Privacy policy

iDeal is determined to protect the privacy of its customers and users. Accordingly, we have prepared these Privacy Policy principles addressing the collection, use, disclosure, transmission and storage of personal data. Our activities on the Internet are consistent with all the relevant activities and applicable European Union legislation and the laws of the Republic of Estonia. Please take a moment to examine our Privacy Policy.

The controller of the processing activities described in this Privacy Policy is iDeal Group AS (registry code 10390835).


Collection and composition of personal data

We collect the following types of personal data:

  • personal data you have provided to us. For example, when you enter your contact data (incl. your name, personal identification code, postal address, telephone number, e-mail address, preferred method of contact) on our website or elsewhere (for example, in a store);
  • personal data generated as a result of ordinary communications (e.g. personal data submitted in written correspondence or via Askly communication app on the website);
  • personal data obviously disclosed by you (e.g. in iDeal social media);
  • personal data generated when you use our services, e.g. when you make a purchase or place an order in our store or e-shop and personal contact information or information about your purchasing preferences are stored (iDeal may ask you to voluntarily provide personal data and information in certain areas of the website. Such data may include your name, address, postal code, e-mail address, phone number and other data) or when you submit a hire-purchase application. We also collect personal data when registering a device for service at one of our shops or online;
  • personal data generated as a result of visiting and using the website; For example, through the customer’s account information or allowed cookies when using the website;
  • personal data received from third parties;
  • personal data created and combined by us (e.g. order history).

The collection of other data

We also collect impersonal data, i.e. data that cannot be linked to any one person (gender, age, language preference, location). We may also collect general data about customer behaviour on our shops and website. This data is consolidated and used for providing useful information to our customers, and also for determining which parts of the website, products and services are the most attractive. Aggregated data are considered impersonal in this Privacy Policy.


Purpose and legal basis for use of personal data collected

We use the following grounds for processing personal data under the law:

Consent – we process personal data on the basis of consent in order to inform customers about iDeal product news, campaigns and upcoming events. Customers who do not want to receive newsletters or notifications of products that may interest them can remove themselves from the mailing list at any time. The withdrawal of consent does not influence the lawfulness of the data processing that took place on the basis of your consent before it was withdrawn.

Fulfilling contractual obligations – we use the personal data we collect to: take pre-contractual measures; identify the customer to the extent required by due diligence; fulfil our obligations to the customer in relation to the provision of our services (e.g. we use it to deliver Goods); communicate with the customer and to ensure that the customer’s payment obligations are met.

Please note that the purpose of data processing may be additionally stipulated in the specific Contract entered into with you.

For the purposes of entering into an employment contract and fulfilling our legitimate interests, the processing of personal data of a job applicant comprises the following:

  • the processing of data provided to us by the applicant for the purpose of entering into an employment contract;
  • the processing of personal data obtained from the person indicated by the job applicant as a reference and, in the absence of a references, the previous employer;
  • processing of personal data collected from public (social) media.
  • In the event that the job applicant is not selected, we will keep the personal data collected up to 36 months for the purpose of entering into an employment contract so that we can make an employment offer to the job applicant when a suitable position becomes available.

Legitimate interest means our interest to manage the company and to provide the best possible Services on the market. We process your personal data on the basis of a legitimate interest for the following purposes:

  • to ensure a trusting customer relationship, which includes processing personal data to prevent fraud;
  • for customer base management and analysis to improve the accessibility, selection and quality of the services, and to make the best and more personal offers with the consent of the Customer;
  • to collect identifiers and personal data when you use our website, our social media pages and services. We use the data we collect for web analytics or analysis of information society services, to ensure the functioning of these channels, to improve them, to compile statistics and to analyse your behaviour and user experience and to provide a better and more personalised service;
  • for the organisation of campaigns, including organisation of personalised and targeted campaigns, carrying out customer satisfaction surveys and measuring the effectiveness of marketing activities;
  • for making recordings. We may record messages and orders given on our premises as well as by means of communication (e-mail, telephone, etc.), also information and other operations we have performed, and if necessary, we use these recordings as proof of orders or other operations;
  • for network, information and cyber security purposes, e.g. the measures taken to combat piracy and guarantee the security of the website, make and save backup copies;
  • for organisational purposes. Primarily for financial management and transmission of personal data within the group for internal administrative purposes, including for processing the personal data of customers or employees;
  • we may share personal data when we conclude business transactions or hold negotiations about a business transaction, which covers our entire business or the sale or transfer of property. These transactions may cover any merger, financing, acquisition or bankruptcy transaction or proceedings;
  • for the establishment, exercising or defence of legal claims;
  • if required, we will also use the data to send you special notifications regarding manufacturer-issued safety announcements and recalls;
  • we use surveillance cameras in our shops. The use of cameras and the processing of recordings are for the purpose of protecting the property of employees, visitors and iDeal Group AS; ensuring security; defending and filing claims; resolving complaints and using the recordings as educational material. Recordings will be deleted after three months at the latest when the storage space is full.

We also process your personal data to comply with legal obligations. For example, legal obligations to process payments or comply with money laundering rules. In addition, we may be required by law to process the video recordings under the law for an investigative authority.

