INTRODUCTION AND SCOPE
In the context of this Policy, Diatom Nutrients acts as a data controller for the Personal Data we process.
CATEGORIES OF PERSONAL DATA
We may process the following types of Personal Data:
biographical information, such as your first and last name; contact information, such as your e-mail address, physical address, and phone number; financial information, such as credit card details. HOW WE RECEIVE PERSONAL DATA We may receive your Personal Data when you share it with us directly as a current or a prospective customer, or when we receive your Personal Data from online marketplaces like Amazon.
BASIS OF PROCESSING
Within the scope of this Policy, we may rely on one or more of the following legal grounds for processing your Personal Data:
the need to perform our obligations under a contract or to perform related pre-contractual duties; the need to pursue our legitimate interests, such as our interest in marketing our products; your consent (which you may withdraw at any time); and any other grounds, as required or permitted by law. If you purchase a product from us, we require certain Personal Data about you (and the intended recipient of the product, if different) in order complete the sale. Without such Personal Data, we may not be able to provide our products to you or the intended recipient. PURPOSES OF PROCESSING We process Personal Data for the purposes of marketing, selling, and delivering our products to you, and responding to your requests and inquiries.
CATEGORIES OF RECIPIENTS & SHARING PERSONAL DATA WITH THIRD PARTIES
We may share your Personal Data with service providers. Such third parties may include those providing:
eCommerce shopping cart software; customer support and live chat software; e-mail marketing software; landing page management software; referral programs; product review management software; advertising services; affiliate marketing; cloud storage; shipping/logistics services; enterprise resource planning software; accounting software; payment processing services; business intelligence software; online sales analytics and management software; and web analytics tools.
We will require that these third-party service providers maintain at least the same level of data protection that we maintain for such Personal Data. TRANSFERS OF PERSONAL DATA TO THIRD COUNTRIES Some of our service providers who receive your Personal Data may be located in countries outside of the EU or the EEA. In some cases, the European Commission may not have determined that the legal environment in those countries provides a level of data protection that is essentially equivalent to the level of protection provided under European law. Transfers of your Personal Data to such service providers will typically be subject to appropriate safeguards, such as the standard contractual clauses for the transfer of Personal Data to third countries, as approved by, and available directly from, the European Commission.
HOW WE RECEIVE PERSONAL DATA
We may also disclose your Personal Data:
to the extent required by law or if we have a good-faith belief that such disclosure is necessary in order to comply with official investigations or legal proceedings initiated by governmental and/or law enforcement officials, or private parties, including but not limited to: in response to subpoenas, search warrants, or court orders; if we sell or transfer all or a portion of our company’s business interests, assets, or both, or in connection with a corporate merger, consolidation, restructuring, or other company change; to our subsidiaries or affiliates only if necessary for business and operational purposes.
We reserve the right to use, transfer, sell, and share aggregated, anonymous data, which does not include any Personal Data, about the users of our services as a group for any legal business purpose, such as analyzing usage trends and seeking compatible advertisers, sponsors, clients, and customers. If we must disclose your Personal Data in order to comply with official investigations or legal proceedings initiated by governmental and/or law enforcement officials, we may not be able to ensure that such recipients of your Personal Data will maintain the privacy or security of your Personal Data.
DATA INTEGRITY & SECURITY
Diatom Nutrients has implemented and will maintain technical, organizational, and physical security measures that are reasonably designed to help protect Personal Data from unauthorized processing, such as unauthorized access, disclosure, alteration, or destruction.
Personal Data will be deleted within thirteen months of the last interaction with the respective data subject.
ACCESS, REVIEW, OBJECTION TO PROCESSING & PORTABILITY
If you are a data subject about whom we store Personal Data, you may have the legal right to request access to, and the opportunity to update, correct, or delete such Personal Data. You may also have the right to ask that we limit our processing of your Personal Data, as well as the right to object to our processing of your Personal Data. You may also have the right to ask to have your Personal Data exported in a machine-readable format. To make such requests, if applicable, pleasecontact us using the information in the Contact Us section of this Policy.
PRIVACY OF CHILDREN
Our websites are not designed to collect data from children under the age of 13. We do not knowingly collect Personal Data from anyone under 18. If you believe your child’s Personal Data may be processed in the services, you can contact us using the information in the Contact Us section of this Policy to request that we delete the Personal Data.
CHANGES TO THIS POLICY
If we make any material change to this Policy, we will post the revised Policy to this web page and update the “Effective on” date above to reflect the date on which the new Policy became effective.
If you have any questions about this Policy or our processing of your Personal Data, please send us an email to Hello@DiatomNutrients.com.
Please allow up to 30 days for us to reply.
VeraSafe has been appointed as Diatom Nutrients’ representative in the EU for data protection matters, pursuant to Article 27 of the General Data Protection Regulation of the European Union. VeraSafe can be contacted in addition to Diatom Nutrients only on matters related to the processing of Personal Data. To make such an inquiry, please contact VeraSafe using this contact form: https://www.verasafe.com/privacy-services/contact-article-27-representative Alternatively, VeraSafe can be contacted at:
Matthew Joseph Zahradníčkova 1220/20A Prague 15000 Czech Republic VeraSafe Ireland Ltd Unit 3D North Point House North Point Business Park New Mallow Road Cork T23AT2P Ireland
SUPERVISORY AUTHORITY OVERSIGHT
If you are a data subject whose Personal Data we process, you may also have the right to lodge a complaint with a data protection regulator in one or more of the European Union member states.
Effective May 1, 2019.