Privacy policy
Vianne OÜ attaches great importance to the protection of your personal data. This policy explains what data we collect, why, how long we keep it, with whom we share it and what your rights are. It complies with the General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
1. Data controller
The data controller is:
- Vianne OÜ, Järvevana tee 9, 11314 Tallinn, Estonia
- Registry code: 17439705
- Contact for any question relating to your data: support@viannecare.com
No data protection officer (DPO) has been appointed, as this designation is not mandatory given the nature of our activity. You may exercise your rights at the contact address above.
2. Data we collect
We collect the following data, depending on your interaction with the website:
- Identity and contact data: surname, first name, postal address, email address, telephone number where applicable.
- Order data: products ordered, amount, purchase history, delivery and billing address.
- Payment data: bank card details are processed directly by our payment providers and are not stored by Vianne OÜ.
- Browsing data: IP address, browser type, pages viewed, data from cookies and trackers (see section 7).
- Marketing preferences: your consent to receive our communications and your history of interaction with our emails.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Process and deliver your orders, manage customer service | Performance of the contract (art. 6.1.b GDPR) |
| Send you marketing communications (newsletter) | Consent (art. 6.1.a GDPR) |
| Manage audience-measurement and advertising cookies | Consent (art. 6.1.a GDPR) |
| Comply with our accounting and tax obligations | Legal obligation (art. 6.1.c GDPR) |
| Prevent fraud, secure the site, improve our services | Legitimate interest (art. 6.1.f GDPR) |
You may withdraw your consent at any time, without affecting the lawfulness of processing carried out before such withdrawal.
4. Recipients and processors
Your data is accessible to authorised personnel of Vianne OÜ and to our processors, who act only on our instructions:
- Shopify (Shopify International Limited, Ireland): hosting of the store, processing of orders and payments.
- PayPal: payment processing for customers using this method.
- Shopify Email: sending our transactional and marketing communications.
- Google (Analytics 4 / Tag Manager): audience measurement and statistical analysis of the site.
- Meta (Pixel): advertising-performance measurement and statistics.
- Judge.me: collection and display of customer reviews (if enabled).
- Logistics providers and carriers: delivery of your orders.
We never sell your personal data.
5. Transfers outside the European Union
Some of our processors (notably Google and Meta) may process data outside the European Union. These transfers are governed by the safeguards provided for by the GDPR: adequacy decision of the European Commission, standard contractual clauses or equivalent mechanisms.
6. Retention periods
- Account and order data: kept for the duration of the commercial relationship, then archived in accordance with legal obligations.
- Accounting documents and invoices: kept for the applicable legal period (generally ten years).
- Marketing prospecting data: kept until your consent is withdrawn or, failing any interaction, for a maximum period of three years from the last contact.
- Cookies and trackers: kept for a maximum period in line with the recommendations of the competent authority (at most thirteen months), consent being renewed thereafter.
7. Cookies and trackers
The website uses cookies. A distinction is made between:
- Strictly necessary cookies for the operation of the site (cart, security, session). They do not require your consent.
- Audience-measurement and advertising cookies (Google Analytics, Meta Pixel in particular). They are only placed after your consent has been obtained via the cookie banner.
You may change your choices at any time via the site's cookie-management module and via your browser settings.
8. Your rights
In accordance with the GDPR, you have the following rights over your data:
- Right of access: obtain a copy of the data concerning you.
- Right of rectification: correct inaccurate or incomplete data.
- Right to erasure: request the deletion of your data, within the limits provided by law.
- Right to restriction of processing.
- Right to portability: receive your data in a structured, machine-readable format.
- Right to object: object to processing based on legitimate interest or to commercial prospecting.
- Right to withdraw your consent at any time.
- Right to issue directives concerning the fate of your data after your death.
To exercise these rights, write to support@viannecare.com. Proof of identity may be requested. We respond within one month.
9. Complaint to a supervisory authority
As Vianne OÜ is established in Estonia, the lead supervisory authority is the Estonian Data Protection Authority (Andmekaitse Inspektsioon, aki.ee).
If you reside in France, you may also lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 (cnil.fr).
10. Changes
This policy may be updated to reflect changes in our practices or in regulations. The date of the last update appears at the top of the document.