Privacy Policy

E-SHOP PRIVACY POLICY
  1. GENERAL PROVISIONS
1.1.This privacy policy (hereinafter - Privacy Policy) of the electronic shop WWW.SAUNASUP.COM (hereinafter - Online Shop) describes how Sauna world, MB (hereinafter - We or Seller) manages the personal data and privacy of its customers and visitors (hereinafter - You or User or Buyer). 1.2 This Privacy Policy, together with the Terms of Use of the Online Shop, governs your use of the Online Shop and/or the Mobile App. 1.3 By ticking the box next to the statement "I have read and understood the rules for the purchase of goods for sale in the electronic shop SAUNASUP.COM, the privacy policy, the rules of use of the website", you confirm that you have read, accept and agree to be bound by this Privacy Policy. If you do not agree with the processing of personal data described in this Privacy Policy, please do not provide us with your personal data. In this case, We will not be able to provide You with access to the Online Shop. 1.4 This Privacy Policy may be amended and updated by Us, and We advise You to read it periodically and familiarize Yourself with the latest version of this Privacy Policy. The current and valid version of the Privacy Policy is always available on the SAUNASUP.COM website.
  1. PERSONAL DATA CONTROLLER
2.1. your personal data as a customer of the e-shop and a user of the mobile application are managed to different extent by Sauna world, MB, legal entity code 307447804, registered office address J. Lukšos g. 14, Garliava, Kaunas r., correspondence address J. Lukšos g. 14, Garliava, Kaunas r. (hereinafter referred to as UAB "Asauto"), store Vytauto g. 67, Garliava, Kaunas r.. 2.2 The security of personal data is ensured by our Data Protection Officer, whose email address is: info@saunasup.comsup.com.
  1. CONNECTIONS
3.1 GDPR - Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). 3.2 Account - the result of the Buyer's use of SAUNASUP.COM on the basis of the Terms and Conditions by registering on the SAUNASUP.COM website, which results in the creation of a personal account of the Buyer, which stores his/her personal data and the history of orders. 3.3 Contract - a contract of sale of the relevant Goods concluded between the Buyer and the Seller, which shall be deemed to be concluded from the moment of placing an Order. The terms of each Contract entered into between the Buyer and the Seller shall be deemed to be identical to the terms of the Regulations in force at the time of the placing of the Order and such Contracts shall always be enforceable by the parties in accordance with the Regulations in force at the time of the placing of the Order. 3.4 Rules - "Rules for the purchase and sale of goods in the SAUNASUP.COM e-shop".
  1. GROUNDS FOR PROCESSING PERSONAL DATA
4.1 We only collect and process your personal data that is sufficient and necessary to achieve our purposes. Almost all of the personal data we process comes only from you. In processing the personal data provided by you, we will assume that it is accurate and correct and that any consents you have given are freely given after having read this Privacy Policy in detail. 4.2 Your personal data is collected and processed on the following legal grounds: 4.2.1. a contract with us to which you are a party (e.g. a contract concluded between us and you on the basis of the "Rules for the purchase and sale of goods in the SAUNASUP.COM online shop"), or our intention to take action at your request prior to the conclusion of the contract (Art. 6 para. 1 lit. b) GDPR). 4.2.2. the performance of a legal obligation arising from and applicable to Us (Art. 6 para. 1 lit. c) GDPR). 4.2.3. Our legitimate interest and the legitimate interest of third parties (Article 6(1)(f) GDPR). 4.2.4. your consent to the processing of your data for one or more specified purposes (Article 6(1)(a) GDPR). 4.2.5. one or more of the above legal bases may apply to the processing of the same personal data about you to the extent and under the conditions provided for by the applicable law. 4.3 Other terms shall have the meanings ascribed to them and defined in the GDPR, the Terms and Conditions and the Contract.
