Privacy Policy

Introduction

This privacy policy ("Policy") describes how Trendful™️ ("we," "our," and "us") processes personal data.

We care about your personal privacy and want you to feel secure with our processing of your personal data. This Policy provides information on how we handle the personal data you provide to us when using our services and the personal data we collect in other ways. Regardless of whether you have used our services in the US or internationally, we are responsible for processing your personal data as the data controller. This means that we are obligated to ensure that the processing is conducted in accordance with this Policy and applicable data protection legislation.

The Policy outlines the categories of personal data we process, the purposes of processing, and the legal basis for processing. We also explain where we obtain the data, who may have access to it, the principles for data deletion, third parties we may share personal data with, where personal data is processed, and your rights as a data subject, including the right to information, rectification, and deletion. We ask you to read the Policy carefully and familiarize yourself with its contents as it applies to all our processing of personal data.

Please note that this Policy only applies to our website and mobile application. When you link from our website or mobile application to another website, the privacy policy of that other website applies. We are not responsible for other websites' processing of your personal data.

We may need to update or change this Policy from time to time. If so, we will inform you appropriately and ask you to review the changes made. The latest version of the Policy is always available on our website.

If you have further questions or concerns, you are always welcome to contact us using the contact form on our contact us page.

How We Process Your Personal Data

This section describes the categories of personal data we process, the purposes for which we process them, the processing activities performed, the legal basis for processing, and the retention periods.

2.1 Where Do We Collect Personal Data From? We process personal data that you provide to us when, for example, you create a user account, purchase goods via our website, initiate a customer service case, or subscribe to our newsletter.

We also process personal data obtained from our payment service provider (a third party) when you make a purchase, personal data obtained from public registers, and personal data generated when you use our online services or mobile application, such as your IP address and browser settings.

2.2 What Personal Data Do We Process and Why?

A. To Administer User Accounts

Purpose: To create and administer user accounts, including providing access to log into your account, offering features to facilitate the use of our services (e.g., placing orders and purchasing goods), and displaying your order history.

Processing Activities: Collecting and storing personal data in our business systems, backup systems, and other online storage spaces.

Categories of Personal Data:

  • Username
  • Email address
  • Customer type (individual/business)
  • Where applicable, name, phone number, and country
  • Password
  • Date of account creation
  • Order information, e.g., details of ordered goods (such data is also processed when you place an order without logging into your account)
  • Payment, purchase, and order history

Legal Basis: For active customers: The processing is necessary to fulfill the contract for the purchase of goods from us. For inactive customers: Legitimate interest. The processing is based on our legitimate interest in administering user accounts and providing our services.

Retention Period: Three (3) years from the creation of the account or your last purchase, after which your account will be closed and your data anonymized or deleted. If your account is closed at your request, your data will be anonymized or deleted within seven (7) days from the request.

B. To Manage Orders/Purchases

Purpose: To manage your orders/purchases (including sending order confirmations, notifying deliveries, delivering your ordered/purchased goods, and handling contacts in case of delayed deliveries). To handle complaints, warranty claims, and customer service inquiries regarding ordered/purchased goods. To conduct billing. To prevent misuse of our, our suppliers', or partners' services or prevent, investigate, and detect crimes. To establish your placed orders (through order number or personal identification number). To ensure our operational security and our ability to restore systems.

Processing Activities: Collecting and storing personal data in our business systems, backup systems, and other online storage spaces. Sending order confirmations, delivery notifications, and correspondence in case of delayed delivery. Transferring personal data to shipping and transport companies.

Categories of Personal Data:

  • Name
  • Username
  • Personal identification number
  • Contact information (such as address, delivery address, email address, phone number, and access code)
  • Order number
  • Order information, e.g., details of ordered goods
  • Customer type (individual/business)
  • Payment, purchase, and order history

Legal Basis: The processing is necessary to fulfill the contract for the purchase of goods from us. In other cases, the processing is necessary to fulfill a legal obligation or to satisfy our legitimate interest in preventing misuse of our, our suppliers', or partners' services, prevent, investigate, and detect crimes, or to protect legal interests.

Retention Period: We retain your personal data as long as necessary to fulfill our contract with you, but no longer than three (3) years from your last purchase. If we are legally required to keep the data longer (e.g., under accounting laws), we may retain the data for up to seven (7) years after the end of the calendar year in which the fiscal year ended.

C. To Manage Customer Service Cases

Purpose: To communicate with you and respond to your inquiries via email, phone, our chat function, or social media. To verify your identity. To prevent misuse of our, our suppliers', or partners' services or prevent, investigate, and detect crimes. To establish your placed orders (through order number or personal identification number). To handle complaints, warranty claims, and customer service inquiries regarding ordered/purchased goods.

Processing Activities: Collecting and storing personal data in our business systems, backup systems, and other online storage spaces.

