PastelPalace cares a lot about your privacy. We therefore only process data that we need for (improving) our services and we handle the information we have collected about you and your use of our services with care. We never make your data available to third parties for commercial purposes.
About the data processing
Below you can read how we process your data, where we store it or have it stored, which security techniques we use and for whom the data is transparent.
Web store software: WooCommerce
Data that you enter when placing an order or sending a message is stored on the servers of our processor WooCommerce. WooCommerce ensures a level of security that matches the data to be processed and takes adequate measures to protect data against loss or any form of unlawful processing. For example, a secure SSL connection is used as standard.
We purchase web hosting and e-mail services from Vimexx. They process personal data on our behalf and do not use your data for their own purposes. However, this party can collect metadata about the use of the services. These are not personal data. Vimexx has taken appropriate technical and organizational measures to prevent loss and unauthorized use of your personal data. They are obliged to observe secrecy on the basis of the agreement.
E-mail and mailing lists: MailChimp
We use the services of Vimexx (hosting) in combination with Gmail for our regular business e-mail traffic. This party has taken appropriate technical and organizational measures to prevent misuse, loss and corruption of your and our data as much as possible. Vimexx & Gmail have no access to our mailbox and we treat all our email traffic confidentially.
We use the Stripe platform to process (part of) the payments in our webshop. Stripe processes your name and your payment details such as your bank account or credit card number. Stripe has taken appropriate technical and organizational measures to protect your personal data. Stripe reserves the right to use your data to further improve the service and to share data with third parties in this context. Stripe does not store your data longer than permitted by the legal terms.
We use the Paypal platform to process (part of) the payments in our webshop. Paypal processes your name, address and residence details and your payment details such as your bank account or credit card number. Paypal has taken appropriate technical and organizational measures to protect your personal data. Paypal reserves the right to use your data to further improve the service and to share (anonymised) data with third parties. All the above-mentioned safeguards with regard to the protection of your personal data also apply to the parts of Paypal’s services for which they engage third parties. Paypal does not store your data longer than permitted by the legal terms.
Shipping and logistics
If you place an order with us, it is our job to have your package delivered to you. We use the services of PostNL to carry out the deliveries. It is therefore necessary that we share your name, address and residence details with PostNL. PostNL uses this information only for the purpose of executing the agreement. In the event that PostNL engages subcontractors, PostNL will also make your data available to these parties.
Invoicing and accounting: E-boekhouden
We use the services of E-boekhouden for our records of our administration and accounting. We share your name, address and residence details and details regarding your order. This data is used for the administration of sales invoices. Your personal data will be securely sent and stored.
E-boekhouden is obliged to observe secrecy and will treat your data confidentially. E-boekhouden does not use your personal data for purposes other than those described above.
Data: PastelPalace processes the following data:
First and last name – Gender – Address details – Telephone number (not required) – E-mail address – IP address – Other personal data that you actively provide, for example by creating a profile on this website, in correspondence and by telephone – Location data – Information about you activities on our website – Information about your surfing behavior across different websites (for example because this company is part of an advertising network) – Internet browser and device type
Our website and/or service does not intend to collect data about website visitors under the age of 16. Unless they have permission from their parents or guardian. However, we cannot check whether a visitor is older than 16. We therefore advise parents to be involved in the online activities of their children, in order to prevent data about children from being collected without parental consent. If you are convinced that we have collected personal information about a minor without this permission, please contact us via firstname.lastname@example.org and we will delete this information.
Data processing retention period
The data provided for the purpose of processing an order is retained for business operations and statistics. After 7 years (mandatory retention period for the Tax and Customs Administration) it is possible to request that data be removed from your order.
A registration for the newsletter will be saved until you unsubscribe.
