Privacy policy
1. General rules
1.1 Cannapaceus (hereinafter referred to as "Company") respects the right to privacy of all of its customers/buyers, including visitors (hereinafter referred to as "Customers") to the Company's website https://www.cannapaceus.com/ (hereinafter referred to as "Website") , and undertakes to ensure the protection of their personal data and their rights as data subjects.
1.2 This Privacy Policy governs the basic principles and procedures for collecting, processing and storing the personal data of the Company's customers (including visitors to the Website).
1.3 By using the Company's Website, as well as by ordering goods and providing the Company with your personal data, you agree to the provisions of this Privacy Policy (except for data processing activities, which will require your separate consent). Customers are deemed to have read and understood the Privacy Policy when they register on the Website/Customer System and tick the "tick" box below the text of this Policy. The Privacy Policy may be re-accessed at any time on the Site.
1.4 In processing your personal data, we comply with the European Parliament and Council of Europe Regulation Privacy Policy dated 27 April 2016. The provisions of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (hereinafter referred to as "Regulation"), the Law on Legal Protection of Personal Data of the Republic of Lithuania (hereinafter referred to as the "LPPD"), the Law on Electronic Communications of the Republic of Lithuania (hereinafter referred to as the "EC Law"), as well as the provisions of any other directly applicable legal acts regulating the protection of personal data, and the instructions of the supervisory authorities for the protection of personal data (in Lithuania - Valstybinė duomenų apsaugos inspekcija).
2. What terms are used?
2.1 Personal data means any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, a personal identification number, location data and an online identifier, or to one or more factors specific to the natural person's physical, physiological, genetic, mental, economic, cultural or social identity.
2.2 Data Subject means a natural person who is a customer of the Company (including visitors to the Website) whose personal data is collected by the Company.
2.3 Data Subject Consent - any freely given, specific and unambiguous indication of the data subject's wishes, by means of a statement or an unambiguous action, which is properly informed and by which the data subject consents to the processing of personal data relating to him or her.
2.4 "Processing" means any operation or set of operations which is performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, sorting, organisation, storage, adaptation or alteration, retrieval, access, use, disclosure by transmission, dissemination or otherwise making available, alignment with or combination with other data, restriction, erasure or destruction.
2.5 "Processor" means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the Data Controller.
2.6 Data Controller - www.cannapaceus.com
2.7 Cookie - a small piece of textual information that is automatically created when you browse the Website and is stored on your computer or other terminal device.
2.8 Direct Marketing - activities designed to offer goods and/or seek the views of individuals about the goods or services offered by post, telephone or other direct means.
3. What personal data do we collect about you?
3.1 The Company collects and further processes the following personal data that you provide when registering and/or ordering goods on the Website or ordering goods in any other way: name, surname, address, email address, telephone number, data related to the delivery of the goods, such as, The delivery of goods and order details, invoice numbers, billing, payment details, information on consent and non-consent to the processing of personal data for direct marketing purposes, passwords, any other data that you provide additionally on your own initiative when registering and/or ordering goods.
3.2 Your personal data referred to in clause 3.1 shall be stored for the duration of the cooperation between the Company and you (during the execution of the orders) and the customer's details in the invoices shall be stored for a period of ten years from the date of the invoice.
3.3 The Company collects and further processes the following personal data that you indirectly provide when registering and/or ordering services on the Website, i.e. these data are automatically collected from the computers and/or mobile devices you use when you log in to the Website: the IP addresses and times of your logins, the browser used and its version, the websites you have visited before you accessed our Website, the data on the use of the services such as, Data collected using cookies and similar technologies related to web browsing, etc.
3.4.Your personal data referred to in clause 3.3 shall be stored for the period of cooperation between the Company and you (during the provision of the services) and, depending on the data, for up to one year from the end of this period. These data may be stored for a longer period if there are other legal grounds for such storage period.
4. For what purposes do we process your personal data?
4.1 The Company processes your personal data for the following processing purposes: for the processing and administration of the purchase (order) of goods, for the identification of the Company's customers in the Company's information systems, for registering on the Website and logging into your account, for the processing of the accounting documents related to the ordering of services, for the contact with you for the fulfilment of your contractual obligations, for direct marketing purposes (only with the prior consent of the data subjects).
