PRIVACY POLICY AND PERSONAL DATA PROCESSING
Natti Nattu™ brand highly respects its customers and users of its informational products and is committed to upholding their rights regarding personal data protection in the spirit and manner defined or implied by this Policy.
1. DEFINITIONS
1.1. The terms used in this Policy have the following meanings:
1.1.1. Personal Data Controller (Owner) – Individual entrepreneur Nataliya Volodymyrivna Fedyk, registered at: 79070, Lviv, Dovzhenka St., 10, apt. 99, mailing address: 04070, Kyiv, Andriivskyi Descent, 2-A, email: nattinattu.official@gmail.com, who sells products under the Natti Nattu™ brand and collects and processes personal data of customers and website users for the purposes defined in this Policy.
1.1.2. Personal Data – Information or a set of information about the customer and/or website user, processed by the Personal Data Controller.
1.1.3. Customer – An individual who, using the tools and means of the website, purchases products for personal use.
1.1.4. Website User – An individual who accesses the website using their own software and hardware.
1.1.5. Website – The website located on the Internet at: nattinattu.com.ua, consisting of separate web pages through which the Personal Data Controller sells products under the Natti Nattu™ brand.
1.1.6. Personal Data Processing – Actions or a set of actions performed by the Personal Data Controller, including collection, registration, accumulation, storage, adaptation, modification, updating, use, dissemination, anonymization, destruction (deletion) of personal data. These actions are performed both directly by the Personal Data Controller and using information (automated) systems.
1.1.7. Confidentiality of Personal Data – A mandatory requirement for the Personal Data Controller and recipients of personal data not to disclose them without the consent of the customer and/or website user or without other legal grounds.
1.1.8. Consent – Informed and voluntary permission given by the customer and/or website user for the processing of their personal data, expressed in writing or through certain actions or a set of actions that allow concluding that consent has been given.
1.1.9. Actions or Set of Actions Indicating Consent – Actions of the customer and/or website user, including but not limited to:
1.1.10 Accessing the website (a specific web page of the website);
1.1.11 Agreeing to the collection and processing of cookies or configuring cookie settings by clicking the appropriate button or selecting relevant options (settings) on the website;
1.1.12 Viewing product offers posted on the website (specific web pages of the website);
1.1.13 Creating (registering) an account on the website, logging into the website;
1.1.14 Contacting support by filling out forms on the website, sending an email to the specified email address, or making a phone call to the specified phone number;
1.1.15 Contacting the Personal Data Controller in any available way;
1.1.16 Placing an order or making a payment;
1.1.17 Receiving the product at the delivery service branch, from the delivery service courier, or through a parcel locker;
1.1.18 Any other actions defined by this Policy and/or current Ukrainian legislation as indicating consent;
1.1.19 Any other actions generally interpreted (perceived) as indicating consent.
1.1.20. Recipients of Personal Data – Legal entities and individual entrepreneurs who are service providers for delivering products to customers or processing payments (payment service providers).
1.1.21. Cookie – A small text file stored by the website on the customer's and/or website user's device, allowing the identification of such a device and containing information about actions performed by the customer and/or website user, including a list of specific web pages of the website visited by them, the time spent by the customer and/or website user on the website or on specific web pages of the website.
1.2. Terms and concepts not defined in this Policy are used in the meaning defined by the Public Offer, current Ukrainian legislation, or in the sense in which they are commonly used.
2. PURPOSE AND GROUNDS FOR PERSONAL DATA PROCESSING
2.1. The Personal Data Controller processes personal data for:
2.1.1. Processing and handling orders placed by customers on the website to conclude and properly execute the sales contract, creating (registering) customers' or website users' accounts.
2.1.2. Assessing and improving the quality of customer and website user service, providing them with customer support.
2.1.3. Providing customers and website users with access to up-to-date information about products, special offers, promotions, sales, order status, etc.
2.1.4. Conducting market research, including studies of demand for Natti Nattu™ brand products.
2.1.5. Identifying and forecasting fashion trends.
2.1.6. Promoting Natti Nattu™ brand products, creating a positive image, and popularizing the brand.
2.1.7. Informing customers and website users about new models of Natti Nattu™ brand products, special offers, promotions, sales, etc.
2.1.8. Sending commercial electronic messages to customers and website users, subject to their consent to receive such messages.
2.1.9. Enhancing the user experience of customers and website users when using website tools for searching, selecting, ordering products, concluding sales contracts, and making payments.
2.1.10. Optimizing business processes, informational services, and brand promotion technologies of the Personal Data Controller.
2.2. The grounds for processing personal data are the consent of the customer or website user, the legitimate interest of the Personal Data Controller, and in cases of concluding a sales contract – its execution.
3. SCOPE, METHODS OF COLLECTION AND PROCESSING OF PERSONAL DATA. TYPES OF DATA PROCESSED
3.1. The Personal Data Controller collects personal data within the minimum necessary to achieve the purpose of personal data processing.
