Data protection and security policy – Loja Online
Data protection information (version 05/02/2020)
The following data protection information provides information on the type and extent of processing of so-called personal data by Frabatex, Lda., As the owner of the EOY brand. Personal data is information that can be directly or indirectly attributed to you.
Data processing by Frabatex, Lda. Can be divided mainly into two categories:
- For the execution of the contract, all the data necessary for the execution of a contract with Frabatex, Lda. are processed. If external service providers are involved in the performance of the contract, for example logistics companies or payment service providers, your data will be transmitted to them as necessary.
- When visiting the site www.eoy.pt , from Frabatex, Lda., various information is transmitted between your device and ours server. This can also include personal data. The information collected in this way will be used to optimize our website or display ads on your device’s browser.
Our website and services are not intended for children under 16.
In accordance with the provisions of the General Data Protection Regulation (hereinafter “GDPR”), you have rights that you can exercise. This includes the following rights:
- Access, under the terms and conditions legally provided, to the Personal Data that concerns you and that is subject to treatment by Frabatex, Lda;
- The correction or updating of inaccurate or outdated Personal Data that respects you;
- The treatment of Personal Data missing when it proves to be incomplete;
- The deletion, in the cases specifically provided for by law, of Personal Data concerning you;
- The limitation, verified the conditions foreseen in the law, of the processing of Personal Data in what concerns you.
Upon written request, addressed to Frabatex, Lda, the holder of Personal Data is also entitled to:
- Withdraw consent, when data processing is based only on consent;
- Oppose processing for reasons related to your particular situation, when data processing is based on the legitimate interest of the controller;
- To receive from Frabatex, Lda., in digital format for current use and automatic reading, the Personal Data that concerns you and that has been provided by you, processed by automated means based on the consent provided by the data subject or in a contract signed, being able to request, in writing, the respective transmission directly to another responsible, whenever this is technically possible.
Personal Data may be processed by other entities to which Frabatex, Lda, has subcontracted its processing, to which the obligations arising from the General Regulation on Data Protection (GDPR) are extended.
Contact details of the entity responsible for data processing and the protection of personal data
This data protection information applies to data processing by Frabatex, Lda., Rua 28 de Setembro, n.º 20, 1º Esq., Póvoa de Santa Iria, to the following website: www.eoy.pt , as the data controller.
Purposes of data processing, legal bases and legitimate interests of Frabatex, Lda., or third parties, as well as categories of recipients
Depending on how you interact with our site and depending on the services, products or features you want to enjoy, we will treat your personal data for the following purposes and the respective legal basis: To manage your registration on the site as a user (fundamentals: consent and interest lawful); For managing the pre-contractual and contractual relationship of the contract (Basics: Pre-contractual and contractual diligences and legitimate interest); for marketing purposes (Rationale: consent); compliance with legal obligations (Basis: compliance with legal obligation) for statistical treatment (Basis: legitimate interest).
We will process your data for as long as necessary to manage the purchase of the products you have purchased, including possible returns, complaints or complaints associated with the purchase of the particular product or service. The data required for tax reporting will be kept for the period established by law. For marketing purposes we will process your data until you cancel your newsletter subscription.
When you visit our website, the browser used on your device automatically sends information to our website’s server and temporarily stores it in a log file. We have no influence on that. The following information will also be collected without your intervention and stored until automatically deleted:
- The IP address of the Internet-enabled device,
- The date and time of access,
- The name and URL of the recovered file,
- The website / application from which you accessed (referring URL), the browser you use and, if necessary, the operating system of your computer with Internet access, as well as the name of your access provider .
The legal basis for processing the IP address is Article 6/1/f) of the GDPR. Our legitimate interest is based on the purpose of collecting data listed below. This collection is not intended to draw direct conclusions about your identity from the data collected, nor will any data be processed for that purpose.
Your device’s IP address and the other data listed above are used by us for the following purposes:
- Ensuring a fast connection,
- Ensuring comfortable use of our website / application,
- The name and URL of the recovered file,
- Assessment of system security and stability.
The data is stored for a period of 7 days and then the IP address is automatically deleted. For security reasons, but without your IP address, this information will be stored in log files for longer and deleted after 31 days. The data contained in the log files are stored separately from other data provided by you.
