Privacy Policy

Last updated:

1. Introduction

Lyxtherozol ("we," "us," or "our") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website lyxtherozol.world and use our services.

We process personal data in accordance with the General Data Protection Regulation (GDPR) (EU) 2016/679 and other applicable data protection laws.

2. Data Controller

The data controller responsible for your personal data is:

Lyxtherozol
Yläkatu 3b
74120 Iisalmi
Finland
Email: request@lyxtherozol.world

3. Personal Data We Collect

We may collect the following categories of personal data:

  • Identity Data: Name, title
  • Contact Data: Email address, phone number (if provided), delivery address
  • Transaction Data: Details about orders placed with us
  • Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform
  • Usage Data: Information about how you use our website and services
  • Communication Data: Messages you send to us, including order inquiries and support requests

4. How We Collect Your Data

We collect personal data through:

  • Direct interactions: When you fill out forms, place orders, or contact us
  • Automated technologies: As you navigate our website, we may automatically collect Technical Data using cookies and similar technologies

5. Purpose and Legal Basis for Processing

We process your personal data for the following purposes:

  • To fulfill orders: Processing and delivering your orders (Legal basis: Contract performance)
  • To communicate with you: Responding to inquiries and providing customer support (Legal basis: Legitimate interest)
  • To improve our services: Analyzing website usage to enhance user experience (Legal basis: Legitimate interest)
  • To comply with legal obligations: Meeting our legal and regulatory requirements (Legal basis: Legal obligation)
  • Marketing communications: Sending promotional materials only with your explicit consent (Legal basis: Consent)

6. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:

  • Order data: Retained for 7 years following the transaction date for accounting and tax purposes
  • Communication records: Retained for 3 years from the last contact
  • Marketing consent records: Retained until consent is withdrawn
  • Technical logs: Retained for up to 12 months

7. Data Sharing and Transfers

We may share your personal data with:

  • Service providers: Companies that assist us with payment processing, order fulfillment, and delivery
  • Professional advisors: Lawyers, accountants, and auditors where required
  • Authorities: When required by law or to protect our rights

If we transfer data outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.

8. Data Subject Requests and Response Time

You can exercise your data protection rights by contacting us at request@lyxtherozol.world. We may request reasonable verification of identity before processing a request.

We respond without undue delay and in any event within one month of receiving a valid request. If permitted by law and due to complexity, this period may be extended by up to two additional months, and we will inform you accordingly.

9. Your Rights Under GDPR

Under the GDPR, you have the following rights:

  • Right of access: Request a copy of your personal data
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to restrict processing: Request limitation of processing in certain circumstances
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests or for direct marketing
  • Right to withdraw consent: Withdraw consent at any time where processing is based on consent

10. Data Security

We implement appropriate technical and organizational security measures to protect your personal data, including:

  • Encryption of data in transit using SSL/TLS
  • Secure storage with access controls
  • Regular security assessments
  • Staff training on data protection

11. Cookies

Our website uses cookies. For detailed information about the cookies we use and your choices regarding cookies, please see our Cookie Policy.

12. Third-Party Links

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites. We encourage you to read the privacy policies of any third-party sites you visit.

13. Children's Privacy

Our services are not intended for individuals under 18 years of age. We do not knowingly collect personal data from children.

14. Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be posted on this page with an updated revision date. We encourage you to review this policy periodically.

15. Complaints

If you believe that your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Finland, this is the Office of the Data Protection Ombudsman:

Data Protection Ombudsman
P.O. Box 800
00531 Helsinki
Finland
Website: tietosuoja.fi

16. Contact Us

For any questions about this Privacy Policy or our data practices, please contact us:

Lyxtherozol
Yläkatu 3b, 74120 Iisalmi, Finland
Email: request@lyxtherozol.world