Updated: May 9, 2018
1. WHO WE ARE
When we say ‘we’ or ‘us’, we mean our company
The Design Chess Company
Läntinen Kehätie 22
The Design Chess Company is the supplementary firm name of ITP International Trading Partners Ltd Oy, business/VAT ID FI09323244.
2. THE GENERAL DATA PROTECTION REGULATION (GDPR)
3. WHAT TYPES OF INFORMATION WE HOLD AND HOW WE COLLECT IT
We collect information from you through your use of online forms and writable fields on our website when you subscribe to our marketing, create a user account, or buy a product from us.
• Your name
• Your address
• Your phone number
• Your email address
• Your order history
• Your communication history (emails) with us
• The feedback and reviews that you give us either in public or privately
In addition, we temporarily ask for and hold the following only in case shipping a product to your country requires:
• Your passport details
• Your tax ID
• Other information that is necessary for shipping because of the regulations of your country
If additional information is needed (i.e. passport details) the representative of our company will contact you by email along with the instructions on how to send the reply back to us securely. We erase this additional data as soon as we get the confirmation from the courier that you have received your shipment.
Please note that we do not handle any payment data. No details of your transaction, such as your credit card information are sent to, handled, collected, or stored by us. Depending on the option that you choose on checkout, they are solely handled by Stripe, Inc. or Paypal, Inc.
4. HOW LONG DO WE KEEP YOUR INFORMATION FOR
Our customer register is based on:
a) Customer relationship (contract between you and us; in other words, when you have bought something)
b) Consent (you have chosen to share your data with us)
How long we keep your information for depends on what your information is in connection with. See Chapters 5 and 6 below.
5. PROCESSING OF PERSONAL DATA BASED ON CUSTOMER RELATIONSHIP
The personal data based on our customer relationship is retained in our customer register for 3 years and 2 months (38 months) from the date of purchase. This is because of our 3-year warranty for our products.
After the expiry of this time, all uniquely identifying data (such as name and the address) will be removed from the customer register. We will only retain the zip code and the country information, together with the purchase information, for statistical purposes.
The sales receipts with the data shown on them will be retained as long as Finnish accounting law requires. The current law requires keeping them for 6 years from the financial statement of the year of the purchase.
5.1 PROCESSING OF ADDITIONAL PERSONAL DATA NEEDED FOR SHIPPING
As explained in Chapter 3, we ship to countries all over the world, and different countries have different import regulations. Sometimes we have to ask for additional information such as passport details or the tax ID from you via email to be able to make the shipment. We erase that additional data as soon as we get the confirmation from the courier that you have received the shipment.
6. PROCESSING OF PERSONAL DATA BASED ON CONSENT – NEWSLETTER AND E-MAIL CAMPAIGNS
We also use the customer data for marketing. We only do this if you have given your consent for these purposes.
By subscribing to our newsletter and e-mail campaigns, you give us permission to use the personal data you provided for the sending of our newsletter and marketing e-mails. This marketing may also be targeted by geography, if you have given your country information to us. This data is retained for as long as you want to receive the newsletter. The subscription can be cancelled at any time. We will then delete your data within two weeks of receiving the cancellation, unless you have recently bought something from us (see Chapter 5). In that case, we will only remove you from the database of recipients of the newsletter and the marketing emails.
7. USER ACCOUNTS
You can create a user account either during the checkout-phase or at any other time. When you create an account, you give us the consent to maintain the information you give in our customer register.
From the user account, it is possible for you to see your order history and edit your shipping and billing addresses and other information. It also makes ordering faster and makes it possible for us to give discounts to regular buyers. You can, however, delete your user account at anytime.
Creating a user account alone does not give us a permission for marketing or for sending newsletters to you. We will always ask for your consent for that.
Unless you delete your account, it will stay active without expiry. For as long as the account exists, we will maintain your data in our customer database. If you choose to delete the account, we will delete your data within two weeks.
Deleting your user account removes your eligibility for offers to regular buyers, since we are not able to connect you anymore with your prior purchases.
8. INFORMATION SECURITY
The computers of the company are password-secured and the content of their hard-drives is encrypted with another password. The personal data is also stored in a highly secure cloud, the password for which is known only to our personnel.
Our personnel have been trained and are committed to obeying our privacy information security policies.
9. WHO HAS ACCESS TO PERSONAL DATA?
The databases containing personal data can be accessed by
• The personnel of The Design Chess Company
• IT service providers that provide technological support
In addition, the accountant and the auditors have access to the sales receipts of the products. We also give your contact information to the courier company to enable it to send the shipment to you.
10. YOUR RIGHT OF ACCESS TO PERSONAL DATA
If you want to know what information we hold about you, you have the right to ask for this information from us. We will provide you with the information on request and you can have that report free of charge once per year.
The Data Subject Request must be sent in hard copy, because there has to be the signature of the person making the request. Therefore it cannot be sent by email. See Chapter 1 for our address.
11. RECTIFICATION AND ERASING OF PERSONAL DATA
You may request that we rectify erroneous or outdated personal data pertaining to yourself. You can also update this data anytime through ”My Account”, if you have a user account.
You may also request that we erase your personal data. We will remove your data within two weeks unless there are overriding legitimate grounds to retain your data.
12. WITHDRAWING CONSENT
You may withdraw your consent to receive any marketing from us by contacting us anytime. We will remove your personal data from the marketing or other services that you had earlier given consent to.
Personal data based upon that contract-based customer relationship between you and us (meaning that you have bought something from us) will, however, be stored as described in Chapter 5, even if you withdraw your consent to receive marketing from us.
13. SHARING PERSONAL DATA WITH THIRD PARTIES
There is only one case in which we may give your personal data to a third party, and we do that only with your permission. This would be in the case of a defective product or for a chess piece replacement service where the manufacturer would send the replacement product directly to you. This arrangement is only to serve you better and faster. For this, we always ask for your consent first.
We never hand out any personal data for any other purpose.