Политика конфиденциальности компании
SLet Europe OÜ (hereinafter - “we”, "our", “us”, “SLet”) is an Estonian company that operates the website https://starsletter.com/ (hereinafter - the “Website”) that allows its Customers to order gifts (the letters of congratulation with a copy of certain celebrities’ signature) for their entourages (including the delivery of such gifts), know more about our services and to contact us.
We adhere to the following principles in order to protect your privacy:
- principle of purposefulness - we process Personal Data fairly and in a transparent manner only, aiming to achieve determined and lawful objectives, and they shall not be processed in a manner not conforming to the objectives of data processing;
- principle of minimalism - we collect Personal Data only to the extent necessary to achieve determined purposes. We do not keep Personal Data if it is no longer needed;
- principle of restricted use - we use Personal Data for all other purposes only with the consent of the data subject or if permitted by a competent authority;
- principle of data quality - we always keep Personal Data up-to-date and complete in order to achieve the end purpose of the data processing more efficiently;
- principle of security - security measures shall be applied in order to protect Personal Data from unauthorised or unlawful processing and against accidental loss, destruction or damage, using appropriate technical and organisational measures;
- principle of individual participation - our Customers and Visitors shall be notified of their data collected. They shall be granted access to their Personal Data and have the right to demand a correction of inaccurate or misleading data.
1. Data we collect and purposes of data processing
1.1. Website Visitors
1.1.1. We may collect, record and analyze information of Visitors of our Website.
Where our Website is accessed purely to gain information, i.e. where you do not provide us information in any way, we only collect the personal data provided by your browser to our server. Where you want to view our website, we collect the following data (hereinafter - “Usage Data”) necessary for technical purposes to be able to demonstrate our Website to you and to ensure adequate access stability and security (therefore, the legal basis for is the legitimate interest of SLet):
- IP address;
- Enquiry date and time;
- Time zone difference to Greenwich Mean Time (GMT);
- Enquiry content (the exact web page accessed);
- Access status/HTTP status code;
- Data volume transmitted in each case;
- Website generating the enquiry;
- OS and its interface;
- Browser language and version.
1.1.2. We use this information in aggregate to assess the popularity of the web pages on our Website and how we perform in providing content to you. When combined with other information we know about you from previous visits, the data could possibly be used to identify you personally, even if you didn’t provided any information to us. We use Google Analytics, Facebook pixel, Google Tag Manager to analyze data. Information collected this way is stored for no longer than one year.
1.1.3. Processing of Usage Data is relied on our legitimate interests. It is necessary for managing and running our business efficiently and effectively, providing quality services including website support, developing and improving products, determining who may be interested in them.
1.1.4. Our Website allows you to contact us by using the contact form. To do so, you need to provide your name, email address, as well as the text of your inquiry. We use the collected Personal Data only to communicate with you, as you reasonably expect us to answer you, and we may also record your request and our reply in order to increase the efficiency of the organisation of our support service.
1.1.5. We collect email address and data of Visitor’s user profile in instant messaging applications (e.g. name, nickname, phone number) only when Visitor wants to contact us and writes us on our email address that is available on the Website or communicates with us via instant messaging applications, that are listed on our Website. We use the collected Personal Data only to communicate with you, as you reasonably expect us to answer you.
1.1.6. While processing Personal Data of our Visitors, we rely on your consent to the processing of your Personal Data for the purpose of communicating with you. We use such Personal Data in ways you would reasonably expect and which have a minimal privacy impact. You can withdraw your consent at any time by sending us an email to email@example.com with your withdrawal request and your Personal Data will be deleted within seventy-two (72) hours.
1.1.7. Processing of Personal Data for marketing purposes is also relied on the consent obtained from you. We use data in ways you would reasonably expect and which have a minimal privacy impact.
1.2.1. In order to provide services to our Customers, we collect their personally identifiable information as well as personally identifiable information about the Addressees, provided by the Customers.
1.2.2. When the Customer uses our services by submitting an online order form on the Website, a contract is formed between the Customer and us. In order to carry out our obligations under that contract we must process the information that the Customer gives to us.
