1. General Provisions.
1.1. This Privacy Policy describes how SIA “ HYPERION LIGHTING” , VAT 40103517495., Legal Address Upesciema iela 44, Rīga (hereinafter also referred to as – “Data Controller”) obtains, processes and stores personal data that shop.hyperion.lv obtains from its customers and persons visiting the website (hereinafter referred to as – “Data Subject” or “You”).
1.2. Personal data is any information relating to an identified or identifiable natural person, i.e. Data Subject. Processing is any operation related to personal data, such as obtaining, recording, modification, use, viewing, erasure or destruction.
1.3. The Data Controller complies with the data processing principles provided for in the legislation and is able to confirm that personal data are processed in accordance with the applicable legislation.
2. Acquisition, processing and storage of personal data.
2.1. The Data Controller acquires, processes and stores personally identifiable information mainly using the online store website and e-mail.
2.2. By visiting and using the services provided in the online store, you agree that any information provided is used and managed in accordance with the purposes set out in the Privacy Policy.
2.3. The Data Subject is responsible for ensuring that the personal data submitted is correct, accurate and complete. Deliberate provision of false information is considered a violation of our Privacy Policy. The Data Subject is obliged to immediately notify the Data Controller of any changes to the submitted personal data.
2.4. The Data Controller is not liable for losses caused to the Data Subject or third parties if they arise due to falsely submitted personal data.
3. Processing of Customer Personal Data
3.1. The Data Controller may process the following personal data:
3.1.1. Name, surname
3.1.2. Date of birth
3.1.3. Contact information (e-mail address and/or telephone number)
3.1.4. Transaction data (purchased goods, delivery address, price, payment information, etc.).
3.1.5. Any other information provided to us during the purchase of services and goods offered by the Site or when contacting us.
3.2. In addition to the above, the Data Controller has the right to verify the accuracy of the data provided using publicly available registers.
3.3. The legal basis for the processing of personal data is Article 6(1)(a), (b), (c) and (f) of the General Data Protection Regulation:
a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;
b) the processing is necessary for the performance of a contract to which the data subject is a party, or to take steps at the request of the data subject prior to entering into a contract;
c) the processing is necessary for compliance with a legal obligation to which the controller is subject;
f) the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.
3.4. The data controller shall store and process the personal data of the data subject for as long as at least one of the following criteria applies:
3.4.1. The personal data are necessary for the purposes for which they were obtained;
3.4.2. As long as the Data Controller and/or the Data Subject can exercise their legitimate interests, such as filing objections or bringing or bringing legal action in court, in accordance with the procedure specified in external regulatory enactments;
3.4.3. As long as there is a legal obligation to store the data, such as in accordance with the Accounting Law;
3.4.4. As long as the Data Subject's consent to the relevant processing of personal data is valid, if there is no other legal basis for the processing of personal data.
Upon the expiry of the circumstances referred to in this paragraph, the period for storing the Data Subject's personal data also expires and all relevant personal data are irreversibly deleted from computer systems and electronic and/or paper documents containing the relevant personal data or these documents are anonymized.
3.5. In order to fulfill its obligations to You, the Data Controller has the right to transfer Your personal data to cooperation partners and data processors who perform necessary data processing on our behalf, such as accountants, courier services, etc. The data processor is also considered a data controller.
Upon request, we may transfer Your personal data to state and law enforcement authorities to defend our legal interests if necessary, including preparing, submitting, and defending legal claims.
Upon request, we may transfer your personal data to state and law enforcement authorities in order to defend our legal interests, if necessary, by drafting, submitting and defending legal claims.
3.6. When processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure and any other unlawful processing.
4. Rights of the Data Subject
4.1. In accordance with the General Data Protection Regulation and the legislation of the Republic of Latvia, you have the right to:
4.1.1. Access your personal data, receive information about their processing, as well as request a copy of your personal data in electronic format and the right to transfer these data to another controller (data portability);
4.1.2. Request the correction of incorrect, inaccurate or incomplete personal data;
4.1.3. Delete your personal data (“be forgotten”), except in cases where the law requires the data to be retained;
4.1.4. Withdraw your previously given consent to the processing of personal data;
4.1.5. Restrict the processing of your data – the right to request that we temporarily stop processing all of your personal data;
4.1.6. Contact the State Data Inspectorate
You can submit a request to exercise your rights by filling out the form in person in Rīga, Brīvības iela 137, or by sending a request electronically by writing to the customer support service customer@hyperion.lv.
5. Final provisions
5.1. This Privacy Policy has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council (April 27, 2016) on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as well as the applicable laws of the Republic of Latvia and the European Union.
5.2. The Data Controller has the right to make changes or additions to the Privacy Policy at any time and without prior notice. Amendments shall enter into force upon their publication on the website shop.hyperion.lv.