  1. WHAT PERSONAL DATA WE PROCESS AND WHERE WE GET IT FROM
5.1 We only collect and process your personal data that is sufficient and necessary to achieve the purposes for which it is processed. 5.2 We may process the following personal data in relation to the services, features and other interactions you have with us in relation to the SAUNASUP.COM Online Shop:
DATA CATEGORY PERSONAL DATA PROCESSED DATA SOURCES
Registration, Account creation, login and Account usage details Registration and login details:email address and password, which We keep securely encrypted and cannot be seen, Facebook ID / Google ID if you connect to the Account via Facebook / Google. Technical/administrative data necessary for the operation and security of the Account:User ID, Account status (active, blocked, etc.), IP address, technical data of logins to and actions in the Account. Other information:an indication that you have read the Terms and Conditions and/or Privacy Policy of the Online Shop, the date and time of reading. Received from you when you register with the Online Shop and create your Account. Created or captured automatically (including by cookies and similar technologies) when you register, log in or use your Account (e.g. technical data).
Your identification, profile and contact details Identification data:Your name. Contact details:email address, phone number, home address. Other profile data that you provide to Us at Your discretion:date of birth, gender, language preference, company name and details if you are communicating with us on behalf of a company, and other information you provide. Received from you when you place an order in the Online Shop and provide us with your data necessary for its execution, create a personal Online Shop Account and provide us with your data, contact us with a request, inquiry, complaint, etc.
Purchasing data Your order details:the goods ordered, their quantity, prices, discounts given, vouchers used, date and time of order. Billing information:method of payment, date and time of payment, payment details (including but not limited to bank account number). Delivery information:method of delivery and/or delivery address, main details of the recipient if you specify a third party as recipient. Information on the status and progress of your order:whether the order has been prepared, dispatched, delivered, information on returns and refunds, etc. Communication data:information about communications and interactions with you about issues related to your order and its performance, your feedback and reviews, and the content of other communications. Other information:an indication that you have read the Terms and Conditions and/or Privacy Policy of the Online Shop, the date and time of reading. If you have made a purchase as a registered customer, the purchase data is linked to other data stored in your personal Account. Received from you when you place an order in the Online Shop, make an order payment, contact us (or we contact you) on issues related to the order and its execution, when you request a return of goods, etc. Generated during the course of the order or received from the sellers whose goods you purchase and/or partners who assist Us in fulfilling orders (e.g., information about order payment, dispatch, delivery, etc.). Collected by means of cookies and similar technologies when and to the extent that such information is necessary for the conclusion of a sales contract, the acceptance of an order and the processing of an order (e.g. cookies record that you have read the Terms and Conditions of Purchase and / or the Privacy Policy).
Your consents, communication and/or service management choices Consents and communication choices:Your consent to receive newsletters, marketing and/or other communications, information about the time and date of consent. Service choices:information about your use of the Online Shop services and loyalty programme (e.g. participation in a discount programme, content personalisation service, city selection, etc.), ordering and/or opting out. Your choices about cookies. Your consents are given in the Discount Programme, Loyalty Programme. Obtained from you (and recorded by automated means, including through cookies and similar technologies) when you tick the relevant consents and/or choices, subscribe to or opt-out of the relevant communications and/or services.
Your browsing data on the Online Shop and/or mobile app Browsing data:pages viewed, products viewed, date and time of viewing, duration of browsing, products uploaded to your shopping basket and/or wish list, date and time of upload, clicks on banners, other clicks and interest in content, information and related information. Technical data:IP address, session ID, browser used, device type, resolution. Collected by means of cookies and similar technologies when you browse the Online Shop and/or the mobile application. Generated from your browsing data (e.g. statistical browsing information).
Other data that is generated when you use the relevant services of the Online Shop Data generated when you use the services of the Online Shop: for example, when you save goods, select and save a city (to see the nearest pick-up points), select the relevant service (to identify the car with which you will arrive to pick up your order without getting out of the car), save the language preference of the website or mobile application, etc. If you do this as a registered customer, the data is linked to your other data as a registered customer. Received from you (and recorded by automated means) when you use the Online Shop service.
