Privacy policy

Personal data use

The responsible data handler of the XFIRE.EE e-store is Xfire Ilutulestik OÜ company (registration number: 14357020), location: Punane 16 and Email address: info@xfire.ee. The responsible handler appointed a data protection specialist, whose contact details are: tel .: 5888 8807 and Email: aleksandra@xfire.ee

How personal data is handled

– name, phone number, and an Email address;
– delivery address;
– Bank account number;
– the cost of goods and services and data related to payments (purchase history);
– data necessary to support customers.

What is the purpose of personal data processing

Personal data is used to manage customer orders and to deliver goods.

Purchase history data (purchase date, product, quantity, customer data) is used to create an overview of purchased goods and services, as well as to analyze customer preferences.

The bank account number is used to return money to the customer.

Personal data such as an Email address, phone number, customer name are handled to resolve issues related to goods and services (customer support).

The IP address of the user of the e-store or other network identifiers are handled to provide services by the e-store as a part of the information society, as well as to conduct statistics on the use of the Internet.

Legal basis

Personal data processing is carried out in order to fulfill the contract of sale concluded with the customer.

The personal data processing is carried out to fulfill a legal obligation (for example, accounting and resolution of consumer disputes).

Hosts to whom personal data is transferred

Personal data is transferred to the customer support service of the e-store to manage purchases and purchase history and to resolve customer problems.

The name, phone number and Email address are provided to the transport service company chosen by the customer. If we are talking about the goods delivered by the courier, then in addition to the contact of sale details, the address of the customer is also transferred.

If the accounting of the e-store is maintained by the provider of the corresponding service, then personal data is transferred to the provider of the corresponding service for conducting accounting operations.

Personal data may be transferred to information technology service providers, if necessary to ensure the functionality of the e-store or data storage.

Security and data access

Personal data is stored on ZONE.EE servers located on the territory of a Member State of the European Union or countries that have joined the European Economic Area. Data can be transferred to countries where the European Commission rated the data protection level as sufficient, as well as to the US companies that have joined the general concept of a “data shield” (Privacy Shield).

The associates of the e-store have access to personal data. They can review personal data in order to solve technical issues related to using the e-store and provide customer support services.

The e-store uses appropriate physical, organizational and information technology security measures to protect personal data from accidental or illegal destruction, loss, alteration or unauthorized access and disclosure.

The transfer of personal data to authorized handlers of the e-store (for example, a transport service company and data storage) is carried out based on agreements concluded with the e-store and authorized handlers. When processing personal data, authorized handlers are required to provide appropriate security measures.

Reviewing of personal data and making corrections

You can review personal data and make corrections to it in the user profile of the e-store. If the purchase is made without creating a user account, you can review personal data by contacting customer support.

Revocation of consent

If the processing of personal data is carried out based on the consent of the customer, then the customer has the right to withdraw consent by informing the customer support service by Email.

Storage

When a customer account is closed in the e-store, personal data is deleted, unless it is necessary to save such data for accounting or the resolution of consumer disputes.

If a purchase in the e-store is completed without creating a customer account, the purchase history is stored for three years.

In case of disputes related to payments and consumer claims, personal data is stored until the relevant requirement is met, or until the expiration of the period on demand.

Personal data required for accounting is stored for seven years.

Disposal

To delete personal data, please contact customer support by Email. A response to the disposal application is sent no later than within a month, and the period of data disposal is also specified.

Transfer

The response to the application for the transfer of personal data submitted by Email is sent no later than within a month. Customer support verifies the identity and reports the transfer of personal data.

Direct Marketing Messages
The Email address and phone number are used to send messages as part of direct marketing, if the customer has given the appropriate consent. If the customer does not want to receive messages as part of direct marketing, then you should click on the appropriate link at the bottom of the Email or contact customer support.
If personal data is handled for direct marketing purposes (profiling), the customer has the right to object to both the initial and subsequent processing of his data at any time, including the profile analysis related to direct marketing. For this it is necessary to inform the service customer support Email.

Disputes resolution

Disputes related to the processing of personal data are resolved through the customer support service by Email aleksandra@xfire.ee. The supervisor is the Estonian Data Protection Inspectorate (info@aki.ee).