Taffy Lilly Ltd., identification number: 8455201000 (hereinafter referred to as "we" only), pays close attention to the protection of personal data. This document provides information about what personal information we process, especially about our customers and users of our online store, whether we process this information on the basis of consent or other legal basis, for what specific purposes we use it to whom we may share it. and what your rights are in relation to the processing of your personal information.

What kind of personal information do we process?

When you use our services, we collect different types of your information, such as your username and password, your contact information, and other settings. We track what items you view in our online store, what device and which of our email offers you were interested in. Based on this, we create additional information so that we can provide you with the offers you want and that we can further improve our online store and services in the future. If you make a purchase or create an account with us, we also process your first and last name, your orders and the information you set on your account.

We process the following personal information:

  1. Identification information, which includes primarily the first and last name, username and password;
  2. contact information that includes personal information that we can use to contact you, especially your email address, telephone number, shipping address, billing address;
  3. your settings, which include your account information, notably stored shipping addresses, profiles, newsletter subscriptions, loyalty program memberships, shopping lists, items searched for, your ratings and comments on items and services;
  4. information about your orders, which include, in particular, information about the items ordered and your payment method, including your bank account number, and claims information;
  5. information about your online habits, including when you are browsing the Web through our mobile app, especially information about the items and services you are looking for, the links you click on, how we search and navigate our site, and device information, which you access on the web, such as IP address and associated location, device ID, its technical parameters such as operating system, version, screen resolution, selected browser and version thereof, and information obtained from cookies and similar recognition technologies devices;
  6. information about your behavior in relation to reading the messages we send you, especially the time it takes to open the message and information about the devices from which you access the web, such as IP address and associated location, device ID, its technical parameters, such as is the operating system, version, screen resolution, browser selected, and version thereof;
  7. derived information, including personal information obtained from your preferences, information about items you buy from us, information about your online habits and behavior;
  8. information in connection with the use of a telephone number, which primarily includes telephone call center records, identification of the messages you send us, including identifiers such as IP addresses.

 

Why are we processing personal information and why are we entitled to it?

We process your personal information in different situations for different purposes. When you visit the websites of our online store, where we also use cookies, we use your information primarily to determine the number of visitors and improve our services. If you are registered with us, we use your information to manage your account and provide related functionality. If you make a purchase with us, we use your information to process your order, protect our legal claims, and fulfill our legal obligations. With the help of your contact information and other information, we can simultaneously display and send you our personalized offers. With your consent, we provide information to third parties to display the offer on other websites, as well as to give you access to certain additional services. We have the right to the processing of your personal data on the basis of the preparation or performance of a contract with you, compliance with legal obligations, our legitimate claims or your consent.

Within our activity we process personal data for different purposes and to a different extent, namely:

  1. without your consent based on the performance of the contract, our legitimate interest or for the purpose of fulfilling our legal obligations, respectively
  2. On behalf of your consent.

 

What kind of data processing we can perform without your consent depends on the purpose for which the relevant processing is related and how you treat us - whether you are just a visitor to our online store, register with us or buy something. We may also process your information if you are the recipient of the goods or services that have been subscribed to us, if you are communicating with us.

 

If you visit our online store

Use of cookies and other technologies, transmission of data to advertising and social networks

If you visit our online store, we store and store small files such as cookies on your device. A cookie is a small collection of letters and numbers stored on your web browser or your computer's hard drive. Some cookies allow us to interconnect your activities while browsing our pages from the moment you open your web browser to the moment you close it. The moment you close your web browser window, the corresponding cookies are deleted. However, some cookies remain on the device for a set time and are activated every time they visit the websites that created the cookies. We also use web beacons (also known as web beacons). These are small images that have a similar function to cookies. Compared to cookies stored on your computer's hard drive, web signals are an integral part of web pages. For the sake of simplicity, we will only refer to these technologies as cookies in the following document. We store cookies on your device, and those stored on your device by our sites are read as well. For the sake of simplicity, we will only talk about storage for simplicity.

Some cookies are stored directly on your device by our websites. Such cookies help us:

Such cookies and other files are indispensable for the operation of our online store. If you disable cookies on your browser, our web pages may not work properly and we may not be able to provide you with any of our products and services.