Viewing data for newsletters and other communications Information about the successful delivery of the message, information about the date and time the message was opened, clicks on links in the message, information about the forwarding of the email, information about unsubscribing from messages. Collected by cookies and similar technologies when you receive and view newsletters and other email communications.
Content you share in the Online Shop Reviews, ratings, questions about products and other content that you publicly post and/or share on your Online Shop and/or Mobile App. The content is made public by you, and you are therefore fully responsible for it. Received from you when you post relevant content on the Online Shop.
Communication data with you When you contact us for help, ask us questions, provide feedback, make complaints, etc., we process the data from your communication with us as well as the data collected by us to the extent that it is necessary for the processing of your enquiry. Received from you when you contact us with a request, feedback, complaint or other enquiry. Collected by Us from data We already lawfully hold about You and/or obtained from third parties (e.g. vendors, government authorities, etc.) when and to the extent necessary to process and respond to Your inquiry.
Candidate data Candidates' data: position applied for, name, surname, telephone number, email address, city from which you would like to work, salary expectation, date of interview, date of consent to further processing and other information. Received from you when you send your CV and cover letter. Other information we may collect from your former employers, professional portals.
  1. PURPOSES OF PROCESSING PERSONAL DATA
6.1 Buying goods and fulfilling your orders. We collect your personal data in order to receive, administer and fulfil your orders for goods, including but not limited to processing payments, delivering goods, accepting returns, billing, communicating with you about, dealing with and resolving issues related to your order and its fulfilment, etc.
CATEGORIES OF PERSONAL DATA PROCESSED LEGAL BASIS PERIOD OF PROCESSING 
Your identification and contact details. Details of the contract of sale, your purchase details. Communication data when and insofar as it relates to a specific order. for the purpose of concluding and executing the Purchase and Sale Agreement between you and us. The specific order and the related data and documents shall be kept for a maximum period of 5 years after the execution of the order. Your data that you have stored in your personal e-shop Account for the purpose of subsequent orders (e.g. name, surname, telephone number, delivery addresses, payment card details) shall be stored for as long as your Account is valid or until you have removed them from your Account.
6.2 Provision of eShop services We collect and process your personal data in order to provide you with the services and features in accordance with the E-shop Terms of Use and/or your choices. 6.2.1 Registration, creation, administration and provision of services related to the Online Shop Account By registering and creating your personal Online Shop Account, you will be able to shop faster and more conveniently, view your purchase history, manage your data and preferences, and enjoy the services of the Online Shop which are available only to registered customers. In order to ensure the proper functioning and security of your Online Shop Account and to provide you with services related to your Account, we process the following data:
CATEGORIES OF PERSONAL DATA PROCESSED LEGAL BASIS PERIOD OF PROCESSING
Registration, login and Account technical and administrative data. Other data stored in and/or linked to your Online Shop Account: - Identification, contact, profile and other data that you enter and store in your Account (delivery addresses, payment card details (last digits), etc.); - Your purchase history and purchase data; - Your consents, communication and/or service management preferences. The rules of use of the Online Shop website and mobile application, i.e. the contract for the use of the Online Shop services. We will keep your registration, login and other Account data for as long as your Online Shop Account is valid. If you delete your Account, your identification, contact and other data will be permanently destroyed or depersonalized so that you cannot be identified. We may retain your consent and proof of consent for a longer period of time if necessary to defend ourselves against claims, demands or actions brought against us. The Purchase Data is disassociated from Your Account and is stored in a personalised form for a specified period of time (i.e. 10 years).
6.2.2. Personalisation of content and recommendations To make your browsing and shopping experience more convenient and faster, and to ensure that the content we provide is relevant to your needs, we recommend products, services, features and content that may be relevant to you in the Online Shop and/or the Mobile App. In order to get to know you better and to provide you with content that is truly relevant to you, We process the following data about you.
