Personal Data Administrator
Craft Holsters is a trademark of The Holsters Company, s.r.o., registered at the office at Ivana Krasku 980/9, Banska Stiavnica, Slovak Republic, postcode 969 01, company identification No. 44638205, incorporated in the Business Register of the District Court in Banská Bystrica, division Ltd, file No 16149/S, as a data administrator shall process your personal data.
Type of Data Processed
Personal Data Provided By You
We process personal data provided by you.
If you order goods or services from us, we need the information which is referred to as mandatory in the ordering process (in particular your first name and surname, and delivery address). If we did not have this information we would not be able to deliver the goods. For the purposes of sale of goods or services, we also need your e-mail address, to which we shall send the order confirmation which serves as a confirmation of entering into the purchase agreement.
You can also fill in optional information when ordering goods or services. Such information helps us perform the concluded purchase agreement more efficiently. For instance, if you fill in your telephone number, we can send you a notice of the goods delivery, etc. Providing optional information is voluntary.
After the goods are delivered, you may get an e-mail message with the request to evaluate the goods purchased.
If you contact us via the customer line or you send us a message, we shall also process your personal data stated in such communication.
By filling in the optional information in your user profile, you may also provide us with other personal data, such as frequently used delivery addresses.
Personal Data of Third Persons Provided by You
In the event you provide us personal data of third persons, you are obliged to inform the person concerned and procure his/her consent to this Personal Data Protection Policy.
Personal Data Processed Automatically
When you visit our website, we may collect certain information such the IP address, date and time of the visit to our website, information about your Internet browser, operation system or language settings. We may also process information about your conduct on our website, such as links opened or goods displayed. The details of your conduct on the web are anonymised for the maximum protection of your privacy, the therefore we are not able to match them with a particular person.
If you access our website from your mobile phone or a similar device, we can process information about your mobile device, too (mobile phone details, records of application failure etc.).
We automatically process cookies. This is done through Google Analytics, which anonymises your personal data. It means that the cookies are not possible to match with a certain person.
Therefore we cannot monitor (even if we wanted to) the conduct of a certain user on our website. You are ensured maximum anonymity while making purchases on our website.
Cookies are collected through a script from Google Inc., which is located in the source code of our website. Your cookies are transferred to Google Inc. for anonymisation. Then we work with the anonymised cookies, which by then have ceased to be personal data. The process of anonymisation, i.e. transfer for anonymisation, is processing of personal data, made by us on the legal grounds of legitimate interest.
What is a cookie file?
It is a small text file created upon a visit to a website. It is used as a standard tool for the storage of information about visits to our website.
Thus we can distinguish (not identify) individual users and customise the content to individual preferences. Cookies are important and web browsing would be more difficult without them.
What are cookies used for?
Cookies serve several purposes. We use the following cookies on the website of our online shop and in our mobile applications:
- Technical cookies: We use technical cookies to make our online shop work properly (e.g. for you to create a user profile, log in, and buy goods and services). The online shop would not work without cookies.
- Functional cookies: These help so that you do not have to log in and set your preferences repeatedly. Your password is always encrypted in such procedures. The use of these cookies is not necessary but they make your visit to our online shop more comfortable.
- Analytical cookies: Analytical cookies help us improve our online shop, which ultimately benefits you. Analytical cookies on our website are collected by the Google Inc. script which subsequently anonymises the data. The data ceases to be personal data after anonymisation: anonymised cookies are not possible to match with a particular user or person. We only work with anonymised cookies. Therefore we are unable to find out the way in which a concrete user behaved on our website (sites visited, goods displayed etc.).
We also use the findings obtained from these cookies for advertising purposes; we may also display an ad that we consider relevant to you on other websites. If you want to have control over what analytical cookies we process, you can use this add-on program from Google (it can run only on a computer).
How You Can Control Which Cookies We Will Process
You can use one of the common browsers (e.g. Internet Explorer, Safari, Firefox, Chrome) with anonymous browsing switched on. This shall prevent storage of data concerning the sites visited. You can also block the storage of cookies in the browser. However, if you block the processing of technical and functional cookies, you will disable certain useful functions.
You can easily control the processing of analytical cookies by us if you use this add-on program from Google (it can run only on a computer). However, if you switch off analytical cookies you will make our improvement of the online shop difficult.
If you access our website from a phone, tablet or similar device, you access the version optimised for such devices. Your personal data is processed similarly to the computer access.
Why We Collect and Process Your Personal Data
Your personal data is processed for the following reasons:
- Purchase of goods and services: the primary purpose of processing your data is due dispatch and delivery of your order. If a problem occurs, we know who to contact from the data you provided.
