Privacy Policy
The online store www.hempethica.com is operated by WidLab Ltd., Štihova ulica 13, 1000 Ljubljana, Slovenia (hereinafter: HEMPETHICA; also derivatives of "we"). This privacy policy explains in detail how we use the personal information you provide to us when using the online store and when ordering products.
What is personal information?
Personal information is information that directly or indirectly identifies you as an individual, where "indirectly" means in combination with other information, such as your name, postal address, email address, telephone number, location data or other identifiers.
What personal data do we collect?
If you are only a visitor to the HEMPETHICA online shop, we only collect information about you using cookies.
If you contact us using the form on our website, we will obtain your name, telephone number and/or email address so that we can respond to your question or enquiry.
If you are a purchaser of products offered in our online shop, we also collect other personal information about you that we need to invoice you and to send you the products you have ordered. This personal data includes:
- first and last name;
- address (street and house number, postcode and city);
- contact email address;
- contact telephone number;
How do we use (process) your personal data?
All personal data provided is treated confidentially and is used only for the purpose for which it was provided. HEMPETHICA takes all necessary measures to ensure that your data is protected by means of appropriate organisational measures, work procedures and technological solutions, as well as by using its own and external experts. In doing so, HEMPETHICA applies an appropriate level of protection and reasonable physical, electronic and administrative measures to safeguard the collected data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure of personal data or against unauthorised access to personal data that have been transmitted, stored or otherwise processed. Access to your personal data is only permitted to staff, service providers who need the data for business reasons or those who need it to perform their work.
If you have ordered a product offered in the HEMPETHICA online shop, personal data is collected and processed for the conclusion and performance of the purchase contract, invoicing and delivery of the product.
HEMPETHICA undertakes not to sell, lend or otherwise disclose to third parties the information you provide through the online shop or in any other way, except in the cases set out below and unless otherwise prohibited by law.
HEMPETHICA will only disclose your personal data to the specified third parties under the conditions set out below, and HEMPETHICA will ensure that your personal data is processed, protected and transferred in accordance with the applicable regulations:
External service providers (delivery services and others)
Where necessary, we will commission other companies and individuals to carry out specific work that contributes to our services. For example, we may provide personal information to providers to host our database and applications, to provide data processing services or to send you information you have requested, to provide support services, etc. We will only provide or make available such information to external service providers to the extent required for the specific purpose. They will not be allowed to use this information for any other purpose. HEMPETHICA's external service providers are contractually bound to respect the confidentiality of your personal data.
Business transfers
In connection with any company or process reorganisation, sale or other transfer of assets (collectively, "Business Transfers"), we will transfer information to the extent and as reasonably necessary for the Business Transfer, provided that the receiving party undertakes to respect your personal data in accordance with applicable data protection laws. We will continue to ensure the confidentiality of all personal information and will notify affected users before personal information becomes subject to another privacy policy.
Public authorities
We will only disclose your personal data to public authorities where required to do so by national or European Union law. For example, HEMPETHICA will respond to requests from courts, law enforcement authorities and other public authorities, which may include public authorities of another EU Member State.
Legitimate interest
We use your personal data on the basis of legitimate interest for the purposes of detecting and preventing fraudulent use and misuse of the Services or subscriptions to the Services, and further for the purposes of ensuring the stable operation of our systems and services, implementing information security measures, meeting quality of service requirements and detecting technical failures of our systems and services.
We also use your personal data for the purposes of possible enforcement, judicial and extrajudicial recovery on the basis of legitimate interest.
Your rights in relation to your personal data
Individuals may request from HEMPETHICA access to personal data, rectification, erasure or restriction of the processing of your personal data, the right to object to processing and the portability of your personal data.
Right to information: you always have the right to know whether personal data is being processed in relation to you and, if so, access to the personal data and the following information: (a) the purposes of the processing; (b) the types of personal data concerned; (c) the users or categories of user to whom the personal data have been or will be disclosed; (d) the envisaged period of retention of the personal data or, failing that, the criteria used to determine that period; (e) where the personal data are not collected from you, any available information regarding their source.
Right to rectification: you have the right to have inaccurate personal data relating to you rectified and, taking into account the purposes of the processing, the right to have incomplete personal data completed.