CATEGORIES OF PERSONAL DATA PROCESSED LEGAL BASIS PERIOD OF PROCESSING
Registered customer data:
- Identification and profile data and user ID provided in your Online Shop Account; - Your purchase data; - Your browsing data in the Online Shop and/or the mobile application; - Other data that is generated when you use the services of the Online Shop; - Your consents, communication and/or service management preferences. The rules of use of the Online Shop and the Mobile App, i.e. the agreement for the use of the Online Shop services. As long as you are a registered customer and/or use the content personalisation and recommendation service. If content personalisation and recommendations are not relevant to you, you may opt out of this service at any time by making the appropriate selections in your Account, in the Self Service. We may retain your consent and proof of consent for a longer period of time, if necessary, to defend ourselves against claims, demands or actions brought against us. If you opt-out of the content personalisation and recommendation service, your data will no longer be collected and processed for this purpose.
Unregistered Customers' data:
- Session ID; - Session data captured during your browsing session on the Online Store and/or the Mobile App. It is important to note that all browsing data of an unregistered Customer is collected and processed on a personalised basis only and does not allow the identification of a specific person. Your consent, which you give by confirming your cookie choices. For as long as your consent is valid, but no longer than 2 years. You can manage and withdraw your consent at any time by changing your cookie preferences as set out in the "Cookie Policy". We may keep your consent and proof of consent for a longer period of time if necessary to defend ourselves against claims, demands or actions brought against us.
6.2.3. the provision of other E-shop services and the sending of related notices We offer you various useful services and functions which require the processing of certain of your data. For more information on the individual services and their content, please refer to the Terms of Use of the Online Shop. When you use the services of the Online Shop as a registered user, We save Your data and link it to Your personal Account and other data We process about You. As a necessary and integral part of the functioning of our Online Shop and related services, we send you various notifications and information relating to the Online Shop and the Mobile App and its operation (e.g. notifications about abandoned shopping cart, reminders, information about changes in the prices of the products you are tracking or have memorised, information about new functionalities, notifications about important news and events, push-up notifications, system notifications, notifications about payments, etc.). In addition to the above, we use your contact details, such as your email address or telephone number, to send such notifications and information. 6.3 Direct marketing and other marketing activities 6.3.1. General and personalised direct marketing messages In the Online Shop, you can receive offers, subscriptions to newsletters, information about the Online Shop's news, promotions, discount codes and sweepstakes, as well as offers tailored specifically to you based on your purchase and browsing history. You can choose which channels you would like to receive these notifications and information, such as mobile app notifications, email and/or telephone. In order for us to provide you with such offers and information: Asauto UAB processes the following data about you:
CATEGORIES OF PERSONAL DATA PROCESSED LEGAL BASIS PERIOD OF PROCESSING 
Your contact details. Your purchase and browsing history in the Online Shop if you have opted to receive tailored offers. Viewing data for newsletters and other communications. Your consent (e.g. by subscribing to the Online Shop's newsletters, general and/or tailored communications and offers). We process the data on the basis of our legitimate interest when viewing newsletters and other communications. The collection and analysis of such data enables us to evaluate the effectiveness, optimality and efficiency of our marketing campaigns, to ensure that the communications are interesting and relevant to you and that our direct marketing is effective. As long as your consent is valid. We may retain your consent and proof of consent for a longer period of time if necessary to defend ourselves against claims, demands or actions brought against us. You may opt-out of direct marketing communications at any time by contacting Us at the contact details set out in clause 11.7 of the Privacy Policy.