3.2. The Personal Data Controller does not collect data on racial or ethnic origin, political, religious, or philosophical beliefs, membership in political parties and trade unions, criminal convictions, as well as data concerning health, sexual life, biometric, or genetic data.
3.3. The Personal Data Controller collects personal data by:
3.3.1. Entering (providing) personal data by the customer or website user when creating (registering) an account on the website.
3.3.2. Entering (providing) personal data by the customer when placing an order on the website and concluding a sales contract.
3.3.3. Entering (providing) personal data by the customer or website user when contacting support.
3.3.4. Entering (providing) personal data by the customer.
3.3.4. The provision (submission) of personal data by the buyer or website user during the completion of account profile forms or forms for participation in special offers, promotions, sales, etc.
3.3.5. Automatically through the collection of cookie files.
3.4. The owner (controller) of personal data collects and processes the following types of data:
3.4.1. Surname, first name, and patronymic (if available).
3.4.2. Mobile or landline phone number, email address.
3.4.3. Login and password of the buyer's or website user’s account.
3.4.4. Residential address (locality, street, building and apartment number, postal code), including the delivery address (branch or parcel locker number of a postal operator or delivery service, etc.).
3.4.5. Taxpayer Registration Card Number (identification code) – of the buyer.
3.4.6. Date or year of birth, gender of the buyer or website user.
3.4.7. Style preferences of the buyer or website user, information about interest in a specific product model or type of product.
3.4.8. Clothing size data, including height, weight, sleeve length, chest, waist, hip measurements, and other metric data necessary to select the correct size and model of the product.
3.4.9. Payment method data of the buyer (card number and issuer information, card expiration date, bank account number, cardholder name, CVV code).
3.4.10. Information about placed orders and completed purchases.
3.4.11. Cookie data.
3.4.12. Voice and phone call recordings of the buyer or website user with the support service, the content of email and written correspondence.
3.4.13. Profile photo of the buyer or website user.
3.4.14. Location data of the buyer or website user.
3.4.15. Information about size, style, models, materials, and colors of clothing items that interested the website user or were purchased by the buyer.
3.4.16. Data of product recipients (including those specified in clauses 3.4.1 – 3.4.15 of this Policy) provided to the personal data owner (controller) by the buyer in cases where the recipient is a person other than the buyer (e.g., purchasing a gift).
3.5. To place an order and conclude a purchase agreement, it is mandatory to collect the data specified in clauses 3.4.1, 3.4.2, and 3.4.4 of this Policy.
3.6. To create (register) an account, authorize a buyer or website user, or restore account access, it is mandatory to collect the data specified in clauses 3.4.1, 3.4.2, and 3.4.3 of this Policy.
3.7. To make a payment for the product, it is mandatory to collect the data specified in clause 3.4.9 of this Policy.
3.8. The personal data owner (controller) informs the buyer or website user about non-mandatory data by marking the respective input fields.
3.9. The personal data owner (controller) does not disclose the personal data of buyers and website users to third parties, except in the following cases:
3.9.1. Transmission of personal data to recipients of personal data to the extent necessary for the delivery of the ordered product to the buyer.
3.9.2. Transmission of personal data, particularly as specified in clause 3.4.9 of this Policy, to recipients of personal data to the extent necessary for payment processing or refund transactions.
3.9.3. Transmission of personal data in response to a justified request from authorized state or local authorities in accordance with the applicable laws of Ukraine.
3.10. If the personal data owner (controller) receives data specified in clause 3.4.16 of this Policy, it is assumed that the recipient of the product has been informed by the buyer and the buyer has obtained the recipient’s consent.
4. PERSONAL DATA PROCESSING PERIODS
4.1. The processing of personal data of buyers and website users begins from the moment of their first visit to the website (or a specific webpage of the site).
4.2. By making their first visit to the website (or a specific webpage), the buyer or website user gives their consent to the processing of personal data. If the buyer or website user does not agree with the processing of their personal data by the data owner (controller), they must immediately leave the website.
4.3. If minors or underage persons access and use the website or create (register) an account, it is considered that such actions are performed with the knowledge and permission of parents, guardians, or other legal representatives. In the absence of such consent, parents, guardians, or other legal representatives must immediately notify the personal data owner (controller).
4.4. Personal data is processed for the period necessary to achieve the purpose defined by this Policy, but not longer than the period established by the applicable laws of Ukraine.
5. PERSONAL DATA PROTECTION MEASURES
5.1. The personal data owner (controller) maintains the confidentiality of buyers’ and website users’ personal data. To this end, all available technical, organizational, and software protection tools are used.
5.2. The personal data owner (controller) monitors and checks the level of data security, including through modern encryption tools, technologies for detecting and preventing unauthorized access, identifying malware, and controlling both physical and technical access to personal data.
