This Privacy Policy explains how MB “Bonideco” collects and uses personal data when you browse the Website, create an account, place an order, communicate with us or use related services.
Website: bonideco.fi
1. Controller
- Seller / data controller
- MB “Bonideco”
- Company code
- 306048688
- Registered address
- Servečės g. 2, LT-02121 Vilnius, Lithuania
- [email protected]
- Telephone
- +370 632 51053
For privacy questions or to exercise your rights, contact [email protected]. We do not designate a data protection officer unless legally required.
2. Principles and legal bases
We process personal data lawfully, fairly and transparently, for specified purposes, using no more data than necessary, keeping data accurate and no longer than needed, and protecting confidentiality and integrity.
Depending on the purpose, processing is necessary to perform a contract or take requested pre-contract steps; comply with legal obligations; pursue legitimate interests such as secure, efficient operations and legal claims, balanced against your rights; or is based on consent. Where consent is used, it may be withdrawn at any time without affecting prior lawful processing.
3. Data we may collect
- identity and contact details, delivery recipient and address;
- order, product, delivery, return, warranty and support information;
- payment status, transaction references, finance status and accounting data, but not full card numbers, CVC/CVV or bank passwords;
- account, authentication and saved preference data;
- communications, recordings where lawfully made and announced, photographs, videos, service reports and repair diagnostics;
- IP address, device, browser, identifiers, security logs, consent choices and Website usage;
- newsletter preferences, campaign interactions and marketing identifiers where consent or another lawful basis applies;
- reviews, ratings, questions, public content and social-network interactions;
- fraud-prevention, risk and compliance information where necessary.
We receive data from you, your authorised representative, payment and finance providers, carriers, service partners, public registers where lawful, and cookies or similar technologies according to your choices.
4. Purposes and bases
- Orders and accounts: contract performance and requested pre-contract steps.
- Payments, invoices and tax records: contract performance and legal obligations.
- Delivery, returns, warranty and support: contract performance, legal obligations and legitimate interests in documenting service.
- Security, fraud prevention and defence of claims: legal obligations and legitimate interests.
- Website functionality: contract-related steps and legitimate interests; consent where a non-essential technology requires it.
- Analytics, personalisation and advertising: consent where required.
- Direct marketing: consent or another basis expressly permitted by applicable law, with an easy opt-out.
- Reviews and community content: your request to publish, consent where relevant, and legitimate interests in moderation.
5. Required and optional data
Fields marked as required, and data objectively necessary for payment, delivery or legal compliance, must be supplied to complete the relevant service. If they are not supplied, we may be unable to accept or perform the Order. Optional account, review and marketing data may be withheld without losing core purchasing functionality.
6. Children
The Website is not intentionally directed to children who cannot validly enter the relevant transaction or provide consent under applicable law. Orders by minors require the involvement or approval of a legal representative where required. If we learn that data were supplied without a valid basis, we take reasonable steps to delete or restrict them unless retention is legally required.
7. Direct marketing
With valid consent, we may send newsletters, product news, promotions and personalised offers. You may unsubscribe using the link in a message or by emailing [email protected]. After an objection or withdrawal, we stop marketing processing; limited suppression data may be retained to respect the choice and demonstrate compliance.
8. Retention
| Data | Retention criterion |
|---|---|
| Orders, invoices and accounting | For the period required by law, generally 10 years from the end of the relevant financial year |
| Account | While active or until deletion is requested; order and legally required data follow their own periods |
| Customer service | Normally up to 2 years after closure, longer where needed for a warranty, dispute or claim |
| Returns, warranty, repair and disputes | Until resolution and expiry of applicable limitation periods |
| Direct marketing | Until consent is withdrawn or you object; proof of choice may be retained for the claims period |
| Technical and security logs | According to documented security, incident-investigation and legitimate-interest needs |
After the applicable period, data are deleted, anonymised or securely destroyed unless longer retention is legally required.
9. Recipients
Data may be disclosed only as needed to hosting, IT and security providers; payment, banking and financing providers; carriers, warehouses, installers and repair partners; accounting, legal, audit and insurance advisers; marketing and analytics providers according to consent; competent public authorities where legally required; and a successor in a lawful business transaction.
Processors act under contract and instructions. Some payment, finance, carrier, platform or advertising providers may act as independent or joint controllers for their own purposes and provide their own privacy information.
10. Transfers outside the EEA
Some service providers or their group companies may process data outside the European Economic Area. Where no adequacy decision applies, we use an appropriate safeguard such as European Commission standard contractual clauses and supplementary measures where necessary. You may request information about applicable safeguards.
11. Cookies and third-party services
Essential technologies support security, basket, checkout, account and language functions. Analytics and advertising technologies are used only according to the consent choices and applicable law. Details and preference controls are in the Cookie Policy.
Embedded payments, maps, videos, reviews, chat, CAPTCHA or social features may send the relevant provider technical and interaction data when loaded or activated.
12. Reviews, questions and public content
Content you submit for publication may show the chosen display name, rating, text, images and date. Do not publish another person’s personal data or unlawful content. Search engines or third parties may index or copy public content. You may ask us to correct or remove your content; limited records may remain for moderation, abuse prevention or legal claims.
13. Automated decisions
We do not make decisions producing legal or similarly significant effects solely by automated means unless this is necessary for a contract, authorised by law with safeguards, or based on explicit consent. Payment or finance providers may conduct their own automated fraud or credit assessments under their policies. Where applicable, you may request human intervention, express your view and contest a decision.
14. Your rights
Subject to the GDPR and applicable conditions, you may request access, correction, erasure, restriction, data portability, and object to processing based on legitimate interests or to direct marketing. You may withdraw consent at any time and lodge a complaint with the Lithuanian State Data Protection Inspectorate or the competent supervisory authority in your country of residence or work.
Send a request to [email protected]. We may request proportionate information to verify identity. We respond without undue delay and normally within one month; this may be extended by two further months for complex or numerous requests, with notice during the first month. Requests are normally free, subject to the GDPR rules for manifestly unfounded or excessive requests.
15. Security and changes
We apply proportionate organisational and technical measures including access controls, authentication, encryption in transit where appropriate, backups, logging, supplier controls, staff confidentiality and incident procedures. No system is entirely risk-free.
We may update this Policy when processing, services or law changes. Material changes are communicated by an appropriate method. The version in force at the stated date is published on this page.