Privacy Policy
Last updated: 2024-07-04
1. Introduction
At Love and Confuse, we value your privacy and are committed to protecting your personal data. This Privacy Policy outlines how we collect, use, safeguard, and handle your information when you visit our website, make purchases, or interact with our services. By using our website, you consent to the data practices described in this policy.
2. Data Controller Information
UAB “Rugpjūtė”, trading as Love and Confuse, located at Balbieriškio gatvė 14, Kaunas, LT-46412, Lithuania, is the data controller for the purposes of the General Data Protection Regulation (GDPR) and other applicable data protection laws.
3. Contact Us
You can contact us at any time for any data protection inquiries:
- Email: [email protected]
- Address: Balbieriškio gatvė 14, Kaunas, LT-46412, Lithuania
4. Data We Collect
We may collect the following types of data:
- Personal Identification Information: Name, email address, phone number, shipping address, billing address.
- Payment Information: Processed securely through third-party payment processors (we do not store your full payment card details).
- Technical Data: IP address, browser type, device information, operating system, time zone setting, language preferences, and other technology on the devices you use to access our website.
- Usage Data: Pages visited, links clicked, time spent on pages, products viewed or searched for, order history, and your interaction with website features.
5. How We Collect Data
We collect this data through:
- Information You Provide: When you place an order, create an account, subscribe to our newsletter, contact customer support, participate in surveys, contests, or promotions, or otherwise interact with our website or services.
- Automated Technologies: Cookies and similar tracking technologies (for more details, see our Cookie Policy).
6. How We Use Your Data
We use your data for the following purposes:
- To Process and Fulfill Orders: Processing your payments, shipping your orders, providing you with order confirmations and updates. Legal Basis: Performance of a contract.
- To Provide Customer Support: Responding to your inquiries, assisting with technical issues, handling returns or refunds. Legal Basis: Performance of a contract, legitimate interests (to provide excellent customer service).
- To Personalize Your Shopping Experience: Showing you relevant product recommendations, tailoring content to your interests. Legal Basis: Consent, legitimate interests (to improve user experience).
- To Send Marketing Communications: Sending you promotional emails or messages about our products, sales, special offers, and new features, but only with your explicit consent. You can opt-out of these communications at any time. Legal Basis: Consent.
- To Improve Our Website and Services: Analyzing website traffic, understanding user behavior, identifying areas for improvement. Legal Basis: Legitimate interests (to develop and improve our products and services).
- To Comply with Legal Obligations: Such as tax laws, accounting regulations, or responding to lawful requests from public authorities. Legal Basis: Legal obligation.
7. Data Sharing
We may share your data with these categories of third parties:
- Payment Processors: To process transactions securely. Legal Basis: Performance of a contract.
- Shipping Companies: To deliver your orders. Legal Basis: Performance of a contract.
- IT Service Providers: For website hosting, data storage, email marketing, analytics, and other IT services. Legal Basis: Legitimate interests (to ensure the technical functionality and security of our website).
- Marketing Service Providers: Only with your explicit consent to manage our email marketing campaigns or deliver targeted advertising. Legal Basis: Consent.
- Legal and Regulatory Authorities: As required by law to comply with legal obligations, such as responding to court orders or government requests. Legal Basis: Legal obligation.
We only share the minimum amount of data necessary for the specific purpose. All third parties are required to respect the security of your personal data and treat it in accordance with applicable data protection laws. We do not allow our third-party service providers to use your personal data for their own purposes.
8. Data Retention
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected and to comply with legal, accounting, or reporting requirements:
- Order Information: 7 years (for tax and accounting purposes).
- Account Information: As long as your account is active or as needed to provide you with services. You can request to delete your account at any time.
- Marketing Communications: Until you withdraw your consent or for as long as required by applicable marketing laws.
9. Your Data Protection Rights
Under GDPR, you have the following rights:
- Right to Access: Obtain confirmation that we are processing your data and request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete personal data.
- Right to Erasure (“Right to be Forgotten”): Request deletion of your personal data under certain circumstances (e.g., if the data is no longer necessary for the purpose it was collected).
- Right to Restriction of Processing: Request that we restrict the processing of your data under certain circumstances (e.g., if you contest the accuracy of the data).
- Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format, and have the right to transmit that data to another controller.
- Right to Object: Object to the processing of your data based on grounds relating to your particular situation (e.g., for direct marketing purposes).
- Rights Related to Automated Decision-Making: Not be subject to a decision based solely on automated processing (including profiling) that produces legal effects concerning you or similarly significantly affects you.
10. Exercising Your Rights
To exercise any of your data protection rights, please contact us using the contact information provided in Section 3 (Contact Us). We will respond to your request within one month of receiving it. We may require you to verify your identity before fulfilling your request.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. These measures include encryption, secure servers, access controls, and regular security assessments.
12. Data Breach Notification
In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach.
13. Cookies and Tracking Technologies
Our website uses cookies and similar technologies to enhance your browsing experience and collect usage data. This helps us understand how visitors use our website so we can improve its functionality and content.
For more detailed information about the specific cookies we use, how to manage your cookie preferences, and your choices regarding cookies, please see our Cookie Policy.
14. International Data Transfers
As we operate within the European Union, most of your data is processed within the EU. However, some of our service providers may be based outside the EU in countries that may not have equivalent data protection laws.
We will only transfer your personal data to countries outside the EU if adequate safeguards are in place to protect your data, such as:
- The European Commission has determined that the country ensures an adequate level of protection for personal data.
- We have implemented appropriate safeguards, such as standard contractual clauses approved by the European Commission or binding corporate rules to ensure the protection of your data.
15. Children’s Privacy
Our website is not intended for children under the age of 16, and we do not knowingly collect personal data from individuals under 16. If you believe that we may have collected personal information from a child under 16, please contact us immediately, and we will take steps to delete that information.
16. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational, legal, or regulatory reasons. The updated policy will be posted on our website with a revised “Last updated” date.
We encourage you to review this policy periodically to stay informed about our privacy practices. Your continued use of our website after any changes constitutes your acceptance of the revised Privacy Policy.
17. Your Right to Complain
You have the right to lodge a complaint with a supervisory authority if you believe we have violated any of your data protection rights. The supervisory authority in Lithuania is the:
Lithuanian State Data Protection Inspectorate
Website Address: https://vdai.lrv.lt/