Privacy and Cookies Policy — Facial Harmony Aesthetic OÜ
Article 1. General provisions and the controller
This policy explains how personal data is processed when you visit aestheticsolutions.ee (the “Website”) or contact Facial Harmony Aesthetic OÜ.
The controller is Facial Harmony Aesthetic OÜ, registry code 16929991, VAT number EE102713868, with its registered address at Lõõtsa tn 5, 11415 Tallinn, Estonia.
For questions about this policy or to exercise your data protection rights, contact us at contact@aestheticsolutions.ee, by telephone at +48 881 524 026, or by post at the address above.
Article 2. Using the Website and contacting us
You can browse the Website without registering an account or submitting a contact form. If you contact us by email, telephone or post, we process the information you provide, such as your name, contact details and the contents of your enquiry. If your enquiry concerns an order, return or complaint, we also process the information needed to handle that matter.
When the Website is accessed, technical connection data, such as an IP address, browser information and the time of the request, may be processed by the hosting infrastructure to deliver the Website and maintain its security.
Article 3. Purposes and legal bases
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, “GDPR”). Depending on the circumstances, we rely on:
- Article 6(1)(b) GDPR — to take steps at your request before entering into a contract and to perform a contract, including handling orders and related enquiries;
- Article 6(1)(c) GDPR — to comply with legal obligations, including applicable accounting and consumer protection obligations;
- Article 6(1)(f) GDPR — for our legitimate interests in responding to general enquiries, protecting the Website against misuse, and establishing, exercising or defending legal claims;
- Article 6(1)(a) GDPR — where we ask for your consent for a specific optional purpose. You may withdraw that consent at any time, without affecting the lawfulness of processing before withdrawal.
Article 4. Processing principles
We process personal data for specified purposes, limit the information used to what is needed for those purposes, and apply appropriate technical and organisational measures to protect it. Providing information in an enquiry is voluntary, but we may be unable to respond or deal with a request without the necessary details.
Article 5. Your rights
Subject to the conditions set out in the GDPR, you have the right to request access to your personal data, its correction or deletion, restriction of processing, and data portability. You may object to processing based on legitimate interests on grounds relating to your particular situation, and you may withdraw consent where processing is based on consent.
You also have the right to lodge a complaint with a data protection supervisory authority, including the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, www.aki.ee/en) or the supervisory authority in the EU country of your habitual residence, place of work or the alleged infringement.
Article 6. Recipients and external services
Where necessary for the relevant purpose, data may be disclosed to providers of hosting, email, IT support, accounting or other administrative services, professional advisers, payment or delivery providers involved in an order, and public authorities entitled to receive it under applicable law. Access is limited to what is necessary for the relevant service or legal obligation.
The Website currently loads fonts from Google Fonts. This causes your browser to connect to Google servers and transmit technical connection information, including your IP address. Information about Google’s processing is available in its Privacy Policy. Where personal data is transferred outside the European Economic Area, applicable GDPR transfer requirements must be met, including an adequacy decision or appropriate safeguards where required.
Article 7. Retention
We keep personal data for as long as necessary for the purpose for which it was collected. Correspondence is retained as needed to handle the enquiry and any related claims. Contract and accounting information may be retained for the periods required by applicable law. Where processing relies on consent, withdrawal ends processing for that purpose unless another lawful basis requires continued retention.
Information is not used to make decisions based solely on automated processing that produce legal or similarly significant effects on you.
Article 8. Cookies and similar technologies
Cookies are small files stored on your device. Similar technologies, such as session storage, can retain technical information within your browser. Strictly necessary technologies may be used to provide requested functionality and maintain security. WordPress may also store a temporary browser capability test in session storage to display emoji correctly.
Analytics, advertising and other non-essential storage or access technologies require your prior consent where applicable. If these features are introduced, information about their purposes and providers and a consent choice will be provided before they are activated. You will be able to refuse optional technologies and withdraw consent as easily as you gave it.
You can also manage cookies and site storage through your browser settings. Blocking necessary technologies may affect certain functions. Cookies associated with logging into the WordPress administration panel are used for the authenticated administration session.