1. Introduction and Data Controller
Thakreonphak.world ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or make a purchase.
Data Controller: Thakreonphak.world, Leipziger Pl. 12, 10117 Berlin, Germany. For any privacy-related inquiries, contact us at ask@thakreonphak.world.
2. Types of Data We Collect
We may collect the following categories of personal data:
- Identity data: Name, title, date of birth.
- Contact data: Email address, telephone number, postal address.
- Financial data: Payment card details, billing address (processed securely by our payment providers).
- Transaction data: Details of purchases, order history, delivery information.
- Technical data: IP address, browser type, device information, operating system.
- Usage data: How you use our website, pages viewed, time spent.
- Marketing data: Your preferences for receiving marketing communications.
3. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (EU) 2016/679, we process your personal data on the following legal bases:
- Contract performance (Art. 6(1)(b)): Order processing, delivery, customer service, and warranty fulfilment.
- Legitimate interests (Art. 6(1)(f)): Website security, fraud prevention, analytics to improve our services, and direct marketing (where permitted).
- Consent (Art. 6(1)(a)): Non-essential cookies, analytics, marketing communications, and newsletter subscriptions.
- Legal obligation (Art. 6(1)(c)): Tax, accounting, regulatory compliance, and responding to lawful requests from authorities.
4. How We Use Your Data
We use your personal data for the following purposes:
- Processing and fulfilling your orders and inquiries.
- Communicating with you about your orders, deliveries, and account.
- Providing customer support and responding to your requests.
- Improving our website, products, and services.
- Sending marketing communications (with your consent).
- Detecting and preventing fraud and abuse.
- Complying with legal and regulatory obligations.
- Analysing website usage to enhance user experience.
5. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements.
- Order and transaction data: 7 years (legal requirement for tax and commercial records).
- Customer inquiries and support: 3 years from the date of last contact.
- Marketing consent: Until you withdraw consent or object.
- Analytics data: Up to 26 months, anonymised where possible.
- Server and security logs: 90 days.
- Cookie data: As specified in our Cookie Policy.
6. Your Rights Under GDPR
You have the following rights in relation to your personal data:
- Right of access (Art. 15): Request a copy of your personal data.
- Right to rectification (Art. 16): Request correction of inaccurate data.
- Right to erasure (Art. 17): Request deletion of your data in certain circumstances.
- Right to restriction (Art. 18): Request limitation of processing in certain cases.
- Right to data portability (Art. 20): Receive your data in a structured, machine-readable format.
- Right to object (Art. 21): Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint: Lodge a complaint with a supervisory authority (e.g. the Berlin Commissioner for Data Protection).
To exercise any of these rights, contact us at ask@thakreonphak.world. We will respond within one month.
7. Data Security
We implement appropriate technical and organisational measures to protect your personal data, including:
- Encryption of data in transit (TLS/HTTPS) and at rest where appropriate.
- Access controls and authentication mechanisms.
- Secure hosting and regular security assessments.
- Staff training on data protection.
- Procedures for handling data breaches and notifying affected individuals and authorities where required.
8. Data Transfers
Your data may be transferred to and processed in countries outside the European Economic Area (EEA). Where we do so, we ensure appropriate safeguards are in place, such as adequacy decisions under Art. 45 GDPR, standard contractual clauses under Art. 46, or other approved transfer mechanisms.
9. Cookies
We use cookies and similar technologies. For detailed information, please see our Cookie Policy.
10. Contact
For privacy-related inquiries, to exercise your rights, or to contact our Data Protection Officer: ask@thakreonphak.world. Address: Leipziger Pl. 12, 10117 Berlin, Germany.