5.3. The personal data owner (controller) enters into necessary agreements with employees, contractors, and service providers regarding confidentiality, which include penalties for breach of data confidentiality.
6. RIGHTS OF BUYERS AND WEBSITE USERS
6.1. Buyers and website users have the following rights in connection with the processing of their personal data:
6.1.1. To know the sources of data collection, the location of their personal data, the purpose of processing, and the location/residence of the personal data owner (controller), or to authorize other persons to obtain this information, except as provided by law.
6.1.2. To receive information about the conditions of data transfer, including the recipients of personal data.
6.1.3. To access their personal data.
6.1.4. To receive, no later than thirty calendar days from the date of the request, except where otherwise specified by law, a response regarding whether their personal data is being processed, and to access the content of such data.
6.1.5. To submit a reasoned request to object to the processing of their personal data.
6.1.6. To submit a reasoned request to amend or delete personal data if such data is processed unlawfully or is inaccurate.
6.1.7. To protect their personal data from unlawful processing and accidental loss, destruction, damage due to intentional concealment, failure to provide or untimely provision, and to protect against false or defamatory information.
6.1.8. To file complaints regarding the processing of personal data with the Ukrainian Parliament Commissioner for Human Rights or with a court.
6.1.9. To use legal remedies in case of violation of personal data protection laws.
6.1.10. To make reservations about restricting the right to process their personal data in written consent.
6.1.11. To withdraw consent to the processing of personal data.
6.1.12. To know the mechanism of automated processing of personal data.
6.1.13. To protection from an automated decision that has legal consequences.
6.2. To exercise their rights, buyers and website users may contact the personal data owner (controller) via any communication channel listed on the website, including by mail, email, phone call to the support service, or by filling out a request form in their account (if available through the site's technical features).
6.3. To fulfill user or buyer requests, the personal data owner (controller) may require identity verification of the applicant.
6.4. A product recipient has the same rights as a buyer or website user and exercises them as described in clauses 6.2 and 6.3 of this Policy.
7. USE OF COOKIE FILES
7.1. When the buyer or website user accesses the site, the personal data owner (controller) may store cookies on their device.
7.2. Cookies are used to identify the buyer or user as a client, collect usage data to tailor services and content, and collect information about access devices to fulfill obligations and ensure account security.
7.3. Some browser settings allow users to block cookies and tracking technologies. If the buyer or user does not wish to use cookies, they must adjust their browser settings accordingly. If no such action is taken, cookie usage on the site is deemed accepted.
8. LIABILITY
8.1. In the event of improper performance of obligations regarding the confidentiality of personal data, the personal data owner (controller) is liable for documented damages incurred by the buyer or website user due to the owner's (controller’s) fault.
8.2. Disclosure of personal data to data recipients, government authorities, or local governments as specified in clause 3.9 of this Policy is not considered a breach of confidentiality.
8.3. The personal data owner (controller) is not liable for the disclosure or loss of personal data if:
8.3.1. The data became publicly available before disclosure or loss.
8.3.2. Any third party obtained or accessed the data before the disclosure or loss.
8.3.3. Disclosure occurred with the buyer's or website user’s consent.
8.3.4. Disclosure or loss occurred due to unlawful actions by third parties, including, but not limited to, unauthorized access, hacking, or bypassing security systems used to protect the data.
8.4. The personal data owner (controller) is not liable for the collection of personal data as specified in clause 3.4.16 of this Policy.
8.5. The buyer or website user is responsible for the accuracy, correctness, relevance, and completeness of the personal data provided and for disclosing recipient data without their knowledge or consent. If the data is outdated or inaccurate, the owner (controller) is not responsible for improper fulfillment of obligations.
8.6. Disclosure or loss of inaccurate data does not entail liability for the personal data owner (controller).
9. DISPUTE RESOLUTION
9.1. Disputes related to personal data processing are resolved through negotiations.
9.2. The buyer, website user, or recipient must first contact the personal data owner (controller) as specified in clause 6.2 of this Policy.
9.3. Legal disputes are resolved in Ukrainian courts in accordance with Ukrainian procedural law.
9.4. The applicable law for personal data processing relations is the law of Ukraine.
10. VALIDITY AND CHANGES TO THIS POLICY
10.1. This Policy is effective from the moment it is published on the website.
10.2. This Policy applies solely to the legal relations between the personal data owner (controller) and buyers or users of the site that arise through their use of the site. It does not apply to interactions via other resources (services or products) unrelated to the website.
10.3. The personal data owner (controller) reserves the right to change this Policy at any time without buyer or user consent, including the scope, basis, and purpose of data processing.
10.4. Buyers and users will be notified of changes by a notice on the website or an email, if they have consented to receive such messages.
10.5. If the buyer or user continues using the website after the Policy changes, including failing to delete their account, it is deemed they have agreed to the new version of this Policy.