete Personal Data (the right to correction);
– Request the deletion of your Personal Data in order to destroy or suspend the processing of your Personal Data (except storage) (the right to delete and the right to be forgotten);
– The right to data portability (the right to transfer). This right will be exercised only if there are grounds for its exercise and appropriate technical measures to ensure that the transfer of the requested Personal Data will not expose the data of other persons to the risk of a security breach.;
– Object to the processing of your Personal Data if we process Personal Data based on the legitimate interests of the Company or a third party, including profiling. If you object, we will continue processing your personal data only for valid legal reasons that prevail over your interests, rights and freedoms, or to create, implement or defend legal claims;
– Object to the processing of your personal data if such data is processed or intended for processing for direct marketing purposes, including profiling** in connection with such direct marketing.
We will process your data for direct marketing purposes only with your prior consent. If you have given us such consent, but no longer want us to process your personal data for direct marketing purposes, including profiling, you can opt out of such processing by clicking on the corresponding link in the information letter sent to you, changing the settings in your account on the Website in the “Direct Marketing” section or by sending us an email to [email protected] or by phone +370 61777113, without specifying the reasons for refusal (objections).
**Based on the personal data provided by you and with your consent, your personal data may be profiled for the purpose of direct marketing in order to provide you with customized solutions and offers. You can revoke or object to the automated processing of your personal data, including profiling, at any time.
We may refuse to exercise your rights listed above, except for the refusal to process personal data for direct marketing purposes or in other cases when Personal Data is processed with your consent, when the GDPR provisions allow us not to fulfill your request, or when it is necessary to ensure the prevention, investigation and detection of criminal offenses, violations of professional or official ethics, as well as the protection of the rights and freedoms of the data subject, the Company and others in case of violation of the GDPR, or in cases provided for by law.
You can send us any request or instruction regarding the processing of Personal Data in writing in one of the following ways: by delivering it directly to Polocko g. 26, Vilnius, Lithuania, LT-01205 or by writing a letter to the data protection officer at [email protected] . When submitting such a request, in order to better understand the content of your request, we may ask you to fill out the necessary forms, as well as provide a personal document or its notarized copy, and other information that will help us verify your identity. If you send a request by email, depending on the content of your request, we may ask you to visit us or send a request in writing.
After receiving your request or order regarding the processing of your Personal Data, we will provide you with a response no later than 1 month from the date of the request and perform the actions specified in the request, or inform you why we refuse to do so. If necessary, the deadline can be extended for another 2 months, depending on the complexity and number of requests. In this case, we will inform you about the extension within 1 month from the date of receipt of the request.
If Personal Data is deleted upon your request, we will retain only those copies of the information that are necessary to protect our legitimate interests and the interests of others, to fulfill the obligations of government agencies, to resolve disputes, to identify interference or to fulfill any agreements that you have concluded with us.
WHO CAN YOU COMPLAIN TO?
If you would like to file a complaint about our processing of your personal data, please send it to us in writing by writing to our Data protection Officer at [email protected] and by providing as much information about the complaint as possible. We will cooperate with you and try to resolve any issues promptly.
If you believe that your rights have been violated in accordance with the GDPR, you can also file a complaint with our supervisory authority, the State Data Protection Inspectorate, for more information and contact details, visit the inspection website www.ada.lt .
DO WE COLLECT CHILDREN’S PERSONAL DATA?
Only persons over the age of 18 can independently purchase our products in the D’ORO boutique online store, accessible through the Website. We do not intentionally collect any information directly from children under the age of 18.
If you are under the age of 18, we advise you to consult and obtain the consent of your parents or guardians before providing us with your Personal Data.
Note for parents of children under 18 years of age: We recommend that you check and monitor your children’s use of the Company’s Website and the services provided through the Website to make sure that your child does not provide us with Personal Data without your permission. Minors may provide us with Personal Data only with the consent of their parents or guardians.
HOW DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
Our site uses cookies (small files that are stored on the hard drive of visitors’ devices) and other tracking technologies to distinguish you from other visitors to the site. The information collected through cookies and other tracking technologies allows us to provide you with a more convenient browsing experience.
We use cookies and other tracking technologies to analyze information flows, adapt services, content and advertising, measure the effectiveness of advertising, build trust and ensure security.
You can choose whether to accept cookies and other tracking technologies. If you do not agree with the placement of cookies or other tracking technologies on your computer or other end device, you can change your web browser settings to disable all cookies or enable/disable them one by one. For more information, visit AllAboutCookies.org or www.google.com/privacy_ads.html .
You can also manage cookies on our website: here you will find cookie settings.
Please note that rejecting cookies in some cases may slow down the speed of your browsing, restrict the operation of certain functions of the Website or block access to the Website.
We use the following categories of cookies:
– Mandatory cookies: cookies are necessary for the functioning of the system. For example, some cookies allow us to identify registered users and provide them with access to the entire system. If the registered user refuses these cookies, he may not be able to see the full contents of the system.
– Functional cookies: cookies that allow us to remember user preferences and adapt them to the Website so that we can provide advanced features.
– Third-party cookies: these cookies are used by third parties for advertising or analytical purposes. Analytical cookies are used to collect information about the use of a Website or Mobile Application. Advertising cookies are used to display ads that are more relevant to your interests, to limit the number of views of the same ad, etc.
Our website uses cookies:
Cookie file name |
Functions performed by the cookie |
Purpose of data processing |
Moment of creation |
Validity period |
We use “third-party cookies” on our website, i.e. cookies that are not managed by us, for example, cookies from Google Partners, Facebook, RTB, Adform, Google Analytics, Hotjar, Mixpanel. We use these cookies to obtain statistical information about the use of the website and for the purposes of online advertising based on your behavior.
You can read more about it here:
https://firebase.google.com/docs/analytics/.
SEE https://firebase.google.com/docs/crashlytics /.
This data does not allow us to establish your identity.