Effective as of April 26, 2021
ARTICLE 1: PREAMBLE
- How their personal data is collected and processed. All data that can identify a user shall be considered as personal data. This includes the first and last name, age, postal address, e-mail address, location of the user or his IP address;
- What are the users' rights concerning this data?
- Who is responsible for processing the personal data collected and processed?
- To whom this data is transmitted;
- The site's policy regarding "cookies".
It also complements the General Terms and Conditions of Sale thatbuyers can consult at the following address
ARTICLE 2: GENERAL PRINCIPLES REGARDING DATA COLLECTION AND PROCESSING
In accordance with the provisions of Article 5 of the European Regulation 2016/679, the collection and processing of data of the users of the site respect the following principles:
- Lawfulness, fairness and transparency: data may only be collected and processed with the consent of the user who owns the data. Whenever personal data is collected, the user will be informed that his/her data is being collected and for what purpose it is being collected;
- Minimisation of data collection and processing: only the data necessary for the proper execution of the purposes pursued by the site are collected;
- Conservation of data reduced in time: the data is kept for a limited period, of which the user is informed. When this information cannot be communicated, the user is informed of the criteria used to determine the duration of conservation;
- Integrity and confidentiality of collected and processed data: the data controller undertakes to guarantee the integrity and confidentiality of the data collected.
In order to be lawful, and in accordance with the requirements of Article 6 of the European Regulation 2016/679, the collection and processing of personal data may only take place if they comply with at least one of the conditions listed below:
- The user has expressly consented to the processing ;
- The processing is necessary for the proper performance of a contract;
- The processing is required by law;
- The processing is necessary to protect the vital interests of the data subject or another natural person;
- Processing may be necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
- The processing and collection of personal data is necessary for the purposes of the legitimate and private interests pursued by the controller or by a third party.
ARTICLE 3: PERSONAL DATA COLLECTED AND PROCESSED IN THE CONTEXT OF NAVIGATION ON THE SITE
A. DATA COLLECTED AND PROCESSED AND METHOD OF COLLECTION
The personal data collected on TheNailsAngels website are the following: Names, surnames, postal address, telephone number and e-mail address, payment method information (if applicable).
This data is collected when the User performs any of the following operations on the site:
- When the User purchases a product on the site;
- When the User uses the contact form to send a request;
- When the User posts a review of a product;
- When the User registers for a customer account;
- When the User registers for the Ambassador program.
Furthermore, when a payment is made on the site, proof of the transaction, including the order form and the invoice, will be kept in the computer systems of the site editor.
The person in charge of processing will keep all the data collected in the site's computer systems under reasonable security conditions for a period of :
- Accounting data: 10 years
- Contractual and commercial documents: 3 years
- Cookies for the analysis of visits: 13 months.
The collection and processing of data meet the following purposes:
- Processing of orders, shipping of packages;
- Response to requests sent through the contact form;
- Publication of the opinions of the customers wishing it;
- Setting up an Ambassador contract;
- Personalization of the customer experience.
The data processing carried out is based on the following legal grounds:
- Contract fulfilment;
- Consent of the user;
- Legal obligations.
B. TRANSMISSION OF DATA TO THIRD PARTIES
Data may be passed on to the following third parties:
- Transport providers;
- The providers of payment institutions;
- The accounting service provider;
- The provider of logistic preparation of order;
- IT service providers for automated data processing.
C. DATA HOSTING
TheNailsAngels website is hosted by: Google LLC (on behalf of the e-commerce platform provider Shopify Inc.), whose headquarters are located at the following address: 1600 Amphitheatre Parkway, Mountain View, CA 94043, USA.
The host can be contacted at the following telephone number: +1 650 253 0000.
The data collected and processed by the site is transferred to the following countries: Estonia, France, USA and Canada.
This transfer of personal data outside the European Union is justified by the following reasons:
As the customers are present all over the world, the data is hosted in the cloud on computer servers distributed in several countries of the world in order to guarantee a fast and secure service to all.
ARTICLE 4: DATA CONTROLLER
A. THE DATA CONTROLLER
The person in charge of processing personal data is TheNailsAngels OÜ.
He can be contacted in the following way:
By contacting the customer service by email at firstname.lastname@example.org.
The data controller is responsible for determining the purposes and means used to process personal data.
B. OBLIGATIONS OF THE DATA CONTROLLER
The data controller undertakes to protect the personal data collected, not to transmit them to third parties without the user's knowledge and to respect the purposes for which the data were collected.
The site has an SSL certificate to ensure that the information and data transfer through the site is secure.
The purpose of an SSL certificate ("Secure Socket Layer" Certificate) is to secure the data exchanged between the user and the site.
In addition, the data controller undertakes to notify the user in the event of rectification or deletion of the data, unless this would entail disproportionate formalities, costs and steps for the user.
In the event that the integrity, confidentiality or security of the user's personal data is compromised, the data controller undertakes to inform the user by any means.
ARTICLE 5: USER'S RIGHTS
In accordance with the regulations concerning the processing of personal data, the user has the rights listed below.
In order for the data controller to comply with the user's request, the user is obliged to provide the following information: first and last name, e-mail address and, if relevant, account number or personal space or subscriber number.
The data controller is obliged to respond to the user within a maximum of 30 (thirty) days.
A. PRESENTATION OF THE USER'S RIGHTS REGARDING DATA COLLECTION AND PROCESSING
a. Right of access, rectification and deletion
The user may access, update, modify or request the deletion of data concerning him/her, by following the procedure set out below:
The user must send an email to the customer service, specifying the subject of his request, to the email address email@example.com. The user can also use the "Privacy Settings" page on the site to guide him/her in his/her efforts.
