Privacy Policy

1. General Provisions

1.1. This privacy policy governs the principles for the collection, processing, and storage of personal data. Personal data is collected, processed, and stored by the data controller Miisumiisu OÜ (hereinafter referred to as the data processor).

1.2. A data subject within the meaning of this privacy policy is a customer or any other natural person whose personal data is processed by the data controller.

1.3. A customer within the meaning of this privacy policy is anyone who purchases goods or services from the data controller’s website.

1.4. The data controller complies with the principles of data processing set out in applicable legislation, including processing personal data lawfully, fairly, and securely. The data controller is able to confirm that personal data is processed in accordance with applicable legal requirements.


2. Collection, Processing, and Storage of Personal Data

2.1. The personal data collected, processed, and stored by the data controller is obtained electronically, mainly via the website and email.

2.2. By providing their personal data, the data subject grants the data controller the right to collect, organize, use, and manage personal data for the purposes defined in this privacy policy, which the data subject provides directly or indirectly when purchasing goods or services through the website.

2.3. The data subject is responsible for ensuring that the data provided is accurate, correct, and complete. The intentional submission of false data is considered a violation of this privacy policy. The data subject is obliged to immediately notify the data controller of any changes to the provided data.

2.4. The data controller is not responsible for any damage caused to the data subject or third parties due to the submission of incorrect data by the data subject.


3. Processing of Customers’ Personal Data

3.1. The data controller may process the following personal data of the data subject:

3.1.1. First and last name;
3.1.2. Date of birth;
3.1.3. Telephone number;
3.1.4. Email address;
3.1.5. Delivery address;
3.1.6. Bank account number;
3.1.7. Payment card details.

3.2. In addition, the data controller has the right to collect data about the customer that is available in public registers.

3.3. The legal basis for processing personal data is Article 6(1)(a), (b), (c), and (f) of the General Data Protection Regulation:

a) the data subject has given consent to the processing of their personal data for one or more specific purposes;
b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract;
c) processing is necessary for compliance with a legal obligation to which the controller is subject;
f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.


3.4. Purposes of processing and retention periods

3.4.1. Purpose – security and safety
Maximum retention period – according to legal requirements.

3.4.2. Purpose – order processing
Maximum retention period – 3 years after the last purchase, unless accounting regulations require longer retention.

3.4.3. Purpose – ensuring the operation of the online store services
Maximum retention period – until the user account is deactivated or 2 years after the last activity in the online store.

3.4.4. Purpose – customer management
Maximum retention period – 3 years after the last customer interaction or purchase.

3.4.5. Purpose – financial activities, accounting
Maximum retention period – according to legal requirements.

3.4.6. Purpose – marketing
Maximum retention period – until consent is withdrawn or 3 years after the last active interaction (e.g. purchase or opened marketing email).


3.5. The data controller has the right to share customers’ personal data with third parties such as authorized processors, accountants, transport and courier companies, and payment service providers. The data controller is the controller of personal data. For payment processing, personal data necessary for transactions is transferred to the authorized processor Maksekeskus AS.

3.6. When processing and storing personal data, the data controller applies organizational and technical measures to ensure protection against accidental or unlawful destruction, alteration, disclosure, or any other unlawful processing.

3.7. The data controller retains personal data depending on the purpose of processing, but not longer than 7 years.


4. Rights of the Data Subject

4.1. The data subject has the right to access and review their personal data.

4.2. The data subject has the right to receive information about the processing of their personal data.

4.3. The data subject has the right to supplement or correct inaccurate data.

4.4. Where processing is based on consent, the data subject has the right to withdraw consent at any time.

4.5. The data subject may exercise their rights by contacting customer support at info@miisu.eu.

4.6. The data subject also has the right to file a complaint with the Data Protection Inspectorate.


5. Final Provisions

5.1. These data protection terms have been prepared in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the Estonian Personal Data Protection Act, and other applicable legal acts of the Republic of Estonia and the European Union.

5.2. The data controller has the right to amend these data protection terms partially or in full by notifying data subjects of the changes via the website miisu.eu.