Data that I collect
To be able to fulfill your order, you must provide certain information to me, such as your name, e-mail address, postal address, payment details and the details of the product you have ordered. If you contact me directly (for example when you place a custom order) you can also choose to give me additional personal information.
Why I need your data and how I use it
I rely on a number of legal bases to collect, use and share your data, such as:
where necessary to provide my services, such as when I use your data to fulfill your order, settle disputes or provide customer service;
when you have given your express permission, which you can withdraw at any time, such as by signing up for my mailing list;
if necessary to comply with a legal obligation or court order or in connection with legal proceedings, such as keeping information about your purchases if required by tax law; and
to the extent necessary for the purpose of my legitimate interests, if those legitimate interests are not overridden by your rights or interests, such as 1) the delivery and improvement of my services. I use your information to provide the services you have requested and in my legitimate interest in improving my services.
Data exchange and disclosure
The details of my customers are important for my company. I only share your personal information for very limited reasons and very specific situations, as follows:
Service providers I engage certain trusted third parties to perform certain functions and deliver services to my shop, such as delivery staff. I will share your personal information with these third parties, but only as far as necessary to provide these services.
Business transfers. If I sell my business or enter into a merger, I may disclose your details as part of that transaction, but only to the extent permitted by law.
Compliance with laws. I may collect, use, store and share your information if I have a good faith belief that it is reasonably necessary to: (a) respond to a legal process or government requests; (b) compliance with my agreements, conditions and policies; (c) the prevention, investigation and handling of fraud and other illegal activities, security or technical problems; or (d) protect the rights, property and safety of my customers or others.
Transfer of personal data to outside the EU
I can store and process your data via third-party hosting services in the United States and other jurisdictions. As a result, I may transfer your personal data to a jurisdiction with other data protection and government enforcement laws than yours. If I am supposed to transfer your data outside the EU, I trust Privacy Shield as the legal basis for the transfer, as Google Cloud is certified by Privacy Shield.
If you live in certain areas, including the EU, you have a number of rights regarding your personal data. Although some of these rights are general, some rights relate to certain limited cases. I describe these rights below:
Access. You may be entitled to access and receive a copy of the personal information that I own from you. You can contact me via the details below.
Change, limit, delete. You may also have the right to change your personal information, to limit my use of it, or to delete it. If there are no exceptional circumstances (such as where I have to store data for legal reasons), I will usually delete your personal data on request.
Objection. You can object to (i) my processing of some of your data based on my legitimate interests and (ii) receiving marketing messages after giving your explicit permission to receive them. In such cases, I will delete your personal information, unless I have compelling and legitimate reasons to continue using that information or if this is necessary for legal reasons.
Complaints. If you live in the EU and you want to express concern about my use of your data (and without prejudice to any other rights that you may have), you have the right to do so with your local data protection authority.
How you can contact me
In the context of EU data protection legislation, I, Dineke (Dino) Girod is the data controller of your personal data. If you have questions or concerns, you can contact me via firstname.lastname@example.org. Or you can send a letter to:
Dino Girod, Ropta 110, 9202KL Drachten, The Netherlands