Privacy policy
Jeļena Jerkina (hereinafter referred to as the “Company”), registration number 210183-10705, VAT No. LV210183-10705, registered address: Miglas iela 35, Bukulti, LV-1024, is committed to protecting and respecting your privacy in accordance with the requirements of the General Data Protection Regulation (GDPR) and the legislation of the Republic of Latvia.
The purpose of this Privacy Policy is to inform you about how we process your personal data, what data we collect, for what purposes, and how you can withdraw your consent to the processing of personal data.
Please read this Privacy Policy carefully. If you have any additional questions, please contact us using the contact information provided in this policy.
I. Data Controller and Contact Information
1.1. The Data Controller of personal data processing is Jeļena Jerkina, Brīvības iela 403, Riga, LV-1024, email: [email protected]; phone: +371 26691010.
II. Purposes of Personal Data Processing
2.1. We process your personal data for the following purposes:
2.1.1. Provision and Administration of Health Care Services:
- Client identification;
- Scheduling appointments with the cosmetologist;
- Maintaining client documentation in accordance with regulatory requirements;
- Reminders about scheduled visits;
- Conducting consultations and procedures;
- Assessing the health status of clients or other individuals;
- Administration of payments;
- Reviewing client objections and quality control;
- Preparation, conclusion, and execution of contracts with clients.
2.1.2. Operation of the E-shop:
- Processing and fulfilling orders in our online store www.skinique.lv;
- Ensuring the delivery of goods to your specified address;
- Communicating with you about order status and responding to your inquiries.
2.1.3. Payment Processing:
- Administration of payments for provided services and sold goods.
2.1.4. Communication:
- To contact you regarding service provision, order fulfillment, delivery, and other matters related to our activities.
2.1.5. Sending News and Offers:
- If you have given your consent, we may send you information about news, promotions, and special offers.
2.1.6. Improving Website Functionality:
- To analyze website traffic and improve its operation.
III. Legal Basis for Personal Data Processing
3.1. We process your personal data based on the following legal grounds:
- Consent: You have given your consent to the processing of personal data (Article 6(1)(a) and Article 9(2)(a) of the GDPR).
- Contract Performance: To perform a contract with you or to take steps at your request prior to entering into a contract (Article 6(1)(b) of the GDPR).
- Legal Obligation: To fulfill our legal obligations under regulatory acts (Article 6(1)(c) of the GDPR).
- Legitimate Interests: To pursue our legitimate interests (Article 6(1)(f) of the GDPR), such as ensuring efficient service provision, website operation, and handling complaints.
- Processing of Health Data: For the provision of health care services in accordance with regulatory acts (Article 9(2)(h) of the GDPR).
IV. Scope of Processed Personal Data
4.1. We may process the following categories of your personal data:
- Identification Data: First name, last name, personal identification number.
- Contact Information: Phone number, email address, residential address.
- Health Data: Information about health status, past illnesses, received and planned health care services necessary for the provision of cosmetology services.
- Payment Information: Bank account number, payment history.
- Technical Information: IP address, cookies, and other data related to website visits.
V. Categories of Personal Data Recipients
5.1. To ensure service provision and the operation of the e-shop, we may transfer your personal data to the following parties:
- Payment Processing Service Providers: To process payments, we transfer the necessary personal data to the authorized processor Maksekeskus AS.
- Delivery Service Providers: To ensure the delivery of goods, we transfer the necessary data to delivery service providers (e.g., Omniva).
- State and Municipal Authorities: In cases and to the extent prescribed by regulatory acts.
- IT Service Providers: For the maintenance of our website and information systems.
- Law Enforcement and Supervisory Authorities, Courts: If necessary to protect our legitimate interests or as required by regulatory acts.
VI. Transfer of Personal Data to Third Countries or International Organizations
6.1. We do not transfer your personal data to countries outside the European Union and the European Economic Area, except when necessary and in compliance with GDPR requirements.
VII. Rights of the Data Subject
7.1. You have the right to:
- Access Your Data: Request confirmation of whether we are processing your personal data and receive a copy of it.
- Rectify Data: Request the correction of inaccurate or incomplete personal data.
- Erase Data: Request the deletion of your personal data (“right to be forgotten”) if there are grounds specified in regulatory acts.
- Restrict Processing: Request the restriction of personal data processing in certain cases.
- Object to Processing: Object to the processing of personal data based on our legitimate interests.
- Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format and transfer it to another controller.
- Withdraw Consent: Withdraw your consent to personal data processing at any time.
7.2. To exercise your rights, please contact us by writing to [email protected].
7.3. If you believe that we are processing your data in violation of data protection regulatory requirements, you have the right to file a complaint with the Data State Inspectorate (www.dvi.gov.lv).
VIII. Security of Personal Data
8.1. We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction.
8.2. Our partners and service providers are carefully selected, and we require them to ensure adequate personal data protection in accordance with regulatory acts.
IX. Retention of Personal Data
9.1. We retain your personal data for as long as necessary to achieve the purposes outlined in this Privacy Policy or as required by regulatory acts.
9.2. Health data is retained in accordance with the terms and requirements specified in regulatory acts.
9.3. After the retention period expires, personal data will be irreversibly deleted or anonymized.
X. Necessity of Providing Personal Data
10.1. Providing your personal data is necessary for us to offer you services and ensure the operation of the e-shop. If you do not provide the required personal data, we will be unable to provide the services.
XI. Withdrawal of Consent
11.1. You can withdraw your consent to personal data processing at any time by writing to [email protected].
11.2. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
XII. Changes to the Privacy Policy
12.1. We reserve the right to make changes to this Privacy Policy by publishing the updated version on our website www.skinique.lv.
12.2. Last updated: [24.09.2024.].
XIII. Contact Information
If you have any questions or wish to exercise your rights, please contact us:
- Email: [email protected]
- Address: Miglas iela 35, Bukulti, LV-1024
- Phone: +371 26691010
This Privacy Policy is designed to ensure the security of your personal data and transparency regarding its processing. We respect your privacy and are committed to protecting your personal data in accordance with applicable regulatory acts.