Privacy Policy

Disclaimer: This document has been created as a template for informational purposes only. By using it, you acknowledge this disclaimer and understand that Webnode is not responsible for any actions taken or content published on this website. We recommend seeking legal advice and adapting this document to meet the specific needs of your business.

The online store [….] on the website [….], Business ID […], located in […], processes personal data provided by customers for the purposes of fulfilling and confirming the Terms & Conditions, processing online orders and deliveries, and providing necessary information for the period required by law.

General Provisions

1. The data controller responsible for processing personal data in accordance with the GDPR (hereinafter referred to as the "Regulation") is […..], Business ID [….], located in [….] (hereinafter referred to as the "Data Controller").

2. The Data Controller's contact details are:
Email: [……]
Phone: [………]

3. Personal data means any information relating to an identified or identifiable natural person.

Source of Personal Data

1. The Data Controller processes personal data provided by the customer in connection with the customer's online purchase and the fulfilment of the resulting agreement […].

2. The Data Controller processes only the customer's identification and contact details that are necessary for fulfilling the sales agreement.

3. Personal data is processed for shipping, accounting and necessary communication between the parties for the period required by law. Personal data is not made publicly available or transferred to other countries.

Purpose of Processing Personal Data

The Data Controller processes the Customer's personal data for the following purposes:

1. Registration on the website [….] in accordance with Chapter 4, Section 2 of the GDPR;

2. Processing of the Customer's online order, including name, address, email address and telephone number;

3. Complying with laws and regulations arising from the contractual relationship between the Customer and the Data Controller;

4. Personal data is necessary for fulfilling the sales agreement. The agreement cannot be entered into without the required personal data.

Retention Period for Personal Data

1. The Data Controller stores personal data for as long as necessary to fulfil the rights and obligations arising from the contractual relationship between the Data Controller and the Customer, and for three years after the contractual relationship has ended.

2. After the applicable retention period has expired, the Data Controller shall delete all personal data that is no longer required to be retained.

Recipients and Processors of Personal Data

The Customer's personal data may be processed by third parties acting as processors or subcontractors of the Data Controller. These services are necessary for processing and fulfilling the online order agreement between the Data Controller and the Customer.

The Data Controller's service providers include:

  • Webnode AG (online store platform);

  • Shipping and delivery providers;

  • Google Analytics (website analytics).

Customer's Rights

Under the GDPR, the Customer has the right to:

1. access their personal data;

2. request correction of inaccurate or incomplete personal data;

3. request the deletion of their personal data;

4. object to the processing of their personal data;

5. request data portability;

6. withdraw their consent to the processing of personal data by written notice or by email to: [….];

7. lodge a complaint with the competent supervisory authority if the Customer believes that the GDPR has been violated.

Security of Personal Data

1. The Data Controller undertakes to implement all necessary technical and organisational measures to protect personal data.

2. The Data Controller has implemented technical safeguards to protect stored data, including protecting access to computers with passwords, using antivirus software and regularly maintaining computer systems.

Final Provisions

1. By placing an online order on the website [….], the Customer confirms that they have been informed of these privacy terms and accepts them in full.

2. The Customer accepts these terms by selecting the appropriate checkbox in the order form.

3. The Data Controller may update this Privacy Policy at any time. The updated version will be published on this website.

This Privacy Policy is effective from [date].