THE PRINCIPLES OF PROCESSING PERSONAL DATA OF THE ONLINE SHOP OF THE TALLINN UNIVERSITY OF TECHNOLOGY
The controller of the personal data of the online shop (shop.taltech.ee) of the Tallinn University of Technology is the Tallinn University of Technology (registry code 74000323) located at Ehitajate tee 5, 19086, Tallinn, e-mail: firstname.lastname@example.org. The processor of the personal data of the online shop of the Tallinn University of Technology is Roller Äritarkvara OÜ (registry code 12235464), located at Veerenni 24c, Tallinn.
Which personal data will be processed
- Name, telephone number and e-mail address;
- Name of company, registry code, VAT No, address, name of company representative, telephone number and e-mail address
- Delivery address of the goods;
- Costs of goods and services and data related to payments (purchase history);
- Client support data.
For which purpose will the personal data be processed
Personal data is used for managing the client orders and delivering the goods. Purchase history data (date of purchase, goods, quantity, client data), is used for compiling an overview of purchased goods and services, as well as analysing client preferences.
The online shop of TalTech uses Google Analytics for analysis.
Personal data such as e-mail, phone number, client name, are processed to resolve questions related to the provision of goods and services (client support).
The IP address or other network identifiers of the TalTech online shop user, are used by the TalTech online shop as a provider of information society service, as well as for creating web use statistics.
The legal basis for the processing of personal data is the sales contract signed with the client.
The processing of personal data is used for fulfilling the contract and fulfilling legal obligations (e.g. accounting and settlement of consumer disputes).
Recipients to whom personal data is transmitted
The personal data is forwarded to the TalTech online shop client support, for managing purchases and purchase history, as well as solving client problems.
The name, telephone number and e-mail address are forwarded to the provider of transport services, selected by the client. The address of the client, in addition to the contact data, will be forwarded, if the goods concerned are to be delivered by courier.
The Tallinn University of Technology is the data controller who will forward the required personal data, for executing payments, to the processor SEB Pank AS. SEB Pank AS will forward the personal data to the Financial Department of the Tallinn University of Technology for accounting purposes.
Personal data may be forwarded to information technology service providers, if this is required to ensure the functionality of the online shop or the hosting of data.
Security and access to data
The personal data are stored in the servers of ShopRoller.com, which are located on the territory of a Member State of the European Union or a country that has joined the European Economic Area. The data may be forwarded to countries in which the level of data protection has been evaluated as sufficient by the European Commission, as well as to US companies that have joined the Privacy Shield framework.
Access to the personal data is available to the employees of the online shop, who can access the personal data to resolve technical questions related to the use of the online shop and provide client support services.
The online shop applies appropriate physical, organisational and information technology security measures, to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.
The forwarding of personal data to the data processors of the online shop (e.g. transport service provider and data hosting), takes place according to the contract signed between the online shop and the data processor. The processors are obligated to ensure appropriate protective measures when processing personal data.
Access to and correction of personal data
It is possible to access and correct personal data in the user profile of the online shop. It is possible to access the personal data with the assistance of client support, if the purchase was made without a user account.
Receiving the newsletter and its withdrawal
The client gives the corresponding consent in order to receive the newsletter. The client has at any time the right to withdraw the above mentioned consent, informing client support thereof by e-mail.
The personal data is deleted, when the client account is closed, except in cases in which such data is required to be stored for accounting purposes or resolving consumer disputes.
The purchase history is stored for three years, if the purchase has been made without a client account.
Personal data is stored until the fulfilment of the claim or end of the expiry period, in the case of disputes related to payments and consumer disputes.
Personal data required for accounting is stored for seven years.
The client support must be contacted by e-mail (email@example.com), to delete the personal data. The application for deletion will be responded to, no later than within one month and the period of data deletion will be clarified. The deletion of data is possible in the case of personal data, which resulting from legislation no longer requires storing.
Applications for the transfer of personal data, presented by e-mail, will be responded to at the latest within one month. Client support identifies the sameness of the person and informs of the personal data that belongs to be transferred.
Direct marketing messages
The e-mail address and phone number are used for sending direct marketing messages, if the client has given the corresponding consent. The corresponding reference in the footer of the e-mail must be selected or contact taken with the client support, if the client does not desire to receive direct marketing messages.
The client has the right at any time to present objections to the initial, as well as future processing of his/her personal data, if the personal data are processed for the purpose of direct marketing (profiling), informing client support thereof by e-mail (the corresponding information must be presented clearly and separately from all other information).
The following cookies are used in the online shop:
- session cookies, which have the purpose of allowing the use of the TalTech online shop;
- permanent cookies, which have the aim of remembering the client’s selections in the TalTech online shop;
- first and/or third party cookies, which have the purpose of showing the client suitable advertisements and offers;
- third party analytical cookies, which have the aim of optimising marketing communications.
The client may delete and/or block the cookies stored in his/her devices, by changing the corresponding settings of his/her browser. The TalTech online shop may not work as planned, if cookies are not used and/or some functionalities might not be accessible to the client.
The TalTech online shop uses pixels (pixel tags, web-beacons), in addition to analytical cookies, through the assistance of which, the seller’s use of the website is monitored. The data allowing the identification of the person is not processed in doing so.
Settlement of disputes
The resolution of disputes concerning the processing of personal data, takes place through the mediation of the client support.
Please contact the data protection specialist of the Tallinn University of Technology at the e-mail address firstname.lastname@example.org, in the case of data protection questions.
The supervisory authority is the Estonian Data Protection Inspectorate (email@example.com).