Right to erasure: you have the right to have your personal data erased where one of the following grounds applies: (a) the personal data is no longer necessary for the purposes for which it was collected or otherwise processed; (b) where you withdraw the consent on which the processing is based and where there is no other legal basis for the processing; (c) where you object to the processing and there are no overriding legitimate grounds for the processing; (d) the personal data has been unlawfully processed.
Right to restriction of processing: you have the right to have us restrict the processing of your personal data where one of the following applies: (a) where you contest the accuracy of the data, for a period of time that allows us to verify the accuracy of the personal data; (b) the processing is unlawful and you object to the erasure of the personal data and instead request the restriction of its use; (c) we no longer need your personal data for the purposes of the processing, but you need it to assert, exercise or defend legal claims; (d) if you have raised an objection to the processing based on legitimate interests of HEMPETHICA, pending verification whether our legitimate grounds outweigh your grounds.
Where the processing of your personal data has been restricted in accordance with the preceding paragraph, such personal data shall, with the exception of its storage, only be processed with your consent, or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person.
We are obliged to inform you before revoking the restriction on the processing of your personal data.
Right to data portability: you have the right to receive your personal data that you have provided to us in a structured, commonly used and machine-readable format and the right to have that data transmitted to another controller where the processing is based on your consent or the processing is carried out by automated means. At your request, where technically feasible, personal data may be directly transferred to another controller.
Right to object: where we process your data on the basis of legitimate interest for marketing purposes, you may object to such processing at any time.
Right to lodge a complaint with the Information Commissioner: if we do not decide on your request within the statutory time limit or if we refuse your request, you have the possibility to lodge a complaint with the Information Commissioner.
Access to and correction of your personal data and exercise of other rights
As a user of the HEMPETHICA online shop or a buyer of HEMPETHICA products, you have the right to check whether HEMPETHICA processes personal data about you and to have access to the personal data we hold or process about you (in which case we will provide it to you in the form of a PDF or other machine-readable document). You can always request that inaccurate personal data about you be corrected. If you believe that there is no longer a legitimate reason for us to continue to use or process your personal data, please let us know, but we may not delete certain personal data that we collect under the Value Added Tax Act. You also have the right to restrict the use of your personal data in cases where you contest the accuracy of the personal data, where you consider the processing to be unlawful but do not want it deleted, and where the personal data is no longer necessary for the purpose of the processing but is needed to assert legal claims. In the case of subscription to the newsletter, you have the right to object to the processing of your personal data
Za morebitno uveljavljanje svojih opisanih pravic, vas prosimo, da nam svojo zahtevo posredujete pisno, preko elektronske pošte na naslov support@hempethica.com. O vaši zahtevi vam bo odgovorna oseba odgovorila v predpisanem roku 1 meseca. V primeru zapletenosti in večjega števila zahtev lahko rok podaljšamo za največ dva dodatna meseca, o čemer boste obveščeni.
Storage
WidLab Ltd. keeps the personal data it has received from you until you unsubscribe from the newsletter (withdrawal of consent).
WidLab Ltd. keeps the data related to the contact form for one month after the end of the communication. After this time, we delete them, unless otherwise provided by law.
Based on the provisions of the tax regulations, WidLab Ltd. is obliged to keep invoices containing personal data of the purchaser of WidLab Ltd. products for 10 years after the invoice date.
WidLab Ltd. will also not delete the data that it needs to provide proof that it has deleted the personal data (the so-called audit trail) and to keep records of persons who do not wish to be contacted by WidLab Ltd. in the future.
Cookies
WidLab Ltd. uses "cookies" on this website - these are small files that are placed on your computer when you visit the site. Cookies can make it easier for you to visit the site again. You can choose whether to accept or reject cookies by adjusting the settings in your browser.
If you do not accept cookies, some web pages may not be displayed correctly or you may not be able to access all the information or functionality of the website, but accepting cookies is not a condition of using the HEMPETHICA website.
Change of privacy policy
WidLab Ltd. reserves the right, at its sole discretion, to change its Privacy Policy and to update and amend this Privacy Policy at any time. You are therefore advised to review this Privacy Policy regularly.
Contact us
If you have any questions about this Privacy Policy or the information we hold about you, please contact us at support@hempethica.com.