Personal Data: any information relating to an identified or identifiable natural person. Processing: any operation or set of operations that is performed on Personal Data or on sets of Personal Data. Data Subject: a natural person whose Personal Data is being Processed. Child: a natural person under 16 years of age. We/us (either capitalized or otherwise): www.mcgrandshop.com
2. DATA PROTECTION PRINCIPLES
We promise to follow the following Data protection principles:
- We process data in a lawful, fair and transparent manner.
- We have lawful grounds for processing data.
- We consider your rights before, while and after processing personal data.
- We can provide you with information regarding our data processing upon request.
- We keep data processing to a minimal. We process only as much data as is required.
- We process data only for the intended use. We don’t have a hidden agenda with regards to gathering data. For instance, if you contact us through our contact page, we don’t send your data to a third party.
- We place a time limit on stored data. We won’t store your data for longer than needed.
- We try to keep your data up to date, while it is in our safekeeping.
- We try to ensure that your data is safe and kept confidential at all times while it is in our hands.
3. DATA SUBJECT’S RIGHTS
The Data Subject has the following rights: Right to information You have the right to know whether your Personal Data is being processed; what Personal Data is gathered, from where it is obtained and why and by whom it is processed. Right to access You have the right to access Personal Data collected from / about you. This includes your right to request and obtain a copy of your Personal Data gathered. Right to rectification You have the right to request rectification or erasure of your Personal Data if it’s inaccurate or incomplete. Right to erasure Under certain circumstances you may request your Personal Data be erased from our records. Right to restrict processing Where certain conditions apply, you have the right to restrict the Processing of your Personal Data. Right to object to processing In certain cases you have the right to object to Processing of your Personal Data, for example in the case of direct marketing. Right to object to automated Processing You have the right to object to automated Processing, including profiling; and not to be subject to a decision based solely on automated Processing. This right you can exercise whenever there is an outcome of the profiling that produces legal effects concerning or significantly affecting you. Right to data portability You have the right to obtain your Personal Data in a machine-readable format or if it is feasible, as a direct transfer from one Processor to another. Right to lodge a complaint In the event that we refuse your request under the Rights of Access, we will provide you with a reason as to why. If you are not satisfied with the way your request has been handled, please contact us. Contact details are at the bottom of this page. Right to help from supervisory authority You have the right to help from a supervisory authority and the right for other legal remedies such as claiming damages. Right to withdraw consent You have the right to withdraw any given consent for Processing of your Personal Data.
4. WHAT HAPPENS WITH PERSONAL DATA?
This is what happens with Personal Data submitted to www.mcgrandshop.com. General contact form In the event Personal Data is added to a general contact form and sent, that Personal Data is emailed to the managers of the website. The submitter of the form consents to have their Personal Data stored in www.mcgrandshop.com’s database, access of which is limited to website managers. Newsletter signup form In the event Personal Data is added to a newsletter signup form, that Personal Data is sent to a newsletter provider used by www.mcgrandshop.com. This is either Mailchimp or MailerLite. The sign up triggers an email, which is sent to a manager to inform us of a sign up. Personal Data (name, email address) submitted to the newsletter signup form is added to our newsletter provider’s database, from where we use it to send consensual emails. Comments form In the event Personal Data is added as a comment on www.mcgrandshop.com, that Personal Data (name or email address) is stored in www.mcgrandshop.com’s database, for the purpose of displaying a commenter’s comment. If social media commenting is active, you may sign in and comment with your social media account, but www.mcgrandshop.com or its managers don’t have access to these details. Online purchases In the event a product is purchased on www.mcgrandshop.com, Personal Data (name, email address, IP address, phone number, physical address, postal address, product preferences, credit card details or debit card details) is sent to a payment processor (such as PayPal, JCC) for the processing of a payment for goods ordered. Personal Data (name, email address, IP address, phone number, physical address, postal address, product preferences) is also sent to a fulfilment and logistics company for shipping product/s to the person who placed the order. Personal Data we collect This section covers which Personal Data we collect. When ordering or registering on our site, as appropriate, you may be asked to enter Personal Data. You may, however, visit our site anonymously. Information you provide us with When a contact form is completed on www.mcgrandshop.com and sent, we receive the following Personal Data:
- Your first name
- Your last name
- Your email address
- Your phone number
When a comment is added to www.mcgrandshop.com, we receive the following Personal Data:
- Your name
- Your email address
When a product is ordered on www.mcgrandshop.com, we receive the following Personal Data:
- Your name and surname
- Your email address
- Your phone number
- Your physical address
- Your postal address
- Your product preferences
Data from our partners We don’t have partners that receive Personal Data at this time. How we use Personal Data We use Personal Data on legitimate grounds and / or with your Consent. On the grounds of entering into a contract or fulfilling contractual obligations, we Process Personal Data for the following purposes:
- If you’ve purchased something from www.mcgrandshop.com, you give us Personal Data (name, email address, phone number, and physical address) to process and send your order.
