01
MIXSOON / ESSENCES
LEGAL / 02
This policy explains how personal data is intended to be processed at MISORA. Actual details, providers and retention periods must be completed once technical setup is finished.
The data controller will be [LEGAL NAME / LEGAL FORM], registered at [ADDRESS], VAT No. [VAT NUMBER], contact details [CUSTOMER SERVICE EMAIL], [PHONE]. You can use these details for questions or to exercise your rights. [TO BE COMPLETED: Data Protection Officer details, only if one has been appointed.]
When you make a purchase or contact us, you may submit your first name, surname, email, phone number, delivery/billing address, message content and order details. If you create an account, your login details and related preferences are retained. For payment, the selected method, the transaction status and identifiers returned by the provider may be recorded. The exact flow of card data will be documented once Viva is connected.
Using the site may also generate technical data, such as IP address, device details, access logs and cookie preferences. Analytics or advertising data from GA4 and Meta Pixel will be collected only if the relevant services are activated and the required consent has been given.
Order details are used to perform the contract, for delivery and for customer service (Article 6(1)(b) GDPR). Tax and accounting records are kept to comply with legal obligations (point (c)). Technical security and abuse management may be based on legitimate interest, following a balancing test (point (f)).
Sending promotional emails and using non-essential cookies/trackers rely on consent where required (point (a)). You may withdraw your consent at any time with effect for the future, without affecting the lawfulness of prior processing.
Data may be transferred, only to the extent necessary, to the hosting and technical support provider, the courier, the payment provider Viva, the accountant and public authorities where required. If GA4 and Meta Pixel are activated with valid consent, they may receive technical data in accordance with their final settings.
[TO BE COMPLETED: exact list of providers, their roles as processors or independent controllers, countries of processing and any safeguards for transfers outside the EEA.]
Data is kept only for as long as necessary for the relevant purpose and for applicable tax, commercial or other legal obligations. Account data is kept for as long as the account remains active, unless there is a legal reason for further retention. Contact and marketing data is deleted or anonymised once the purpose ceases or consent is withdrawn, subject to legal exceptions.
[TO BE COMPLETED: specific periods or clear criteria per data category and provider.]
You may request access to, rectification, erasure, restriction or portability of your data, and object to processing based on legitimate interest or carried out for direct marketing. You may also withdraw your consent. Rights are exercised at [CUSTOMER SERVICE EMAIL] and are assessed in accordance with the conditions and exceptions of the GDPR.
If you believe your rights have been infringed, you can lodge a complaint with the Hellenic Data Protection Authority (www.dpa.gr).
The business must implement appropriate technical and organisational measures, proportionate to the risk. The final policy will reflect how the site actually operates and will be updated whenever purposes, providers or technologies change. The frontend preview does not send purchase or contact forms to a MISORA server.
Draft for review before publication. Bracketed fields and the actual e-shop flows must be completed and confirmed.