Personal data protection and processing policy
- GENERAL PROVISIONS
- 1.1. The Policy on the Protection and Processing of Personal Data is compiled in accordance with the requirements of the Law "On the Protection of Personal Data" and defines the procedure for processing personal data and measures to ensure the security of personal data in the online store curlgirl.shop (hereinafter referred to as the Policy).
- 1.2. The online store curlgirl.shop (hereinafter referred to as the Online Store) sets the most important goal and condition for carrying out its activities as the observance of the rights and freedoms of a person and a citizen when processing their personal data, including the protection of the rights to privacy, personal and family secrets.
- 1.3. The Policy defines the requirements of the Online Store for the processing and the procedure for ensuring the protection of personal data of personal data subjects at all stages of their processing, including through organizational and technical measures.
- 1.4. The Policy applies to an unspecified range of persons - personal data subjects who enter or may enter into any relationship with the Online Store.
- DEFINITIONS OF TERMS AND ABBREVIATIONS
- 2.1. Owner of personal data - Online store
- INThe owner of personal data determines the purpose of processing personal data, establishes the composition of these data and the procedures for their processing, unless otherwise provided by law.
- 2.2. Consent of the personal data subject is a voluntary expression of the will of an individual (provided that he is informed) to grant permission for the processing of his personal data in accordance with the formulated purpose of their processing, expressed in writing or in a form that allows to conclude that consent has been granted. In the field of e-commerce, the consent of the personal data subject may be granted during registration in the information and communication system of the e-commerce subject by marking a mark on granting permission for the processing of his personal data in accordance with the formulated purpose of their processing, provided that such system does not create opportunities for the processing of personal data until the mark is marked. In addition, consent to the processing of personal data may be granted by:
- the Client's accession to the Public Offer Agreement for the sale of goods and provision of services of the Online Store, by registering the Client on the Site or by confirming the order on the Site (including, but not limited to, by clicking the "Place an order" or "Pay for the order" button),
- by the Counterparty concluding a relevant transaction with the Online Store;
- by the User participating in a relevant survey conducted by the Online Store or its partners;
- by the Employee signing a consent to the processing of personal data (application for employment, etc.);
- by providing the User with documents/information containing personal data, in case the User intends to conclude a relevant transaction/employment contract with the Online Store.
- 2.3. Personal data (hereinafter referred to as PD) – information or a set of information about an individual who is identified or can be specifically identified.
- 2.4. Client – a personal data subject (an individual or a representative of such a person) who is a consumer of goods/services provided by the Online Store and whose personal data is processed by the Online Store, as well as any visitor who has registered on the website of the Online Store curlgirl.shop or has provided the Consent of the Personal Data Subject.
- 2.5. Counterparty – a subject of personal data (an individual, an individual entrepreneur, a representative of a legal entity, individuals without the status of a business entity) who acts in civil and economic relations with the Online Store.
- 2.6. Users – Clients, Counterparties and Employees when collectively referred to in the text of the Policy.
- 2.7. Processing of personal data – any action or set of actions, such as collection, registration, accumulation, storage, adaptation, modification, renewal, use and dissemination (dissemination, sale, transfer), depersonalization, destruction of personal data, including using information (automated) systems.
- 2.8. Employee – an individual who directly performs a labor function by his own labor in accordance with an employment agreement (contract) concluded with the Online Store or intends to enter into an employment relationship (provides his personal data for the purpose of employment, as a response to the Online Store's information about available vacancies)
- 2.9. Personal data processor - a natural or legal person who is granted the right by the personal data controller or by law to process this data on behalf of the controller.
- 2.10. Site - the curlgirl.shop website, located on the Internet.
- 2.11. Personal data subject - an individual whose personal data is processed.
- 2.12 Third party - any person, except for the Subject of personal data, the owner or manager of personal data and the Commissioner of the Verkhovna Rada of Ukraine for Human Rights (hereinafter referred to as the Commissioner), to whom the Online Store or the manager of personal data transfers personal data.
- MAIN PART
- 3.1. Processing of personal data in the online store.
- 3.1.1 The Online Store is the owner of personal data, and in cases provided for by the current legislation of Ukraine and/or on the basis of concluded agreements, the Online Store is the manager of personal data.
