Privacy policy
PRIVACY NOTICE
Data privacy is of high importance for PopCultArt and we want to be open and transparent with our processing of your personal data.
We have a policy setting out how your personal data will be processed and protected.
Who is the controller of your personal data?
The UK company, Lazy Llama Ltd, is the controller of the personal data you submit to us and responsible for your personal data under applicable data protection law.
Where do we store your data?
Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
Your data is stored through Shopify’s data storage, databases, and the general Shopify application. They store your data on a secure server behind a firewall.
The data that we collect from you is stored within the European Economic Area (“EEA”) but may also be transferred to and processed in a country outside of the EEA. Any such transfer of your personal data will be carried out in compliance with applicable laws.
For transfers outside the EEA, PopCultArt will use Standard Contractual Clauses and Shields as safeguards for countries without adequacy decisions from the European Commission.
Who can access your data?
Your data may be shared within our organisation. We never pass on, sell or swap your data for marketing purposes to third parties outside the organisational group.
PopCultArt will only act as the personal data processor and processes the personal data on behalf of Lazy Llama Ltd.
Data that is forwarded to third parties, is only used to provide you with our services. You will find categories of third parties under every specific process below.
What is the legal ground for processing?
For every specific process of personal data we collect from you, we will inform you whether the provision of personal data is statutory or required to enter a contract and whether it is an obligation to provide the personal data and possible consequences if you choose not to.
What are your rights?
Right to access:
You have the right to request information about the personal data we hold on you at any time. You can contact PopCultArt and we will provide you with your personal data via e-mail.
Right to portability:
Whenever PopCultArt processes your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.
Right to rectification:
You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed.
If you have a PopCultArt account, you can edit your personal data under your account page.
Right to erasure:
You have the right to erase any personal data processed by PopCultArt at any time except for the following situations:
*you have an ongoing matter with Customer Service
*you have an open order which has not yet been shipped or partially shipped
*you have an unsettled debt with PopCultArt, regardless of the payment method
*if you are suspected or have misused our services within the last four years
*your debt has been sold to a third party within the last three years or one year for deceased customers
*if you have made any purchase, we will keep your personal data in connection to your transaction for bookkeeping purposes
Your right to object to processing based on legitimate interest:
You have the right to object to processing of your personal data that is based on PopCultArt's legitimate interest. PopCultArt will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.
Your right to object to direct marketing:
You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes.
You can opt out from direct marketing by the following means:
* following the instruction in each marketing emails
* by emailing PopCultArt.
Right to restriction:
You have the right to request that PopCultArt restricts the process of your personal data under the following circumstances:
* if you object to a processing based PopCultArt:s legitimate interest, PopCultArt shall restrict all processing of such data pending the verification of the legitimate interest.
* if you have claim that your personal data is incorrect, PopCultArt must restrict all processing of such data pending the verification of the accuracy of the personal data.
* if the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data instead
* if PopCultArt no longer needs the personal data but it is required by you to defend legal claims.
Right to complain with a supervisory authority:
If you consider PopCultArt to process your personal data in an incorrect way you can contact us. You also have the right to raise a complaint to a supervisory authority.
Controller of personal data
Lazy Llama Ltd.
14 Norval Road,
London
UK
Company registration number: 9601289
Privacy notice for online purchases:
Why do we use your personal data?
We will use your personal data to manage your purchase online at PopCultArt by processing your orders and returns via our online services and send you notifications of delivery status or in the event of any problems with the delivery of your items.
We will use your personal data to manage your payments.
We will also use your data in order to handle complaints and warranty matters for products.
Your personal data is being used to identify you and to confirm your address with external partners.
We want to offer you different payment alternatives and will carry out analysis in order to find out what payment alternatives are available to you, including your payment history and credit checks.
What types of personal data do we process?
We will process following categories of personal data
* contact information such as name, address, e-mail address and telephone number
* payment information and payment history
* credit information
* order information
If you have a PopCultArt account, we will also process your personal data submitted in relation to the account or membership such as
* account or membership ID
* shopping history
Who has access to your personal data?
