Loua cares about your privacy. We therefore only process data that we need for (improving) our services and we handle the information we have collected about you and your use of our services with care. We never make your data available to third parties for commercial purposes.
About the data processing
Below you can read how we process your data, where we store it (or have it stored), which security techniques we use and for whom the data is transparent.
Online store software
Our webshop has been developed with software from WooCommerce and we have chosen Strato for our web hosting. Personal data that you make available to us for the purpose of our services will be shared with this party. Strato has access to your data to provide us with (technical) support, they will never use your data for any other purpose. Strato is obliged to take appropriate security measures on the basis of the agreement we have concluded with them. These security measures consist of the application of SSL encryption and a strong password policy. Regular backups are made to prevent data loss.
Our webshop has been developed with software from WooCommerce, we host our webshop on a server under our own management. We have taken appropriate technical and organizational measures to prevent misuse, loss and corruption of data as much as possible.
We purchase web hosting and email services from Strato. Strato processes personal data on our behalf and does not use your data for its own purposes. However, this party can collect metadata about the use of the services. This is not personal data. Strato has taken appropriate technical and organizational measures to prevent loss and unauthorized use of your personal data. Strato is obliged to observe secrecy under the agreement.
Email and mailing lists
We use the services of Gmail for our regular business e-mail traffic. This party has taken appropriate technical and organizational measures to prevent misuse, loss and corruption of your and our data as much as possible. Gmail does not have access to our mailbox and we treat all our e-mail traffic as confidential.
We use the Stripe Payments platform to handle payments in our web store. Stripe processes your name, address and residence details and your payment details such as your bank account or credit card number. Stripe has taken appropriate technical and organizational measures to protect your personal data. Stripe reserves the right to use your data to further improve the service and to share (anonymized) data with third parties in this context. All the above-mentioned safeguards with regard to the protection of your personal data also apply to the parts of Stripe’s services for which they engage third parties. Stripe does not store your data for longer than permitted by law.
Shipping and logistics
When you place an order with us, it is our job to have your package delivered to you. We use the services of PostNL to carry out the deliveries. It is therefore necessary that we share your name, address and residence details with PostNL. PostNL only uses this information for the purpose of executing the agreement. In the event that PostNL engages subcontractors, PostNL will also make your data available to these parties.
Purpose of the data processing
General purpose of the processing
We only use your data for the purpose of our services. This means that the purpose of the processing is always directly related to the order you provide. We do not use your data for (targeted) marketing. If you share information with us and we use this information to contact you at a later time – other than at your request – we will ask you for explicit permission for this. Your data will not be shared with third parties, other than to comply with accounting and other administrative obligations. These third parties are all kept confidential by virtue of the agreement between them and us or an oath or legal obligation.
Automatically collected data
Data that is automatically collected by our website is processed with the aim of further improving our services. This data (for example your IP address, web browser and operating system) is not personal data.
Cooperation with tax and criminal investigations
In some cases Loua can be held on the basis of a legal obligation to share your data in connection with government tax or criminal investigations. In such a case, we are forced to share your data, but we will oppose this within the possibilities that the law offers us.
We keep your data for as long as you are a client of ours. This means that we keep your customer profile until you indicate that you no longer wish to use our services. If you indicate this to us, we will also regard this as a request for forgetting. On the basis of applicable administrative obligations, we must keep invoices with your (personal) data, so we will keep this data for as long as the applicable term runs. However, employees no longer have access to your client profile and documents that we have prepared in response to your assignment.
On the basis of the applicable Dutch and European legislation, you as a data subject have certain rights with regard to the personal data that are processed by or on behalf of us. We explain below which rights these are and how you can invoke these rights. In principle, to prevent misuse, we only send copies and copies of your data to your already known e-mail address. In the event that you wish to receive the data at a different e-mail address or, for example, by post, we will ask you to identify yourself. We keep records of completed requests, in the event of a request to be forgotten we administer anonymised data. You will receive all copies and copies of data in the machine-readable data format that we use within our systems. You have the right at all times to submit a complaint to the Dutch Data Protection Authority if you suspect that we are using your personal data in the wrong way.
Right of inspection
You always have the right to inspect the data that we process or have processed and that relate to your person or can be traced back to you. You can make a request to that effect to our contact person for privacy matters. You will then receive a response to your request within 30 days. If your request is granted, we will send you a copy of all data with an overview of the processors who have this data at the e-mail address known to us, stating the category under which we have stored this data.
Right of rectification
You always have the right to have the data that we process or have processed and that relate to your person or can be traced back to you adjusted. You can make a request to that effect to our contact person for privacy matters. You will then receive a response to your request within 30 days. If your request is granted, we will send you a confirmation that the data has been adjusted to the e-mail address known to us.
Right to restriction of processing
You always have the right to limit the data that we process or have processed that relate to your person or that can be traced back to you. You can make a request to that effect to our contact person for privacy matters. You will then receive a response to your request within 30 days. If your request is granted, we will send you a confirmation to the e-mail address known to us that the data will no longer be processed until you lift the restriction.
Right to portability
You always have the right to have the data that we process or have processed and that relate to your person or can be traced back to it, have it performed by another party. You can make a request to that effect to our contact person for privacy matters. You will then receive a response to your request within 30 days. If your request is granted, we will send you copies or copies of all data about you that we have processed or that have been processed on our behalf by other processors or third parties to the e-mail address known to us. In all likelihood, we will no longer be able to continue the service in such a case, because the secure linking of data files can then no longer be guaranteed.
Right to object and other rights
In some cases you have the right to object to the processing of your personal data by or on behalf of Loua. If you object, we will immediately stop the data processing pending the processing of your objection. If your objection is justified, we will make copies and/or copies of data that we process or have processed available to you and then permanently discontinue the processing. You also have the right not to be subject to automated individual decision-making or profiling. We do not process your data in such a way that this right applies. If you believe that this is the case, please contact our contact person for privacy matters.
Cookies are placed via our website from the American company Google, as part of the “Analytics” service. We use this service to keep track of and get reports on how visitors use the website. This processor may be obliged to provide access to this data on the basis of applicable laws and regulations. We have not allowed Google to use the obtained analytics information for other Google services.
Third Party Cookies
Contact person for privacy matters
Yente Friederichs E firstname.lastname@example.org