Browsing the LumiVitae website and customer registration on the online store requires the acknowledgment and the acceptance of this Privacy and Data Protection Policy.
LumiVitae maintains a constant concern for the protection of the privacy of personal data and a preventive action regarding the security of the site and the protection of the data of its customers and visitors.
To reinforce the guarantees of the confidentiality of personal data, data protection measures were implemented, both in terms of verifying the legitimacy of the use of personal data processed as in terms of ensuring compliance with the rights granted to the data subjects. In this context, and through the specialization of customer support channels, LumiVitae aims to promote a clearer and more objective communication of the purposes underlying the processing of personal data and the transparency of processing operations.
Thus, the information contained in this text is intended to convey, clearly and unambiguously, the content of the privacy policy and protection of personal data that will be processed under the terms of the General Data Protection Regulation in force (hereinafter GDPR) and delimited by the content of the business relationship to be established between the data subject and LumiVitae.
In general terms, personal data are collected in three situations directly arising from LumiVitae activity:
For the purpose of creating the customer account, a personal area is provided in which the customer must enter the data necessary for their identification as a customer. The first purchase will depend on the provision of additional personal data, indispensable for order processing and delivery.
Required fields on the forms available for those registration stages are marked with an asterisk (*).
LumiVitae is committed to protecting customer data which will never be made available to third parties without the acknowledgment or consent of the data subject, as legally required.
Besides that, when making a purchase on the site, customers will also be asked for their shipping address and payment details to promote maximum effectiveness and to ensure that the delivery times are met. Such data will be transmitted to the carrier which will guarantee the delivery operation, that entity being obliged to process such data in strict compliance with the GDPR key principles on the protection of personal data.
When processing a customer's order, it is possible that certain personal data - such as address and zip code - may be disclosed to third parties for the sole purpose of fraud prevention and detection and always following a request from the competent authorities. Such entities are also required to implement protection and security measures of such data.
The data provided will be stored for the strictly necessary period, which usually corresponds to the period of existence of the customer account. For this reason, when the customer triggers the deactivation of their account, the personal data will be permanently deleted, except for the data necessary to comply with legal obligations, namely but without limitation, for billing and accountancy purposes. Such data will be stored in a database specifically created for such purpose and only for the time absolutely necessary. Likewise, on an exclusive database, the data regarding the transactions made by Shopify, PayPal and Credit Card will be stored, respectively for six and twelve months. Such storage is made for the sole purpose of allowing future reimbursements due to customers during the said periods, from the date of issuance of the respective invoice.
Therefore, once the account has been deactivated, if customer wants to place a new order on the site, the customer must make a new initial registration, subject to the terms and conditions in force at that same date.
Any functionality or platform that LumiVitae may own and that the customer intends to use shall be conditioned to the acceptance of the respective terms and conditions of use as well as to, whenever specifically provided for, to the respective Privacy and Data Protection Policy. In all matters not covered by the before mentioned texts will be governed by, with the necessary adjustments, by the terms set out on the present document.
In regards to the accuracy of the customer's data and the respective registry, whenever the customer intends to verify the data provided to LumiVitae, the customer may do so on their personal area. Customer should keep their account access data secure, as any action or request made through your account will be their responsibility, provided that the customer follows the customer identity validation procedures described below.
We recommend customers not to store their password in their browser, as someone else with access to their computer can access their personal data.
For what purpose is the collected data used?
Customer data are processed in the context of actions such as order processing, customer's notification of any changes to site functionalities, surveys and the evaluation of interactions for statistical purposes.
Customers may, periodically and by email, receive information about products and services, campaigns, promotions and special offers. If the customer does not wish to be contacted for these purposes, the customer may unsubscribe from the newsletter by opting--out of the Manage Permissions tab in the account data area or by clicking on the hyperlink provided in the newsletter text for that specific purpose.
LumiVitae undertakes to use the personal data of its customers and visitors for the purposes strictly necessary for the pursuit of its activity, with the limitations arising from the scope of the same or the extent of the consent expressly granted by its holder. This also means that the data will not be transmitted to any third party without their knowledge and / or authorization where LumiVitae is so legally bound to.
In this sense, LumiVitae also ensures the access to such data by its employees to the extent deemed absolutely necessary to carry out the action in question. Those employees are identified and tracked according to the functions and tasks assigned to them and within the framework of the contractual relationship set between them.
All data processed by LumiVitae, whether directly indicated by the data subject or collected by LumiVitae for the sole purpose of executing the contract set between them or for the execution of any functionality requested or accessed by the customer will be definitely erased as soon as the purpose which has determined the processing fails to exist. For that reason, the storage of personal data shall observe the principles of data minimisation, purpose limitation and storage limitation since only the strictly needed data for the compliance with the legal and contractual obligation will be collected, which will be stored in a specific proper database for the period strictly necessary to such purposes.
The customer may at any time request information about the stored personal data, whether concerning the category of personal data, the source and recipient (s) thereof, the length of the storage period and the underlying purposes, or concerning the identification of the data controller, the data protection officer and their contacts.
In the event of a manifestly unfounded or excessive exercise of the right to be informed, LumiVitae may charge a fee of 100,00 € / hour (one hundred Euros per hour). This amount should be settled within five business days of receipt of payment instructions. The instructions shall be sent in writing to the email address provided by the data subject and / or via SMS to the mobile contact registered in their account or indicated as response to such request.
In order to exercise their right to rectification of their personal data, customer shall send the request, identifying the data to be modified and the up-to-date information, via email sent to [email protected] or by registered letter sent to data controller: LumiVitae, lda, Rua Bela São Tiago, n.º 20, sala 10, 9060-400 Funchal, Portugal. The same procedure should be followed if the customer wishes to exercise their right to erasure of personal data. In either case, the customer will receive confirmation, via the same channel used, that their request has been answered as requested.
In reinforcement of the principle of transparency in the processing of personal data and customer communications, LumiVitae allows the customer to, at any time, modify the data processing permissions granted for each of the stated purposes. Through the opt-in and opt-out features made available for the activation and deactivation of the granted permissions, in the tab "Manage Permissions" of the customer's personal account, the customer can modify or revoke the previous consents, namely those given for the purpose of receiving advertising campaigns, newsletters and other individualized communications including profiling, designed for the LumiVitae-customer relationship or for the optimization of the custom navigation experience as well as for the data processing by the remaining Group companies or by third parties which are LumiVitae partners for the execution of any of the functionalities that may be made available at the customer's request.
This text shall govern all the matters regarding the privacy and the data processing done within the framework of the use of the apps and further functionalities, whether accessible through a hyperlink made available by LumiVitae on the website, or on any other platform owned by LumiVitae. For that reason, it shall be applicable on a subsidiary basis to all the situations which may not be specifically regulated.
Any changes made to this Privacy and Data Protection Policy will be posted on the LumiVitae website and all versions prior to this will be made available upon express request of the customer.
Irregularities, non-compliance and any security restrictions on the processing of personal data should be immediately reported to the Data Protection Officer of LumiVitae by email: [email protected].