Privacy policy
Data Controller
AS Prisma Peremarket, registry code: 10569681, address: Mustakivi tee 17, Tallinn 13912, Estonia, e-mail: andmekaitse@prismamarket.ee
Contact information of the Data Protection Officer
Registrar
Name of the register
Prisma Customer Register
Purpose of personal data use
We process personal data for the purposes of managing AS Prisma Peremarket’s loyalty program and providing related services and discounts, monitoring purchasing behaviour, enabling the use of the online store, marketing, creating targeted and personalized content, as well as for business planning and development, including analysis and profiling, for market research, opinion surveys and handling customer feedback.
Lawful basis for processing personal data, personal data to be processed, and retention period
We process personal data on the following grounds:
Management of general customer data
Type of data: Management of general customer data
Basis for processing: Contract
Personal data: General customer data (e.g., name, other individuals linked to the customer program, phone number, address, and email), Estonian personal identification code, and other relevant data
Retention period: As long as data retention is necessary
Discounts, offers
Type of data: Discounts, offers
Basis for processing: Contract
Personal data: Purchase data and all customer personal data
Retention period: 5 years + current year
Analysis of customer purchasing behaviour for business planning
Type of data: Analysis of customer purchasing behaviour for business planning
Basis for processing: Contract
Personal data: Purchase data and all customer personal data
Retention period: 5 years + current year
Offering targeted discounts
Type of data: Offering targeted discounts
Basis for processing: Contract
Personal data: Purchase data and all customer personal data
Retention period: 5 years + current year
Marketing using loyalty customer data in external channels
Type of data: Marketing using loyalty customer data in external channels
Basis for processing: Consent
Personal data: Purchase data and all customer personal data
Retention period: 5 years + current year
Personal data collected through cookies and linking data to loyalty customers
Type of data: Personal data collected through cookies and linking data to loyalty customers
Basis for processing: Consent
Personal data: Purchase data and all customer personal data
Retention period: 5 years + current year
Transfer of data to cooperation partners
Type of data: Transfer of data to cooperation partners
Basis for processing: Consent and contract
Personal data: Required personal information
Direct marketing
Type of data: Direct marketing
Basis for processing: Consent
Personal data: Purchase data and all customer personal data
Retention period: 5 years + current year
Carrying out surveys
Type of data: Carrying out surveys
Basis for processing: Contract, legitimate interest and consent
Personal data: All required personal information
Retention period: 5 years + current year
Video surveillance in stores
Type of data: Video surveillance in stores
Basis for processing: Legitimate interest
Personal data: Video surveillance related data
Retention period: 30 days, but recordings sent to authorities will be kept as long as necessary
Feedback
Type of data: Feedback
Basis for processing: Legitimate interest
Personal data: All feedback-related data
Retention period: 1 year
Request for information by a registered person
Type of data: Request for information by a registered person
Basis for processing: Statutory requirement
Personal data: All data related to the information request
Retention period: 6 months from the reply to the request for information and sending the reply
Lottery and prize coupons
Type of data: Lottery and prize coupons
Basis for processing: Legitimate interest or consent
Personal data: All data related to lotteries
Retention period: 1 month after the prize received in the raffle is delivered
Information sources and information available from public sources
We receive your data when you join and use the loyalty program, and also directly from you via websites, email, or other similar means, as well as through the use of services.
We may also receive your name, address, mobile number, and death-related data from the relevant authorities and companies.
Recipients of personal data
We may disclose personal data within the limits prescribed by applicable laws, such as in response to information requests from authorities. We may also share your data with our business partners.
Additionally, with your consent, we may transfer data to third parties for other purposes.
Transfer of personal data to third countries or international organisations and the safeguards used
We use subcontractors to process personal data, which is why your data may be transferred, to a limited extent, outside the European Union (EU) or the European Economic Area (EEA) for the purposes of providing services, technical administration and support. We may transfer data in this manner if the European Commission has decided that the data protection level of the target country or organization is adequate, or if we can otherwise ensure an adequate level of data protection in accordance with applicable laws.
In such cases, we require our subcontractors to commit to complying with the applicable laws and the data protection and information security requirements set by AS Prisma Peremarket.
Rights of the data subject
The data subject has the following rights:
- right to access personal data;
- right to rectification of inaccurate personal data
- right to erasure of personal data (for example, if the basis for processing is a consent or if there is no lawful basis for retaining the data);
- right to restriction of processing (the accuracy of personal data is contested or unlawful processing);
- right to object to processing of personal data for direct marketing purposes or other processing based on legitimate interest;
- right to withdraw the consent;
- right to have the personal data transmitted from one system to another (regarding automated processing);
- right to receive information about breaches of personal data security under the General Data Protection Regulation (GDPR).
You may withdraw your consent and object to the processing of your data for legitimate interest and direct marketing purposes, thereby decide how we use your personal data.
If you wish to exercise your rights or obtain more information about the processing of your personal data, please contact the data controller by sending an email to: andmekaitse@prismamarket.ee.
If you believe that we are violating applicable data protection laws in the processing of your personal data, you have the right to lodge a complaint with a supervisory authority. The website of the Data Protection Inspectorate: www.aki.ee.
Data Protection Inspectorate
Tatari 39, Tallinn 10134
+372 627 4135