Wellsping
(“Wellsping”, “us” or “we”) is committed to your right to privacy, and we will
only use your data as set out in this Privacy Policy. This Privacy Notice
explains how we process information that can be used to directly or indirectly
identify you as an individual (“personal data” or “PI”) collected through our
website (“site”) both online and including the physical purchase of goods in our
stores. Please read this information carefully.
Wellsping
D.O.O. is the controller for processing personal data on the site.
PERSONAL
DATA WE COLLECT ABOUT YOU
Data provided by you. Through our site, you may
typically provide us with the following data:
Contact data (Name, Email)
Order data (Product details, Shipping address, Billing
address)
Data collected about you. When you use our site, we
will typically collect the following data:
Technical data (device type, web browser, IP address)
Usage data (account log ins, site navigation, clicks and
browsing time)
Location data (Location when using the site)
Preference data (Products and activities you have indicated
an interest in)
Social media data
The
purposes why we collect and use your personal data, the categories of PI we
collect and legal basis for processing
1. To manage and fulfil your orders.
Both onlane and including the physical purchase of goods in Wellspring retail
stores: contact data, order data. Basis: performance of our contract,
compliance with legal obligation.
2. For bookkeeping purposes: order
data. Basis: performance of our contract, compliance with legal obligation.
3. To provide customer care and manage
potential clams: contact data, order data. Basis: performance of our contract.
4. To provide access to the site and
enhance user experience: technical data, usage data, location data, preference
data. Basis: legitimate interest to improve quality of service.
5. For analytics (market, customer and
product analysis): we typically use aggregate data that may not be linked to
you, however we may use order data and preference data. Basis: legitimate
interest to improve quality of service.
6. For marketing purposes: contact data,
marketing data, preference data, social media data. Basis: explicit consent of
user.
We also
collect cookie data when you visit our site.
HOW LONG
WE STORE YOUR PERSONAL DATA
We will store your personal data for as long as necessary to
fulfil the purposes described in this Privacy Policy. These are the criteria
that we use to determine when we will delete your data:
We retain data to the extent required by law (such as
tax/bookkeeping laws)
We retain data such as contact data, order data and
communication data to the extent relevant for limitation periods for potential
claims (typically two to five years after date of a purchase)
We retain data such as contact data, order data, marketing
data, location data and preference data as long as you have consented to
receive marketing communication from us.
We
endeavour to delete other data two years after your last interaction with us
(such as last purchase or last communication).
THIRD PARTIES AND SOCIAL MEDIA
Our
websites may contain links to third-party online websites. Such third
parties have their own policies that govern their collection, use, and
disclosure of information. We suggest that you read their privacy policies to
learn about their practices.
Social
media provides tools and links that we may include on our websites. If
you chose to use such tools or links, the social media may collect information
from your visit on our site. We also have pages on social media, where we
provide information about our products and interact with the users. On such
social media pages, we may receive anonymised insight, such as statistics about
age, sex and location of our users. We may also receive information that you
decide to share with us, such as chat, comments and likes.
Your
experience on the social media sites will be governed by the privacy and other
policies of those sites. The privacy settings you have chosen on those
sites will determine the degree to which your information is made public. We
encourage you to choose your privacy settings on those sites accordingly. As we
are joint controllers with the social media for data processed from your use of
social media tools or links on our site, and for aggregated insight that we get
from your use of our pages on social media, you may also contact us if you
would like to have more information, or if you want to exercise your privacy
rights. However, please note that we may not be able to respond to all request,
and that we may have to refer you to the social media for further information.
As the recipients mentioned above may be established
anywhere in the world, the personal data may be transferred globally. If data
originating from the EEA is transferred to countries outside the EEA, we will
adopt appropriate safeguards to protect the privacy such as by means of
standard agreements and additional safety measures. You may receive a copy of
the relevant parts of the agreements by contacting us.
YOUR PRIVACY RIGHTS
Within the conditions/limitations set out in applicable law,
you have the following privacy rights:
Right to information. You have the right to obtain
further information on our use of your personal data.
Right of access. You have the right to receive a copy
of your personal data.
Right to rectification. You have the right to ask us to
correct your personal data if it is incorrect or incomplete, such as by
changing your details on your account.
Right to be forgotten. You have the right to request
the erasure of your data if we do no longer need them.
Right to restrict processing of personal data. You have
the right to request that we suspend our processing of your personal data.
Right to data portability. You have the right to obtain
personal data that you have provided to us in a format that enables you to
transfer that personal data to another organization. You may also have the
right to have your personal data transferred directly from us to such
organization.
Right to object to processing of personal data. You
have the right to object to our use of your personal data, such as to
unsubscribe to marketing emails.
Right to withdraw consent. If you have given your consent to
our processing of personal data, you are free to withdraw the consent at any
time.
Certain Unidentifiable Personal Information. There may
be information that is designated as personal information under data protection
law, but this information, on its own, does not allow us to identify you in our
systems—for example, search or browsing history. For this information, we will
not be able to comply with your request.
Verification
Process and Required Information. We may need to request additional
information from you to verify your identity or understand the scope of your
request, although you will not be required to create an account with us to
submit a request or have it fulfilled. We will require you to provide, at a
minimum, your email address, full name, billing address (with zip code) and
phone number, and for access requests may require (if you have made a purchase
with us) that you identify some items ordered.
Authorized Agent. You may designate an authorized agent
to make a request on your behalf, which, for your protection, we will also need
to verify as authentic.
If you think that we have processed your personal data in a manner that is not
in accordance with data protection law, we hope that you contact us, so that we
can provide answers and correct any misunderstandings. You have the right to
make a complaint to the relevant data protection authority). If you live or
work in another EEA country, you may contact the authority in your country.
CHILDREN
The
services provided by Wellspring D.O.O. are not intended for the use of
individuals under the age of 16, and we do not knowingly collect information
online from individuals under the age of 16 without prior guardian consent.
SAFEGUARDING YOUR DATA
We have
reasonable and appropriate physical, electronic, and administrative measures in
place to safeguard the security of your personal information.
Although we
will do our best to protect your personal data, we cannot guarantee the
security of your data transmitted to our site. Any transmission is at
your own risk. When you
communicate with customer service via email, these communications may not be
encrypted. For that reason, we ask that you do not share sensitive
information via these communication channels.
COOKIES
We use
cookies and similar technologies on our site.
CONTACT
If you have any comments or queries in connection with our Privacy Policy or wish you use any of your privacy rights, please email hh.wellspring@gmail.com
CHANGES TO THIS PRIVACY NOTICE
This
Privacy Notice was last updated on 28.03.2021.
This Privacy Notice may change from time to time. You will always find the latest
version of this Privacy Notice on our Site www.wellspring.com.hr