Effective as of January 23, 2019
1. SCOPE
At Zira Jewels by Sprint-Euro Kft., we respect the basics of privacy law and data protection rights and will do our best to make sure they are implemented and maintained. We integrate various technical solutions to comply with applicable laws and regulations related to personal data protection in countries where we operate. This Policy sets forth the basic rules and principles by which we collect and process your personal data, and mentions our responsibilities while processing personal data.
We may be a data processor or data controller according to the applicable law. Regardless of our status, we will deal with any personal data as required by any applicable regulation, including but not limited to, Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (the “GDPR”).
We do not knowingly attempt to solicit or receive information from children. Our services do not aim at children. The concrete age of the children are defined differently, so any case involving a child will be reviewed individually.
We understand that you are aware of and care about your own privacy interests, and we take that seriously. This Privacy Policy describes the rules and practices with regard to the collection and use of your personal data and details your privacy rights. We recognize that privacy is an ongoing responsibility, and so we will from time to time update this Privacy Policy as we undertake new personal data practices or adopt new privacy and security rules.
2. TERMS WE USE AS LEGAL GUIDELINES OF THE PROCESSING
There are some legal bases for the processing of your personal data and we count on them to process your personal data. We use the main three bases to process your personal data: consent, contract, and legitimate interest.
Consent – your clear agreement to the processing of your personal data for a specific purpose.
Contract – the reason why the processing is necessary based on a contract you have with us, or because we have asked you to take specific steps before entering into that contract.
Legitimate Interests – the reason why the processing your data is necessary which is based on the legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your rights and interests.
Articles 6(1) and 9(2) of the GDPR also indicate other legal grounds for the processing and when applicable we will count on such grounds.
3. CONSENT RULE AND INTERRELATION WITH OTHER LEGAL GROUNDS
If you have given consent to the processing of your data you can freely withdraw such consent at any time by emailing us or contacting via other available communication channels.
If you do withdraw your consent, and if we do not have another legal basis for the processing of your data, then we will stop the processing of the personal data.
If we have another legal basis for the processing of your data, then we may continue to do so, subject to your legal interests and rights.
4. OUR RESPONSIBILITIES
As we may have both roles as a data controller and data processor, we have obligations according to the GDPR. We act as a data controller when we determine the purposes and means of the processing of your personal data. As a data processor, we process personal data on behalf of the controller.
5. RECOMMENDATIONS
You should read this Privacy Policy carefully. We want to make sure that you understand all your rights. It is important for both of us that you treat your personal data confidential and secure.
If you provide us with personal data about other individuals, we will only employ that data for the special reason for which it was provided to us. By sending the data, you shall be sure that you have the right to dispose to process the personal data on your behalf in accordance with this Privacy Policy. In case if you submit third party’s personal data, be sure that you have a legal basis for the processing of such data.
According to the applicable law, you may become a data controller/processor and it will impose on you additional obligations.
6. PROCESSED DATA
We process personal data when you interact with our website – https://www.zirajewels.com (the “Website”), especially when:
– you browse any page of the Website;
– you purchase products available on the Website;
– you sign up or log in;
– you communicate with us;
– we deliver the products;
– you receive emails or notification from us;
– we measure Website traffic;
– in cases which do not depend on you but we have a legal basis to collect such data (see articles 6 and 9 of the GDPR).
We collect the following types of data:
– contact details such as you’re your first name, last name, email address, address (it may include your company name, street address, city, ZIP, postal code), phone;
– your country and region;
– your password;
– some verification payment information through third parties;
– purchasing history;
– favorite activities and your interests;
– data that identifies you such as your IP address, login information, browser type, and version, time zone setting, browser plug-in types, some location information about where you might be, operating system and version;
– data on how you use the Website such as your URL clickstreams (the path you take through the Website), goods/services viewed, page response times, download errors, how long you stay on webpages, what you do on those pages, how often, and other actions;
– other personal data you share with us or personal data which we may legally obtain for our legitimate interests.
The recipients of the collected data are the highest management level of the company.
7. PURPOSES AND LEGAL BASIS FOR THE PROCESSING
We process the data for:
– Registering users. We need your email and password to register you and identify each time you access the Website. Legal basis: Consent; Legitimate Interests.
– Providing services. We need to provide services accessible via the Website. Legal basis: Consent; Legitimate Interests.
– Delivering goods. We need to know where we must deliver the products you purchased. So we use your name, your company name (if applicable), street address, city, ZIP, postal code to deliver the products. We also may contact you to clarify delivery terms or ask you to provide additional information. Legal basis: Consent; Legitimate Interests.
– Identifying your location to define applicable delivery fees. Legal basis: Contract; Legitimate Interests.