If personal data are processed for a purpose other than the purpose for which the personal data were collected, we will carefully analyse the possibility of such processing in accordance with data protection legislation (General Data Protection Regulation 2016/679, Article 6(4).)


Disclosure and/or transfer of personal data to third parties

To ensure better services for customers, iDeal has the right to share information about particular persons with third parties that provide services to iDeal. Third parties can, for example, be our partners who are responsible for transporting products sold in our e-shop or providing hire-purchase services, advertising and marketing partners; partners offering payment services; partners offering recruitment services; customer satisfaction polling companies, debt collection service providers, payment default registers, ICT partners, i.e. providers of various technical services, invoice transmission service providers. The transfer will only take place on the condition that the purpose of the transfer is lawful and the third party is processing the information on the basis of a contract in which, among other things, the third party undertakes to keep the shared information confidential.

In regard to servicing, iDeal also processes data via an online environment (a service database) that is managed by a third party, and the server which stores the data is located in the EU.

As a general rule, we don’t transmit personal data outside the European Economic Community. If we transmit personal data outside the European Union, we do it in compliance with he requirements of data protection legislation, e.g. if the European Commission has decided that adequate protection exists in the respective country, or we have taken adequate protection measures if such a decision does not exist (e.g. binding internal rules or standard data protection clauses).


Amendment of personal data collected and your rights

As a data subject, you have the following rights in relation to the processing of personal data:

  • receive information about personal data collected about you;
  • access data, which covers your right to obtain a copy of the processed personal data;
  • have incorrect personal data corrected;
  • in some cases, have data deleted deletion of data, i.e. you may have the right to demand deletion of personal data, e.g. if processing is done only on the basis of consent. With the erasing of your data, you will no longer be eligible for any personal discounts;
  • request restriction of personal data processing;
  • transfer data, i.e. in certain cases, you have the right to obtain your personal data in machine-readable format, or demand their transmission in machine-readable format to another controller;
  • obtain an opinion of a supervisory authority on whether the processing of your personal data is lawful;
  • compensation for damage if the processing of your personal data has damaged you;
  • rights related to automated processing, which means that you have the right to object to the processing of personal data concerning you at any time depending on the specific situation if such processing is based on automated decisions/profiling. You have the right to avoid any decisions based on automated processing of personal data, if they can be classified as profiling;
  • file a complaint with us, the Data Protection Inspectorate or a court. The contact details of the Data Protection Inspectorate can be found on its website at https://www.aki.ee/et/inspektsioon-kontaktid/tootajate-kontaktid.

Personal data collected to identify and contact the customers can be viewed, changed and renewed under ‘Minu konto’ (My account) on our website.


Cookies and other tracking technologies

We may collect data, if you give consent, about you on the website and other information society services (e.g. self-service) through the use of cookies (i.e. little pieces of information saved by the browser on the hard disk of a computer or another device), or other similar technologies, and process such data (e.g. the IP address, device information, location information).
We use the collected data to be able to provide the Service according to your habits, to ensure the best service quality; to inform you of content and make recommendations; to personalise advertisements and improve marketing efforts; to make logging in easier and to protect data. The collected data are also used to count visitors and record their usage habits.
The cookies we use can be categorized as follows: neccessary; statistics; preference; marketing and unclassified. Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies. Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies. Preference cookies enable a website to remember information that changes the way the website behaves or looks, like your preferred language or the region that you are in. Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers. Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies. The details are available to read before giving consent to cookies. Allowing or declining cookies and other similar technologies is controlled by you through the cookie modal and cookie settings. You can change or decline consent at any time in the consent settings.

Smartlook


Some of our websites use Smartlook software to improve the user experience. Smartlook allows us to measure and evaluate user activity (mouse movements, number of clicks, scrolling range). For this purpose, Smartlook places cookies on the user's device and may store user data, e.g. about the browser, operating system, time spent on the website, etc. For more information on Smartlook's processing of data, see https://help.smartlook.com/en/articles/3244454 -data-security.

Protection of personal data

iDeal takes all precautions (incl. administrative, technical, and physical measures) to protect the customer’s personal data. Only authorised persons have access to personal data for making alterations and processing the same. We store personal data strictly for the minimum required period of time. We store personal data for up to five years from the date of the most recent order or servicing. When storing the data, we are also guided by the requirements of the Accounting Act.
Personal data whose retention term has passed will be destroyed or anonymised by using the best practices.


Security

The personal data of the Customer that have become known during their visits to and while making purchases in the iDeal e-shop are regarded as confidential information. The use of an encrypted bank data link guarantees the safety of the personal data and bank details of the person making a purchase. In the event of a personal data breach, we will take all necessary measures to mitigate its consequences and to address relevant risks in the future. We will register all incidents and, if required, inform the Data Protection Inspectorate and the data subjects. All data on the iDeal website, in our online store and in our service database are encrypted and are considered confidential information.


Terms and conditions of and amendments to Privacy Policy

Upon using our website or filling out an application to become a loyal customer, you confirm that you have read these terms and conditions and agree to them. We retain the right to make any necessary changes to the general terms and conditions of the Privacy Policy by giving notice on our website and by e-mail, if possible.

If you have any questions or concerns about this Privacy Policy or data processing, please contact us at klienditugi@ideal.ee.

This Privacy Policy was last amended in March 2024.