- Customer care: if you address us with a question/issue, we have to process your personal data in order to answer/resolve it. The data may be transferred to third parties in certain cases (e.g. delivery company).
- User account: thanks to the personal data entered in your user profile, you will be able to use a number of functions (e.g. if you enter your telephone number, we can easily inform you about the time of the order delivery). You can change the entered details at any time, except for the e-mail address that serves for signing into your user account.
- Electronic marketing: e-mail commercial communication is sent to you upon your consent. You can easily unsubscribe from getting commercial communication by adjusting your user profile settings, using our contact form. In case you create more user profiles in which you enter the same contact details, (e.g. you have several accounts for different e-mail addresses, but the telephone number is the same in all the accounts), an automatic sign-off from commercial communication cannot be effected for all the user accounts due to technical reasons. You have to contact us by phone or through the contact form so that all your user accounts may be unsubscribed.
- Improvement of services: we are able to offer relevant goods thanks to the history of your orders and conduct on the website (e.g. accessories to the product purchased). Therefore we display such products that are intended just for you and correspond to your needs and interests. In order to optimise web features, we can also use tools testing different variants (A/B testing), such as Google Analytics, Facebook Analytics etc.
- Customer reviews of goods and services: after you purchase products or services from us, your may be asked to evaluate them. You may also post a review on your own initiative.
- Assertion of rights and legal claims and inspection by public authorities: we can also process your personal data in order to assert our rights and legal claims (e.g. in the event that we have an overdue invoice in your name). We may also process your data for inspections by public authorities and other serious reasons.
Legal Grounds for Processing of Personal Data
Conclusion and Performance of Agreement
A large part of your personal data are needed by us in order to conclude the purchase agreement or another contract for goods and services you intend to purchase. After the agreement is concluded, we process your personal data in order to duly deliver the purchased goods, or to render the purchased services. We process in particular billing and delivery details on the above legal grounds.
We also use your personal data to provide you the relevant content, which may be of interest to you. On the grounds of legitimate interest, we process particular personal data, which is processed automatically, and cookies.
We may also send you e-mails and text messages on the same legal grounds.
In case we process your personal data on these legal grounds, you are entitled to raise an objection to such processing (see Contact us) on our website.
For the purposes of e-mail marketing, we process your personal data upon your consent. If you do not grant your consent and you are our customer, we can send you commercial communication even without your consent. In any case, you are entitled to ban such marketing communication simply by (a) adjusting you user profile settings or (b) using our contact form.
If you grant your consent to the personal data processing, you are entitled to withdraw it at any time through our contact form.
Transfer of Personal Data to Third Parties
Your personal data is transferred to third parties in the following cases:
- Delivery of goods: the carrier chosen by you would not be able to deliver the goods ordered unless we transfer the information on where and to whom the goods should be delivered. This data is transferred to the carrier as entered in the order. Such data includes in particular your first name and surname, delivery address, telephone number where the carrier may contact you. The carrier is only entitled to process the personal data we transfer for the purposes of delivery; the carrier must delete the personal data promptly afterwards.
- Payment Cards: Our company does not possess the details of payment cards used by you. The details of your payment cards are only available to the secure payment gateway and the relevant bank.
- Commercial Communication: in case we send commercial communication (e.g. via e-mail or text message), we may use a third party to distribute the messages or make phone calls. Such third party is bound by the obligation of confidentiality and is not allowed to use your personal data for any other purpose.
- Public Authorities: in the event that we enforce our rights, your personal data may be transferred to a third party (e.g. an Attorney-at-Law). If we are obliged to transfer your personal data by virtue of law or upon a request by a public authority we have to do so.
When you pay by payment card from a mobile phone, you will be redirected to the secure payment gateway server. When you pay by payment card from a computer, iframe is used for interaction with the payment gateway server (the payment gateway site is displayed on our website and redirecting is not necessary). Thus, your card details are not sent to our company but directly to the payment gateway provider via secure transmission. The payment gateway transfers the data to the relevant bank for the payment to be effected, again via secure transmission.
Our payment gateway providers are:
- 2Checkout.com 2Checkout.com, Inc., 855 Grandview Avenue, Suite 110, Columbus, OH 43215, USA
- PAYPAL (EUROPE) S.A R.L. ET CIE S.C.A., 22 Boulevard Royal L-2449, Luxembourg (Lëtzebuerg)
What Is the Period for Processing Your Personal Data?
We shall process your personal data for the entire duration of the contractual relationship between you and us.
In case your personal data processing is based on consent, your personal data shall be, in general, processed for 7 years or until such consent is withdrawn.
