Privacy Policy

The data controller for personal data of the decobox.ee online store is decobox OÜ (registration code 17001374), located at Aardla 25e Tartu 50110. Phone +372 51 911 944 and email info@decobox.ee.

decobox OÜ transfers the personal data necessary for processing payments to the authorized processor Montonio Finance UAB.

What Personal Data is Processed
  • name, phone number and email address
  • shipping address
  • bank account number
  • cost of goods and services and payment-related data (purchase history)
  • customer support data
  • IP address
Purpose of Processing Personal Data

Personal data is used for managing customer orders and delivering goods.
Purchase history data (date of purchase, product, quantity, customer data) is used to compile an overview of purchased goods and services, analyze customer preferences, and resolve consumer disputes.

The bank account number is used for refunding payments to the customer.
Personal data such as email, phone number, and customer name are processed to resolve issues related to the provision of goods and services (customer support). Email is also used for sending invoices, and the phone number is used for notifying about goods that have arrived at a parcel locker, as well as for arranging suitable courier service times.
The IP address or other network identifiers of the online store user are processed for providing the online store as an information society service and for generating web usage statistics.

Legal Basis

Personal data is processed for the purpose of fulfilling a contract concluded with the customer (managing customer orders, delivery, returning goods and payments).
Personal data is processed to fulfill a legal obligation (e.g., accounting and resolving consumer disputes).
The processing of personal data is necessary due to the legitimate interest of the data controller, which consists of collecting purchase history data for the purpose of resolving potential consumer disputes.

Recipients to whom Personal Data is Transferred

Name, phone number, and email address are transferred to the transport service provider chosen by the customer. If the goods are delivered by courier, the customer’s address is also transferred in addition to contact details.
If the online store’s accounting is handled by a service provider, personal data is transferred to the service provider for accounting purposes.
Personal data may be transferred to information technology service providers if necessary to ensure the functionality or data hosting of the online store.

Security and Data Access


Personal data is stored on Elkdata OÜ servers located in the territory of an EU member state or countries that have joined the European Economic Area. Data may be transferred to countries whose data protection level has been deemed adequate by the European Commission, or to a third-country company for which the safeguards referred to in Article 46 have been applied.
Access to personal data is granted to online store employees who can view personal data to resolve technical issues related to the use of the online store and provide customer support services.
The online store implements appropriate physical, organizational, and IT security measures to protect personal data against accidental or unlawful destruction, loss, alteration, or unauthorized access and disclosure.
The transfer of personal data to authorized processors of the online store (e.g., transport service provider and data hosting) takes place based on agreements concluded between the online store and the authorized processors. Authorized processors are obliged to ensure appropriate protective measures when processing personal data.

Access and Rectification of Personal Data


Personal data can be accessed and corrected in the online store’s user profile. If a purchase was made without a user account, personal data can be accessed via customer support. If a request for access to personal data is submitted electronically, information will also be provided via commonly used electronic means.

Withdrawal of Consent


If the processing of personal data is based on the customer’s consent, the customer has the right to withdraw consent under the customer account settings or by notifying customer support via email.

Retention

Upon closing an online store customer account, personal data is deleted, except for personal data (purchase history data) that needs to be retained for accounting purposes or for resolving consumer disputes. In the event of disputes related to payments and consumer disputes, personal data is retained until the claim is
fulfilled or until the expiry of the limitation period. Personal data contained in original accounting documents is retained for seven years.

Restriction of Processing

The customer has the right to request the restriction of processing of their personal data if the data is inaccurate or incomplete, or if their personal data is processed unlawfully.

Right to Object


The customer has the right to object to the processing of their personal data if they have reason to believe that there is no legal basis for processing their personal data.

Deletion

To delete personal data, please contact customer support via email. Deletion requests will be answered within one month, and the data deletion period will be specified.
The response to the request will also state which personal data will not be deleted and on what legal basis and for what reason.

Data Portability


Requests for the transfer of personal data submitted via email will be answered within one month at the latest.
Customer support will verify identity and inform about the personal data eligible for transfer.

Direct Marketing Communications


Email address and phone number are used for sending direct marketing communications if the customer has given their consent. If the customer does not wish to receive direct marketing communications, they should select the corresponding link in the email footer or contact customer support.
If personal data is processed for direct marketing purposes (profiling), the customer has the right to object at any time to the initial and further processing of their personal data, including profiling related to direct marketing, by notifying customer support via email.

Dispute Resolution


Disputes related to the processing of personal data are resolved through customer support by sending an email to info@decobox.ee or calling +372 51 911 944.
The supervisory authority is the Estonian Data Protection Inspectorate (info@aki.ee).

Fast Delivery
Products delivered within 5 business days in Estonia, and within 14 days to Finland, Latvia, and Lithuania!
Secure Payments
Securely pay with bank link and installment options!
Customer Service 10:00 AM - 5:00 PM
We answer your inquiries Monday to Friday, 10:00 AM - 5:00 PM, by phone and email!
Money-Back Guarantee
We refund 100% of the costs for all canceled and returned orders!