Privacy Policy

The controller of the personal data of the online shop is POLGENT.EE (registry code 10259319), located at Pärnu mnt 142 Tallinn, Eesti, phone +372 6556 995 and e-mail info@polgent.ee.

Which personal data are processed?

  • name;
  • phone number;
  • e-mail address;
  • billing and delivery address;
  • payment information (excluding full card details);
  • purchase history (products, quantities, dates, amounts);
  • customer support communications;
  • IP address;
  • cookies and online identifiers (including Google Analytics identifiers).

For which purposes are personal data processed?

Personal data is used to manage customer orders and deliver goods.

Purchase history data is used to analyse customer preferences and to resolve consumer disputes.

Payment data is used for processing payments and refunds.

Personal data (name, e-mail address, phone number) is used for customer support and communication with customers.

E-mail is used to send invoices, order confirmations and other transactional information.

Phone number is used to notify customers about delivery and order status.

IP address and online identifiers are used to ensure the technical functioning, security and improvement of the online shop.

Cookies and analytics data (including Google Analytics) are used to analyse website usage, improve user experience and optimise the online shop.

Legal basis

The processing of personal data is necessary for the performance of a contract concluded with the customer (order management, delivery, returns and refunds).

Personal data is processed to comply with legal obligations (e.g. accounting and tax requirements).

The processing of personal data for maintaining purchase history, ensuring IT security and resolving disputes is based on the legitimate interest of the controller.

The legitimate interest of the controller includes ensuring the proper functioning and security of the online shop, preventing fraud, and protecting legal claims.

A legitimate interest assessment has been carried out in accordance with Article 6(1)(f) of the GDPR, including balancing the interests of the controller and the rights of data subjects. To access this assessment, please contact info@polgent.ee.

Cookies and analytics data (including Google Analytics) are processed based on the user’s consent.

Recipients of personal data

Personal data is shared with the following recipients:

  • payment service provider Montonio Finance UAB for processing payments;
  • delivery service provider DPD Eesti AS for delivering goods to the customer;
  • hosting and IT service provider Zone Media OÜ for ensuring the functionality and data storage of the online shop;
  • analytics service provider Google LLC (Google Analytics) for analysing website usage.

Security and access to data

Personal data are stored in the servers of Zone Media OÜ, which are located on the territory of a member state of the European Union or states of the European Economic Area. Data may be forwarded to states whose level of data protection is sufficient according to the European Commission or to a company of a third state to which a safeguard specified in articles 46 or 47 or in subsection 49 (1) of the GDPR has been applied.

Personal data can be accessed by the staff of the online shop in order to resolve technical issues related to the use of the online shop and to provide customer support.

The online shop applies the relevant physical, organisational and IT security measures in order to protect personal data from accidental or unlawful destruction, loss, amendment or unauthorised access and disclosure. These measures are:

  • data transmission is encrypted using HTTPS;
  • access to personal data is restricted to authorised users;
  • servers are protected by firewall and security monitoring;
  • regular backups are ensured by the hosting provider;
  • software and systems are regularly updated.

Personal data are forwarded to processors (e.g. the transport service provider and data hosts) on the basis of contracts between the online shop and processors. Upon processing data, the processors are obliged to ensure the relevant safeguards in accordance with article 28 of the GDPR.

Access to and rectification of personal data

Personal data can be accessed and rectified via the online shop’s user profile or customer support.

If a purchase is made without a user account, personal data can be accessed via customer support.

If the request to access personal data has been submitted electronically, the information will also be provided via commonly used electronic means.

Withdrawal of consent

If personal data are processed with the customer’s consent, the customer has the right to withdraw

their consent by making relevant changes in the user account’s settings or by notifying customer

support via e-mail.

Storage

Personal data are erased upon deleting the online shop’s customer account, except for the personal data (purchase history) which are necessary for accounting or to resolve consumer disputes.

In the event of disputes regarding payments and consumer disputes, personal data are stored until the claim is settled or the limitation period expires.

The personal data in original accounting documents is stored for seven years.

Restriction

If the data are incorrect, incomplete or processed unlawfully, the customer has the right to request the restriction of the processing of their personal data.

Objections

The customer has the right to submit objections regarding the processing of their personal data if they have a reason to believe that there is no legal basis to process their personal data.

Erasure

For the erasure of personal data, customer support should be contacted by e-mail. Requests for erasure are responded to within one month and the period of erasure is specified. The response to the request will also indicate which personal data will not be erased, on which legal basis and why.

Transfer

Requests to transfer personal data submitted via e-mail are responded to within one month.

Customer support identifies the person and indicates which personal data is to be transferred.

Direct marketing messages

The e-mail address and telephone number are used to send direct marketing messages if the customer has consented to receiving such messages. If the customer does not wish to receive direct marketing messages, they should select the relevant link at the footer of the e-mail or contact customer support.

Where personal data are processed for direct marketing purposes (profiling), the customer has the right to object at any time both to the initial and further processing of their personal data, including profiling related to direct marketing, by notifying customer support thereof via e-mail.

Resolution of disputes

Disputes concerning the processing of personal data are settled through customer support (info@polgent.ee, phone +372 6556 995). The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).

Login

From your account you can view your recent orders, manage your shipping and billing addresses, and edit your password and account details.