– Providing offers which may be interesting to you. Legal basis: Consent; Legitimate Interests.
– Collecting your purchase history to identify your interests and offer of similar or related products. Legal basis: Legitimate Interests.
– Processing payments to sell our products. Legal basis: Legitimate Interests.
– Informing you about our products or news (for example, you may receive our newsletters). Legal basis: Consent; Legitimate Interests.
– Keeping the Website running (managing your requests, login, and authentication, remembering your settings, processing payments, hosting and back-end infrastructure). Legal basis: legitimate Interests.
– Preventing frauds, illegal activity or any violation of the terms or Privacy Policy. We may disable access to the Website in some cases. Legal basis: legitimate Interests.
– Improving the Website (testing features, interacting with feedback platforms, managing landing pages, heat mapping the Website, traffic optimization, and data analysis and research, including profiling and the use of machine learning and other techniques over your data and in some cases using third parties to do this). Legal basis: Contract; legitimate Interests.
– Customer support (notifying you of any changes to the Website, products, services, solving issues, any bug fixing). Legal basis: Contract; Legitimate Interests.
8. YOUR RIGHTS AS DATA SUBJECT
You may turn off cookies in your browser via settings. You can block cookies on your browser refusing cookies. You may delete cookies. If you turn off cookies, you can continue to use the Website and browse its pages, but the Website and certain services will not work properly.
You may ask us to refrain from using your data for marketing (when applicable). You can opt-out from marketing by emailing us or contacting via the contact form.
You can exercise the following rights by sending us an email or contacting via the contact form.
You have the right to access information about you, especially:
– the categories of data;
– the purposes of data processing;
– third parties to whom the data disclosed;
– how long the data will be retained and the criteria used to determine that period;
– other rights regarding the use of your data.
You have the right to make us correct any inaccurate personal data about you.
You can object to using your personal data for profiling you or making automated decisions about you. We may use your data to determine whether we should let you know information that might be relevant to you (for example, tailoring emails to you based on your behavior).
You have the right to the data portability of your data to another service or website. We will give you a copy of your data in a readable format so that you can provide it to another service. If you ask us and it is technically possible, we will directly transfer the data to the other service for you.
You have the right to be “forgotten”. You may ask erasing any personal data about you if it is no longer necessary for us to store the data for purposes of your use of the Website.
You have the right to lodge a complaint regarding the use of your data by us. You can address any complaint to your national regulator (see the list at http://ec.europa.eu/justice/article-29/structure/data-protection-authorities/index_en.htm).
In the context of the right to access information, we shall provide you with the information within one month of your request unless there is a justified requirement to provide such information faster. This term may be prolonged according to the GDPR.
9. SECURITY
We have security and organizational measures and procedures to secure the data collected and stored. You acknowledge that no data transmission is guaranteed to be 100% secure and there may be risks. You are responsible for your login information and password. You shall keep them confidential. In case if your privacy has been breached, please contact us immediately.
10. LOCATION OF THE PROCESSING OF PERSONAL DATA AND THIRD PARTY SERVICE PROVIDERS
The personal data collected by our establishment incorporated in Hungary.
The Website is created on the platform which belongs to WordPress.com. We also use their servers to store personal data.
We use MailChimp to manage newsletters and for marketing automation and email marketing.
We use Google AdWords to analyze data, advertise and improve our services and Website.
Payments are processed by PayPal, Direct Bank Transfer, Cash on Delivery for local orders.
11. RETENTION PERIOD
We store personal data as long as we need it and the retention practice depends on the type of data we collect, regulatory burden, and how we use the personal data. The retention period is based on criteria that include legally mandated retention periods, pending or potential litigation, intellectual property or ownership rights, contract requirements, operational directives or needs, and historical archiving.
12. COOKIE POLICY
We collect certain types of information when you access or use the Website, including cookies and similar tracking technologies.
Cookies are small data files that are placed on your computer or mobile device when you visit the Website. Cookies are used by the Website in order to make the Website work, or to work more efficiently, as well as to provide reporting information.
You may always turn off some of the cookies through your browser. If you turn off the cookies, this may influence the functionality of the Website.
The list of cookies we use is listed in your browser.
13. TRANSFER OF YOUR PERSONAL DATA
Some of our third parties are located outside the EU/EEA. We have data processing agreements or special legal arrangements requiring them to process and store your personal data within the EU/EEA.
14. CONTACT INFORMATION
We welcome your comments or questions about the Privacy Policy, terms, services, Website. You may contact us in writing at:
Sprint-Euro Kereskedelmi es Szolgaltato Kft.
Registration number: 01-09-896076
Registered address: Hungary, Budapest 1029 Feketerigo utca 12/b
Email: zira@zirajewels.com
Phone number: +36203150338