When you participate in promotions and games, we will inform you of your prize winnings by a personalised message using the contact details we have on file for you. If We need additional personal data about You for the purpose of organising the game, announcing the winner or transferring the prize, or if We wish to transfer Your data to a third party (e.g. the supplier organising the game), We will make sure to contact You in advance and coordinate any such action with You. If you have indicated in the consent form that you would like to receive offers for the whole family by indicating the year of birth of your children, we will provide offers and information about products for children through the channels you have indicated and through your Account. You have the right to withdraw your consent at any time and the processing based on your consent will cease. Withdrawal of these consents will not prevent You from continuing to use Our Online Shop, but it will mean that We will not be able to provide You with useful offers, communications and news. Please note that Our Online Shop SAUNASUP.COM is an interconnected network of various interrelated information systems, so it may take several days to update the personal data processed in Our systems. Therefore, you may still receive the aforementioned notifications for some time while your request to unsubscribe from direct marketing communications is being processed. If you opt-out of direct marketing communications, information about the goods you have ordered (for example, updates on changes to the status of your order) will continue to be provided to you. 6.3.2. Other online marketing activities We may use Google and other online advertising providers. As independent controllers of personal data, advertising service providers collect data about your browsing on the E-Commerce website and/or mobile application by means of cookies and similar technologies in order to provide you with relevant online advertising on the E-Commerce website and/or other online advertising channels (social networks, mobile applications, internet search engines, etc.). Your browsing data on the E-shop website and/or mobile application for advertising purposes is collected and processed on the basis of your consent, which you can provide or revoke by accepting or rejecting targeted (commercial) cookies. You can find more information about the advertising partners of the Online Shop and the cookies they use, and you can manage the settings for targeted (commercial) cookies in the Cookie Policy. 6.3.3. Handling your requests and enquiries When you contact Us for assistance, ask Us questions, submit requests, feedback, complaints, etc., you provide Us with your personal data. We use your data to process your request or other enquiry, to provide you with the information you need, to answer your questions, and to resolve your requests or claims. We may also use the data from your requests, claims and other enquiries for the purpose of protecting our rights and legitimate interests.
Categories of personal data processed Legal basis Processing period
Your identification and contact details. Communication data. Other data necessary to process your request or enquiry. - Fulfilling our legal duty to respond to Client requests and inquiries - Contract performance where your request or enquiry relates to a contract and/or its performance - Our legitimate interest in protecting our rights and interests As long as we are investigating your request or other query, we will continue to respond for 2 years after the query has been resolved. If your request, demand or other enquiry is the subject of a legal dispute or the likelihood of such a dispute, we may keep your data for longer, until the expiry of the statutory periods of limitation for lodging a complaint or bringing an action, and/or until a final judgment has been delivered.
6.4. Analytics and statistics for the purpose of performance analysis, development and improvement We want to make it as easy and convenient as possible for you to use the Online Shop website and/or mobile app, to make our services relevant and useful to you and to provide you with the best experience possible. Therefore, in order to develop and improve our activities, we continuously analyse your use of the Online Shop website, mobile application and services and process the following data. For analytics and statistics purposes, we process non-personalised aggregated data and do not process your contact or other information that personalises you, i.e. analytical and statistical data does not allow the identification of a specific user, is not linked to other data of an identified user, and is not combined into user-specific data sets.
Categories of personal data processed Legal basis Duration of data processing
Aggregated and non-personalised browsing Online shops data on the website and/or mobile app. Aggregated and non-personalised Customer Purchase Data. Aggregated and non-personalised viewing data for newsletters and other communications. Aggregated and non-personalised Customer communication data. We carry out analytics and statistics and collect and process data for this purpose on the basis of Our legitimate interest. We keep it for as long as is necessary for the purposes set out in this section.