5. How do we process your personal data?
5.1. We ensure that your personal data will: Processed in a lawful, fair and transparent manner; collected for specified, explicit and legitimate purposes and not further processed in a manner incompatible with those purposes; adequate, relevant and only as necessary to achieve the purposes for which it is processed (data minimisation principle applies); accurate and, where necessary, kept up to date (accuracy principle applies), processed in such a way as to ensure, through appropriate technical and organisational measures, adequate security of personal data, including protection against unauthorised or unlawful processing and against accidental loss, destruction or damage (integrity and confidentiality principles apply).
6. What data subject rights do you have?
6.1 You have the following data subject rights, which we will exercise upon your request (by email) and upon your proper identification: access to your personal data and how it is processed, request the rectification of inaccurate personal data relating to you, as well as the supplementation of incomplete personal data relating to you, and the erasure of your personal data by the Company, if: a. They are no longer necessary for the purposes for which they were collected or otherwise processed; b. You withdraw your consent and there is no other legal basis for the processing of your personal data; c. The processing of the personal data was unlawful; d. other grounds set out in the Regulation; to request the Company to restrict the processing of your personal data, to obtain the personal data relating to you which you have provided to the Company in a structured, commonly used and computer-readable format, to object to the processing of personal data relating to you (e.g, for direct marketing or other purposes).
6.2 Please be informed that you may lodge a complaint with the State Data Protection Inspectorate if you consider that your rights as a data subject have been violated. More information about the State Data Protection Inspectorate and the complaints procedure can be found here: https://www.ada.lt/
7. How do we process personal data for direct marketing purposes?
7.1 Only with your prior consent and in accordance with the provisions of the LPPD, the EC law and the Regulation, we will send you Company newsletters by email and/or enquire about the quality of our existing services.
7.2 We process the following personal data for the purpose of direct marketing: name, surname, email address.
7.3 Your personal data for the purpose of direct marketing is retained until you have opted out of receiving direct marketing communications.
8. To whom do we provide your personal data?
8.1 Access to your personal data by employees of the Company is only granted on a need-to-know basis for the performance of their duties and only after the employee has undertaken to comply with the confidentiality requirement.
8.2 The Company may provide your personal data to: data processors who provide services to the Company and process your personal data on behalf of the Company and for the benefit of the Company or for your benefit, law enforcement authorities where there is a legal basis for doing so, other third parties with your consent.
8.3 We only use processors who ensure that appropriate technical and organisational measures are implemented in such a way that processing complies with the requirements of the Regulation and that your rights as data subjects are protected.
8.4 We note that the processors listed above are only entitled to process your personal data on our instructions.
8.5 A processor may not engage another processor without the prior specific or general written permission of the Company (the data controller).
8.6 Your personal data may also be provided in response to official requests from public authorities and the courts, but only after we have ascertained the lawfulness of these requests.
8.7 The e-shop processes payments using the makecommerce.lt platform, which is operated by Maksekeskus AS (Niine 11, Tallinn 10414, Estonia, reg. no.:12268475), and therefore your personal information necessary for the execution and confirmation of the payment will be transmitted to Maksekeskus AS.
9. Which cookies do we use and how?
9.1 In order to provide you with a more convenient and efficient browsing experience and to provide you with useful offers, we use the following cookies on the Website: "consent" (Confirmation of acceptance of the privacy policy of the website), "_ga", "_gid", "_gat_gtag_UA-108123585-1" (Google Analytics statistical information).
10. What links do we provide on the website?
10.1 The Website may contain links to third-party websites, to legislation, as well as links to social networks (the possibility of sharing the content of the Website on the social networks Facebook and Instagram). It should be noted that third party websites linked to the Website are subject to the privacy policies of those websites and the Company does not accept any responsibility for the content of the information provided by those websites, their activities and the provisions of their privacy policies.
11. Disclaimer
This is a translated copy of the original privacy policy in Lithuanian. If any of the provisions or rules of the Privacy Policy differ from the same provision or rule in the Lithuanian version of the Privacy Policy, please refer to the Lithuanian version.