My Cart

GDPR - General Data Protection Regulation

GDPR - General Data Protection Regulation

Introduction

At HERBSPAN, we are committed to protecting the privacy and security of our customers and visitors to our website. This GDPR Privacy Policy explains how we collect, use, and protect your personal data in accordance with the EU General Data Protection Regulation (GDPR).

Data Controller

The data controller responsible for your personal data is HERBSPAN. If you have any questions about how we process your personal data or would like to exercise your rights under the GDPR, please contact us at info@herbspan.com

What Personal Data We Collect

We may collect the following types of personal data from you:

Contact information, such as your name, email address, and phone number.

Payment information, such as your credit card number and billing address.

Shipping information, such as your shipping address and phone number.

Order information, such as the products you have ordered and their delivery status.

Information about your use of our website, such as your IP address, browser type, and operating system.

Marketing preferences, such as your subscription to our newsletter.

How We Use Your Personal Data


We use your personal data for the following purposes:

To process and fulfill your orders, including shipping and delivery.

To communicate with you about your orders and our products.

To send you marketing communications about our products and promotions, if you have subscribed to our newsletter.

To improve and customize our website and services.

To comply with legal and regulatory requirements.

Legal Basis for Processing


We process your personal data based on the following legal bases:

Contract: We need to process your personal data to fulfill our contractual obligations to you, such as processing and delivering your orders.

Legitimate interests: We have a legitimate interest in processing your personal data to improve our website and services and to send you marketing communications, if you have subscribed to our newsletter.

Legal compliance: We need to process your personal data to comply with legal and regulatory requirements.


Data Retention

We will retain your personal data for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.


Your Rights

Under the GDPR, you have the following rights with respect to your personal data:

Right to access: You have the right to request access to your personal data that we hold.

Right to rectification: You have the right to request that we correct any inaccurate or incomplete personal data we hold about you.

Right to erasure: You have the right to request that we delete your personal data in certain circumstances, such as where the data is no longer necessary for the purposes for which we collected it.

Right to restrict processing: You have the right to request that we restrict the processing of your personal data in certain circumstances, such as where you contest the accuracy of the data.

Right to data portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit that data to another controller.

Right to object: You have the right to object to our processing of your personal data in certain circumstances, such as where we are processing the data based on our legitimate interests.

To exercise any of these rights, please contact us at info@herbspan.com

Data Transfers

We may transfer your personal data outside of the European Economic Area (EEA) to our third-party service providers who are located in countries that do not have the same data protection laws as the EEA. In such cases, we will ensure that appropriate safeguards are in place to protect your personal data, such as using standard contractual clauses approved by the European Commission.

Changes to this Policy

We may update this GDPR Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any updates to this policy will be posted on our website and will take effect immediately upon posting. We encourage you to review this policy periodically for any changes.

Complaints

If you believe that we have violated your rights under the GDPR, you have the right to lodge a complaint with a supervisory authority, such as the Information Commissioner’s Office (ICO) in the UK. We would, however, appreciate the opportunity to address your concerns before you approach a supervisory authority, so please contact us at info@herbspan.com if you have any concerns.

Links to Other Websites

Our website may contain links to other websites that are not under our control. We are not responsible for the privacy practices or content of such websites. We encourage you to review the privacy policies of those websites before providing any personal data.

Official Links

If you would like more information about the GDPR or your rights under the GDPR, you may find the following links helpful:

EU GDPR website: https://gdpr.eu/

Information Commissioner’s Office (ICO): https://ico.org.uk/

European Data Protection Board (EDPB): https://edpb.europa.eu/

×