Purpose of the policy

The purpose of this privacy policy is to acquaint customers or visitors of the website www.two-little-dots.com with the purposes and basis of the processing of personal data by the company Urška Biberović (“the provider”).

Contact details:

Company name: Urška Biberović
Address: Peter Rosegger Str. 33, 8053 Graz, Österreich
Email address: info@two-little-dots.com
Phone number: +43 676 510 3956

At our company, we pay special attention to the fact that the information we have about you is accurate, so we ask you to report this change to info@two-little-dots.com in the event of any change in personal data.

General information about data processing

The controller of personal data is the company Urška Biberović, Peter Rosegger Straße 33, 8053 Graz, Österreich.

By opening and using the website, various information and data are exchanged between your device and the server, including personal data according to the EU General Regulation. In the following, we present the data exchange and precisely define the use, interest and reasons. The data processing software and marketing tools we use are fully compliant with the EU General Regulation, so your data is secure.

The website is accessible on the HTTPS secure protocol, which provides encrypted connection and data exchange, and our servers are updated to the latest versions, which increases the level of security.

Personal data and their processing

Personal information is information that identifies you as an identified or identifiable individual. The provider collects the following personal data in accordance with the purposes defined in the following privacy policy:

• Basic information about the user, which is collected in the case of placing an order in the online store (name, surname, address of residence, e-mail address, phone number)

• Information on user purchases and issued invoices

• Data from voluntarily completed forms by users

The provider does not collect or process your personal data, except when you provide or consent to it or there is a legal basis for this and the provider has a legitimate interest in the processing.

Data processing on the basis of law or contractual relationship

Buy in an online store

In the case of concluding and implementing a contract with a provider (in the case of a purchase in an online store), you must provide personal data for the purposes of concluding the contract. The processing of the order in the online store is not possible without the provision of personal data. There is thus a legitimate interest of the tenderer in fulfilling the contract in accordance with Article 6 of the GDPR.

Sending promotional messages

In accordance with paragraph 2 of Article 158 of ZEKom-1, the provider may send you e-mails about sales promotions or news to your e-mail address that you provided with your order, or you can log in with it in the pop-up box on the website thereby giving consent to receive promotional messages. The provider does not pass on your e-mail address to a third party under any circumstances, and you always have the option to unsubscribe from receiving promotional messages by clicking on the link in the message itself. The provider always respects your decision and unsubscribe in an automated manner and takes effect immediately. You can also unsubscribe from receiving messages by sending an e-mail to info@two-little-dots.com.

Processing of personal data on the basis of a legitimate interest

Under the GDPR, a provider may also process data on the basis of a legitimate interest. The provider always strives to ensure that the rights and freedoms of the individual or visitor of the website always prevail over these interests. If you do not want data processing or you want to delete or interrupt the processing, you can let us know via e-mail at info@two-little-dots.com.

Access to order history and other data

Upon your call or e-mail, employees of the provider may, if you provide them with your personal data or account or order number, access your history of orders and personal data. Based on access, they can offer you a better service and offer, as well as an effective solution to any complaints.

Customized communication

We use personalized communication (via e-mail, browser notifications or social networks) to present the relevant offer, send discounts and other content that may be of interest to you based on your past interactions with our website. To perform this type of communication, we use your demographics (gender, age, and location), purchase history (products purchased, number of purchases), product responses and views (opening messages, clicking links), and addressing behavior and clicking on a website that may trigger sending customized messages.

When using customized communication, we never create user profiles, nor do we profile you or pay attention to your personal data, but only perform processing on the basis of larger groups, which makes it impossible to identify you as an individual.

Using the Facebook tool “Custom Audience”

The company also uses the Facebook Custom Audience service as part of the customized communication mentioned in the previous point. We provide the service on the basis of a legitimate interest or as part of the consent obtained from you. Facebook Custom Audience works by uploading your email address, which you entered during the purchase process or by voluntary entry, to Facebook and the latter connects it in its database to your Facebook profile, if any. Then Facebook adds you to the list of customized audiences or t.i. Custom Audience and allows us to display customized ads this way.

Processing of personal data on the basis of consent

The provider may process and collect your personal data with your consent, for the purpose of verifying and ensuring that you access and use your online account created by registering on the website, and for sending promotional messages and other content via e-mail, when there is no other legal basis for this and you have given your explicit consent. The provider may also process and collect your personal data for other purposes, but only if you have been informed of these purposes in detail and have also given your explicit consent.

If you do not want data processing or you want to delete or interrupt the processing, you can let us know via e-mail at info@two-little-dots.com.

Using the contact form

Using the contact form on the website, your data (text content, your name and surname, telephone number and your e-mail address) will be sent to our e-mail address. We keep the mentioned data exclusively for the purposes of correspondence and do not pass it on to third parties, nor do we use it for marketing purposes.

Cookies

This website does not use cookies for its operation.

Retention of personal data

The provider keeps your data for as long as necessary to achieve the purpose for which the personal data was collected and processed. If a special law prescribes the storage of data for a certain period, then the provider processes this data in accordance with this law.

If you have placed, completed and received the order, then the order information is stored on the server for 2 years from the receipt of the order from your site. If you submit a request for deletion of your data from our databases, we may delete the data earlier, except for data on the account, which according to the law are not allowed to be deleted and must be kept by the provider for 5 years.

Data in Google Analytics is deleted after 26 months.

Processing of personal data on the basis of a contract

By using the website, you are aware that the provider may also entrust your personal data to other contractual processors, who may process the data exclusively on behalf of the provider and within the limits of the provider’s authorization. The company cooperates with the following contractual processors:

• Printing house (Copigraf Faganelj d.o.o.)

• Provider of sending electronic messages (Zoho Mail)

• Providers of online advertising solutions (eg Facebook, Google)

Your privacy means a lot to us, so the provider will never pass on your personal data to unauthorized third parties, and the provider selects only verified contract processors who have the software regulated in accordance with the GDPR. Users do not send personal data to third countries, outside the EU, except in the USA. All contract processors located in the U.S., however, are part of the Privacy Shield Association.

Your rights in relation to data processing and contact person

In accordance with Articles 15, 16, 17, 18, 20 and 21 of the EU General Data Protection Regulation, you have the right to obtain information about your personal data stored with us, the right to rectify and supplement data, the right to delete data, the right to restrict data processing, the right to refuse and the right to transfer data.

You can request a printout of the data we keep via e-mail at info@two-little-dots.com or in writing to the company’s address (Urška Biberović, Peter Rosegger Straße 33, 8053 Graz, Österreich; by letter for two little dots). You can also send a request to delete or change the data to the mentioned e-mail address.

For more information on data processing and additional questions, you can contact the representative of our company, which is Urška Biberović, via the aforementioned e-mail or with a written request to the aforementioned company address.

Date of the last change of the privacy notice: 13.08.2020