We also store the following on your device:

 

For the purpose of displaying personalized offers and tailored ads within advertising and social networks on other websites outside our domain, we also provide information about your behavior on the Internet to advertisers and social networks. However, we do not provide your partners with your identification information. The list of social and advertising networks we use is listed under Who processes your personal information and who we share it with.

If you do not disable the use of third-party cookies and provide your information to the advertising and social networks under the Cookies tab, and after our warning, click on any link on our web pages (outside the alert box) or click on the "I understand" button that is part of the alert , you are deemed to agree to the use of these cookies and the provision of your information to advertising and social networks. You can withdraw your consent at any time by prohibiting this feature under the Cookies tab.

 

Use of personal information of website visitors

When you visit the Taffy & Lilly Online Store, we process information about your online behavior based on our legitimate interest (that is, without your consent) for the purposes of:

 

We do not collect information about your behavior on web pages only through cookies. We also supplement them with the following information:

 

For this purpose, we use personal data for a maximum of 38 months, keeping the data only in pseudonymized form, ie without connection to your identifying information (name, address, etc.).

We also process information about your behavior on the websites based on our legitimate interest (i.e. without your consent) to prepare personalized offers and tailored ads that we serve online. In this case, our legitimate interest is to tailor-make and offer you as effectively as possible. Namely, we also disseminate the named data by means of analysis and derive derived data from them. According to this information, we can group our users into different groups, with each group receiving its own customized quotes. If you then buy anything from us, we will additionally use your order information for this purpose.

So if you were looking for dry dog food in our online store or clicked on the offer in the email we sent you, that food may appear on the first page of our online store at your next visit. Based on what kind of food you were looking for, we can estimate which customer group you belong to. Based on this, we can offer you other items in our online store that you think may be of interest to you.

For this purpose, we use personal information for 1 month.

 

If you register with us

In order to register you, you must visit our online store, so the processing described in your visit to our site applies to you. If you register, your data processing is expanded as follows:

Processing based on contract

If you create an online Taffy Lilly account, we process your identification and contact information, your settings and your order information (if you make a purchase with us later) based on the performance of a contract with you (without your consent) so that we can maintain your account. The contract on which our processing is based is formed at the same time as your account. For this purpose, we use personal information for the entire duration of your account, which can be deleted at any time.

Processing on the basis of legitimate interest

If you create an account at the Taffy Lilly Online Store, we process your identification and contact information, your preferences and your order information (if you make a purchase with us later, even if you make a purchase without logging into your account) and your online behavior and e-mail reading behavior also based on our legitimate interest (ie without your consent) for the following purposes:

 

In order to prepare a custom online store offer for you, we analyze all of the above information and derive other derived information that we use for that purpose. In this way, we may also use information about your online behavior that we obtained prior to your registration. Based on this information, we can break down our users into different groups, with each group receiving their own customized quotes.

Therefore, if you were looking for dry dog food in our online store or clicked on the offer in the email we sent you, this dog food may appear on the first page of our online store at your next visit. Based on what kind of food you were looking for, we can estimate which customer group you belong to. Based on this, we can offer you other items on our web pages that you think may be of interest to you.

Based on our legitimate interest (that is, without your consent), we may also use your preferences to test new features and applications before launching, as described in the If You Visit Our Websites section.

To this end, we use your personal information at the time of your account's existence, which can be deleted at any time.

 

If you make a purchase with us

In order to make a purchase with us, you need to visit our online store, so the treatments described in the If you visit our web pages tab apply to you. If you make a purchase with us, your data processing is expanded as follows:

Processing based on contract

If you make a purchase with us, we process your personal information for the purpose of processing your order. It is identification and contact information and information about your orders. If you have a user account with us, we can also use your settings for this purpose.

If you make a purchase with us as a legal representative, we process the same information for the same purpose based on our legitimate interest, based on the conclusion and performance of a contract with the person you represent.

Using information to process your order means that we use the information specifically to:

 

For this purpose, we use personal information at the time strictly necessary to process your order or. resolution of contractual obligations such as complaints.

 

Processing on the basis of legitimate interest

If you make a purchase with us, we store your identification and contact information and your order information based on our legitimate interest (without your consent) for the purposes of safeguarding legal claims and our internal records and controls. Our legitimate interest in this case is to safeguard legal claims and to monitor the regular performance of our services.

