Addicted to perfection. Dedicated to woman.

General

These privacy terms are compiled in accordance with the Regulation on the Protection of Personal Data (Regulation (EU) 2016/679 of the European Parliament and of the Council) and the Personal Data Protection Act and apply to customers of NAUDIN LINGERIE OÜ.

The data controller of NAUDINLINGERIE.COM is NAUDIN LINGERIE OÜ (registry code 16845082).

The Privacy Policy forms an integral part of the agreements concluded between NAUDIN LINGERIE and the customer and includes the following information:

• What types of personal data we collect;

• Why and on what basis we collect your personal data;

• How we handle your personal data;

• Your rights;

• Our contact details so you can obtain information about your rights regarding the processing of your personal data and exercise those rights.

Definitions

NAUDIN LINGERIE uses the following terms in these rules:

Customer – a natural or legal person who uses, has used, or has expressed a desire to purchase goods and services offered by NAUDIN LINGERIE or is otherwise associated with NAUDIN LINGERIE’s services.

Data subject – a natural person about whom NAUDIN LINGERIE has information and data to identify the person. Data subjects include, for example, individual customers, visitors, query and request submitters. Also referred to as an individual or customer in this Privacy Policy.

Personal data – any information relating to an identified or identifiable natural person (“data subject”);

Processing – any operation or set of operations which is performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure, or destruction.

Personal data

NAUDIN LINGERIE processes customer personal data only on legal grounds and for purposes stated in this Privacy Policy. NAUDIN LINGERIE processes the following customer personal data:

• Name, phone number, and email address;

• Delivery address;

• Bank account number;

• Cost of goods and services and payment-related information (purchase history);

• Customer support data.

NAUDIN LINGERIE collects the above data in various ways:

• Data provided by the individual to NAUDIN LINGERIE (data provided on order);

• Data sent when paying for goods and services (making card payments, information related to bank transfers, etc.).

Purpose and legal basis for data processing

NAUDIN LINGERIE has a legal basis and interest to process customer or customer representative personal data in establishing, maintaining, and terminating cooperation and customer relationships and to maintain all data related to the process, including retaining data for fulfilling legal obligations, making claims, and resolving legal disputes.

NAUDIN LINGERIE collects and processes personal data for the following purposes and legal bases:

Purpose of Personal Data Processing

• Personal data is used for managing customer orders and delivering goods.

• Purchase history data (purchase date, item, quantity, customer data) is used to compile overviews of purchased goods and services and analyze customer preferences.

• Bank account numbers are used to refund customers.

• Personal data such as email, phone number, and customer name are processed to resolve issues related to the provision of goods and services (customer support).

• The user’s IP address or other network identifiers are processed for providing the website as an information society service and for making web usage statistics.

Legal Basis

• Personal data processing is carried out for the performance of a contract with the customer.

• Personal data processing is carried out to fulfill a legal obligation (e.g., accounting and consumer dispute resolution).

• Data processing is carried out with the customer’s consent for the following activities: marketing, informing about new products and campaigns of interest to the customer.

Access to Personal Data and security

NAUDIN LINGERIE ensures the confidentiality and secure storage of customer data required by law and organizes the protection of personal data against unauthorized access, unlawful processing or disclosure, accidental loss, alteration, or destruction.

Access to personal data is limited to NAUDIN LINGERIE’s authorized representatives or designated employees. Certain personal data may be disclosed to a third party, namely an authorized processor, for the purpose of fulfilling obligations arising from contracts and laws (see data sharing below).

NAUDIN LINGERIE organizes all information exchange securely, using multiple personal access and authentication codes and secure information transmission channels, thereby preventing access by third parties and minimizing the risk of data leakage.

Cookies

To ensure the proper functioning of the website, the website stores small files – so-called cookies – on the user’s device. A cookie is a small text file that the website stores on the user’s computer or mobile device when the user visits the service provider’s website. This allows the website to remember the user’s actions and preferences (such as username, language, font size, and other display preferences) for a certain period. Thus, the user does not have to enter them again every time they return to the page or browse pages. The legal basis for using cookies is our legitimate interest in ensuring the technical functionality and operation of the website according to user preferences and choices. Cookies usually remain valid for a short period (day, week, or month), in some cases, they can remain valid for up to a year. We may use cookies and cookie-like tools to provide the service and improve the quality of the service and enhance user experiences. Cookies may also be used by third parties whose services we use. Cookies are used for several reasons:

• Personalizing content and advertisements,

• Providing social media features, and

• Analyzing website usage.

We may also provide information about how the website is used to our social media, advertising, and analytics partners. Implementing such cookies is not directly necessary for the functioning of the website, but it ensures a better browsing experience. Cookies can be deleted or blocked, but in this case, not all website functions may work as intended. Cookies help us provide better services.