Categories of Personal Data:

  • Name
  • Username and password (e.g., for support with login issues)
  • Personal identification number
  • Contact information (such as address, email address, and phone number)
  • Order number
  • Order history, e.g., details of ordered goods
  • Customer type (individual/business)
  • Photographs you send to customer service
  • Your correspondence with us
  • Health data you provide to us if necessary to handle your customer service case (e.g., information about an allergic reaction). We never request health data from you but only process such data if you provide it to us on your initiative.

Legal Basis: Legitimate interest. Our legitimate interest in assisting you with inquiries or complaints about purchased goods or issues with using our services. In other cases, the processing is necessary to satisfy our legitimate interest in preventing misuse of our, our suppliers', or partners' services, prevent, investigate, and detect crimes, or protect legal interests.

Retention Period: We retain your personal data only as long as necessary to handle your customer service case, but no longer than one (1) year from the closure of your case. If the data is needed to handle complaints, warranty claims, and customer service inquiries regarding ordered/purchased goods, they may be retained longer, but no longer than three (3) years from the purchase to which the data relates.

D. To Market Our Products and Services

Purpose: To send direct marketing (such as newsletters) via post, email, SMS, social media, or other similar electronic communication channels. To conduct targeted marketing campaigns (such as personalized offers, benefits, or gifts). To analyze your purchasing habits to provide relevant information and marketing.

Processing Activities: Collecting and storing personal data in our business systems, backup systems, and other online storage spaces. Transferring data to third-party providers for direct marketing and targeted marketing campaigns.

Categories of Personal Data:

  • Name
  • Address
  • Email address
  • Mobile number
  • Gender
  • Date of birth
  • Name day
  • Purchase and order history
  • Search history

Legal Basis: Legitimate interest. Our legitimate interest in marketing our products and services and conducting customer surveys.

Retention Period: For active customers: We retain your personal data for marketing purposes as long as the customer relationship exists or until you request to stop receiving marketing, but no longer than one (1) year after your last purchase.

For individuals who have signed up to receive newsletters/marketing communications: We retain your personal data for marketing purposes until you request to stop receiving marketing.

Based on the data we collect about you and your purchases, as well as other customers with similar purchasing behavior, we perform an analysis at the individual level. The analysis will form the basis for the targeted offers, such as within specific product categories, that you may receive. Different customers may therefore receive different benefits and offers, such as additional offers on organic products for those who purchase eco-labeled products.

E. To Evaluate, Develop, and Improve Our Services

Purpose: To evaluate the use of, develop, and improve our services, website, and mobile application. To conduct customer surveys.

Processing Activities: Analyzing aggregated technical information provided during visits to the website and mobile application regarding, for example, how our customers use our web pages, mobile application, and other digital channels (e.g., which pages or parts of pages were visited, how visitors access and leave the service, and which searches were made on our pages and via our mobile application). Transferring data to third-party providers for customer surveys.

Categories of Personal Data:

  • Technical information about devices (e.g., mobile, computer, or tablet) used during visits to our website and mobile application (e.g., IP address) and statistics on how you have interacted with us, i.e., how you have used our website and mobile application.
  • Results from customer or market surveys, including individual customer feedback.
  • Email address (for conducting customer surveys).

Legal Basis: Legitimate interest. Our legitimate interest in evaluating the use of and improving our services, website, and mobile application.

Retention Period: Technical information about how visitors interact on our website and mobile application is retained for a maximum of ninety (90) days from the visit.

2.3 Direct Marketing We may use your personal data for direct marketing via electronic means if you have previously purchased from us or consented to such marketing. Direct marketing refers to all types of outreach marketing actions, e.g., email and SMS. You have the right to object to the use of your data for these purposes free of charge, and every marketing communication from us includes an option to unsubscribe (opt-out). If you choose to unsubscribe from further communications, we will make a note in our business systems to stop targeting marketing to you.

Protecting Your Personal Data We have implemented several security measures to ensure that our processing of personal data is secure and to protect the personal data we process from unauthorized access, unauthorized processing, and misuse. For example, access to the systems where personal data is stored is limited to our employees and service providers who need to access the data as part of their job duties. These individuals are also informed about the importance of maintaining the security of personal data. We continuously monitor our systems to detect vulnerabilities and protect your personal data.

Who We May Share Your Personal Data With To provide our services and send marketing communications, we share your personal data with third parties. The following applies:

a) Service providers: We share personal data with service providers for IT operations (such as data storage, support, maintenance, and development), communication services, and marketing services, including customer surveys and marketing administration.

b) Suppliers and partners: We share personal data with suppliers and partners within payment services, transport services, warehousing, delivery planning, and delivery information services to deliver your ordered/purchased goods and to prevent misuse of our services or those of our suppliers and partners, prevent, investigate, and detect crimes.

c) IT security providers: We share personal data with IT security providers when required by law, to protect you or our customers and partners, or to protect our services.

d) Advisors and potential buyers: If all or part of Trendful™️'s operations are sold or integrated with another business, your personal data may be disclosed to our advisors and any buyer and their advisors.

e) Government authorities: We share personal data with authorities if we are required to do so by law or if there is a suspicion of a crime.