1.2.3. During the submission of an online order form on the Website, the Customer provides us with its first and last name. This information is used by us to identify our Customers and provide them with services and to meet other contractual obligations.
1.2.4. Also, the Customer provides us with the following information about the Addressee during the submission of an online order form on the Website:
188.8.131.52. Addressee’s first and last name;
184.108.40.206. Addressee’s gender;
220.127.116.11. Addressee’s date of birth or approximate age;
18.104.22.168. Addressee’s address, to which the letter of congratulation shall be delivered.
This information is used by us to identify Addressees, to personalize the letters of congratulations for them and to deliver such letters to them (including forwarding this information to the post or courier companies to organise and execute transportation and delivery).
We assume, that the Customer obtained Addressee's explicit consent for the sharing of its Personal Data. The Customer shall respect Addressee's privacy rights.
1.2.5. We may obtain Customers’ Personal Data from third parties such as payment service providers, whose services we use.
1.2.6. We process this information on the basis there is a contract between us and the Customer, we use the information before we enter into a legal contract.
1.2.7. At the point of payment, you are transferred to a secure page on the website of Fondy payment service provider.
1.2.8. Processing of Personal Data for marketing purposes is also relied on the consent obtained from you. This processing has appropriate safeguards and a minimal privacy impact. You can object to the processing by following the “unsubscribe” link you will find on all the email marketing messages we send you. Alternatively, you can contact us at firstname.lastname@example.org
1.2.9. If you no longer wish to receive promotional emails, you may opt out of them by replying to one of such emails or send us an email with a request.
2. Compliance with General Data Protection Regulation (GDPR)
2.1. For Visitors, Customers and Addressees located in the European Economic Area (EEA) privacy rights are granted and all processing of Personal Data is performed in accordance with regulations and rules of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, known as the General Data Protection Regulation (GDPR).
2.2. We process Personal Data as a Controller, as defined in the GDPR:
- SLet will be the Controller of Customer and Addressee Data, as outlined above in the “Customer” section.
- Also, SLet will be the Controller for Visitor Data, as outlined above in the “Visitor” section.
2.3. The processing and transfer of Personal Data is carried out in accordance with the requirements set out in regulations and rules of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, known as the General Data Protection Regulation (GDPR).
3. Your rights as a data subject
3.1. Visitors, Customers and Addressees can review, correct, update, delete or transfer their personally identifiable information. For that, contact us directly at email@example.com . We will acknowledge your request within seventy-two (72) hours and handle it promptly and as required by law.
3.2. Right to object to processing of your Personal Data. Visitors, Customers and Addressees have the right to object to the processing of their Personal Data by us.
3.3. Right to access to your Personal Data. Visitors, Customers and Addressees have the right to learn if Personal Data is being processed by Data Controller, obtain disclosure regarding certain aspects of the processing and obtain a copy of the Personal Data undergoing processing.
3.4. Right to verify and seek rectification. Visitors, Customers and Addressees have the right to verify the accuracy of their Personal Data and ask for it to be updated or corrected.
3.5. Right to restrict the processing of your Personal Data. Visitors, Customers and Addressees have the right, under certain circumstances, to restrict the processing of their Personal Data. In this case, Data Controller will not process their Personal Data for any purpose other than storing it.
3.6. Right to have your Personal Data deleted or otherwise removed. Visitors, Customers and Addressees have the right, under certain circumstances, to obtain the erasure of their Personal Data from Data Controller.
3.7. Right to receive your Personal Data and have it transferred to another controller. Visitors, Customers and Addressees have the right to receive their Personal Data in a structured, commonly used and machine-readable format and, if technically feasible, to have it transmitted to another controller without any hindrance.
3.8. You can withdraw your consent at any time by replying to the email with your withdrawal request and your Personal Data will be deleted within seventy-two (72) hours.
3.9. Also, you have the right to lodge a complaint with a supervisory authority if you think that we violate your rights. But we kindly ask you to contact us first so that we can help you.
3.10. When we receive any request to access, edit or delete personally identifiable information, we shall first take reasonable steps to verify your identity before granting you access or otherwise taking any action. This is important to safeguard your information.