- 3.1.2 The procedure for processing personal data in the Online Store is determined by this Policy based on the current legislation of Ukraine.
- 3.1.3 The online store processes personal data - any action or set of actions performed with personal data, including collection, systematization, storage, modification, use, depersonalization, blocking, distribution, provision, deletion of personal data.
- 3.1.4 The Online Store will take all necessary measures to ensure that Users' personal data will be processed securely and in accordance with this Policy, and will not be transferred to a third party until it provides appropriate controls for the protection of personal data.
- 3.1.5 The primary sources of information about an individual are: documents issued in their name, documents signed by them, information that the individual provides about themselves.
- 3.1.6 Personal data processing processes are part of the business processes of the Online Store. Personal data processing processes can be automated or non-automated.
- 3.1.7 The online store may entrust the processing of personal data to a personal data controller in accordance with a written agreement. The personal data controller may process personal data only for the purpose and to the extent specified in the agreement.
- 3.1.8 The online store does not process personal data revealing racial or ethnic origin, political, religious or ideological beliefs, membership in political parties and professional unions, criminal convictions, as well as data relating to sex life, biometric or genetic data.
- 3.1.9 User data is collected and processed exclusively on the territory of Ukraine and in accordance with the current legislation of Ukraine.
- 3.1.10 The period of processing personal data is set by the Online Store depending on the category of Personal Data Subjects, the purpose of personal data processing and is determined by the current legislation of Ukraine.
- 3.1.11 The grounds for processing personal data are:
- consent of the Personal Data Subject to the processing of his/her personal data.
- permission to process personal data granted to the personal data controller in accordance with the law solely for the exercise of his powers;
- conclusion and performance of a transaction to which the Personal Data Subject is a party or which is concluded for the benefit of the Personal Data Subject or for the implementation of measures preceding the conclusion of a transaction at the request of the Personal Data Subject;
- protection of the vital interests of the Personal Data Subject;
- the need to fulfill the obligation of the Owner of personal data, which is provided for by law;
- the need to protect the legitimate interests of the Owner of personal data or a third party to whom the personal data are transferred, except in cases where the needs to protect the fundamental rights and freedoms of the Personal Data Subject in connection with the processing of their data prevail over such interests.
- 3.1.12 The Online Store shall notify the Subject of Personal Data of the transfer of personal data to a third party within ten business days, except in the following cases:
- transfer of personal data upon request when performing tasks of operational-search or counterintelligence activities, combating terrorism;
- execution by state authorities and local self-government bodies of their powers stipulated by law;
- processing of personal data for historical, statistical or scientific purposes;
- going to court to protect your rights;
- the possibility of transferring personal data to third parties is provided for by the terms of the transaction concluded between the Online Store and the Subject of personal data
- transfer of personal data in other cases specified in clause 3.4. of this Policy.
- 3.1.13 Personal data being processed shall be destroyed or depersonalized after the purposes of processing are achieved or in the event of the loss of necessity for achieving these purposes, unless otherwise provided for by the legislation in force in Ukraine.
- 3.2 Personal data of Users received and processed by the Online Store.
- 3.2.1 In order to carry out its activities and fulfill its obligations, the Online Store processes the personal data of the Personal Data Subject provided by him during registration on the website (Internet resource) of the Online Store or provided in another way.
- 3.2.2 Personal data of Users may include, but is not limited to, the following:
- last name, first name, patronymic (if available),
- date of birth and/or age,
- become,
- marital status,
- passport data and registration number of the taxpayer's registration card,
- email address,
- phone number,
- residential address (delivery),
- date of birth,
- information necessary for communication between Users and the Online Store,
- data obtained as a result of conducting various surveys by the Online Store and/or third parties authorized by the Online Store, in order to improve the efficiency of the Online Store's communication with Users;
- information obtained by the online store as a result of marketing activities;
- information obtained by the Online Store in a lawful manner from partners and/or third parties;
- other information, the purpose of processing which coincides with the purpose of processing personal data, and which will be provided by the User independently or received by the Online Store in the process of conducting its activities.