Your personal data that is forwarded to third parties, is only used to provide you with the services mentioned above, companies to validate your address, communication agencies to send you order confirmation, warehouse and distribution suppliers in connection with the delivery of your order. Payment service providers for your payment. Credit reference agencies for identity and credit checks and debt collection agencies.
Please be aware that many of these recipient companies have an independent right or obligation to process your personal data.
What is the legal ground to process your personal data?
The processing of your personal data is necessary for PopCultArt to fulfil the service of managing and delivering the order to you.
How long do we save your data?
We will keep your data as long as you are an active customer.
For customers with an account, we will keep your personal data for 36 months after your last purchase.
How is your payment processed?
To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, Mastercard, American Express and Discover.
PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).
Age consent:
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
Privacy Notice for direct marketing
Why do we use your personal data?
We will use your personal data to send you marketing offers, information surveys and invitations through emails.
In order to optimise your experience of PopCultArt we will provide you with relevant information, recommended products, send you reminders of products left in your shopping bag and send you personalised offers. All these great services are based on your previous purchases, what you have clicked on and information you have submitted to us.
What types of personal data do we process?
We will process following categories of personal data
* contact information such as e-mail address, telephone number and postal code
* gender (if you choose to provide that to us)
* what products and offers you have clicked on
If you have a PopCultArt account, we will also process your personal data submitted in relation to the account such as
* name
* address
* age
* shopping history
* how you navigated and clicked on the site
Who has access to your personal data?
Data that is forwarded to third parties is only used to provide you with the service mentioned above, to media agencies and technical suppliers for distribution of physical and digital direct marketing.
We never pass on, sell or swap your data for marketing purposes to third parties outside the PopCultArt group.
What is the legal ground to process your personal data?
The processing of your personal data is based on your consent when you agree to direct marketing.
Your right to withdraw your consent:
You have the right to withdraw your consent for the processing of your personal data at any time and also object to direct marketing.
When you do so, PopCultArt won't be able to send you any further direct marketing offers or information based on your consent.
You can opt out from direct marketing by the following means:
* following the instruction in each marketing email
* by contacting us by email.
How long do we save your data?
We will keep your data for direct marketing until you withdraw your consent.
For e-mail marketing we will consider you an inactive customer if you haven't opened an e-mail within the last year.
After this time period your personal data will be deleted.
Privacy notice- PopCultArt account
Why do we use your personal data?
We will use your personal data to create and manage your personal account in order to give you a personalised and relevant experience at PopCultArt.
We will provide you with your order history, details around your orders and enable you to handle your account settings (including marketing preferences). We will also provide you with easy ways to maintain accurate and updated information such as contact details and payment information.
Furthermore, we will enable you to save items in your shopping cart, offer you recommendations and enable you to rate and review the products you've purchased from order to provide you with relevant product recommendations. PopCultArt will process your navigation and browsing on our digital platforms (including website and app), your shopping history and product reviews as well as the data you submitted to us through your account.
Once you leave our store’s website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website’s Terms of Service.
What types of personal data do we collect?
We will always process your e-mail address and password that you submit to us when you sign up for PopCultArt account.
We will process following categories of personal data if you choose to provide it to us:
* contact information such as name, address, telephone number
* country
* account settings
* encrypted payment card information
We will process the following categories of personal data if you make a purchase
* order history
* delivery information
* payment history
We will also process the following categories of personal data connected to your cookies
* click history
* navigation and browsing history
Who has access to your personal data?
Data that is forwarded to third parties, is only used to provide you with the services mentioned above, to optimize the website we use, website agencies and analysis tools for product rating.
What is the legal ground to process your personal data?
The processing of your personal data for your account is based on your consent when you create your PopCultArt account.
The processing of your personal data provide you with relevant product information is based on our legitimate interest.
Your right to withdraw your consent:
You have the right to withdraw your consent from the processing of your personal data at any time. When you do so your account will cease to exist and PopCultArt will not be able to provide you with the services mentioned above.
