Effective Date: November 27, 2023
1. Introduction
Welcome to Festey.com (“Festey”). This GDPR Policy is designed to provide a detailed overview of how we collect, process, and protect your personal data in accordance with the General Data Protection Regulation (GDPR).
2. Data Controller
The data controller for Festey.com is Festey.com, registered at 555 W 5th St, Los Angeles, CA 90013. If you have any questions or concerns about the processing of your personal data, please contact our Data Protection Officer at DPO@festey.com.
3. Legal Basis for Processing Personal Data
We process personal data based on the legal grounds provided by the GDPR:
- Consent: When you provide explicit consent for specific processing activities.
- Contractual Necessity: When processing is necessary for the performance of a contract with you.
- Legal Obligation: When processing is necessary to comply with legal obligations.
- Legitimate Interests: When processing is necessary for our legitimate interests or the legitimate interests of a third party.
4. Types of Personal Data Processed
We collect and process various types of personal data, including but not limited to:
- Contact information (e.g., name, email address, phone number)
- Account information (e.g., username, password)
- Transaction and payment data
- Preferences and user settings
- Device and browser information
5. Purposes of Processing
We process personal data for the following purposes:
- Providing and improving our services
- Personalizing your experience on Festey
- Processing transactions and fulfilling orders
- Communicating with you about updates, promotions, and relevant information
- Analyzing user behavior and trends to enhance user experience
- Responding to your inquiries and providing customer support
6. Data Subject Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request information about the personal data we hold about you.
- Right to Rectification: You can request corrections to inaccurate or incomplete data.
- Right to Erasure: You can request the deletion of your personal data under certain circumstances.
- Right to Restriction of Processing: You can request restrictions on certain types of processing.
- Right to Data Portability: You can request a copy of your personal data in a machine-readable format.
- Right to Object: You can object to certain types of processing, including direct marketing.
7. Lawful Processing
We ensure that our processing activities meet the lawful processing principles outlined in the GDPR, including fairness, transparency, and purpose limitation.
8. Data Protection Impact Assessments (DPIAs)
We conduct Data Protection Impact Assessments when processing activities are likely to result in high risks to individuals’ rights and freedoms.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, and destruction. Regular audits and reviews are conducted to maintain data security.
10. Data Breach Notification
In the event of a data breach that poses a risk to your rights and freedoms, we will notify the relevant supervisory authority and affected individuals in accordance with the GDPR.
11. International Data Transfers
We may transfer personal data to countries outside the European Economic Area (EEA) when necessary for the purposes outlined in this policy. We ensure that such transfers comply with the GDPR requirements, including implementing appropriate safeguards.
12. Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected unless a longer retention period is required or permitted by law.
13. Changes to this GDPR Policy
Festey reserves the right to update this GDPR Policy at any time. We will notify you of any changes by posting the updated policy on our website.
14. Contact Information
If you have any questions or concerns about this GDPR Policy or your personal data, please contact our Data Protection Officer at DPO@festey.com.