- 3.2.2.1 In addition to what is stated in clause 3.2.2. of the Policy, the Online Store processes the following Personal Data of the “Customers” category:
- list and status of orders from the profile on the Site,
- information (including photos) posted in the profile and in reviews / comments on the Site, requests to customer support, complaints, claims, other requests
- cookies and data about the use of the Site,
- data for making calculations,
- delivery branch numbers,
- processing data (login in the form of a phone number or email address and password in encrypted form),
- information posted or provided by the Client during their participation in bonus programs, quizzes, promotions, special offers that take place on the Site, the organizer of which is the Online Store,
- 3.2.2.2 In addition to what is stated in clause 3.2.2. of the Policy, the Online Store processes the following Personal Data of the “Employees” category:
- data received by the online store from job candidates;
- the registration number of the taxpayer's registration card or information about the refusal to obtain such a number;
- data of the identity document, in particular, copies of documents in paper and/or electronic form;
- place of registration, place of permanent residence or temporary stay;
- family composition and number of dependents, surnames, first names, patronymics of such persons, their gender, age, place of registration and residence, contact details;
- profession, specialization, qualification class;
- work experience and places of work;
- attitude to military duty;
- education (including academic degrees, advanced training courses, etc.), language skills;
- possession of driving licenses and driving experience;
- positions held;
- images (photos, videos) and sound recordings made by the employer during the performance of work duties;
- address of the workplace;
- the amount of basic and additional wages, bonuses, bonuses, other income;
- sample personal signature;
- bank account details.
- 3.2.2.3 In addition to what is stated in clause 3.2.2. of the Policy, the Online Store processes the following Personal Data of the “Counterparties” category:
- data received by the Online Store from potential counterparties who intend to conclude civil and commercial contracts with the Online Store;
- the registration number of the taxpayer's registration card or information about the refusal to obtain such a number;
- place of registration, place of permanent residence or temporary stay;
- data of the identity document, in particular, copies of documents in paper and/or electronic form;
- sample personal signature;
- data on the registration of the entity as an individual entrepreneur;
- contact persons, for communications within the framework of fulfilling the terms of the concluded transactions (surnames, first names, patronymics of such persons, telephone numbers, email address);
- bank details;
- 3.2.2.4 Data that is automatically transmitted to the Online Store during its use using the software installed on the device, including cookie information, information about the User's device:
- the Internet Protocol address of the User's computer (e.g., IP address);
- browser type, browser version;
- service pages, time of visit by the User, time spent on these pages;
- unique device identifiers and other diagnostic data, mobile device type, mobile device IP address, mobile operating system, mobile internet browser type;
- cookies and other data from these files
- The information that the Online Store collects includes data, for example, on the number of Users who have visited the Site, the pages that have been visited, data on whether the User has visited the Online Store services before, and helps the Online Store determine the services in which the User is most interested. This data also gives the Online Store the opportunity to improve and expand the User's experience. The Online Store uses cookie data (cookies) and similar tracking technologies to track activity and store information. Cookies are small amounts of data that may include an anonymous unique identifier. Cookies are sent to the browser from the website and stored on the User's device. Tracking technologies that are also used are beacons, tags and scripts to collect and track information, as well as to improve the services. The User can refuse all cookies (by changing the browser settings). By refusing to use cookies, the User agrees that some parts (functions) of the services may not be available to him/her for use.
- 3.3 Purpose and legal basis for collecting and processing Personal Data
- 3.3.1 Depending on how Users interact with the Online Store, the scope, method, purpose and legal grounds for the collection and processing of Personal Data by the Online Store may vary.
- 3.3.2 The Online Store collects and processes the following categories of Users' Personal Data:
- Clients (individuals and representatives of such persons);
- Counterparties (entities that are in civil and economic relations with the Online Store - representatives of a legal entity, individual entrepreneurs, individuals without the status of a business entity, and their representatives);
- Employees.