How long do we save your data?
We will keep your data for as long as you have an active PopCultArt account.
You have the right to terminate your account at any time, if you choose to do so your account will cease to exist and you will be considered inactive. We will keep your personal data if there are any legal requirements and if there is an open dispute.
We will consider you an inactive account owner if you haven't
* opened an e-mail within 1 year,
* not placed any orders within 3 years or
* not logged in within 2 years
After your account has been terminated your data will be deleted.
Your right to object to processing of your data:
You have the right to object to processing of your personal data that is based on PopCultArt's legitimate interest by contacting us via email or post. Your account will then be deleted and we will not be able to carry out our services to you.
Privacy policy - Customer service
Why do we use your personal data?
We will use your personal data to manage your queries, to handle complaints and warranty matters for products and technical support matters through e-mail, our chat function, telephone and through social media.
We may also contact you if there is a problem with your order.
What types of personal data do we process?
We will process any data you provide to us, including the following categories
* contact information such as name, address, e-mail address and telephone number
* payment information and payment history
* credit information
* order information
* account or member number
* all correspondence in the matter
Who has access to your personal data?
Data that is forwarded to third parties, is only used to provide you with the services mentioned above.
In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies with respect to the information we are required to provide to them for your purchase-related transactions.
For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
What is the legal ground to process your personal data?
The processing of your personal data is based on PopCultArt’s legitimate interest.
How long do we keep your data?
We will keep your data for 7 days for telephone and e-mails logs and correncepondation and for 12 months for case management.
Your right to object to processing based on legitimate interest:
You have the right to object to the processing of your personal data that is based on PopCultArt's legitimate interest. PopCultArt will not continue to process the personal data unless we can demonstrate a legitimate ground for the process which overrides your interest and rights or due to legal claims.
Text Marketing and notifications:
By subscribing to text notifications you agree to receive recurring automated marketing messages at the phone number provided. Consent is not a condition of purchase. Reply STOP to unsubscribe. HELP for help. Msg & Data rates may apply. More info view Privacy Policy and ToS.
Cookies
A cookie is a small text file that is saved to, and, during subsequent visits, retrieved from your computer or mobile device. If you use our services, we will assume that you agree to the use of such cookie.
How do we use cookies?
We use permanent cookies to store your choice of start page and to store your details if you select "Remember me" when you log in.
We will use cookies to save your favourite products.
We use session cookies for example when you use the product filtration function, to check whether you are logged in or if you put an item in your shopping bag.
We use both first- and third-party cookies to collect statistics and user data in aggregate and individual form in analysis tools to optimize our site and to present you with relevant marketing material.
Some third-party cookies are set by services that appear on our pages and are not in our control. They are set by social media providers such as Twitter, Facebook and Instagram and relate to the ability of users to share content on this site, as indicated by their respective icon.
We also use third-party cookies which performs cross-site tracking in order for us to give you marketing in other sites/channels.
What types of personal data do we process?
We will only connect your cookie ID to your personal data submitted and gathered in relation to your account, if you are logged in to your account.
Who has access to your personal data?
Data that is forwarded to third parties is only used to provide you with the services mentioned above, analysis tool in order to collect statistics to optimize our site and present you with relevant material.
What is the legal ground to process your personal data?
We will only connect your cookies to your personal data if you are logged in to your PopCultArt account.
If you are logged in to your account the legal ground is based on our legitimate interest.
How long do we save your data?
PopCultArt does not save your personal data. You can easily erase cookies from your computer or mobile device using your browser. For instructions on how to handle and delete cookies please look under "Help" in your browser. You can choose to disable cookies, or to receive a notification each time a new cookie is sent to your computer or mobile device. Please note that if you choose to disable cookies, you will not be able to take advantage of all our features.
CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.
If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
QUESTIONS AND CONTACT INFORMATION
If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer here or by mail at
PopCultArt
[Re: Privacy Compliance Officer]
14 Norval Road London GB HA0 3TE
----