Purpose of processing your data
General purpose of processing data
We only use your data for the benefit of our services. This means that the purpose of the processing is always directly related to the assignment you provide. We do not use your data for (targeted) marketing. If you share information with us and we use this information to – other than at your request – contact you at a later time, we will ask you explicitly for this. Your data will not be shared with third parties, other than to meet accounting and other administrative obligations. These third parties are all bound by confidentiality on the basis of the agreement between them and us or an oath or legal obligation.
Automatically collected data
Data that is automatically collected by our website is processed with the aim of further improving our services. This data (e.g. IP address, web browser and operating system) is not personal data.
Participation in tax and criminal investigations
In some cases Pastel-Palace.com can be held on the basis of a legal obligation to share data in connection with a tax or criminal investigation by the government. In such a case, we are forced to share your data, but we will oppose this within the possibilities that the law offers us.
We keep your data as long as you are our customer. This means that we keep your customer profile until you indicate that you no longer wish to use our services. If you indicate this to us, we will also regard this as a request to forget. On the basis of applicable administrative obligations, we must keep invoices with your (personal) data, so we will keep this data for as long as the applicable term runs. However, employees no longer have access to your client profile and documents that we have produced as a result of your assignment.
On the basis of the applicable Dutch and European legislation, you as a data subject have certain rights with regard to the personal data that are processed by or on behalf of us. We explain below which rights these are and how you can invoke these rights.
In principle, to prevent misuse, we will only send copies and copies of your data to the e-mail address already known to us. In the event that you wish to receive the data at a different e-mail address or, for example, by post, we will identify your questions. We keep records of completed requests, in the case of a request to be forgotten, we administer anonymous data. You will receive all statements and copies of data in the machine-readable data format that we use within our systems.
You have the right to file a complaint with the Dutch Data Protection Authority at any time if you suspect that we are using your personal data in the wrong way. This can be done via the following link: https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons
Right of inspection
You always have the right to view the data that we process or have processed that relate to your person or that can be traced back to you. You can submit a request to that effect to our contact person for privacy matters. You will receive a response to your request within 28 days. If your request is granted, we will send you a copy of all data with an overview of the processors who have this data, stating the category under which we have stored this data to the e-mail address known to us.
Right of rectification
You always have the right to have the data that we process or have processed that relates to your person or that can be traced back to you. You can submit a request to that effect to our contact person for privacy matters. You will receive a response to your request within 28 days. If your request is granted, we will send a confirmation to the e-mail address known to us that the details have been adjusted.
Right to restriction of processing
You always have the right to limit the data that we process or have processed that relates to your person or that can be traced back to you. You can submit a request to that effect to our contact person for privacy matters. You will receive a response to your request within 28 days. If your request is granted, we will send you a confirmation to the e-mail address known to us that the data will no longer be processed until you cancel the restriction.
Right to portability
You always have the right to have the data that we process or have processed that relates to your person or that can be traced back to you handled by another party. You can submit a request to that effect to our contact person for privacy matters. You will receive a response to your request within 28 days. If your request is granted, we will send copies or copies of all data about you that we have processed or that have been processed by us by other processors or third parties to the e-mail address known to us. In all probability, in such a case we can no longer continue the service, because the secure linking of data files can then no longer be guaranteed.
Right to object & other rights
In some cases you have the right to object to the processing of your personal data by or on behalf of Pastel-Palace.com. If you object, we will immediately stop the data processing pending the settlement of your objection. If your objection is well-founded, we will make copies and / or copies of data that we process or have processed available to you and then permanently discontinue the processing.
You also have the right not to be subject to automated individual decision-making or profiling. We do not process your data in such a way that this right applies. If you believe that this is the case, please contact our contact person for privacy matters.
Via our website, cookies (text files that are placed on your computer) are placed from the American company Google, as part of the “Analytics” service. We have entered into a processor agreement with google. We have disabled data sharing. We use this service to keep track of and receive reports on how visitors use the website. This processor may be obliged to provide access to this data on the basis of applicable laws and regulations. We have not allowed Google to use the obtained analytics information for other Google services.
Cookies from third parties
Cookies, or similair tech that we use