We may use Google Analytics and/or other website analytics providers' tools on the e-shop website and/or mobile application. Google Analytics and other analytics tools collect browsing data using cookies and similar technologies. However, as a general rule, cookies from Google Analytics and/or other analytics tools on the Online Shop function as first party cookies, i.e. cookies under Our own control. We collect and use analytical and statistical data on the use of the E-Store website and/or mobile application on the basis of Our legitimate interest for the purpose of evaluating the performance of Our services and/or marketing campaigns and to make important decisions on the development and improvement of Our activities, such as the creation of the E-Store product range, the development of services, the improvement of the website and mobile application, the improvement of customer service, etc. Accordingly, we consider analytics and statistics cookies to be necessary because otherwise we would not be able to achieve the above-mentioned purposes and ensure our legitimate interest. However, if You object to the installation of analytical cookies, You may reject them in Your web browser as set out in the Cookie Policy. 6.5 Information on the processing of CCTV data The e-shop has CCTV cameras installed inside and outside the pick-up points of the e-shop, which capture and record the images that come into the field of view of the cameras. The video recordings may only be viewed in the event of accidents with customers or employees, loss, damage or destruction of material assets, conflicts (incidents) between customers and employees. Video recordings may only be viewed by responsible and duly authorised persons who are aware of the requirements of the legislation on the protection of personal data and have undertaken to comply with them by signing a contract or by any other means of proof of awareness and commitment. CCTV footage may be provided to those persons concerned by the incident, such as law enforcement authorities and officials, insurance companies, visitors (where their property has been damaged or where the incident involves injury to health). In these cases, the data will only be provided once it has been established that there is a suitable and sufficient legal basis for providing the data. In order for Us to pursue Our legitimate interest in the safety, health and public order of individuals, We process the following data about You:
Categories of personal data processed Legal basis Duration of data processing
Your image and related image data The need to pursue Our legitimate interests, to protect the health, safety, public order and property of the persons in the Electronic Shop's collection centres. Video recordings are kept for up to 30 calendar days and are automatically deleted when new video recordings are stored on the medium, unless there are grounds to believe that an illegal act, criminal act or other unlawful act has been recorded (until the end of the relevant investigation and/or proceedings).
6.6. Profiling and automated decision-making In order to provide you with personalised content and recommendations, tailored marketing offers and/or to provide you with relevant money, We use automated data analysis and decision-making, including profiling, i.e. We use automated tools to group and analyse your data processed for the relevant purpose and to make insights and predictions about what content and/or communications may be relevant to you. In order to get to know our Customers, their needs and interests even better, we may also categorise our Customers according to various attributes (such as age, location, browsing and/or purchasing habits, etc.). Such automated analysis, profiling and decision-making activities allow Us to process the information We have about Customers efficiently and to achieve the specific purposes set out above, i.e. to tailor content, recommendations and/or offers to Your needs and interests. These actions do not constitute an independent purpose of processing, do not have any significant impact on you and do not give rise to any legal consequences for you. 6.7 Data collected for the purpose of selection of administrative and other staff Please note that, in order to assess your candidature, we may contact the former employers you have indicated in order to obtain information about your qualifications, professional abilities and business qualities. We may only request such information from your current employer with your separate consent. We also note that we may check your own publicly published data for professional purposes (e.g. on LinkedIn or similar professional social networks, portals). If, after considering your candidature, We select a candidate who better meets Our requirements, We may ask for your separate consent in order to store and use your personal data obtained during the selection process for other recruitment processes. Please note that if you send your CV, cover letter or other personal data to Our general email address without a selection being advertised by Us, by submitting your data, you consent to the transfer of your data to other companies managed by Us for recruitment purposes.
Categories of personal data processed Legal basis Duration of data processing
Your identification and contact details. Data about how we communicate with you. Other data necessary for selection, etc. Your consent, which you have expressed by participating in our selections. Our legitimate interest in verifying the information you have provided, as well as in processing your data in the event of any claims or demands made. Up to 3 (three) months after the end of the selection process. With your separate consent, for 2 (two) years from the date of consent. We may keep your consent and proof of consent for a longer period of time if necessary to defend ourselves against claims, demands or actions brought against us.