Further, based on our legitimate interest (ie without your consent), we process your identification and contact information, your preferences and your order information (if you make a purchase with us later) for the purposes of:


Therefore, if you have purchased dry dog food from us, we can address you with a tailored offer for an additional purchase. Based on your purchase, we can also determine which customer group you belong to. Based on this, we can send you an offer for related items that may be of interest to you. If you do not have an account with us, we will not adjust your bids based on what kind of goods you have searched for on our web sites or on what links you have opened in the submitted offers.

For the purpose of designing custom bids and tailored ads that we display on webpages, as described in the section If you visit our webpages, we also use your order information.

We measure your satisfaction with our services based on an NPS survey that we send to you by email. We send the questionnaire to random users who have made a purchase with us last month. The results of the survey are for our own use only.

In order to safeguard legal claims and maintain our internal records and controls, we process data for a period of 3 years and for a further 1 year thereafter in relation to claims that are due by the end of the statute of limitation. In the case of legal, administrative or other proceedings, we process your personal information for the period necessary for the duration of such proceedings and for the remainder of the statute of limitations after its completion.

For the purpose of safeguarding legal claims and our internal records and controls, we process data for the duration of the limitation period, which is 5 years, if necessary, one year after its expiry in the event of a valid claim at the end of the limitation period. When initiating legal, administrative or other proceedings, we process your personal data during the time strictly necessary to complete such proceedings, and until the rest of the limitation period has expired after its completion.

For the other purposes stated above, we use personal information for a maximum of 6 months,

You may object to such processing, which is performed on our legitimate interest.

 

3.3 Processing based on fulfillment of legal obligations

We too must fulfill certain obligations prescribed by Slovenian law. If we process your personal data for this reason, we do not need your consent to such data processing. On this legal basis, we process your identification and contact information, procurement information, in order to comply with the laws in force at any time, which are, in particular, the following at the time of drafting the Memorandum:

 

For this purpose, we use personal information for a maximum of 10 years (plus the current year) after the last document issued regarding your order.

 

If you are the recipient of goods or services that have been ordered from us

If you are the recipient of goods or services that have been ordered from us, we process your identification and contact information:

 

We use personal information to prepare, conclude and execute a contract with our client during the time strictly necessary to process the order. Upon expiry of this time, we continue to retain the information on the basis of our legitimate interest for the purpose of safeguarding legal claims and our internal records and controls, during the limitation period of 5 years, and, if necessary, one year after its expiry in the event of an enforced one. claims at the end of the limitation period. When initiating legal, administrative or other proceedings, we process your personal data during the time strictly necessary to complete such proceedings, and until the rest of the limitation period has expired after its completion. Our legitimate interest in this case is to safeguard legal claims and to monitor the regular performance of our services. For the purpose of fulfilling our legal obligations, we use personal data for a maximum of 10 years per order.

If you have concerns about this kind of processing based on a legitimate interest, please contact us.

 

If you communicate with us through different channels:

If you communicate with us through various channels, in particular via e-mail, chat rooms and social networks, your identification and contact information and records of communication, including recordings of speeches, are processed based on our legitimate interest (ie without your consent) for the purposes of:

 

For this purpose, we keep personal information for a period of 3 months. If you place orders through one of our channels, we may retain information to protect legal claims for a statute of limitation of 5 years and for a further period of one year after the expiry of the claims that have been enforced at the end of the statute of limitations. In the case of legal, administrative or other proceedings, we process your personal information to the extent necessary for the duration of such proceedings and the remainder of the statute of limitations after its termination.

If you have concerns about this kind of processing based on a legitimate interest, please contact us.

 

Who processes your personal information and who we share it with?

In most cases, we process your data for our own purposes as their controller. In this case, we provide your information to our partners to provide payment, transportation and other matters related to your order. We also provide information to our processors who process it according to our instructions. With your consent, we may also share information with our advertising and social networks to serve customized ads on other websites.

We process all personal information described as a controller. This means that we determine the purposes defined above, for which we collect your personal data and the processing methods, and are responsible for the proper implementation of this information.

We may also share your personal information with other entities that also have a processor role, such as:

 

From what sources do we obtain personal information?

We mostly collect personal information directly from you through our online store or when communicating with you. Some other information can also be obtained from our partners, e.g. banks or transport companies.

We mostly process personal information you provide to us directly when ordering items and services, during the creation and use of an account, or when communicating with us, such as a call center. We also obtain personal information directly from you by monitoring your online habits while browsing our online store or when reading our messages, recording calls via a phone number.