- 3.3.3 The Online Store processes the User's personal data, including collection, receipt, recording, systematization, accumulation, storage, clarification, (update, change), extraction, use, transfer (provision, access), blocking, deletion, destruction both with the use of automation tools and without the use of such tools, as well as through mixed processing for the following purposes (for the following purpose):
- Client registration on the Site;
- User identification when registering in the services or authentication of a registered User;
- ensuring the operation of the Site or its individual components;
- processing orders placed by the Client on the Site and transferring data to relevant sellers, executors, partners, companies and services that carry out delivery, provide payment, etc. (including foreign subjects of relations related to personal data) for the proper execution of the order;
- providing the User with access to personalized resources;
- establishing feedback with the User, including sending messages, requests related to the use of services, processing requests and applications from the User;
- confirmation of the accuracy and completeness of the personal data provided by the User;
- providing the User with effective customer and technical support;
- monitoring the use of the services of the online store and its partners;
- sending advertising messages to the User, providing the User with personal offers, additional opportunities to use the service, services;
- improving user experience, quality of service and operation of services, ease of use, development of new services;
- conducting marketing events, research and campaigns, analyzing consumer sentiment;
- analysis of user data, conducting statistical and other studies of the User's interaction with the Online Store and third parties;
- ensuring the exchange of comments/impressions from purchases made;
- conducting surveys related to the activities of the online store and its partners;
- carrying out business activities of an online store;
- preparation of statistical, administrative and other reporting information on the activities of the online store in accordance with the requirements of the legislation and the internal documentation of the online store;
- ensuring communications with Counterparties and their representatives;
- maintaining accounting, financial, tax and management records;
- conducting business correspondence, including responding to requests from government agencies;
- implementation of labor relations, employment and internships;
- implementation of administrative and legal relations;
- implementation of relations in the field of human resources management, in particular human resources potential;
- ensuring the rights and legitimate interests of the online store and interested parties;
- compliance with the requirements of Ukrainian legislation;
- implementation of other relationships that require the processing of personal data and are aimed at obtaining income and implementing the provisions of the legislation of Ukraine, the Statute of the Online Store and its internal regulations and policies.
- 3.4 Terms of processing of Users' personal data and its transfer to third parties
- 3.4.1 The processing of users' personal data is carried out in accordance with the Law of Ukraine "On Personal Data Protection".
- 3.4.2 All personal data of the User is kept confidential and secure.
- 3.4.3 The Online Store has the right to transfer the User's personal data and/or entrust its processing to third parties in the following cases:
- performance of legal obligations (including processing and fulfilling the Client's Order);
- preventing or investigating possible offenses;
- in order to ensure the protection of the rights and legitimate interests of the online store and its partners;
- providing information to law enforcement and other competent state bodies at their request, which meets the requirements of the current legislation of Ukraine;
- protecting the personal safety of Users or third parties
- 3.4.4 The Online Store may transfer Users' personal data to the following third parties (including, but not limited to):
- to administrators (enterprises, institutions and organizations of all forms of ownership, state authorities or local self-government bodies, natural persons - entrepreneurs who have been granted or will be granted the right to process personal data by the Online Store or current legislation);
- to third parties involved in the provision of money transfer services by the Online Store and/or participating in the provision of money transfer services by the Online Store, banks, non-bank financial institutions;
- to third parties involved by the Online Store to fulfill orders placed on the Site (carriers, contractors, business entities that issue orders or business entities that are the owners of goods or services ordered on the Site and/or organize delivery and payment of such orders, etc.)
- archival institutions and other persons providing the Online Store with information and document storage services (related services);
- participants, affiliated persons of the Online Store, persons who have a significant stake in the Online Store and/or exercise control over the Online Store;
- other private individuals and organizations to ensure the performance by the latter of their functions or the provision of services of the Online Store in accordance with the transactions concluded between such individuals (organizations) and the Online Store, which may process and use personal data for the purpose specified in clause 3.3.3. of this Policy.
- 3.5 Measures taken to protect the User's personal data
- 3.5.1 The processing and protection of personal data in the Online Store is based on a risk-based approach to prevent, identify and eliminate threats of unauthorized access to personal data and/or their unlawful processing.
- 3.5.2 When processing personal data, the Online Store takes the necessary legal, organizational and technical measures to protect personal information from unauthorized or accidental access, destruction, distortion, blocking, copying, provision, dissemination of personal information, as well as from other unlawful actions in relation to the User's personal information regarding the processing of personal data by the Online Store and the requirements of personal data legislation.