  1. DATA RECIPIENTS
Where it is necessary for the conclusion or performance of a contract with you, We may transfer your personal data to Our business partners, service providers, other data controllers. We may only transfer data on sufficient lawful grounds and only where you have been informed of the transfer. The data processors we engage may only process your personal data on Our instructions and may not use it for other purposes or transfer it to other persons without Our consent. In each case, We will only provide the processor with as much data as is necessary to carry out a specific order or provide a specific service. We may use third party service providers (data processors) to process Your personal data. Such processors include, for example, companies providing data centre services, companies providing information technology infrastructure services, companies developing, providing, supporting and developing software, companies providing advertising and marketing services, companies providing web browsing or online activity analysis and services, newsletter providers, leasing companies, call centres, call and communication services, couriers, carriers, market research or business analytics service providers and other service providers. When we use third parties to process your personal data, we always ensure that the recipients comply with appropriate data protection, security and confidentiality obligations set out in a written contract. Data may also be disclosed to financial institutions, competent government or law enforcement authorities, supervisory authorities, courts, insurance companies, bailiffs, tax authorities and other recipients with a right to receive the data, where required to do so by applicable law or to enforce Our rights, ensure the safety of Our customers, employees and resources, or to assert, bring and defend legal claims.
  1. TERRITORY AND JURISDICTION OF PROCESSING OF PERSONAL DATA
Your personal data may be transferred outside the European Economic Area (EEA). Your personal data is transferred outside the EEA if the following conditions are met: - the data is only transferred to Our trusted partners who ensure the provision of Our services to You; and - such partners have data processing contracts in accordance with the standard data processing clauses approved by the European Commission, whereby they ensure the security of your personal data in accordance with the requirements of the law; or - the European Commission has issued a decision on the adequacy of the country in which Our partner is established, i.e. an adequate level of security is ensured; or - there are other grounds, conditions and requirements under the GDPR.
  1. DATA RETENTION PERIODS
In cases where the data retention period is not specified in this Privacy Policy, the personal data provided by you will be retained for no longer than is necessary to fulfil the purposes (as specified in this Privacy Policy) for which the data was collected or for such period as may be required by law. The storage of your personal data for a longer period than specified in this Privacy Policy may be carried out only in exceptional cases, where:
  1. (a) it is necessary for us to defend ourselves against actual or threatened claims, demands or actions and to exercise our rights;
  2. (b) there are suspicions of illegal activity;
  3. c) Your data is necessary for the proper resolution of the dispute or complaint;
  4. (d) for back-up and other purposes related to the operation and maintenance of information systems or similar purposes;
  5. (e) on other grounds provided for by law.
  6. PROCESSING OF PERSONAL DATA OF MINORS
Our Online Shop is only available to persons over the age of 18. If you are under 18 years of age but have already reached the age of 14, you may only use the Online Shop services with the consent of your parents or guardians, or if you have the right to dispose of your income independently in accordance with the requirements of the law.
  1. YOUR RIGHTS
We ensure that you have access to all the rights you have under data protection legislation. Below you will find information on the specific rights you can freely exercise and how to exercise them. To exercise these rights, please submit a written request to Us at the contact details provided in this Privacy Policy. 11.1 Right of access to personal data processed (Article 15 GDPR) You have the right to ask Us for confirmation as to whether We are processing your personal data. You also have the right to access the personal data we process about You and information about the categories of data processed, the purpose of the processing, the duration of the processing, the sources of the data, the categories of recipients of the data, automated decision-making, including profiling, if applicable, and its implications and consequences for You. 11.2 Right to rectification of incorrect and completion of incomplete personal data (Article 16 GDPR) You have the right to request that the personal data We process about you be amended, supplemented, clarified or rectified if You believe that the information We process about You is inaccurate or incorrect. 11.3 Right to erasure of the personal data stored by us (right to be forgotten) (Art. 17 GDPR) You have the right to request that We erase your personal data if certain circumstances specified in the legislation on the processing of personal data exist (where the processing of personal data is unlawful, the basis for processing has ceased to exist, etc.). 