The processing of personal data by Honeysu abides by the norms of REGULATION (EU) 2016/679on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). All requests concerning the processing of personal data by Honeysu as a data controller are managed by our organisation and our data protection officer in due time and in strict respect for the right to data protection enjoyed by our customers under the EU privacy and data protection framework.
SECTION 1 - WHAT DO WE DO WITH YOUR INFORMATION (PURPOSE SPECIFICATION & CATEGORIES OF DATA)?
When you purchase something from our store, as part of the buying and selling process, we collect the personal information you give us.
The data we collect includes buyer's name, address and email address, shipping address, phone number, and billing address as informed at the moment of checkout.
All the information requested is strictly necessary for the performance of the contract of sale between Honeysu and its customer and no additional information is requested that goes beyond the fulfilment of that contract. Our legal basis for collecting information for the purpose of sale of a product is Art. 6(1)(b) - processing of personal data that is necessary for the performance of a contract. Additionally, data may be processed on the basis of explicit, unambiguous, and consent (Art. 6(1)(a), but also for the purpose of fulfilling a legal obligation, such as those connected to taxes and accounting duties (Art. 6(1)(c)).
Additionally, when you browse our store, we receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system. Cookie identifiers will be processed by Honeysu following consent by a customer after clicking on the Cookie banner at our homepage. For more information on cookies, see section 7 ("cookies"). We are in the process of implementing a full option form for cookie identifiers, but so far these tools are not available on Shopify. Once the tools become available, customers will be given the option to opt-out of cookies as they continue to browse through our store and to retrieve their consent on cookies at any time.
Email marketing: With your permission, we may send you emails about our store, new products and other updates. Permission for email marketing is granted after a customer requests to subscribe to our mailing list (double opt-in) or after checking the box requesting email marketing during the checkout process. The information kept for the purpose of email marketing includes name, last name, and email address as informed by the customer.
Our newsletter is delivered through Mailchimp. The information collected for the purpose of email marketing (Newsletter) will not be used for any other purpose other than sharing the latest news about sales, new arrivals, and other information about our store that may be of relevance to our customers. We do not share your newsletter information with other parties that are not involved in facilitating the delivery of the newsletter itself and you will always have the opportunity to unsubscribe from our newsletter.
SECTION 2 - CONSENT & ORDER PROCESSING
When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for the specific reason of he purchase of a product or service offered by Honeysu, following Art. 6(1)(b) of the GDPR. Please note that it is not possible to place an order with us if you do not disclose valid and trustworthy information about billing and shipping details.
If we ask for your personal information for a secondary reason, like Newsletter marketing, we will either ask you directly for your expressed consent, or provide you with an opportunity to say no. Honeysu does not send unsolicited email marketing and, if you feel you are no longer interested in receiving news from us, you will be offered an easy way to unsubscribe from our mailing list at the bottom of every communication ("unsubscribe").
Honeysu does not collect sensitive data ("special categories of personal data") about customers and will not request you to disclose any information that is not strictly necessary for placing an order with us or improving our services through cookies.
How do I withdraw my consent?
If after you opt-in, you change your mind, you may withdraw your consent for us to contact you, for the continued collection, use or disclosure of your information, at anytime, by contacting us at firstname.lastname@example.org or mailing us at:
De Braak 1B Ravels BE 2380
You are also entitled to the erasure/alteration/rectification of your data (as well as other applicable individual rights following Art. 8 of the GDPR) on our customer database at any time. You may exercise your right at any time by contacting us at email@example.com or mailing us at:
De Braak 1B Ravels BE 2380
SECTION 3 - DISCLOSURE
We may disclose your personal information if we are required by law to do so following Art. 6(1)(c), (d), (e) and (f) of the GDPR.
SECTION 4 - SHOPIFY
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
SECTION 5 - THIRD-PARTY SERVICES
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
As an example, if you are located in France and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 6 - SECURITY
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
SECTION 7 - COOKIES
By continuing to use our website after clicking positively on our cooking banner, we assume your permission to use the cookies described below. We are trying to find new ways for ensuring privacy of our users, but currently cookies are the most helpful tools to our continuous improvement and without them is hard to grow our business.
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
_session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
_shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
_shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer.
cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
_secure_session_id, unique token, sessional
storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 8 - AGE OF CONSENT
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
SECTION9 - DATA RETENTION
When you create an account at our website, information supplied by you will be kept in our records to allow for the use of the customer account. If you no longer wish to have this information stored in our database, you may at any time delete your customer account and request erasure of your data in our records.
Please note that for the purpose of fulfilling tax obligations, auditing, and accounting duties, we must keep all order records in our system for 7 years, following Art. 6(1)(c) and Belgian Tax Law. This includes information about the billing and shipping data offered at the moment of purchase. All transaction records are erased after that period has elapsed.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at firstname.lastname@example.org or by mail at
[Re: Privacy Compliance Officer]
De Braak 1B Ravels BE 2380