On the ground of legitimate interest, we Process Personal Data for the following purposes:
- If you contact us through a contact form, we use your Personal Data to reply to your query.
- If you leave a comment, we display your comment and your name on www.mcgrandshop.com (without revealing your email address), and we may use your Personal Data to contact you with regards to your comment.
- If you sign up for our newsletter, we use your Personal Data to send you newsletters of interest to you.
As long as you have not informed us otherwise, we consider offering you products / services that are similar or same to your purchasing history / browsing behaviour to be our legitimate interest. By using www.mcgrandshop.com, our analytics providers (Google Analytics, Facebook Pixel, hotjar.com (optional), luckyorange.com (optional)) receives the following Personal Data:
- Your IP address
- Your browser
- Your operating system
We Process Personal Data in order to fulfil obligation rising from law and / or use Personal Data for options provided by law. We reserve the right to anonymize Personal Data gathered and to use any such data. We will use data outside the scope of this Policy only when it is anonymized. We save your billing information and other Personal Data gathered about you for as long as needed for accounting purposes or other obligations deriving from law, but no longer than 5 years. We might process Personal Data for additional purposes that are not mentioned here, but are compatible with the original purpose for which the data was gathered. To do this, we will ensure that:
- the link between purposes, context and nature of Personal Data is suitable for further Processing;
- the further Processing would not harm your interests and
- there would be appropriate safeguard for Processing.
We will inform you of any further Processing and purposes.
5. WHO ELSE CAN ACCESS PERSONAL DATA?
We don’t share Personal Data with strangers. We do not sell, trade, or otherwise transfer Personal Data to outside parties. This does not include trusted third parties who assist us in operating our website, conducting our business, or providing the services that you ask us to arrange on your behalf, so long as those parties agree to keep your Personal Data confidential. We may also release your information when we believe release is appropriate to comply with the law, enforce our site policies, or protect ours or others’ rights, property, or safety. However, non-personally identifiable visitor information may be provided to other parties for marketing, advertising, or other uses. We only work with processing partners who offer a sufficient level of protection of Personal Data. We disclose Personal Data to third parties or public officials when legally obliged to do so. If you’ve given consent, we might disclose Personal Data to third parties, or on legal grounds. If we provide trusted partners with Personal Data, it’s to make the provision of our service/s to you possible or to enhance your experience on www.mcgrandshop.com. Our processing partners Our business partners We do not currently have any business partners offering a service on or through this site. Connected third parties Google Analytics Uses your IP address for analytics purposes. Facebook Pixel Uses your IP address for analytics purposes.
6. HOW WE SECURE PERSONAL DATA
We do our best to keep Personal Data safe. We use safe protocols for communication and transferring data (such as HTTPS). We use anonymizing and pseudonym sing where suitable. We monitor our systems for possible vulnerabilities and attacks. We rely on software to help thwart brute force login attacks. After a transaction, your private information (credit card numbers, name and address details, etc.) will not be stored on our servers. We do not store customer credit card details. We take every reasonable action to prevent security breaches and to assist authorities if a breach occurs. Even though we try our best we cannot guarantee the security of information. However, in the unlikely event of a data breach, we shall notify the appropriate authorities about it. We shall also notify Data Subjects if a breach occurs. If you have an account with us, note that you have to keep your username and password secret.
7. THIRD PARTY LINKS
Occasionally, at our discretion, we may include or offer third party products or services on our website. These third party sites have separate and independent privacy policies. We therefore have no responsibility or liability for the content and activities of these linked sites. Nonetheless, we seek to protect the integrity of our site and gratefully welcome any feedback about these sites.
We are in compliance with the requirements of COPPA (Children’s Online Privacy Protection Act). We don’t knowingly collect, or intend to collect Data from children. We don’t target children with our services.
9. COOKIES AND OTHER TECHNOLOGIES WE USE
Learn more about the cookies we use on this site by visiting www.mcgrandshop.com/pages/cookie-policy
11. TERMS AND CONDITIONS
Please also visit our Terms and Conditions section establishing the use, disclaimers, and limitations of liability governing the use of our website
13. CONTACT INFORMATION
Our contact details If you’d like to discuss the handling of your data, please contact us.
- Email: [email protected]
- Telephone: +357 25340903
Alternatively, you may write to us at our correspondence address: Alexandrias 7 , Limassol 3013 , Cyprus