Personal data processing

/
Personal data processing

Personal data processing

Personal data processing at Padel Locus explains how customer data is collected, used and protected when you visit our website, place an order or contact us.

This page gives information about what data may be processed, why it is needed and what rights customers have regarding their personal data.

1. General provisions

This personal data processing policy regulates the collection, processing and storage of personal data on the website padellocus.com, which is operated by Tomand OÜ.

  • Registration code: 16531308
  • Address: Laki tn 15-206, 12915 Tallinn, Estonia
  • Telephone: +372 58 23 76 76
  • E-mail: info@padellocus.ee

The data controller is responsible for the protection of personal data in accordance with applicable legislation, including the European Union General Data Protection Regulation (GDPR) and the Estonian Personal Data Protection Act.

This document supplements our data protection terms, the full content of which can be found on this page.

2. Collection, processing and storage of personal data

Our website collects and processes personal data electronically, mainly through the website and e-mail.

Data is processed for the following purposes:

  • Order management and delivery: we process customer orders, arrange delivery of goods and, if necessary, organise refunds.
  • Customer support: we answer customer questions and provide information about orders, products, delivery and returns.
  • Accounting and legal obligations: we process data required for accounting, tax reporting and other legal obligations.
  • Website functionality: we use data to ensure the operation, security and user experience of the website.
  • Marketing and communication: we may process data for marketing purposes only where there is a legal basis or the user has given consent.

3. Processing principles and legal basis

Our data processing is carried out according to the following principles:

  • Lawfulness, fairness and transparency: we process data in accordance with applicable legislation.
  • Purpose limitation: data is collected only for specific and clearly defined purposes.
  • Data minimisation: we process only the data that is necessary for achieving the relevant purpose.
  • Accuracy and up-to-date data: data is kept accurate and corrected when necessary.
  • Storage limitation: data is stored no longer than necessary for fulfilling the purpose.
  • Security: we apply appropriate technical and organisational measures to protect personal data.

The legal basis for data processing is based on Article 6(1)(a), (b), (c) and (f) of the GDPR.

4. Cookies and analytics

The website uses cookies and other tracking technologies to ensure:

  • Website functionality and improvement of user experience;
  • Collection of statistical data, including Google Analytics and Yandex.Metrika;
  • Display of personalised content and advertisements where necessary, based on the user’s consent.

When using cookies, the user is first shown a notice where they can give consent or refuse the use of cookies.

5. Sharing and transfer of data

Data is shared with third parties only for purposes that are necessary for providing services:

  • Transport service providers: for delivering orders, we may share first name, last name, address, phone number and other delivery-related information.
  • Accounting service providers: for tax reports and other legal obligations.
  • IT and website management service providers: for ensuring website functionality and data hosting.
  • Customer support service providers: for resolving questions and providing technical support.

Data transfer is carried out based on contractual measures, and where necessary, we use the European Commission’s standard data protection clauses.

6. Security measures

We apply appropriate technical, organisational and physical measures to protect personal data against accidental or unlawful destruction, alteration, unauthorised access and disclosure.

Main measures include:

  • Encrypted connection for data transfer, including HTTPS.
  • Storage of data on secure servers located in the European Union or countries belonging to the European Economic Area.
  • Access restriction – data can only be accessed by employees who need it for their work tasks.
  • Firewalls, antivirus protection and regular backups.
  • Regular internal audit and risk assessment.

7. Data retention and purposes of processing

7.1. Purpose of processing and retention periods

7.1.1. Security and safety
Personal data is stored for security purposes in accordance with the time limits specified by law. For example, security log files are stored according to applicable requirements.

7.1.2. Order processing
Data related to orders is stored for up to 2 years after the order has been fulfilled, in order to allow the resolution of consumer disputes and, where necessary, refunds.

7.1.3. Accounting and legal obligations
Data required for accounting and legal obligations is stored for the period required by applicable law.

7.1.4. Customer communication
Communication related to customer support is stored for as long as necessary to resolve the request and protect the rights of both parties.

7.1.5. Marketing communication
Marketing-related data is processed based on consent until the user withdraws consent or until the data is no longer necessary for the relevant purpose.

8. Rights of the data subject

Users, or data subjects, have the following rights:

  • Right of access: to request information about the data processed about them.
  • Right to rectification: to request correction of inaccurate or incomplete information.
  • Right to erasure: also known as the right to be forgotten, to request deletion of their data where there is no legal basis for processing.
  • Right to restriction of processing: to request restriction of data processing in certain situations.
  • Right to data portability: to receive their data in a machine-readable format and transfer it to another data controller.
  • Right to object: to object to data processing, especially for direct marketing purposes.
  • Right to withdraw consent: where processing is based on consent, the user may withdraw that consent at any time.

To exercise data subject rights, please contact customer support at info@padellocus.ee or call +372 58 23 76 76. You also have the right to submit a complaint to the Estonian Data Protection Inspectorate at info@aki.ee.

9. Changes

We reserve the right to amend this personal data processing policy. All changes will be published on the website padellocus.com, and continued use of the website means that you agree to the changes.

10. Additional information

Additional information about personal data processing and all technical details can be found in our data protection terms.

11. Contact

All questions, requests and rights-related enquiries concerning personal data processing should be sent to:

  • Telephone: +372 58 23 76 76
  • E-mail: info@padellocus.ee

Padellocus.com

Our physical store is located in the Cool Padel hall. Akadeemia tee 47, Tallinn.
Entrance with door code 1199#.

Store opening hours:
Tue, Wed, Thu, Fri – 12:00–19:00
Sat, Sun – 11:00–17:00
Mon – Closed

Shopping Cart0

No products in the cart.