We also use so-called cookies, tracking tools, targeting methods and social media plug-ins for our website / application. The exact procedures used and how your data is used for this purpose are described in more detail
Conclusion, performance or termination of a contract
Data processing at contract completion
The objective of Frabatex, Lda. Is the distance selling of goods. In this context, we process the data necessary to conclude, execute or terminate a contract. That includes:
- First name, last name
- Delivery and billing address, if necessary, additional address
- Email address
- Taxpayer number
- Date of birth
- Phone / mobile number
The legal basis for this collection is Article 6/1 / b) of the GDPR, which means that you provide data based on the contractual relationship between you and us. In order to process your email address, we are also required to send an electronic order confirmation in the form of a shipping confirmation. To the extent that we do not use your contact details for advertising purposes, we store the data collected for the performance of the contract until the expiration of the legal or possible contractual guarantee and the guarantee rights. After the end of this period, we retain the information required by the commercial and tax laws of the contractual relationship for the legal periods. For this period (usually ten years from the conclusion of the contract), the data will be processed if necessary for the purposes of determinations or compliance with obligations by legal authorities.
We will transmit details of your delivery address to a logistics company hired by us for the purpose of processing the purchase contract.
In order to ensure that the goods are delivered according to your wishes, we use your email address and / or telephone number to contact you before delivery in order to inform you of the delivery time.
Data processing for advertising purposes
The following statements refer to the processing of personal data for advertising purposes. The GDPR provides that data processing based on Article 6 (1) (f) is fundamentally conceivable and has a legitimate interest. The duration of data storage for advertising purposes does not follow any strict principles and is based on the question of whether storage is necessary for the promotional approach.
You can exercise your right of opposition by sending an email to email@example.com.
Advertising purposes of Frabatex, Lda. and third parties
From the moment you have concluded a contract with us, we will keep you as an existing customer. In that case, we will process your postal contact details outside the scope of a specific consent to provide information about new products and services in this way. We process your email address to provide information about similar products, outside the availability of specific approval.
On our website, we offer you the opportunity to subscribe to our Newsletter. To make sure that no errors occurred when entering the e-mail address, we use the double-opt-in procedure: After entering your e-mail address in the registration field, we will send you a confirmation link. Only if you click on this confirmation link will your email address be included in our email list. The processing of your electronic contact data takes place here only on the basis of your consent [Article 6/1 / a) of the GDPR]:
By signing up, you agree that EOY collects the information (basic customer data, purchase data) and usage data (use of EOY Online Services) stored in your customer account, and to be processed for analysis statistics from our own market and opinion polls and exclusively make personalized advertising and special product offers, namely:
- By e-mail and any other form of contact with EOY,
- On the website of EOY.
You can revoke this consent at any time, for example, here or through the unsubscribe link included in all emails. Its revocation does not affect the legality of the processing of your data until it is revoked.
Online presence and website optimization
Overview and contradictions to web analytics and marketing services
Cookies and cookie-like technologies – General notes
If you have a customer account with Frabatex, Lda. And you are logged in or activate the “stay connected” function, the information stored in the cookies will be added to your customer account.
Using Google Analytics
This site also uses Google Analytics, a web analytics service from Google Inc. (“Google”). Google Analytics uses so-called “cookies” – text files that are stored on your computer and allow the analysis of the use of the website. The information generated by the cookie about the use of this website is generally transmitted to a Google server in the USA and stored on it. If you enable IP anonymity on this site, Google will mask your IP address before that, that is, within the member states of the European Union or in other states that are part of the European Economic Area Agreement. Only in exceptional cases will the full IP address be transmitted to a Google server in the USA and masked there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activities and to process for the website operator other services related to website use and Internet use. The IP address transmitted by your browser to Google Analytics will not be associated with other data by Google. You can prevent the storage of cookies using the corresponding setting in the browser software; however, we advise that in this case it is possible that you may not be able to use all the functions of this website. You can also prevent the transmission of data (including your IP address) generated by the cookie and related to your use of the website for Google and the processing of that data by Google, by downloading and installing the browser plug-in available via the following link : DOWNLOAD HERE .
Other vendors, including Google, place ads on websites on the Internet.
The purchase history can be used to make personal product recommendations on eoy.pt. In particular, they include items and categories of products that you have seen, researched or purchased previously. All information collected for this purpose is stored anonymously, which makes it impossible to identify the individual involved. You can choose to analyze your browsing behavior at any time. Please note that in such cases, we are no longer able to offer personalized recommendations through the browser in question.
Individual visits chosen at random by sampling (only with masked IP addresses) are recorded to identify possible improvements on the site.