11.4 Right to restrict the processing of personal data (Article 18 GDPR) In certain circumstances listed in the legislation on the processing of personal data (where personal data is processed unlawfully, you have contested the accuracy of the data, you have objected to the processing on the basis of our legitimate interest, etc.), you also have the right to restrict the processing of your personal data. 11.5 Right to data portability (Article 20 GDPR) You have the right to transfer to another controller the personal data which We process on the basis of your consent and the processing of which is carried out by automated means. We will provide you with the data you have requested to be transferred in a format that is commonly used in our systems and is computer-readable, or, if you so request and if technically possible, we will transfer the data directly to the other controller you have indicated. 11.6 Right to object where processing is based on legitimate interests (Article 21 GDPR) You have the right to object to the processing of personal data where the processing is based on Our legitimate interests. You can do this very simply and quickly in the following ways: by phone: +370 601 50011;
  1. email: info@saunasup.comsup.com;
by de-selecting to receive notifications in your Account Settings in the Online Shop; or by de-selecting to receive notifications in your Account Settings in the Mobile App. You can opt out of active push notifications: by de-selecting active notifications in your Account settings in the Mobile App; by changing the operating system settings on your device. 11.7 Right to withdraw consent to the processing of personal data (Article 7(3) GDPR) You have the right to withdraw your consent at any time and the processing based on your consent will cease. You can withdraw your consent to receive direct marketing communications, offers and information at any time. You can do this very simply and quickly by: by phone: +370 601 50011;
  1. email: info@saunasup.comsup.com;
at any time by clicking on the "Unsubscribe from newsletters" link in the email; by de-selecting to receive marketing communications in the Account Settings in the Online Shop; or by de-selecting to receive marketing communications in the Account Settings on the Mobile App. If your consent expires, is withdrawn or revoked, we will no longer process your personal data. In any event, We will retain the consent You have given and proof of consent for at least 2 years after withdrawal of consent and for a longer period if necessary to defend against claims, demands or actions brought against Us. 11.8 Right to lodge a complaint (Art. 77 GDPR) If you believe that your rights in the area of personal data processing have been violated, you have the right to lodge a complaint with the supervisory authority for personal data protection - the State Data Protection Inspectorate (www.vdai.lrv.lt) at L. Sapiegos g. 17, Vilnius. However, We always ask and recommend that you contact Us directly first. We believe that through good faith efforts We will be able to resolve your complaint, satisfy your requests or correct Our errors, if any.
  1. PROCEDURES FOR DEALING WITH REQUESTS FROM PERSONAL DATA SUBJECTS
To exercise your rights set out in this Privacy Policy, you may contact us by email at info@saunasup.comsup.com. In the letter, please include your name, contact details for contact and information about the reason, the scope and extent of the rights you wish to exercise and the manner in which you wish to receive a response. In order to comply with your request, we have the right to verify your identity, which will always be established in the simplest and most convenient way for you. If the verification procedure is successful, we will provide you with the information you have requested no later than one month from the receipt of your request and the completion of the identity verification procedure. Taking into account the complexity and number of requests, We have the right to extend the one-month time limit by a further two months, informing You thereof no later than one month after receipt of Your request and completion of the identity verification procedure, and stating the reasons for such extension. If your request is made by electronic means, we will also provide you with a reply by electronic means, unless this is not possible or if you request a different reply. We may only refuse to comply with your request if the circumstances set out in the legislation are established. You will be informed of such refusal in writing.
  1. OUR CONTACT DETAILS
You can contact us in the following ways for all personal data processing issues: by email to info@saunasup.com; by calling +370 601 50011. online via the SAUNASUP.COM e-shop enquiry form. Contact details of the Data Protection Officer: Email address: info@saunasup.com; Address for postal correspondence - J. Lukšos g. 14, Garliava, Kauno r. Address the letter to. Our details as a data controller: Sauna world, MB Legal entity code 307447804 Registered office address: J. Lukšos g. 14, Garliava, Kauno r., Republic of Lithuania.
  1. VALIDITY OF THE PRIVACY POLICY
This Privacy Policy is effective from 01 October 2024. If any provision of this Privacy Policy is held to be invalid or unenforceable, that provision shall not affect the legality and validity of the remaining provisions of this Privacy Policy.