Your Cart

Processing of personal data

The controller of personal data of the MGI Beauty e-boutique is MGI Paris OÜ (registration code 16553304), Riia 20a-1, Tartu, Estonia, phone +372 563 99 999 and e-mail info@mgibeauty.ee.

1. What personal data is processed

1.1. name, telephone number and e-mail address;

1.2. delivery address;

1.3. bank account number;

1.4. the cost of goods and services and the details of payments (purchase history);

1.5.customer support details.

2. Purposes for which personal data are processed

2.1. Personal data is used for the management of customer orders and the delivery of goods.

2.2. Purchase history data (date of purchase, goods, quantity, customer details) is used to compile an overview of goods and services purchased and to analyse customer preferences.

2.3. The bank account number is used to return payments to the customer.

2.4. Personal data such as e-mail, telephone number and customer name are processed in order to resolve issues related to the provision of goods and services (customer support).

2.4. The IP address or other network identifiers of the user of the online shop are processed for the purpose of providing the e-boutique as an information society service and for web usage statistics.

3. Legal basis

3.1. The processing of personal data is carried out for the purpose of the performance of a contract concluded with a customer.

3.2. Processing of personal data is carried out for the fulfilment of a legal obligation (e.g. accounting and consumer dispute resolution).

3.3. Data processing is carried out with the consent of the customer in order to perform the following activities: sending a newsletter.

4. Recipients to whom personal data are disclosed

4.1. Personal data will be transferred to the online shop’s customer support for the purpose of managing purchases and purchase history and resolving customer issues.

4.2. The name, telephone number and e-mail address will be forwarded to the transport service provider chosen by the customer. In the case of goods to be delivered by courier, the customer’s address is provided in addition to the contact details.

4.3. If the accounting of the online shop is carried out by the service provider, the personal data will be provided to the service provider for the purpose of carrying out accounting operations.

4.4. Personal data may be transferred to information technology service providers if this is necessary to ensure the functionality or data availability of the online shop.

4.5. MGI Beauty may transfer data for the purpose of providing the payment initiation service to a payment service provider for the purpose of processing such payments.

5. Security and data access

5.1. Access to personal data is granted to the employees of the online shop, who can access personal data in order to resolve technical issues related to the use of the online shop and to provide customer support services.

5.2. The online shop implements appropriate physical, organisational and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration or unauthorised access and disclosure.

5.3. Transfers of personal data to processors (e.g. transport service providers and data aggregators) The processing of personal data takes place on the basis of contracts between the online shop and the processors. Data controllers are required to ensure appropriate safeguards when processing personal data.

5.4. The authorised processor of card payments is Nets Estonia AS, which processes card data for the purpose of the transaction, and the payment solutions provider is Modena Estonia OÜ.

6. Access to and correction of personal data

6.1. Personal data can be accessed and corrections can be made in the online shop user profile. If the purchase has been made without a user account, the personal data can be accessed via the login.

7. Withdrawal of consent

7.1. If the processing of personal data is based on the customer’s consent, the customer has the right to withdraw the consent by informing Customer Support by e-mail.

8. Storage

8.1. Personal data will be deleted when you close your online shop account, unless such data needs to be stored for accounting purposes or to resolve consumer disputes.

8.2. If a purchase is made in an online shop without a customer account, the purchase history is kept for three years.

8.3. In the case of disputes relating to payments and consumer disputes, personal data will be kept until the claim is settled or the limitation period expires.

8.4. Personal data necessary for accounting purposes are kept for seven years.

9. Deletion

9.1. In order to delete personal data, you must contact MGI Beauty by e-mail. A reply to the deletion request will be given within one month at the latest, specifying the period of deletion.

10. Transfer

10.1. Requests for the transfer of personal data made by e-mail will be answered within one month at the latest. The customer support will verify the identity and notify the personal data to be transferred.

11. Direct marketing communications

11.1. The email address and telephone number will be used to send direct marketing messages if the customer has given their consent. If the customer does not wish to receive direct marketing communications, he/she should select the appropriate link in the footer of the email or contact customer support.

11.2. Where personal data is processed for the purposes of direct marketing (profiling), the customer has the right to object at any time to both the initial and further processing of his or her personal data, including profiling in relation to direct marketing, by informing Customer Support by e-mail.

12. Dispute settlement

12.1. Disputes relating to the processing of personal data can be settled by e-mail to info@mgibeauty.ee. The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).