Tuoteluettelo

Tietosuojakäytäntö

  • In this privacy policy (hereinafter referred to as the Privacy Policy), we provide you with information on how UAB Sveika tema, legal entity code 305164017, VAT payer code LT100012392514, registered office address Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania (hereinafter referred to as the Seller or we) processes your personal data in the HAIRFREE online store (hereinafter referred to as the E-store).

    You can contact the Seller at the following addresses:

    Tel.: +370 679 888 77
    Email: [email protected]
    Address: Perkūnkiemio g. 19, LT-12120 Vilnius, Lithuania

    What personal data do we process?

    We process personal data in the E-shop for the following purposes:

    Purpose: Order fulfillment and delivery

    • Personal data processed: First name, last name, address, phone number, email address.
    • Legal basis: Contract (when the buyer is a natural person) or the Seller's legitimate interest in conducting business (when the buyer is a legal entity).
    • Storage period: 10 years after order fulfillment.
    • We may transfer the data necessary for order delivery (first name, last name, address, telephone number, email address) to the delivery service provider (courier).
    • Please note that if you pay for the goods in installments, the Seller may transfer the data to the relevant financial institution - UAB ESTO (legal entity code: 305219905, address: Lvivo g. 25-104, Vilnius, e-mail: [email protected], telephone: +370 524 09 988) or UAB Artea lizingas (legal entity code 234995490, address: Karaliaus Mindaugo pr. 35, 44307 Kaunas, e-mail [email protected], telephone: +370 610 44447, data protection officer: [email protected]), as an independent personal data controller, some of the personal data you provided when placing your order: first name, last name, email address, phone number. All personal data related to installment purchases and consumer credit will be collected and processed by your chosen financial institution as an independent personal data controller, so please read its privacy policy before using this service.

    Purpose: Payment refunds

    • Personal data processed: First name, last name, bank account number, other details.
    • Legal basis: Contract, legal obligation.
    • Storage period: 10 years after the payment order.
    • We may transfer personal data to payment service providers.

    Purpose: Sale and administration of gift vouchers

    • Personal data processed: First name, last name, email address, telephone number, gift voucher value, date of sale, gift voucher number, expiry date.
    • Legal basis: Contract or the Seller's legitimate interest in conducting business.
    • Storage period: until the end of the gift voucher's validity or until the gift voucher is used.

    Purpose: Creation and administration of an account in the E-shop

    • Personal data processed: First name, last name, account name and password, telephone number, email address, address, order history.
    • Legal basis: Contract.
    • Storage period: as long as the account is active and for 24 (twenty-four) months after the last login to the account.

    Purpose: Communication with e-shop visitors and other persons

    • Personal data processed: First name, last name, e-mail address, telephone number.
    • Legal basis: The desire to take action at the request of the data subject before concluding a contract or the Seller's legitimate interest in carrying out activities and/or ensuring quality.
    • Storage period: 1 year after the date of resolution of the request.

    Purpose: Direct marketing (newsletters, invitations to events, offers of similar goods or services)

    • Personal data processed: First name, last name, email address, telephone number.
    • Legal basis: Consent or the Seller's legitimate interest in offering similar goods or services to customers.
    • Storage period: 2 years after consent is obtained or after the person has purchased goods or services.
    • We may transfer personal data for the purpose of sending newsletters.

    Purpose: Conclusion and performance of other contracts with suppliers, service providers, partners, and customers

    • Personal data processed: First name, last name, address, email address, telephone number, other data included in the contract.
    • Legal basis: Contract (when a contract is concluded with a natural person) or the Seller's legitimate interest in carrying out its activities (when the personal data of a representative of a legal entity is processed).
    • Storage period: 10 years after the end of the contract.

    Purpose: Social media account administration

    • Personal data processed: User name, unique ID, profile photo, information contained in comments or correspondence, IP address, device information.
    • Legal basis: Consent or the Seller's legitimate interest in communicating with customers.
    • Storage period: As long as the person is a follower of our social media account.
    • We control the information you provide to us via social media when visiting our accounts (including messages, use of the "Like" button, and other communication) jointly with social network administrators as joint controllers of personal data.
    • We currently have the following social media accounts:

    We recommend that you read the privacy notices of third parties and contact the service providers directly if you have any questions about how they use your personal data.

    Cookies

    What is a cookie?

    A cookie is information that an internet server sends to your internet browser and is stored in the browser. This information is sent to the web server each time your browser requests to open the E-shop website from the server, and it is used to distinguish your computer or other device from other devices. Cookies therefore ensure a more convenient use of the website and allow us to improve it.

    There are several types of cookies, depending on their purpose:

    Essential (technical) – ensure that the E-shop website functions properly. For example, without them, the shopping cart or account login would not work.
    Functional – help the e-shop website remember your choices, such as language, and thus ensure a more convenient browsing experience.
    Statistical/analytical – provide anonymous information about how visitors use the e-shop website (e.g., how many people visit it, which pages are most popular). This data helps us improve the performance of the website.
    Marketing – allows us to show you more relevant ads tailored to your interests. This helps ensure that you see information that is useful to you, rather than just any information.

    It is also important to know the difference between different sources of cookies:

    • First-party cookies are created and used on our e-shop website.
    • Third-party cookies are installed by external partners (e.g., advertising or analytics tools) and may therefore also function on other websites you visit.

    When are cookies used?

