Privacy policy
General Terms
MSM NATTY highly values and protects the privacy of its customers' data. This Privacy Policy clearly and transparently describes how SIA MSM NATTY, located at Madona region, Bērzaune parish, Sauleskalns "Pakalniņi", Registration No: 50203542861 (hereinafter referred to as the "Data Controller") obtains, processes, and stores personal data obtained from its customers and individuals visiting the natty.lv website (hereinafter referred to as the "Data Subject" or "You").
This Policy applies to cases when You visit the natty.lv website, purchase goods from the natty.lv online store, register on the website, or subscribe to newsletters. This policy also aims to inform you about other personal data processing activities carried out by natty.lv and the main principles aimed at ensuring your privacy. Personal data means any information relating to an identified or identifiable natural person, i.e., the Data Subject. Processing refers to any operation or set of operations performed on personal data, such as collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, or otherwise making available, alignment, or combination, restriction, erasure, or destruction.
The Data Controller complies with the European Union Regulation No. 2016/679 on the protection of personal data, the Personal Data Processing Law of the Republic of Latvia, the Electronic Communications Law of the Republic of Latvia, other related legislation, and requirements from supervisory authorities. Individuals under the age of 16 are not permitted to provide personal information on our website.
If you are under the age of 16, you must obtain consent from your parent or legal guardian before providing personal information.
Acquisition, Processing, and Storage of Personal Data
The Data Controller obtains, processes, and stores personally identifiable information primarily through the use of the online store website, during visits, registration, and email communication. By visiting and using the services provided on the online store, you agree that any information provided is used and managed in accordance with the purposes set forth in the Privacy Policy. The Data Subject is responsible for ensuring that the personal data provided are accurate, precise, and complete. Intentional provision of false information is considered a violation of our Privacy Policy. The Data Subject has an obligation to promptly notify the Data Controller of any changes to the submitted personal data. The Data Controller is not liable for any losses incurred by the Data Subject or third parties due to inaccurately submitted personal data.
Processing of Customer Personal Data
The Data Controller may process the following personal data:
Name, surname
Date of birth
Contact information (email address and/or telephone number)
Transaction data (purchased items, delivery address, price, payment information, etc.).
Any other information submitted to us during the use of website services and purchasing goods or when contacting us.
IP address (Unique code on the network that identifies a computer. It can be used to identify visitors and collect various demographic data)
Cookies (A small amount of data downloaded to your computer or device when visiting websites.) Information about cookies, types of cookies, and their purposes used on natty.lv website:
Required:
keep_alive - Used in connection with the buyer's localization. - Stored for 30 minutes
secure_customer_sig - Used to identify the user after they have logged in to the store as customers, so they do not have to log in again. - Stored for 1 year
localization - Used in connection with payment. - Stored for 1 year
_cmp_a - Used for managing client privacy settings, stored for 1 day
_tracking_consent - Used to store user preferences if the seller has set privacy policies in the visitor's region. - Stored for 1 year
wpm-domain-test - Required for website security - Stored for the duration of the session
Improves functionality:
_shopify_y - Shopify analytics - stored for 1 year
_orig_referrer - Records incoming page information - stored for 2 weeks
_landing_page - Records incoming page information - stored for 2 weeks
_shopify_s - Shopify analytics - stored for the session duration
_shopify_sa_t - Shopify analytics related to marketing and referrals - stored for 30 minutes
_shopify_sa_p - This cookie is set by Shopify and used for marketing and referral analytics - stored for 30 minutes
shopify_sa_p (HTTP cookie) - Collects data on visitor behavior and interactions - used to tailor advertisements on the website according to visitor preferences. The cookie also allows the site to determine referrals from other websites. - stored for 1 day
In addition to the aforementioned, Data Controller has the right to verify the accuracy of the submitted data using publicly available records. The legal basis for processing personal data is Article 6(1) of the General Data Protection Regulation, subparagraphs (a), (b), (c), and (f):
a) the data subject has given consent to the processing of their personal data for one or more specific purposes; b) processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; c) processing is necessary for compliance with a legal obligation to which the controller is subject; f) processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.
The Data Controller stores and processes the Personal Data of the Data Subject as long as at least one of the criteria listed below exists:
The personal data are necessary for the purposes for which they were received;
As long as in accordance with external regulatory acts, the Data Controller and/or the Data Subject may pursue their legitimate interests, such as lodging objections or raising or defending claims in court;
As long as there is a legal obligation to store the data, such as in accordance with the Accounting Law;
As long as the Data Subject's consent to the respective processing of personal data is valid, if there is no other lawful basis for processing personal data.
Upon the expiration of the circumstances mentioned in this section, the storage period for the Personal Data of the Data Subject ends, and all relevant personal data are irreversibly deleted from computer systems and electronic and/or paper documents containing the respective personal data, or these documents are anonymized.
In order to fulfill our obligations to you, the Data Controller has the right to transfer your personal data to our cooperation partners, data processors who perform the necessary data processing on our behalf, such as accountants, courier services, etc. The data processor acts as the data controller. Payment processing is provided by the payment platform makecommerce.lv, so our company transfers the personal data necessary for payment execution to the owner of the platform, Maksekeskus AS.
We use Shopify to operate our online store - you can learn more about how Shopify uses your Personal Information here: Shopify Privacy Policy.
Upon request, we may disclose your personal data to state and law enforcement authorities to defend our legal interests, if necessary, by preparing, submitting, and defending legal claims.
When processing and storing personal data, the Data Controller implements organizational and technical measures to ensure the protection of personal data against accidental or unlawful destruction, alteration, disclosure, and any other unlawful processing.
Rights of the Data Subject
In accordance with the General Data Protection Regulation and Latvian legislation, you have the following rights:
Access to your personal data, receive information about its processing, and request a copy of your personal data in electronic format and the right to transfer this data to another controller (data portability).
Request correction of incorrect, inaccurate, or incomplete personal data.
Delete your personal data ("be forgotten"), except in cases where the law requires data retention.
Withdraw your previously given consent to the processing of personal data.
Restrict the processing of your data - the right to request that we temporarily cease all processing of your personal data.
Contact the Data State Inspectorate.
You can exercise your rights by submitting a request electronically or writing to the customer support service at info@natty.lv.
We will respond to your request no later than 30 calendar days from the date of receipt. If you have any questions about the information included in this Privacy Policy, please contact MSM NATTY using the email address info@natty.com.
Conclusion
This Privacy Policy has been developed in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), as well as the applicable laws of the Republic of Latvia and the European Union.
The Data Controller reserves the right to make changes or additions to the Privacy Policy at any time and without prior notice. Amendments come into effect upon their publication on the natty.lv website.