Controlling Cookies. Users can control and/or delete cookies as they wish (see www.youronlinechoices.com/). Users can delete all cookies already on their computers and decline cookies at any time by changing their browser settings (if their browser allows) or by discontinuing the use of the website. Be aware that certain website functions can only be provided using cookies, and if you opt-out of cookies, these functions may not be available to you. You can disable cookies in your browser settings or by visiting the following websites:

https://tools.google.com/dlpage/gaoptout?hl=en

http://www.youronlinechoices.com/.

Google analytics

We may use Google Analytics, a web analytics service provided by Google, Inc. (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”). Google Analytics uses cookies to analyze how users use the website. As mentioned above, users can disable the storage of cookies on their computer using their web browser settings, but in this case, users may not be able to use all the features of the website. Users can opt out of their data being collected by Google Analytics at any time. To do this, the user must download the appropriate browser add-on from the following website: tools.google.com/dlpage/gaoptout?hl=en.

More information can be found by reviewing Google Analytics’ data processing rules: https://support.google.com/analytics/answer/6004245?hl=en.

Website logs. The server hosting our website may record queries made by the user to the server (web address opened by the user, browser and device used by the user, IP address, access time). This data is used only for technical purposes to ensure the functioning and security of the website and to identify security incidents.

Data sharing

NAUDIN LINGERIE may disclose customer personal data to third parties if required by law, necessary for the organization of NAUDIN LINGERIE’s work, for the exercise of legal obligations or rights, or on another legal basis. Personal data provided to authorized processors are processed on the legal bases provided by law and only to the extent necessary.

NAUDIN LINGERIE discloses personal data to the following recipients:

• Authorized processors for organizing NAUDIN LINGERIE’s work (e.g., accounting service provider, IT system administrator, such as customer program manager, business software, accounting software, archiving service, etc.), in addition to the web store customer support for managing purchases and purchase history and resolving customer issues;

• Authorities (law enforcement agencies, bailiffs, bankruptcy trustees, notary offices, court, Road Administration, etc.);

• Third parties involved in the sale of goods, provision of services, and fulfillment of contracts with the customer – transportation and courier service providers, payment intermediaries, communication, IT and postal service providers, advertising and marketing specialists;

• Legal advisors, financial advisors, insurers;

• In the event of assignment of claim rights, a new creditor.

Transfers of personal data outside the European Union (EU) – We transfer your personal data outside the EU and retain it there only if we have a legal basis for doing so, including the recipient of the data being: i) in a country where the protection of personal data is ensured at an adequate level; or ii) subject to a measure that fulfills the EU requirements for the transfer of personal data outside the EU.

Retention and period of personal data

NAUDIN LINGERIE does not process personal data for longer than necessary for the purposes related to the relevant data, including for the fulfillment of obligations specified in legislation.

• When closing the customer account in the web store, personal data is deleted unless such data needs to be retained for accounting or consumer dispute resolution purposes;

• If a purchase is made in the web store without a customer account, the purchase history is retained for three years.

• In the case of payment and consumer disputes, personal data is retained until the claim is fulfilled or the limitation period expires;

• Information arising from a customer agreement is retained for three years;

• Accounting documents and data required by law are retained for seven years;

• Information obtained with consent is kept until the consent is withdrawn.

The customer has the right to withdraw their consent at any time by notifying NAUDIN LINGERIE’s representative by email or in person. Withdrawal of consent does not affect the lawfulness of processing personal data before consent was withdrawn.

Customer rights

In organizing the protection of personal data in NAUDIN LINGERIE, the customer has the following rights:

• To access information concerning oneself and, if necessary, to obtain a copy of the data;

• To request correction of outdated or incorrect data;

• To request deletion of data or termination of processing if there is no longer a legal basis for retaining or processing the data and if retaining personal data is no longer necessary for processing the data;

• To request transfer of data to a third party;

• The right to lodge a complaint with a supervisory authority.

Personal data can be accessed and corrections made in the NAUDIN LINGERIE web store user profile. If a purchase is made without a user account, personal data can be accessed via customer support.

Withdrawal of consent. If processing of personal data is based on customer consent, the customer has the right to withdraw consent by informing customer support via email.

Deletion. To delete personal data, contact customer support by email. A response to the deletion request will be provided within one month, specifying the period for deletion of data.

Transfer. A response to transfer requests submitted by email will be provided within one month. Customer support verifies the identity and informs about the personal data subject to transfer.

Direct marketing messages. Email addresses and phone numbers are used for sending direct marketing messages if the customer has given consent. If the customer does not wish to receive direct marketing messages, they must select the appropriate link in the email header/footer or contact customer support. If personal data is processed for direct marketing purposes (profiling), the customer has the right to object to the processing of their personal data, including profiling related to direct marketing, at any time by notifying customer support via email (clear and separate information must be provided from any other information).

If the customer suspects misuse of their personal data, they must immediately notify NAUDIN LINGERIE customer support: info@naudinlingerie.com

NAUDIN LINGERIE has the right to update and amend privacy terms. Changes are made visible to customers on the NAUDIN LINGERIE website.

X