Privacy Policy
1. General Provisions
1.1. This Privacy Policy (hereinafter referred to as the "Policy") outlines the principles and practices of ZORA TRADE 12 LTD (hereinafter referred to as the "Provider") regarding the collection, processing, storage, and protection of personal data of customers obtained during the sale of coffee and instant products through the online store.
1.2. This Policy is prepared in accordance with applicable legislation, including the Personal Data Protection Act and the General Data Protection Regulation (GDPR).
Collection of Personal Data
2.1. The Provider collects personal data under the following circumstances:
When registering a user profile on the online store.
When placing an order for products.
When subscribing to newsletters or promotions.
When directly communicating with the customer (e.g., via email, phone).
2.2. The personal data that may be collected includes, but is not limited to:
First and last name
Delivery address
Phone number
Email address
Payment details (including credit/debit card number information, if necessary)
Information about previous orders (purchase history)
Purpose of Processing Personal Data
3.1. The collected personal data will be processed for the following purposes:
Processing and fulfilling orders, including delivery and invoicing.
Communicating with the customer regarding the order status, as well as informing about new products and promotions.
Administrative purposes related to managing customer profiles.
Improving the Provider's products and services by analyzing customer behavior and preferences.
Legal Basis for Processing
4.1. The processing of personal data is based on the following legal grounds:
Fulfillment of contractual obligations related to the sale of goods.
Customer consent when subscribing to receive newsletters and information about promotions.
Legal obligations for data retention (e.g., for accounting purposes).
Storage of Personal Data
5.1. Personal data is stored securely in digital format on servers and in paper format, where applicable.
5.2. The personal data of customers will be stored for the period necessary for the purposes for which it was collected:
Order data: 5 years after the last order.
Customer data with profiles: until the customer decides to delete their profile or unsubscribe from the newsletter.
5.3. After the expiration of the relevant period, personal data will be anonymized or securely destroyed.
Protection of Personal Data
6.1. The Provider applies the necessary technical and organizational measures to protect personal data from accidental loss, unauthorized access, disclosure, or destruction.
6.2. Access to personal data is restricted only to authorized employees of the Provider and partners who process data on behalf of the Provider, and only for the purposes stated in this Policy.
6.3. We guarantee that all employees who process personal data are trained on the importance of data protection and are aware of the appropriate security procedures.
Data Subject Rights
7.1. Customers have the following rights regarding their personal data:
Right of access: The right to request information about the processed personal data and a copy of it.
Right to rectification: The right to request the correction of inaccurate or incomplete data.
Right to erasure: The right to request the deletion of personal data under certain circumstances (e.g., when the data is no longer necessary).
Right to restriction of processing: The right to request the restriction of processing personal data under certain conditions.
Right to data portability: The right to receive personal data in a structured, commonly used, and machine-readable format.
Right to object: The right to object to the processing of personal data, especially in the case of direct marketing.
7.2. To exercise their rights, customers can contact us using the provided contact details.
Sharing of Personal Data
8.1. The Provider does not sell, distribute, or lease personal data to third parties. Personal data may be shared only in the following cases:
With service providers who perform services on our behalf (e.g., couriers, payment companies), provided that they comply with the same data protection rules.
In compliance with legal obligations or upon request from public authorities.
8.2. The Provider ensures that every third-party service provider processing personal data signs a confidentiality agreement and complies with the personal data protection rules.
Changes to the Policy
9.1. The Provider reserves the right to update and modify this Privacy Policy. All changes will be published on the website and will take effect from the moment of publication.
9.2. Customers will be notified of significant changes to the Policy by email or through a notification on the website.
9.3. We recommend that customers periodically review this Policy to stay informed about how we protect their personal data.