In case you subscribe to commercial communication, your personal data shall be processed for 7 years or until you express your disapproval of such communication. You can easily express your disapproval by adjusting your user profile settings, using our contact form.
Please note that the personal data necessary for the due rendering of services or for the fulfillment of all our duties, ensuing either from the contract between us or from generally binding legal regulations have to be processed regardless of whether you granted your consent for the period set out in the relevant legal regulations and in compliance therewith (e.g. tax documents must be processed for at least 10 years).
The data obtained through the user account or in a similar way are processed for the period of using our services and then usually for 5 years after cancellation. Basic identification data and the information why the user account was canceled or information which is a part of operational advance deposits are usually stored for the relevant period.
The recordings of phone calls from and to the call center are archived for a short period, not exceeding 1 year, unless it is necessary for us to store them for a longer period due to a legitimate interest (e.g. suspicion of data misuse, fraud etc.).
Personal Data Security
Your personal data is safe with us. We have adopted adequate technical and organisational measures in order to prevent unauthorised access and misuse of your personal data.
At Craft Holsters we are concerned about the protection of your personal data. Therefore we regularly check and improve our security. All communication between your device and our web servers is encrypted. Logins are hashed and your data is only stored on servers in secure data centers with limited, carefully controlled and audited access.
We try to use such safety measures that provide sufficient security based on state-of-the-art technology. The safety measures adopted are regularly updated.
Personal Data of Children Younger Than 16 Years of Age
Our online shop is not intended for children under 16. A person under 16 is allowed to use our online shop only upon consent of his or her parent or guardian.
What Are Your Rights Related to Personal Data Protection?
In relation to your personal data, you have in particular the right to withdraw your consent to the processing of your personal data at any time, the right to correct or supplement your personal data, the right to request restriction of processing, the right to raise an objection to or a complaint of the processing of your personal data, the right to access your personal data, the right to request the transfer of your personal data, the right to be informed of a breach of security of your personal data and, under certain conditions, the right to the deletion of certain personal data we process about you ("the right to be forgotten").
Changes and Amendments
You control your personal data mainly through your user account. You can also contact us through the contact form.
In case you believe that your personal data has been processed incorrectly, you can contact us through the contact form. It will be faster and better for you to correct the personal data by yourself in your user profile.
You can ask us to send you the overview of the personal data through our contact form.
You also have the right to access the following information concerning your personal data:
- What are the purposes of processing your personal information
- What are the categories of the affected personal data
- Who is the recipient of your personal data, besides you
- What is the planned period of storage of your personal data
- Whether you have the right to claim the correction or deletion, restriction of personal data processing or to raise an objection to such processing
- Information on the source of the personal data in case we did not obtain them from you
You may also claim the deletion of your personal data (this shall not apply to data in documents that are subject to the obligation of archiving under the law (e.g. invoices or credit notes). In case we need your personal data to determine, execute or defend our legal claims, your request may be rejected (e.g. if we have an overdue invoice in your name or if the complaint procedure is in progress).
Please note that the essential details of your payment card are not stored by our company; they are stored at the payment gateway. Therefore, we are not able to delete such data; you have to address the payment gateway which mediated the payment.
You are entitled to the deletion of data in the following cases:
- The personal data is not needed for the purposes for which it was being processed
- You have withdrawn your consent under which the data was processed and there is no further legal grounds for being processed
- You have objected to the processing of personal data and you believe that after assessing your objection, it will become clear that your interest in the particular situation prevails over ours
- The personal data has been processed unlawfully
- The deletion obligation is stipulated by a special legal regulation
- The personal data concerns a person under 16
You may assert you right through the contact form.
Raising an Objection
Certain personal data is processed on the grounds of our legitimate interest (see section “Legal grounds for processing of personal data”). In the case that you have concrete reasons, you are entitled to raise an objection to the processing of this personal data. The objection can be raised through our contact form.
Restriction of Processing
In case (a) you deny the accuracy of your personal data, (b) your personal data is processed unlawfully, (c) we do not need your personal data for processing purposes, but it is needed to determine, execute or defend your legal claims, or (d) you raised an objection under the preceding paragraph, you shall be entitled to us restricting the processing of your personal data.
In such cases, we may process your personal data only upon your consent (except for the storage or backup of the personal data concerned).
Lodging a Complaint
If you believe that your personal data has been processed unlawfully, you are entitled to lodge a complaint at the Office for Personal Data Protection. However, we will appreciate if you address us first and we can try to resolve your concerns. You can always easily contact us through our contact form.
This Personal Data Protection Policy including its parts is valid and effective from 25 May 2018 and it is available in electronic form at www.craftholsters.com.