Skip to content
Prisma
Products

Privacy policy

Data Controller

AS Prisma Peremarket, registry code: 10569681, address: Mustakivi tee 17, Tallinn 13912, Estonia, e-mail: andmekaitse@prismamarket.ee

Contact information of the Data Protection Officer

andmekaitse@prismamarket.ee

Registrar

andmekaitse@prismamarket.ee

Name of the register

Prisma Customer Register

Purpose of personal data use

We process personal data for the purposes of managing AS Prisma Peremarket’s loyalty program and providing related services and discounts, monitoring purchasing behaviour, enabling the use of the online store, marketing, creating targeted and personalized content, as well as for business planning and development, including analysis and profiling, for market research, opinion surveys and handling customer feedback.

Lawful basis for processing personal data, personal data to be processed, and retention period

We process personal data on the following grounds:

Management of general customer data

Type of data: Management of general customer data

Basis for processing: Contract

Personal data: General customer data (e.g., name, other individuals linked to the customer program, phone number, address, and email), Estonian personal identification code, and other relevant data

Retention period: As long as data retention is necessary

Discounts, offers

Type of data: Discounts, offers

Basis for processing: Contract

Personal data: Purchase data and all customer personal data

Retention period: 5 years + current year

Analysis of customer purchasing behaviour for business planning

Type of data: Analysis of customer purchasing behaviour for business planning

Basis for processing: Contract

Personal data: Purchase data and all customer personal data

Retention period: 5 years + current year

Offering targeted discounts

Type of data: Offering targeted discounts

Basis for processing: Contract

Personal data: Purchase data and all customer personal data

Retention period: 5 years + current year

Marketing using loyalty customer data in external channels

Type of data: Marketing using loyalty customer data in external channels

Basis for processing: Consent

Personal data: Purchase data and all customer personal data

Retention period: 5 years + current year

Personal data collected through cookies and linking data to loyalty customers

Type of data: Personal data collected through cookies and linking data to loyalty customers

Basis for processing: Consent

Personal data: Purchase data and all customer personal data

Retention period: 5 years + current year

Transfer of data to cooperation partners

Type of data: Transfer of data to cooperation partners

Basis for processing: Consent and contract

Personal data: Required personal information

Direct marketing

Type of data: Direct marketing

Basis for processing: Consent

Personal data: Purchase data and all customer personal data

Retention period: 5 years + current year

Carrying out surveys

Type of data: Carrying out surveys

Basis for processing: Contract, legitimate interest and consent

Personal data: All required personal information

Retention period: 5 years + current year

Video surveillance in stores

Type of data: Video surveillance in stores

Basis for processing: Legitimate interest

Personal data: Video surveillance related data

Retention period: 30 days, but recordings sent to authorities will be kept as long as necessary

Feedback

Type of data: Feedback

Basis for processing: Legitimate interest

Personal data: All feedback-related data

Retention period: 1 year

Request for information by a registered person

Type of data: Request for information by a registered person

Basis for processing: Statutory requirement

Personal data: All data related to the information request

Retention period: 6 months from the reply to the request for information and sending the reply

Lottery and prize coupons

Type of data: Lottery and prize coupons

Basis for processing: Legitimate interest or consent

Personal data: All data related to lotteries

Retention period: 1 month after the prize received in the raffle is delivered

Information sources and information available from public sources

We receive your data when you join and use the loyalty program, and also directly from you via websites, email, or other similar means, as well as through the use of services.

We may also receive your name, address, mobile number, and death-related data from the relevant authorities and companies.

Recipients of personal data

We may disclose personal data within the limits prescribed by applicable laws, such as in response to information requests from authorities. We may also share your data with our business partners.

Additionally, with your consent, we may transfer data to third parties for other purposes.

Transfer of personal data to third countries or international organisations and the safeguards used

We use subcontractors to process personal data, which is why your data may be transferred, to a limited extent, outside the European Union (EU) or the European Economic Area (EEA) for the purposes of providing services, technical administration and support. We may transfer data in this manner if the European Commission has decided that the data protection level of the target country or organization is adequate, or if we can otherwise ensure an adequate level of data protection in accordance with applicable laws.

In such cases, we require our subcontractors to commit to complying with the applicable laws and the data protection and information security requirements set by AS Prisma Peremarket.

Rights of the data subject

The data subject has the following rights:

  • right to access personal data;
  • right to rectification of inaccurate personal data
  • right to erasure of personal data (for example, if the basis for processing is a consent or if there is no lawful basis for retaining the data);
  • right to restriction of processing (the accuracy of personal data is contested or unlawful processing);
  • right to object to processing of personal data for direct marketing purposes or other processing based on legitimate interest;
  • right to withdraw the consent;
  • right to have the personal data transmitted from one system to another (regarding automated processing);
  • right to receive information about breaches of personal data security under the General Data Protection Regulation (GDPR).

You may withdraw your consent and object to the processing of your data for legitimate interest and direct marketing purposes, thereby decide how we use your personal data.

If you wish to exercise your rights or obtain more information about the processing of your personal data, please contact the data controller by sending an email to: andmekaitse@prismamarket.ee.

If you believe that we are violating applicable data protection laws in the processing of your personal data, you have the right to lodge a complaint with a supervisory authority. The website of the Data Protection Inspectorate: www.aki.ee.

Data Protection Inspectorate

Tatari 39, Tallinn 10134

+372 627 4135

info@aki.ee