4. Promotional offers, newsletters or marketing communications from us
4.1. We deliver marketing and event communications to Customers and Visitors across various platforms such as email, text messaging and online. Where required by law, we will ask you to explicitly opt in to receive marketing from us. If we send you a marketing communication it will include instructions on how to opt out of receiving these communications in the future.
4.2. We may use your data to form a view on what we think you may want or need, or what may be of interest to you. This is how we decide which products, services and offers may be relevant for you (we call this marketing).
4.3. You will receive marketing communications, newsletters, and other news and information about our services from us if you have requested information from us or purchased services from us or if you provided us with your details when you contacted us and explicitly opted in to receive such information.
4.4. We may send the following commercial communications by email to a targeted selection of individuals from our marketing database: invitations to industry events we are hosting or attending; newsletters; industry updates; updates about our company and the services we offer; other information that we reasonably think may be interesting to our Customers and Visitors.
4.5. We may also inform you of products or services available from carefully selected partners. We may also contact you via surveys to conduct research about your opinion of our services.
4.6. We do not give or provide in any way Customer and Visitor lists to third parties, except as set forth hereunder.
5. Data Retention
5.1. Personal Data shall be processed and stored only for as long as required for the purpose they have been collected for.
5.3. Information obtained via contact forms is deleted on an annual basis. Your information will be deleted if you did not communicate with the support team for more than twelve (12) months.
5.4. Any Usage Data collected for the purpose of analytics will be deleted in not more than twelve (12) months after being collected.
5.5. Once the retention period expires, Personal Data shall be deleted. Therefore, the right to access, the right to erasure, the right to rectification and the right to Personal Data portability cannot be enforced after expiration of the retention period.
6.1. We work with third party service providers which provide website development, hosting, maintenance, sending emails, marketing, technical support and assistance, IT and cyber security services, customer service and other services for us. These contractors may have access to, or process Personal Data on behalf of us, as part of providing those services to us. We limit the information provided to these service providers to the extent it is reasonably necessary for them to perform their functions.
6.6. We may need to share your Personal Data with the third parties that provide those services. Where your Personal Data are transferred outside of the European Economic Area (“EEA”), we require that appropriate safeguards are in place.
6.7. We guarantee that we have Data Processing Agreements in place with our service providers, ensuring compliance with the GDPR and our contracts with them requiring to maintain the confidentiality of Personal Data. All data transfers inside and outside of the EEA are being done in accordance with these Data Processing Agreements. All data transfers are performed in accordance with the strictest security regulations.
6.8. For more detailed information about the international information transfers to our business partners, service providers and developers outside of the EU/EEA, please contact us using the details given in the “Contact us” section below.
7. Information Security
7.1. We care to ensure the security of your Personal Data. We follow generally accepted industry standards to protect the information submitted to us, both during transmission and once we receive it. We maintain technical, physical, and administrative security measures to provide reasonable protection for your Personal Data. When we process your information, we also make sure that your information is protected from unauthorized access, loss, manipulation, falsification, destruction or unauthorized disclosure. This is done through appropriate administrative, technical and physical measures.
7.2. There is no 100% secure method of transmission over the Internet or electronic storage. We, therefore, cannot guarantee its absolute security.
7.3. We never process any kind of sensitive data and/or criminal offense data. Also, we never undertake profiling of Personal Data.
8. Use of site by children
8.1. We do not provide services to children. Visitors and Customers declare themselves to be adult according to their applicable legislation.
8.2. Our Website and services are not directed to persons under the age of 16. Minors may use our Website only with the assistance of a parent or guardian. Under no circumstances persons under the age of 13 may use the Website.
8.3. We collect data about all Customers, Addressees and Visitors without verification of their age. We do not anticipate that some of those Customers, Addressees and Visitors will be children.
8.4. Customers shall not provide us with any Personal Data of children, therefore a Customer shall not choose a child as an Addressee.
10. Acceptance of these Conditions
Policy, you should refrain from using our website.
12. Contact us!
12.1. If you have any questions about the practices of this website or your dealings with this website, please contact us at firstname.lastname@example.org
SLet Europe OÜ
registry code: 14965304
registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Narva mnt 7-634, 10117