1. General rules.
1.1 This Privacy Policy describes how SIA BCB-Eko, Reg. No 50103222391, address: Bernāti, Baldones pag., Ķekavas nov., LV-2125 (hereinafter also referred to as “Data
the Controller”) collects, processes and stores the personal data collected by www.zipa.lv from its customers and persons visiting the website (hereinafter referred to as
“Data Subject” or “You”).
1.2 Personal Data means any information relating to an identified or identifiable natural person, i.e. the Data Subject. Processing means any processing involving personal data
an act, such as obtaining, recording, modifying, using, viewing, deleting or destroying.
1.3. The Data Controller complies with the principles of data processing as laid down in the legislation and is able to confirm that personal data are processed in accordance with the legislation in force.
2. Collection, processing and storage of personal data.
2.1. Personally identifiable information is collected, processed and stored by the Data Controller primarily through the online shop website and email.
2.2. By visiting and using the services provided by the Online Shop, you agree that any information provided will be used and managed in accordance with the Privacy
the objectives set out in the policy.
2.3. The data subject is responsible for ensuring that the personal data provided are correct, accurate and complete. Knowingly providing false information is considered a violation of our Privacy Policy. The data subject shall immediately notify the Data Controller of any changes to the personal data provided.
2.4. The Data Controller shall not be liable for damages suffered by the Data Subject or third parties as a result of incorrectly provided personal data.
3. Processing of customers’ personal data
3.1. The Data Controller may process the following personal data:
3.1.1. Name, surname
3.1.2. Date of birth
3.1.3. Contact details (e-mail address and/or telephone number)
3.1.4. Transaction details (goods purchased, delivery address, price, payment details, etc.)
3.1.5. Any other information provided to us in the course of purchasing services and goods offered by the Site or contacting us.
3.2. In addition to the above, the Data Controller shall have the right to verify the accuracy of the data submitted using publicly accessible registers.
3.3. The legal basis for processing personal data is Article 6(1) of the General Data Protection Regulation a), b), points (c) and (f):
(a) the data subject has given consent to the processing of his or her personal data for one or more specified purposes;
(b) the processing is necessary for the performance of a contract to which the data subject is a party or for the performance of measures at the request of the data subject prior to the conclusion of the contract;
(c) processing is necessary for compliance with a legal obligation to which the controller is subject;
(f) the processing is necessary for the pursuit of the legitimate interests of the controller or of a third party,
except where the interests or fundamental rights and freedoms of the data subject which require the protection of personal data override such interests, in particular where
the data subject is a child.
3.4. The Data Controller shall store and process the Data Subject’s personal data for as long as at least one of the following criteria applies:
3.4.1. Personal data is necessary for the purposes for which it was received;
3.4.2. While the Data Controller and/or the Data Subject may exercise their legitimate interests, such as objecting to or
bring or pursue legal action
3.4.3. As long as there is a legal obligation to keep the data, such as under the Accountancy Law;
3.4.4. As long as the Data Subject’s consent to the processing of personal data is valid, unless there is another lawful basis for the processing of personal data. Upon termination of the circumstances referred to in this paragraph, the Data Subject’s retention period shall also terminate and all relevant personal data shall be permanently erased from the computer systems and electronic and/or paper documents that contained the relevant personal data, or such documents shall be anonymised.
3.5. In order to fulfil its obligations towards you, the Data Controller has the right to transfer your personal data to business partners, data processors who carry out the necessary data processing on our behalf, such as accountants, courier services, etc. The Data Processor is the controller of the personal data. The payment processing is provided by the payment platform www.montonio.com, therefore our company transfers the personal data necessary for the execution of payments to the owner of the platform www.montonio.com. Upon request, we may transfer your personal data to public and law enforcement authorities to defend our legal interests where necessary by drafting, submitting and defending legal claims.
3.6. When processing and storing personal data, the Data Controller shall implement organisational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure or any other unlawful processing.
4. Rights of the data subject
4.1. In accordance with the General Data Protection Regulation and the laws of the Republic of Latvia, you have the right to:
4.1.1. Access to your personal data, information about the processing of your personal data, a copy of your personal data in electronic format and the right to transfer your personal data to another controller (data portability);
4.1.2. Request the rectification of incorrect, inaccurate or incomplete personal data;
4.1.3. Delete your personal data (“be forgotten”), except where required by law to keep the data;
4.1.4. To withdraw your prior consent to the processing of personal data;
4.1.5. Restrict the processing of your data – the right to request that we temporarily stop processing all your personal data;
4.1.6. Contact the State Data Inspectorate
You can make a request to exercise your rights by filling in a form in person at SIA
BCB-Eko, Reg. No 50103222391, Address: Bernāti, Baldones pag., Ķekavas nov.,
LV-2125, or by sending your request electronically to the Customer Service
[email protected].
5. Final provisions
5.1. This Privacy Policy has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data and repealing Directive 95/46/EC (General Data Protection Regulation), as well as the applicable laws of the Republic of Latvia and the European Union.
5.2. The Data Controller shall have the right to make changes or additions to the Privacy Policy at any time and without prior notice. The amendments shall enter into force upon their publication on the website www.zipa.lv