1. General Provisions
1.1. This Privacy Policy governs the principles for collecting, processing, and storing personal data. The personal data controller is AM Music OÜ (hereinafter referred to as the "Controller").
1.2. The data subject within the scope of this Privacy Policy is any individual whose personal data is processed by the Controller.
1.3. A client within the scope of this Privacy Policy refers to any individual who purchases goods or services through the website www.alikamusic.eu.
1.4. The Controller adheres to the principles of data processing established by applicable laws, ensuring that personal data is processed lawfully, fairly, and securely. The Controller can confirm that personal data is processed in compliance with legal requirements.
2. Collection, Processing, and Storage of Personal Data
2.1. Personal data collected, processed, and stored by the Controller is primarily obtained electronically via the website and email.
2.2. By sharing their personal data, the data subject grants the Controller the right to collect, organize, use, and manage personal data for the purposes defined in this Privacy Policy.
2.3. The data subject is responsible for ensuring that the information they provide is accurate, correct, and complete. Providing knowingly false information is considered a breach of this Privacy Policy. The data subject must notify the Controller promptly of any changes to the provided data.
2.4. The Controller is not liable for damages caused to the data subject or third parties resulting from the provision of incorrect data by the data subject.
3. Processing of Client Personal Data
3.1. The Controller may process the following personal data of the data subject:
- First and last name
- Phone number
- Email address
- Delivery address
(Note: Update this list based on the specific data collected. Remove items not applicable.)
3.2. Additionally, the Controller has the right to collect publicly available data about the client from public registers.
3.3. The legal basis for processing personal data is Article 6(1) of the General Data Protection Regulation (GDPR):
- (a) The data subject has given consent for the processing of their personal data for one or more specific purposes.
- (b) Processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract.
- (c) Processing is necessary for compliance with a legal obligation to which the Controller is subject.
- (f) Processing is necessary for the purposes of the legitimate interests pursued by the Controller or a third party, except where such interests are overridden by the data subject's interests or fundamental rights and freedoms.
3.4. Processing purposes and retention periods:
- Security and safety: Retained in accordance with legal timeframes.
- Order processing: Retained for [Insert Duration].
- E-commerce service functionality: Retained for [Insert Duration].
- Customer management: Retained for [Insert Duration].
- Financial activities and accounting: Retained in accordance with legal requirements.
- Marketing: Retained for [Insert Duration].
(Note: Specify retention periods where indicated.)
3.5. The Controller may share personal data with third parties, including authorized processors, accountants, delivery and courier companies like Smartpost Itella, and payment service providers such as Maksekeskus AS, as necessary for payment processing.
3.6. Organizational and technical measures are implemented to protect personal data from accidental or unlawful destruction, alteration, disclosure, or any other unlawful processing.
3.7. Personal data is stored depending on the purpose of processing but no longer than 10 years.
4. Rights of the Data Subject
4.1. The data subject has the right to access their personal data and review it.
4.2. The data subject has the right to receive information about the processing of their personal data.
4.3. The data subject has the right to correct or supplement inaccurate data.
4.4. Where processing is based on consent, the data subject has the right to withdraw their consent at any time.
4.5. To exercise their rights, the data subject can contact customer support at info@alikamusic.eu.
4.6. The data subject may file a complaint with the Estonian Data Protection Inspectorate if they believe their rights have been violated.
5. Final Provisions
5.1. This Privacy Policy is drafted in accordance with the GDPR (EU Regulation 2016/679), the Estonian Personal Data Protection Act, and applicable EU and Estonian legislation.
5.2. The Controller reserves the right to modify this Privacy Policy partially or in full by notifying data subjects via the website www.alikamusic.eu.
For questions about this Privacy Policy, please contact us at info@alikamusic.eu.