If you make a purchase with us, we may receive additional information regarding your execution of the purchase agreement from your banks, our payment management partners and our transport partners, e.g. information about your account number, successful payments, or delivery and pickup.

 

Transmission of data outside EU countries

In some cases, your personal information may also be transmitted to countries not members of the European Economic Area.

As part of the communication of information to the recipients mentioned in the section Who processes your personal data and with whom we share it, we may also transmit your information to third countries outside the European Economic Area, where an adequate level of personal data protection is not necessarily guaranteed. Any such intervention will only be undertaken if the recipient concerned undertakes to comply with the standard contractual provisions issued by the European Commission, which are available also at https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:32016R0679&from=EN

 

What are your rights in relation to the processing of personal data?

You have many rights in connection with your personal information. These include the right to access, review, delete and restrict the processing, transmission, objection and appeal. You can also follow all this HERE.

Just as we have our rights and obligations regarding the processing of your personal information, you also have certain rights in connection with the processing of your personal data. These rights include:

 

Right to be informed

Simply put, you have the right to find out what information we collect about you, for what purposes, and for how long, where we collect your personal information from, who we share it with, who processes it with us, and what your other rights are in connection with the processing of your personal information. You can read all this in the document "Protecting Customer Personal Information". However, if you are not entirely sure what personal information we collect about you, you can ask us to confirm whether we collect personal information about you or not, and if so, you have the right to become aware of that information. In accordance with the right to be informed, you can request a copy of the processed data from us, and we will provide you with a first copy for free and any further copy for a fee.

Right to change

Being wrong is human. If you notice that the personal information we hold about you is incorrect or incomplete, you have the right to request that we correct or supplement it as soon as possible.

Right of erasure

In some cases, you have the right to delete your personal information. We will delete your personal information as soon as possible if any of the following is fulfilled:

 

However, please be aware that even if any of the reasons described above are met, this does not mean that all your personal information will be deleted immediately. However, this right cannot be exercised if the processing of your personal data continues to be necessary for the fulfillment of our legal obligations or for the determination, execution or defense of our legal claims (see Why we process personal data and why we are entitled to do so).

Right to restrict data processing

In some cases, in addition to the right of erasure, you may also exercise the right to restrict the processing of personal data. This right allows you to request, in certain cases, that your personal data be specifically marked and exempted from any processing operations - in which case the effect is limited in time (not as lasting as in the right of erasure). We must restrict the processing of personal data:

 

Right to data portability

You have the right to obtain from us all of your personal information that you have provided to us and which we process based on your consent (see section If you give us your consent) and on the performance of the contract. We provide your personal information in a structured, established and machine-readable format. Easy data transfer is only possible for data that is automatically processed in our electronic databases.

Right to object to data processing

On grounds relating to your particular situation, you have the right to object to the processing of personal data based on point (e) or (f) of Article 6 (1) of Regulation (EU) 2016/679 and to object to the processing of data for the purposes direct marketing (see Why we process personal information and why we are entitled to it.). We will immediately stop processing your information for marketing activities; in other cases, we will do the same unless we have legitimate reasons to process which outweigh your rights or to enforce legal claims.

Right of appeal

The enforcement of the above rights shall in no way affect your right to lodge a complaint with the competent authority. This right can be exercised especially if you suspect that we are processing your personal information unjustifiably or contrary to generally binding legal provisions. You can contact the Information Commissioner at Bezjakova 29, 2341 Limbuš for information about processing of information we perform on our site.

 

How can you establish certain rights?

Just look at and complete things on the GDPR toolbar page or give us a call so we can help you.

We ask users without registration to fill in the additional information we need to process the application. In case of ambiguity or questions in this regard, you can contact us at info@taffylilly.com, tel .: +386 31 524 090) and our operators will assist you.

We will respond to your request as soon as possible, but in any case within one month. In exceptional cases, especially in the case of more complex claims, we have the right to extend this deadline by two additional months. In the event that such an extension would be necessary and of course the reasons for it will be notified.

 

Personal Data Protection Officer

In all matters relating to the processing of your personal data, our personal data protection officer is at your disposal.

The Commissioner can be contacted by e-mail: info@taffylilly.com , please add  "For DPO" in the email subject, which means "Data Protection Officer".