If he/she has one, the user has the right to request the deletion of his/her personal space by following the procedure below:
The user must send an email to the customer service, specifying the subject of his request, to the email address firstname.lastname@example.org. The user can also use the "Privacy Settings" page on the site to guide him/her in this process.
b. Right to data portability
The user has the right to request the portability of his personal data, held by the site, to another site, by complying with the following procedure:
The user must send an email to the customer service, specifying the subject of his request, to the email address email@example.com. The user may also use the "Privacy Settings" page on the site to guide him/her in this process.
c. Right to limit and oppose data processing
The user has the right to request the limitation of or to oppose the processing of his/her data by the site, without the site being able to refuse, unless he/she can demonstrate the existence of legitimate and compelling reasons, which can prevail over the interests and rights and freedoms of the user.
In order to request the limitation of the processing of his/her data or to formulate an opposition to the processing of his/her data, the user must follow the following procedure:
The user must send an email to the customer service, specifying the subject of the request, to the email address firstname.lastname@example.org. The user can also use the "Privacy Settings" page on the site to guide him/her in his/her request.
d. Right not to be subject to a decision based exclusively on an automated process
In accordance with the provisions of Regulation 2016/679, the user has the right not to be subject to a decision based exclusively on an automated process if the decision produces legal effects concerning him or her, or significantly affects him or her in a similar way.
e. Right to determine the fate of data after death
The user is reminded that he/she can arrange what should happen to his/her collected and processed data if he/she dies, in accordance with the legislation in force.
f. Right to refer to the competent supervisory authority
In the event that the data controller decides not to respond to the user's request, and the user wishes to contest this decision, or if he/she believes that one of the rights listed above has been infringed, he/she is entitled to refer the matter to the competent authority in his/her country of residence.
ARTICLE 6: USE OF "COOKIES" FILES
The site may use "cookies" techniques.
A "cookie" is a small file (less than 4 kb), stored by the site on the user's hard disk, containing information about the user's browsing habits.
These files allow the site to process statistics and information on traffic, to facilitate navigation and to improve the service for the user's comfort.
For the use of "cookies" files involving the storage and analysis of personal data, the user's consent is necessarily requested.
This consent of the user is considered valid for a maximum period of 6 (six) months. At the end of this period, the site will again request the user's permission to save "cookies" files on his or her hard drive.
a. Opposition of the user to the use of "cookies" files by the site
Cookies that are not essential to the operation of the site are only deposited on the user's terminal after obtaining his consent. The user can withdraw his consent at any time, as follows:
The "Privacy settings" page accessible from all pages of the site allows the user to withdraw his consent.
More generally, the user is informed that he/she can oppose the recording of these "cookies" by configuring his/her browser.
For information, the user can find at the following addresses the steps to follow in order to configure his browser software to oppose the recording of "cookies" files:
- Chrome: https://support.google.com/accounts/answer/61416?hl=fr
- Firefox: https://support.mozilla.org/fr/kb/enable-and-disable-cookies-website-preferences
- Safari: http://www.apple.com/legal/privacy/fr-ww/
- Internet Explorer : https://support.microsoft.com/fr-fr/help/17442/windows-internet-explorer-delete-manage-cookies
- Opera : http://www.opera.com/help/tutorials/security/cookies/
In the event that the user decides to deactivate the "cookies" files, he/she will be able to continue browsing the site. However, any malfunction of the site caused by this manipulation could not be considered as being due to the site editor.
b. Description of the "cookies" files used by the site
The site editor draws the user's attention to the fact that the following cookies are used during navigation.
Strictly necessary cookies:
These cookies are essential to enable you to move around the website and use its features, such as accessing secure areas of the website. Without these cookies, the services you have requested, such as shopping carts or electronic billing, cannot be provided.
Strictly necessary cookies set by Shopify for the operation of the store:
Cart, Secret, Secure_customer_sig, _ab, _pay_session, _secure_session_id, _shopify_country, _shopify_m, _shopify_tm, _shopify_tw, _storefront_u, _tracking_consent, cart, cart_currency, cart_sig, cart_ts, cart_ver, checkout, checkout_token, cookietest, master_device_id, previous_checkout_token, previous_step, remember_mehopify_pay_redirect, storefront_digest, tracked_start_checkout
These cookies collect information about how visitors use a website, such as which pages visitors visit most often and whether they receive web page error messages. These cookies do not collect information that can identify a visitor. All information collected by these cookies is aggregated and therefore anonymous. It is only used to improve the functioning of a website.
Performance cookies set by Shopify for the operation of the store:
_landing_page, _orig_referrer, _shopify_fs, _shopify_s, _shopify_sa_p, _shopify_sa_t,_shopify_y
Cookiesperformanceset by Google Analytics:
_ga, _gat, _gid
These cookies are used to serve ads that are more relevant to you and your interests. They are also used to limit the number of times you see an ad and to help measure the effectiveness of the ad campaign. They are usually placed by ad networks with the permission of the website operator. They remember that you have visited a website and this information is shared with other organisations such as advertisers. Very often, targeting or advertising cookies will be linked to the site features provided by the other organisation.
Targeting cookies set by Shopify:
_s, _shopify_d, _y
Targeting cookies set by Facebook:
When browsing the site, the user is informed that third-party cookies may be stored.
More specifically, these are the following third parties: Shopify, Facebook, Google, PayPal, Stripe.
In addition, the site integrates social network buttons, allowing the user to share his activity on the site. Cookies from these social networks may therefore be stored on the user's computer when they use these features.
The user's attention is drawn to the fact that these sites have their own confidentiality policies and general conditions of use that may differ from the site. The site editor invites users to consult the privacy policies and general conditions of use of these sites.
The site editor reserves the right to modify it in order to guarantee its conformity with the law in force.