PRIVACY POLICY
1. Introduction
Privacy and personal data protection regulations apply to the processing of your data, in particular the EU Regulation 2016/679 of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation or "GDPR").
In accordance with this regulation, you will find below information on the processing that we carry out in the context of the use of our website "ANJALI MUDRA", www.anjalimudra.be.
If you have any questions regarding our privacy policy or if you wish to exercise any of your rights regarding your personal data, you may contact us by e-mail at the following address: hello@anjalimudra.be.
2. Person responsible for processing your personal data
Personal data are processed by Mrs. Charlotte Laffineur, manager of the commercial activity "ANJALI MUDRA", registered at the Banque Carrefour des Entreprises under the number 0755 451 737, having its registered office at Grand-Place Baudouin 1er, n°17, 1420 Braine-l'Alleud.
3. Personal data collected
We collect your data either through cookies, through your user account or through the purchase process.
For more information on the data collected through cookies, please see our "Cookie Policy" available on our site.
The data we may collect includes:
-
your first and last name;
-
your telephone number;
-
your email address;
-
your geographical address; f
-
your navigation data ;
-
your bank details;
-
your preferences for using the site.
4. Purposes and basis of processing and data retention period
The personal data you provide to us may be processed for the following purposes and on the following grounds:
a) For the performance of contracts or the execution of pre-contractual measures taken at your request
Purposes
This purpose includes the processing of your data for the performance of the contract or pre-contractual measures taken at your request.
This purpose thus covers in particular the following purposes:
- Responding to any pre-contractual request from you, such as a request for pre-purchase information; placing the order and ensuring the shipment of the product; managing returns and exchanges; invoicing; managing the payment of the product(s) you purchase;
- The use of features or services offered on our site as part of the purchase process, such as the customer account with the memorization of the order basket;
- To provide after-sales service (SAV) or to manage any dispute/complaint relating to an order or a purchase
Basis
According to Article 6.1. b) of the GDPR, the processing of your personal data is necessary for the performance of the contract or the execution of pre-contractual measures taken at your request.
Duration of storage
The data is kept until the expiration of the applicable statute of limitations and the accounting and tax retention periods.
b) Newsletter and advertising e-mails
Purpose
With your prior consent, we may send you e-mails about updates or information regarding features, products or new products and for completed orders, for which the processing of your data is required.
You can withdraw your consent at any time and unsubscribe from our mailing list.
Basis
The legal basis for processing your data is consent in accordance with Article 6.1 a) of the GDPR.
Duration of storage
The data is kept until the consent is withdrawn, with the understanding that we will ask you once a year to renew your consent.
c) Analytical and marketing management
Purpose
This purpose includes processing your data to personalize your browsing experience on our site, for example by allowing us to offer you recommendations based on your interactions and to better understand your use of our site and your preferences for our products.
Basis
The legal basis for processing your data for marketing purposes is our legitimate interest, in particular our interest in improving our site and the attractiveness of our products, in accordance with Article 6.1 f) GDPR.
Retention period
The data is kept for a period of 13 months from the date of collection.
d) To defend our rights and interests
Purpose
We may process your personal data in order to defend our rights, either amicably or in court.
Basis
We have a legitimate interest (Article 6.1.f of the GDPR) to process personal data necessary to defend our rights and interests.
Duration of storage
The data is kept for the time necessary to defend our rights and interests.
e) To ensure the security of our computer system
Purpose
We may process your personal data to protect the security of our computer system.
Basis
We have a legitimate interest (Article 6.1.f of the GDPR) to process personal data necessary for the security of our IT system.
Duration of storage
The data is kept for the time necessary for the aforementioned purpose.
f) Responding to requests to exercise rights
Purpose and basis
When you exercise your rights listed below, we are legally authorized to process your data to respond to them, as required by the GDPR (Article 6.1.c of the GDPR).
Retention period
The data is kept until the end of the applicable statute of limitations.
5. Your rights
You have, under the conditions defined by the applicable regulations, and in particular the RGPD:
(1) the right to withdraw your consent to parts of the processing at any time;
(2) the right to obtain confirmation as to whether or not personal data relating to you are being processed and, where they are, access to such personal data and to various information about the processing operations;
(3) the right to obtain, as soon as possible, the rectification of personal data concerning you that are inaccurate;
(4) the right to obtain the erasure, as soon as possible, of personal data concerning you;
(5) the right to obtain the limitation of the processing;
(6) the right to receive the personal data concerning you that you have provided in a structured, commonly used and readable format and the right to transmit such data to another controller without hindrance;
(7) the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning you or which significantly affects you in a similar way.
_ The right to object
You also have:
(1) the right to obtain at any time on grounds relating to your particular situation, that we no longer process personal data concerning you where such processing, including profiling, is based on our legitimate interests,
(2) the right to object at any time to the processing of your personal data for marketing purposes, including profiling insofar as it is related to such marketing.
_Exercise of rights
You may exercise the rights described above free of charge by writing to us at the following e-mail address hello@anjalimudra.be.
In the event of manifestly unfounded or excessive requests, in particular because of their repetitive nature, we may :
- charge a reasonable fee that reflects the administrative costs incurred in providing the information, making the communication or taking the action requested; or
- refuse to comply with such requests.
The burden of proof is on us to demonstrate that the request is manifestly unfounded or excessive.
_Right of complaint to the Data Protection Authority
You may also contact the Data Protection Authority (DPA) if you are not satisfied with the processing of your personal data.
6. Disclosure
If necessary, we will share your personal data with its partners such as suppliers, services related to logistics, transportation and delivery, accountants, lawyers, business consultants and advisors, in order to achieve any of the purposes listed above.
Please note that we may be required by law to disclose personal data following a request from the relevant authorities.
7. Transfer
Any transfer of personal data to a third party within the EU/EEA will only take place if the recipient complies with EU privacy and data protection regulations.
Any transfer of personal data to a third party outside the EU/EEA will be made to a country with a Commission adequacy decision or, if not, will be made on the basis of EU standard clauses or similar constructions such as binding corporate rules.
8. E-commerce subcontractor
The site is hosted on WIX which provides us with the online e-commerce platform that allows us to sell our services and products to you.
Your data is stored in the WIX data storage system and databases, and in the general WIX application. Your data is stored on a secure server protected by a firewall.
If you make your purchase through a direct payment gateway, then WIX will store your credit card information. This information is encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction information is retained for as long as necessary to complete your order. Once your order is finalized, your purchase transaction information is deleted.
All direct payment gateways are PCI-DSS compliant, managed by the PCI Security Standards Council, which is a joint effort of companies such as Visa, MasterCard, American Express and Discover.
PCI-DSS requirements ensure the secure processing of credit card data by our store and its service providers.
For more information, please see the WIX Terms of Service or the Privacy Policy.
9. Changes
We may change this Privacy Policy, in accordance with applicable law.
If you are registered with our site, we will notify you by email of the update.
10. Applicable law and jurisdiction
This policy is governed by Belgian law, without prejudice to any mandatory consumer or data subject protection provisions to the contrary.
Any dispute relating to this policy will be under the exclusive jurisdiction of the French-speaking courts of Nivelles, without prejudice to any mandatory provisions protecting the consumer or the person concerned that would go in the opposite direction.