    Essential cookies are used automatically because they are necessary for the proper functioning of the E-shop website (e.g., to maintain the selected language or ensure the functionality of the shopping cart). In this case, data is processed in accordance with our legitimate interest in ensuring the reliable and secure operation of the website.
    Other cookies (e.g., analytical or advertising cookies) are only enabled with your consent. The data collected by these cookies is only processed with your consent, which you can revoke at any time.

    What data is processed with cookies?

    Cookies may be used to process certain technical information, such as your IP address, browser used, pages visited, time spent on the website, etc.
    A list of cookies used on the E-shop website and more detailed information about them and the data they process can be found in the cookie management tool installed on the Website by selecting "Detailed information."

    When can data be transferred outside the EU?

    When using certain cookies on the E-shop website (e.g., Google Analytics, Meta Pixel, or other third-party tools), your data may be transferred outside the European Union/European Economic Area, including to the United States (US).
    Currently, the US is subject to the European Commission's adequacy decision, which allows US companies participating in the EU-US Data Privacy Framework to be certified and commit to complying with EU personal data protection standards. This means that companies such as Google, Meta, or Amazon (the full list can be found here) can be used with confidence that your data is adequately protected. If data is transferred to a recipient who is not certified under this mechanism, the data transfer is based on Standard Contractual Clauses (SCCs). If you would like more information about this, please contact us.

    How can you manage cookies?

    If you do not want your personal data to be processed using cookies, you can do so using the cookie management tool installed on the E-shop website, or you can change your web browser settings so that cookies are not accepted, or delete the cookies that have been stored. If you delete essential cookies and do not allow them to be used in your web browser, some features of the E-shop website will not work properly and this may interfere with your use of the website.
    You can change your cookie settings in your browser at any time. All browsers allow you to delete cookies, and you can find more detailed information in your browser settings.

    Who can we share your personal data with?

    In addition to the above, we may share information about you with our employees, intermediaries, service providers, such as debt management or collection companies, archiving service providers, legal and marketing services, IT service providers or subcontractors, if reasonably necessary for the purposes set out in this Privacy Policy.
    We may also disclose information about you if we are required to do so by law or in order to protect our rights or interests (including disclosing your personal data to third parties in order to collect debts owed to us), as well as when we intend to transfer the E-shop, part of the company's business or assets, or reorganize the company, or when carrying out these processes, by disclosing your personal data to the (potential) acquirer of the business or part thereof, or other participants in the reorganization.

    How is your personal data processed?

    Your personal data will be processed in accordance with the General Data Protection Regulation (hereinafter referred to as GDPR), the Law on Legal Protection of Personal Data of the Republic of Lithuania, and other legal requirements. When determining the means of processing personal data and during the processing of the data itself, the seller implements appropriate technical and organizational measures for data protection as established by law, designed to protect the personal data being processed from accidental or unlawful destruction, damage, alteration, loss, disclosure, as well as any other unlawful processing. The appropriate measures are determined taking into account the risks arising from the processing of personal data.

    What are your rights?

    Below is information about your rights in relation to the processing of your personal data by the Seller and the circumstances in which you can exercise these rights. If you would like more information about your rights or to exercise them, please contact us at the email address provided in this Privacy Policy.

    • You can contact us at any time to ask whether we are processing any of your personal data. If we store or use your personal data in any way, you have the right to access it. To do so, please submit a written request to us at the email address provided in this Privacy Policy. We may ask you to verify your identity in order to fulfill your request. When submitting such a request, please act in good faith and reasonably.
    • If you have given us your consent to process your data, you can revoke it at any time by sending an email to the email address specified in this Privacy Policy.
    • You have the right to request that we correct any inaccuracies in the data we hold. In this case, we may ask you to confirm the corrected information.
    • You have the right to request that we delete your personal data. This right is exercised in the cases provided for in Article 17 of the GDPR.
    • You have the right to request that we restrict the processing of your personal data or that we do not process it.
    • You have the right to transfer data that is processed by automated means and that we have received from you with your consent or for the purpose of concluding a contract. If you exercise this right, we will transfer a copy of the data you have provided at your request.
    • You have the right to object to our use of your personal data in the cases and in the manner specified in Article 21 of the GDPR, if the personal data is processed on the basis of the Seller's legitimate interest.

    How can you exercise your rights?

    To exercise your rights, please submit your requests, complaints, or claims to us in writing using the contact details provided in this Privacy Policy.

    We will respond to your requests, complaints or claims in writing in accordance with the procedure and within the time limits established by law. We will endeavor to provide you with information as soon as possible, but no later than within 30 days of receiving your request.

    If, upon receiving a request, complaint, or claim, we have doubts about the identity of the person making the request, we have the right to ask for the person's identity document.

    Complaints

    If you believe that your rights as a data subject have been or may be violated, please contact us immediately at the email address provided in this Privacy Policy. We guarantee that we will contact you within a reasonable period of time after receiving your complaint and inform you about the progress of the investigation and, subsequently, the outcome. If you are not satisfied with the results of the investigation, you can lodge a complaint with the supervisory authority: in Lithuania – the State Data Protection Inspectorate (https://vdai.lrv.lt/), and a list of supervisory authorities in other EU Member States can be found on the website of the European Data Protection Board: https://www.edpb.europa.eu/about-edpb/about-edpb/members_lt.

    Responsibility

    You are responsible for ensuring that the data you provide to us is accurate, correct, and complete. If the data you have provided changes, you must inform us immediately by email. We shall in no event be liable for any damage caused to you as a result of your providing incorrect or incomplete personal data or failing to inform us of any changes thereto.

     Cookie Declaration