The data controller of the Llama.ee online store is Llama Holding OÜ, registry code 12750723, address Lehola tn 5, Nõmme district, Tallinn, Harju County 11620, phone (+372) 56985088, and email info@llamalifestyle.shop (hereinafter “the merchant”).
What personal data is processed:
name;
contact information, such as phone number and email address;
billing and delivery address;
bank account number;
information related to the cost of goods and services and payments (purchase history);
customer support data;
other information related to customer surveys and/or offers.
Purpose of processing personal data:
The processing of personal data is carried out for the performance of a contract concluded with the customer. It is also carried out to fulfill legal obligations (e.g. accounting and resolution of consumer disputes). Personal data is used to manage customer orders and deliver goods. Purchase history data (purchase date, item, quantity, customer details) is used to provide an overview of purchased goods and services and to analyze customer preferences.
The bank account number is used to refund payments to the customer.
Personal data such as email address, phone number, and customer name is processed to resolve issues related to goods and services (customer support), and for preparing and sending offers and news.
The IP address or other online identifiers of the e-store user are processed for the provision of the information society service and for web usage statistics.
Transfer of personal data to authorized processors:
The merchant keeps customer personal data obtained during account registration and usage confidential and only discloses it to third parties with the customer’s consent, except when required or permitted by law. The user agrees that the merchant has the right to process their data to provide suitable services, including transferring data to persons involved in providing services to the customer.
List of authorized processors:
IT service providers – Personal data is shared with IT service providers to ensure the functionality and hosting of the e-store:
Veebimajutus.ee
Business and inventory software – for accounting and warehouse management:
Erply
Suppliers – for delivering orders to the customer:
DPD
Itella
Omniva
Payment processors – for handling order payments:
Swedbank
SEB
Luminor
LHV
Coop
Citadele
Revolut
N26
Montonio
Statistics collection – for improving the user experience:
Google Analytics
Facebook
Security and access to data:
Personal data is stored on Veebimajutus.ee servers located in EU member states or countries in the European Economic Area. Data may be transferred to countries that the European Commission considers to have adequate data protection levels and to US companies under the Privacy Shield framework.
The e-store applies appropriate physical, organizational, and IT security measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorized access, or disclosure.
Personal data is processed under agreements between the e-store and authorized processors. Processors are required to implement appropriate safeguards.
Access to and correction of personal data:
Personal data stored in the e-store can be accessed and corrected in the account management section.
Withdrawal of consent:
If data processing is based on customer consent, the customer can withdraw this consent in the account management section of the e-store.
Retention:
When a customer account is closed, personal data is deleted unless required for accounting or consumer dispute resolution.
If a purchase is made as a guest (without an account), the personalized purchase history is stored for three years.
In the case of payment or consumer-related disputes, data is retained until the claim is resolved or until the limitation period ends (three years).
Personal data required for accounting is retained for seven years.
Deletion:
Personal data stored in the e-store along with the user account can be deleted in the account management section.
To request the deletion of other personal data, a data request form can be submitted. The deletion request will be answered within one month, and if necessary, the deletion period will be specified.
Data portability:
An electronic extract of personal data stored in the e-store can be downloaded via account management.
To request the transfer of other personal data, a data request form can be submitted. The request will be answered within one month. Customer support will verify identity and provide details about the transferable data.
Direct marketing messages:
Email addresses and phone numbers are used to send direct marketing messages if the customer has given consent.
If the customer no longer wishes to receive such messages, they can unsubscribe using the link in the email header or contact customer support.
If personal data is processed for direct marketing (profiling), the customer has the right to object to such processing at any time by notifying customer support via email.
Dispute resolution:
Disputes related to the processing of personal data are resolved through customer support.
The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).
Consumer disputes may also be resolved via the Consumer Disputes Committee and the ODR platform.