PRIVACY POLICY

1. BASIC TERMS

1.1. Company or Data Controller – Beauty Insanity House, a small partnership established and operating under the laws of the Republic of Lithuania, legal entity code: 307537970, registered address: V. Nagevičiaus St. 3, LT-08237 Vilnius, Lithuania.

1.2. Client or Data Subject – a natural person who is a client of the Company (including website visitors) whose personal data is collected by the Company.

1.3. Online Store – the Company’s online store available at www.bih.lt.

1.4. Services – all services provided by the Company.

1.5. Personal Data – any information relating to a natural person – the Data Subject – whose identity is known or can be directly or indirectly identified by reference to such data as a personal identification number or one or more physical, physiological, psychological, economic, cultural or social characteristics.

1.6. Processing of Personal Data – any operation performed on personal data: collection, recording, storage, classification, grouping, linking, modification (supplementing or correcting), provision, disclosure, use, logical and/or arithmetic operations, retrieval, dissemination, destruction or any other operation or set of operations.

1.7. Partner – a legal entity providing services to the Company related to its activities, supplying goods to the Company, or implementing joint projects with the Company, including but not limited to marketing campaigns, joint sales campaigns, loyalty programs, media channels, websites, the Online Store, retail outlets, distribution networks, etc.

1.8. Cookie – a small piece of text information automatically created when browsing a website and stored on the visitor’s computer or other device.

1.9. Direct Marketing – activities aimed at offering goods or services to individuals by post, telephone or other direct means and/or requesting their opinion about offered goods or services.

1.10. Privacy Policy – this document setting out the principles and rules for the processing of Personal Data when using the Online Store services.

1.11. Account – the main login data of the Client to the Online Store consisting of an email address and password.

1.12. Password – a unique combination of numbers, letters, or symbols created by the Client and used to access the Online Store.


2. GENERAL PROVISIONS

2.1. The Client grants the Company the right to perform all personal data processing operations within the scope and purposes defined in this Privacy Policy.

2.2. Personal data is processed in accordance with the Law on Legal Protection of Personal Data of the Republic of Lithuania and other legal acts regulating personal data protection, as well as this Privacy Policy.

2.3. Personal data is processed in the Company according to the following principles:

  • Personal data is collected for specified and lawful purposes;

  • Personal data is processed accurately, fairly and lawfully;

  • Personal data is adequate and limited to what is necessary;

  • Personal data is constantly updated;

  • Personal data is stored in a form allowing identification of the Data Subject no longer than necessary for the purposes for which it was collected;

  • All personal data information is confidential;

  • Personal data is not used for unlawful purposes.

2.4. By purchasing in the Online Store, the Client confirms that they have read the current version of the Privacy Policy and agree with it. If the Client does not agree with any part of the Privacy Policy, they must not place an order or purchase goods in the Online Store.

2.5. The Privacy Policy is available in the Online Store and may be printed at any time. The Company may amend, supplement or update it at its discretion. The updated version is published in the Online Store.

2.6. The Client may place orders in the Online Store without registration or by registering through an Account.

2.7. During initial registration, the Client must provide an email address, create a secure password and submit accurate personal data. The Client is responsible for the accuracy of such data. After creating an Account, an identification code is assigned.

2.8. When using the Services or purchasing in the Online Store, the Client must always provide accurate personal data and is responsible for its accuracy.

2.9. The Client has the right to change and supplement personal data in the Account or request deletion of the Account at any time.

2.10. The Client must keep the password confidential and not disclose it to third parties. Responsibility for any misuse rests with the Client.


3. COLLECTION, USE, CORRECTION AND STORAGE OF PERSONAL DATA

3.1. The Company respects each Client’s right to privacy. Personal data (name, surname, email address, phone number, delivery address, age/year of birth, payment details, purchase history, and with consent – gender, date of birth, place of residence) is collected and processed for the following purposes:

3.1.1. E-commerce purposes. Processed data: name, surname, email address, phone number, delivery address, age/year of birth, IP address, payment information. Retention period – 5 years from the last login to the Online Store.

3.1.2. Direct marketing purposes. Processed data: name, surname, phone number, email address, address, age, gender, date of birth, place of residence. Retention period – 5 years from the last login.

3.2. The Client may consent to the processing of personal data for direct marketing. If consent is withdrawn, the Company will stop processing data for this purpose and will no longer send marketing communications, except information related to orders.

3.3. Consent for direct marketing may be withdrawn at any time by contacting the Company at [email protected].

3.4. The Client may also opt out by clicking the unsubscribe link in marketing emails.

3.5. The Client has the following rights:

  • to receive information about personal data processing;

  • to access personal data and learn how it is processed;

  • to receive information about data sources, purposes and recipients;

  • to request correction, deletion or suspension of data processing if it violates legal requirements.

3.6. To exercise rights, the Client must verify identity (passport, ID card, driver’s license). Information about processed data is provided free of charge once per year. Requests may be submitted by email: [email protected].

3.7. Personal data is not transferred to third parties except:

  • with Client consent;

  • to Partners providing services related to Company activities;

  • to competent authorities as required by law;

  • for payment processing via MakeCommerce.lt platform operated by Maksekeskus AS (Liivalaia 45, Tallinn 10145, Estonia, reg. no. 12268475).

3.8. The Client has the right to object to processing of personal data for direct marketing at any time.

3.9. The Client agrees that personal data may be transferred to Partners for order fulfillment and service provision.

3.10. If the Client does not agree with this Privacy Policy, they may not use the Online Store services.

3.11. The Company implements organizational and technical measures to protect personal data from unauthorized access, destruction, disclosure or unlawful processing.

3.12. Personal data may be stored longer if required by law enforcement authorities or legal obligations.

3.13. The Company responds to data-related requests within 30 calendar days.

3.14. Cookies may be stored on the Client’s device to ensure full functionality of the Online Store, recognize returning users and collect statistics. The Client may review and delete cookies at any time.

3.15. More information about cookies is available at www.allaboutcookies.org.


4. FINAL PROVISIONS

4.1. The Company has the right to amend or supplement this Privacy Policy at any time. Changes take effect from the date of publication.

4.2. Contact details:

Beauty Insanity House, MB
Company code: 307537970
Address: V. Nagevičiaus St. 3, LT-08237 Vilnius, Lithuania
Email: [email protected]
Website: www.bih.lt