PROCESSING OF PERSONAL DATA
The Werner website, hereinafter referred to as the ''Online Store'', is committed to protecting the privacy of its customers and users. This privacy policy sets out the principles for the collection, use, disclousure, transfer and storage of customer data.
The controller of personal data is Werku Kohvik OÜ Registry code: 16396810 Address: Ülikooli 11, Tartu, Tartu County 51003, Estonia Phone: +372 5124328 E-mail: cafe@werner.ee
Personal Data Processed by the Online Store
- customer's name, phone number and e-mail address;
- delivery address or delivery location;
- customer's bank account number;
- cost of goods and services and payment-related data (purchase history);
- data related to customer support.
In addition, the controller has the right to collect data available in public registers.
Personal data is processed in accordance with article 6 lg 1 p-d a), b), c) ja f):
a) the data subject has given consent for specific purposes;
b) processing is necessary for the performance of a contract;
c) processing is necessary to comply with a legal obligation;
f) personal data processing is necessary for the legitimate interests of the controller or a third party, except where such interests are overridden by the interests, fundamental rights and freedoms of the data subject which require the protection of personal data, especially where the data subject is a child.
For the purpose of this privacy policy, a data subject is a customer or any other natural person whose personal data is processed by the controller. A customer is anyone who purchases goods or services from the controller's website.
The online Store complies with the data processing principles set out in legislation and processes personal data lawfully, fairly and securely. The controller is able to confirm that personal data has been processed in accordance with applicable legal requirements.
Purpose of Processing Personal Data
The personal data collected, processed and stored by the Online Store is collected electronically, mainly through the website and e-mail.
By sharing their personal data, the data subject grants the Online Store the right to collect, organise, use and manage the personal data provided by the data subject directly or indirectly when purchasing goods or services from the website, for the purposes defined in this privacy policy.
The data subject is responsible for ensuring that the information provided is accurate, correct and complete. Knowingly providing false information is considered a violation of this privacy policy. The data subject is obliged to notify the Online Store immediately of any changes to the submitted data. The Online Store is not responsible for any damage caused to the data subject or third parties due to the submission of incorrect information.
Personal data is used to manage customer orders and deliver goods.
Purchase history data (purchase date, product, quantity, customer details) is used to compile an overview of purchased goods and services and to analyse customer preferences.
The customer’s bank account number is used for processing refunds.
Personal data such as e-mail address, phone number and customer name is processed in order to resolve issues related to the provision of goods and services (customer support), as well as to send promotional offers and information.
The Online Store user’s IP address and other network identifiers are processed to provide the Online Store’s information society services and to compile website usage statistics.
Legal Basis
The processing of personal data is carried out for the purpose of fulfilling the contract concluded with the customer and for complying with legal obligations (accounting, resolving consumer disputes).
Recipients of Personal Data
Personal data is shared with the Online Store’s customer support for managing purchases, purchase history and resolving customer issues.
Personal data is shared with the financial department for accounting purposes.
Personal data may be shared with IT service providers if this is necessary to ensure the functionality of the Online Store or data hosting.
For the management of payments, the necessary personal data is transferred to the authorised processor Maksekeskus AS.
Security and Access to Data
Personal data is stored on servers located within the European Union or in countries that are part of the European Economic Area. Data may also be transferred to countries whose data protection level has been deemed adequate by the European Commission, and to U.S. companies that have joined the Privacy Shield framework.
Access to personal data is granted to Online Store employees only for the purpose of fulfilling orders, resolving technical issues related to the use of the website, and providing customer support.
The Online Store applies appropriate physical, organisational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised access and disclosure.
The transfer of personal data to authorised processors (such as payment service providers and hosting services) is carried out on the basis of contracts concluded between the Online Store and the authorised processors. Authorised processors are obliged to ensure appropriate data protection measures.
Access to and Correction of Personal Data
The data subject has the right to access and review their personal data.
The data subject has the right to receive information about the processing of their personal data.
The data subject has the right to supplement or correct inaccurate data.
Since the Online Store processes the data subject’s personal data on the basis of the data subject’s consent, the data subject has the right to withdraw their consent at any time.
To exercise these rights, the data subject may contact the Online Store’s customer support at cafe@werner.ee.
The data subject also has the right to submit a complaint to the
Data Protection Inspectorate in order to protect their rights.
Withdrawal of Consent
If the processing of personal data is based on the customer’s consent, the customer has the right to withdraw their consent by notifying customer support via e-mail at cafe@werner.ee.
Retention, Deletion, and Transfer of Personal Data
When a customer account is closed, personal data is deleted, except for data that must be retained for accounting purposes or the resolution of consumer disputes.
If a purchase is made in the Online Store without a customer account, the purchase history is retained for three years.
In cases of disputes related to payments or consumer issues, personal data is retained until the claim is fulfilled or the statute of limitations expires.
Personal data required for accounting purposes is retained for seven years.
To request the deletion of personal data, customers should contact customer support via e-mail at cafe@werner.ee.
Deletion requests will be processed no later than one month after submission, and the period of data deletion will be clarified.
Requests to transfer personal data submitted via e-mail will be answered within one month. Customer support will verify the identity of the data subject and provide information on the data eligible for transfer.
The Online Store has the right to share customer personal data with third parties, such as authorised data processors, accountants, transport and courier companies, and companies providing transfer services. The Online Store acts as the data controller. Personal data necessary for payment processing is transferred to the authorised processor Maksekeskus AS.
The Online Store applies organisational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.
Direct Marketing
The e-mail address and phone number may be used to send direct marketing messages if the customer has given consent. If the customer does not wish to receive direct marketing messages, they can unsubscribe via the link in the e-mail footer or contact customer support.
Dispute Resolution
Disputes related to the processing of personal data are resolved through customer support: E-mail: cafe@werner.ee. Phone: +372 5124328. The supervisory authority is the Data Protection Inspectorate: info@aki.ee.