- 3.5.3 The processing of users' personal data is carried out on equipment located in premises with limited access by designated employees of the Online Store and only in accordance with their professional or employment duties. Such persons are prohibited from disclosing this data even after termination of employment relations with the Online Store.
- NOTICE OF THE RIGHTS OF THE PERSONAL DATA SUBJECT
- 4.1 The Online Store informs the Personal Data Subjects of their rights as Personal Data Subjects, which are stipulated in Article 8 of the Law of Ukraine "On Personal Data Protection", including that the Personal Data Subject has the right:
- to know about the sources of collection, location of their personal data, the purpose of their processing, location or place of residence (stay) of the owner or manager of personal data or to give the appropriate instruction to obtain this information to persons authorized by him, except in cases established by law;
- receive information about the conditions for providing access to personal data, in particular information about third parties to whom their personal data is transferred;
- to access your personal data;
- receive no later than thirty calendar days from the date of receipt of the request, except in cases provided for by law, a response on whether their personal data are being processed, as well as the content of such personal data;
- to submit a reasoned request for the modification or destruction of their personal data by any controller and processor of personal data if these data are processed unlawfully or are inaccurate;
- to protect their personal data from unlawful processing and accidental loss, destruction, damage due to intentional concealment, failure to provide or untimely provision of such data, as well as to protect against the provision of information that is unreliable or defamatory of the honor, dignity and business reputation of an individual;
- to file complaints about the processing of their personal data in accordance with the procedure established by applicable law;
- apply legal remedies in case of violation of personal data protection legislation
- to make reservations regarding the restriction of the right to process their personal data when providing consent;
- withdraw consent to the processing of personal data;
- know the mechanism of automatic processing of their personal data;
- to protect against automated decision-making that has legal consequences for them.
- 4.2 The subject of personal data has the right to receive any information about himself from any Subject of relations related to personal data, without specifying the purpose of the request, except for cases established by law.
- 4.3 The Personal Data Subject's access to personal data is free of charge. The Personal Data Subject submits a request to the Online Store for access to his/her personal data.
- 4.4 The request shall be satisfied within thirty calendar days from the date of its receipt, unless otherwise provided by law. The requested information shall be provided to the personal data subject in writing by sending a letter.
- 4.5 Reference in any documents (contracts) to this Policy is a proper notification of the Personal Data Subject about his rights.
- FINAL PROVISIONS
- 5.1 The online store takes measures to ensure the protection of personal data at all stages of its processing.
- 5.2 The online store independently determines the list and composition of measures aimed at the security of personal data processing, taking into account the requirements of legislation in the areas of personal data protection and information security.
- 5.3 Protection of personal data includes measures aimed at preventing their accidental loss or destruction, unlawful processing, including unlawful destruction of or access to personal data.
- 5.4 The Site may contain links to other sites that have other owners and administrators and are not affiliated with the Online Store. If the User follows such a link, he will be directed to a third-party site. The Online Store strongly recommends that Users familiarize themselves with the privacy policy of each site before proceeding. The Online Store does not control and does not assume responsibility for the content, privacy policy of any third-party sites or services.
- 5.5 The User may obtain any clarifications on the necessary issues relating to the processing of his personal data by contacting the Online Store via e-mail.curl.girl.shop@gmail.com
- 5.6 The User assumes responsibility for the possible negative consequences of his actions aimed at providing the Online Store with incomplete and/or unreliable and/or irrelevant personal data and/or personal data of third parties.
- 5.7 Any requirements of the User related to the establishment of additional restrictions on the processing of Personal Data and/or the prohibition of their processing and/or the destruction of personal data may result in the inability of the Online Store to fulfill its obligations to the User when providing services in accordance with the terms of the public contract. In this case, the Online Store is not liable for non-fulfillment or improper fulfillment of the obligations assumed.
- 5.8 This document will reflect any changes to the Online Store's personal data processing policy. The policy is valid indefinitely until replaced by a new version.
- 5.9 The Policy is published on the official website of the Online Store (curlgirl.shop) on the Internet for the purpose of familiarizing the Personal Data Subjects whose data is processed by the Online Store in the course of its statutory activities.
- 5.10 In all cases not regulated by this Policy, the current legislation of Ukraine must be followed
Sale
Today is a good day, today you can buy these silk products at bargain prices;)