Privacy and Security Policy

This privacy policy defines how Maria Avillez Jewellery Unipessoal, lda, with registered office at Rua do Sacramento à Lapa, Nº62 - R/C Dto . 1200-795 Lisboa , uses and protects the information you provide when using the website www.mariaavillezjewellery.com .

Maria Avillez Jewellery reserves the right to change this policy from time to time, updating this text in accordance with any changes that may be implemented, and disclosing them through this means.

Responsible for data processing

The data controller is Maria Avillez Jewellery, who can be contacted through the following methods:

Telephone: +351 917570591 or 213905240

Address: Rua do Sacramento à Lapa, Nº62 - Ground Floor Right . 1200-795 Lisbon

Email: info@mariaavillezjewellery.com

 

Scope of the Privacy Policy

This Privacy Policy applies to data that has been directly provided by the data subject or collected during the data subject's access to our website.

The following information may be requested:

  • Name – for identification of the client and/or user of our website;
  • Mobile phone number and email address – for all communications related to your orders, as well as for sending promotional and informational emails about our products and services;
  • Address – for sending your orders or accounting documents (which may be different);
  • Tax identification number – for billing purposes;
  • IBAN – for refund purposes in case of returns.

Personal data processing and consent

By providing their personal data to Maria Avillez Jewellery Unipessoal, lda, the data subject gives prior, free, informed, specific and unequivocal consent for their data to be processed for the purposes described in this Privacy Policy.

Purpose

Data processing is necessary for the conclusion and performance of the purchase and sale or service provision contract to be entered into between the client/user and Maria Avillez Jewellery, or for carrying out pre-contractual due diligence at the client/user's request.

Data retention period

The period during which the data will be stored and retained varies according to the purpose for which the information is processed, with a maximum of 3 years of inactivity, after which you will be contacted to express your wish to preserve or delete your data from our database, without prejudice to the limitation periods and expiry of the exercise of rights of Maria Avillez Jewellery, under the law, as well as the retention of personal data arising from legal obligations.

Sharing and/or storing data with third parties.

The data will only be shared with partner companies for specific purposes, such as order fulfillment and delivery, and we ensure that these companies comply with the GDPR and this privacy policy.

For order delivery purposes, we may share shipping information (name, address, and phone number) with the carriers we work with.

We store your data on the e-commerce platform we use (Shopify), in our billing software, and on our email marketing platform (Mailchimp).

Rights of Personal Data Holders

The data subject has the right to request access to personal data concerning him or her, such as:

  • Rectification of personal data : the holder of personal data has the right to obtain from Maria Avillez Jewellery, without undue delay, the rectification of inaccurate or incomplete personal data concerning him or her.
  • Right of access: The holder of personal data has the right to obtain from Maria Avillez Jewellery confirmation as to whether or not data concerning him or her are being processed and, if so, to access his or her personal data and the information provided for by law.
  • Right to erasure of data (“right to be forgotten”): the data subject has the right to request Maria Avillez Jewellery to erase their data without undue delay, and Maria Avillez Jewellery has the obligation to erase personal data when one of the following grounds applies, in particular:
    1. The personal data is no longer necessary for the purpose that motivated its collection or processing;
    2. The data subject has withdrawn their consent to the processing of data (in cases where the processing is based on consent) and there is no other legal basis for said processing;
    3. The data subject objects to the processing and there are no overriding legitimate interests that justify the processing.

 

  • Right to restriction of processing: the data subject has the right to obtain from Maria Avillez Jewellery the restriction of processing if one of the following situations applies, in particular:
    1. To contest the accuracy of personal data for a period that allows Maria Avillez Jewellery to verify its accuracy;
    2. The data processing is lawful and the data subject objects to the erasure of their personal data and requests, instead, the restriction of its use;
    3. Maria Avillez Jewellery no longer needs personal data for processing purposes, but this data is required by the data subject for the establishment, exercise or defense of a legal claim.
    4. If you have objected to the processing, it will remain pending until it is verified that the legitimate grounds of the controller override those of the data subject.

  • Right to data portability: if the processing depends on the data subject's consent and that consent has been given by automated means, the data subject has the right to receive the personal data concerning him or her, which he or she has provided to Maria Avillez Jewellery, in a structured, commonly used and machine-readable format.
  • Right to object : In cases where data processing is carried out for the purposes of the legitimate interests pursued by Maria Avillez Jewellery, or data processing is carried out for direct marketing purposes; or profiling, the data subject may also, at any time, object to the processing of their personal data.
  • Right to Complain : You also have the right to lodge a complaint with the competent supervisory authority, the National Data Protection Commission, if you believe that Maria Avillez Jewellery has violated the rights available to you under the GDPR.
  • Revocation of consent : If consent is legally required for the processing of personal data, the data subject has the right to withdraw consent at any time, although this right does not compromise the lawfulness of the processing carried out based on the consent previously given, nor the subsequent processing of the same data based on another legal basis, such as compliance with a contract or legal obligation to which Maria Avillez Jewellery is subject.

These rights can be exercised through the following contacts:

Telephone: +351 917570591

Address: Rua do Sacramento à Lapa, Nº62 - Ground Floor Right, 1200-795 Lisbon

Email: info@mariaavillezjewellery.com

Responses to your requests may be provided in writing, electronically.

Responses will be provided without undue delay, within 1 month of receiving the request, or within 2 months followed by information to the data subject, when the request is complex or there are multiple requests.

Security

In order to prevent unauthorized access or disclosure, appropriate physical, electronic, and administrative procedures have been established to safeguard and protect the information we collect online, restricting access to stored data to employees specifically authorized for that purpose.

 

Cookies

Our website/online store uses cookies. Cookies are small software tags that are stored on access devices through the browser, retaining only information related to preferences, and therefore do not include personal data.

 

There are two groups of cookies that can be used.

  • Persistent cookies – these are cookies that are stored at the browser level on access devices (PC, mobile and tablet) and are used whenever you visit one of the Maria Avillez Jewellery Unipessoal, lda. websites again. They are generally used to direct navigation to the user's interests, allowing for a more personalized service.
  • Session cookies – these are temporary cookies that remain in your browser's cookie file until you leave the website. The information obtained by these cookies is used to analyze web traffic patterns, allowing us to identify problems and provide a better browsing experience.

Cookies enable website navigation and application use, as well as access to secure areas of the site. Without these cookies, necessary services cannot be provided.

 

Links to other websites

Our website may contain links to other websites of interest. However, once you have used these links, you should note that we do not have any control over these other websites. Therefore, we cannot be responsible for the protection and privacy of any information you provide while visiting such websites that are not governed by this privacy statement.

You should pay attention to the privacy statement applicable to the website in question.

Personal Data Breach

In the event of a personal data breach, the controller shall notify the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the personal data breach is unlikely to result in a risk to the rights and guarantees of natural persons.

Contact information for the National Data Protection Commission:

Rua de São Bento n.º 148-3.º 1200-821 Lisboa

Tel: +351 213928400

Fax: +351 213976832

Email: geral@cnpd.pt

Website: www.cnpd.pt