Most third parties with whom we share personal data are data processors in relation to us. They may only process the transferred data on our behalf and following our explicit instructions. We only transfer your personal data to such data processors for purposes compatible with the purposes for which we collected the data. We ensure through written agreements with the data processors that they commit to following our security requirements and restrictions and requirements regarding the international transfer of personal data.

Government authorities and, in some cases, companies to whom we transfer personal data may be independent data controllers for the transferred data. When your personal data is transferred to an independent data controller, we do not control how the data is subsequently processed. The responsibility for this lies with the authority or company to which the data has been transferred, including the obligation to inform you about their processing of your personal data and ensure that the processing is legal.

Where We Process Your Personal Data We aim to always process your personal data within the EU/EEA, where all our IT systems are located. However, your personal data may be shared with data processors established or storing information in a country outside the EU/EEA. In such cases, we will take all reasonable legal, organizational, and technical measures required to ensure that the protection level for the processing corresponds to that within the EU/EEA. This will be done either through a decision by the EU Commission that the country in question ensures an adequate protection level or through appropriate safeguards such as standard contractual clauses or approved codes of conduct in our agreements with such data processors.

You can read more about which third countries the EU Commission has deemed to ensure an adequate data protection level at EU Commission Adequacy Decisions.

Your Rights as a Data Subject This section describes your rights as a data subject. You can always exercise these rights by contacting us using the contact form on our contact us page.

6.1 Right of Access If you want information about the personal data we process about you, you can request access to the data. The information will be provided in the form of a record extract indicating which personal data we process, for what purposes we process them, where the data has been obtained from, which third parties the data has been transferred to, and how long the data will be retained. If your request is made electronically, the information will be provided in an electronic format that is widely used unless you request otherwise.

6.2 Right to Rectification You have the right to have incorrect data about you corrected without undue delay. You also have the right to complete incomplete data.

6.3 Right to Erasure You have the right to have your personal data erased without undue delay if any of the following occur:

  • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed.
  • You withdraw your consent for processing based on consent, and there is no other legal basis for the processing.
  • You object to processing based on a legitimate interest, and your reason for objection outweighs our legitimate interest.
  • The personal data has been unlawfully processed.
  • The personal data must be erased to comply with a legal obligation.

6.4 Right to Restriction of Processing You have the right to request the restriction of processing of your personal data if any of the following apply:

  • You contest the accuracy of the personal data during a period that allows us to verify the accuracy of the data.
  • The processing is unlawful, and you oppose the erasure of the data and instead request the restriction of their use.
  • We no longer need the personal data for processing purposes, but you need them to establish, exercise, or defend legal claims.
  • You have objected to processing based on a legitimate interest, and we are verifying whether our legitimate grounds override your legitimate grounds.

If processing is restricted in accordance with this point, such personal data may, with the exception of storage, only be processed to establish, exercise, or defend legal claims, protect the rights of another person, or for reasons of important public interest for the EU or an EU Member State.

6.5 Right to Object to Processing for Direct Marketing You have the right to object to the processing of your personal data for direct marketing. This right also covers the analysis of personal data (profiling) for direct marketing purposes.

6.6 Right to Data Portability Where our processing of personal data is automated and based on your consent or the performance of a contract, you have the right to request that the data concerning you and which you have provided to us be provided to you or transferred to another data controller in a structured, commonly used, and machine-readable format. However, this is subject to the condition that the transfer is technically possible.

6.7 Withdrawal of Consent Where our processing of your personal data is based on your consent, you have the right to withdraw your consent at any time. Such withdrawal of consent does not affect the lawfulness of processing based on your consent before its withdrawal. If you withdraw your consent, we will no longer process the personal data based on your consent, unless we are legally required to continue processing it. If our legal obligations prevent us from erasing your data, we will instead mark it so that it is no longer actively used in our systems.

You can use the contact form on our contact us page at any time to withdraw your consent. We will respond to your request promptly.

6.8 Right to Lodge a Complaint If you believe that we are processing your personal data incorrectly, you can, in addition to contacting us, lodge a complaint with the relevant supervisory authority in your country of residence.

Use of Cookies We use cookies on our website and mobile application to improve your browsing experience, our services, and our website and mobile application. A cookie is a text file sent from our web server and stored on your browser or device (e.g., mobile, computer, or tablet). We also use cookies for aggregated analytical information regarding your use of our website and mobile application and to save functional settings. You can change your browser or device settings for the use and scope of cookies, such as blocking all cookies or deleting cookies when you close your browser or our mobile application.

Read more about our use of cookies in our Cookie Policy.

Contact Information

If you have any questions about this Privacy Policy or our treatment of your personal data, please use the contact form on our contact us page.

By using our website and purchasing our products, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.