In case you do not want to have this feature enabled, you must click on the following so that you can adjust your settings.
Opposition / exclusion possibility
In addition to the deactivation methods described above, you can avoid the targeting technologies explained through cookies by setting a corresponding cookie on your browsers. In addition, you have the option to disable preference-based advertising with the help of the preference manager, so that all tags are no longer delivered.
Social media plug-ins
We use social plug-ins from Facebook and Instagram on our website based on Article 6/1 / f) of the GDPR to offer you the opportunity to share featured articles on the article details pages with your friends. The underlying business objective should be considered as a legitimate interest in the meaning of the GDPR.
On our website, so-called Facebook social network plug-ins are used, which is offered by Facebook Inc. Facebook plug-ins are marked with a Facebook logo or the addition “Like” or “Share”. If you use this type of plug-in, the browser will connect directly to Facebook servers. The content of the plug-in is transmitted by Facebook directly to your browser and integrated into the page. Through this integration, Facebook receives information that your browser has accessed the corresponding page of our website, even if you do not have a Facebook profile or are not connected to Facebook. This information (including your IP address) will be transmitted directly from your browser to a Facebook server in the USA and stored there. If you are logged in to Facebook, Facebook can immediately assign the visit to our website to your Facebook profile. If you interact with plug-ins, for example, by clicking on the “Like” button, this information will also be transmitted directly to a Facebook server and stored there. The information will also be posted to your Facebook profile and displayed to your Facebook friends.
Client account “My EOY account”
For our customers registered on “eoy.pt”, buying on eoy.pt becomes a special experience. Registration is free and opens the door to your personal space with many “eoy.pt” benefits. To offer you the greatest possible comfort during your purchase, we offer you the permanent storage of your personal data in a password protected customer account. Registration of the customer’s account is optional and takes place on the basis of his consent, in accordance with the meaning of Article 6, paragraph 1, letter a) GDPR. After setting up a customer account, re-entry is not required. In addition, you can view and change the data stored in your customer account at any time.
In addition to the data requested during an order, you must provide a password to set up a customer account. This is used together with your email address to access your customer account. Please treat your personal access data confidentially and, in particular, do not make it accessible to unauthorized third parties. We cannot accept responsibility for badly used passwords unless we are responsible for the abuse. Please note that even after you leave our site, you will be automatically logged in, unless you log out.
In addition, you can decide for yourself what personal information you entrust to us. The more we know about you, the better we can respond to your needs and the greater the comfort we can offer you at EOYlisbon.pt. In addition, you can select preferred payment methods and save your payment details or different shipping addresses.
You have the option to delete your customer account at any time. Note, however, that this does not mean that the data in the customer’s account can be deleted. As a general rule, the data stored about you will be deleted or anonymized immediately after the end of the existing commercial and taxable storage duty after 10 years.
Customer service / telephone order
If you contact our customer service by e-mail, all personal data collected is intended to enable you to perform the contract or respond to your request. The processed categories of personal data include, in particular, your main data (such as name, surname, your customer number, as well as your date of birth), contact details (address, mobile phone, phone number, e-mail address), registration data generated by the use of IT systems, as well as other data that allow us to process your request).
For certain tasks, we can commission external service providers with data processing (in particular for responding to your online order requests).
Integration of third party content
The legal basis for processing your data is Article 6, paragraph 1, sentence 1, paragraph f) of the GDPR. We have a legitimate interest in optimizing our website and improving our offering, including third party content.
For a more detailed description of who we embed the content and how their data is processed, see the description of the embedded content below.
- YouTube (Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA). Data protection: https://policies.google.com/privacy – Exclusion is possible at: https://adssettings.google.com/authenticated
- Google Maps (Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA). Data protection: https://policies.google.com/privacy – Exclusion is possible at: https://adssettings.google.com/authenticated
- Instagram (Instagram LLC, 1601 Willow Rd, Menlo Park CA 94025, USA). Data protection: https://help.instagram.com/155833707900388
Data security measures
All personally transmitted data, including your payment details, will be transmitted using the common and secure SSL (Secure Socket Layer) standard. SSL is a secure and proven standard, eg. it is also used in online banking. You will see a secure SSL connection, including attachments on http (i.e. https://…) in the browser’s address bar or the lock icon at the bottom of the browser.
By the way, we use appropriate technical and organizational security measures to protect your stored personal data against manipulation, partial or total loss and against unauthorized access by third parties.
Links to Third Party Sites
Modifications to this statement