Last update: March 4th, 2020

Introduction

At Horta da Maria, we value the trust that our users and customers place in us when they give us access to their personal information. The Privacy Policy describes how we work to maintain that trust and protect this information.

Specifically, this Privacy Policy describes how the personal and non-personal data that you provide to Horta da Maria are collected, used and disclosed when you access or use the services and online and/or mobile websites and the websites of Codebehind Lda or in relation to those services or websites (collectively, the "Site").

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Definitions

When the text reads “us”, “our website”, “Loja Online”, “Horta da Maria”, it refers to the Company CodeBehind Lda, to which this online store belongs.

Horta da Maria is an online sales store, whose scope is the marketing of various food-related products, including all types of fruit and vegetables such as: vegetables, vegetables, legumes, seasonal fruit, exotic fruits, baskets and the most diverse grocery stores, all primarily originating from National productions or selected imports, among others of the kind.

When in the text it reads “users”, “visitors”, it refers only to visitors without registration on the site; “Customers” are users who have already registered on the Online Store.

When in the text it reads “data holder” it refers to the personal data of the customer/users. When in the text it reads “RGPD” it refers to European data protection law.

‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

About Data Protection Law

In accordance with the European Law, General Data Protection Regulation (RGPD), which enters into force on May 25, 2018 and supersedes the current directive and data protection law in force, we carry out all these clarifications. However, we always advise a more detailed consultation by the user about their rights, so you can consult more information on the websites:

https://www.cnpd.pt/bin/rgpd/rgpd.htm

https://ec.europa.eu/commission/priorities/

justice-and-fundamental-rights/data-protection/

2018-reform-eu-data-protection-rules_en

Horta da Maria updated its privacy policy, so that the information provided to its users / customers is more transparent, and undertakes to comply with and implement all necessary measures to meet it.

Horta da Maria does not (and will not) have the objective of processing, selling or exchanging personal data, but due to its online activity, it is responsible for their security, for the clarification of its users / customers, and for compliance with the new rules into force.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

What is considered Personal Data

- name and surname;
- home address;
- e-mail address, such as firstname.lastname@company.com
- ID card number
- location data (eg the location data function on a mobile phone)
- IP (Internet Protocol) address
- cookie ID
- your phone's advertising identifier;
- data held by a hospital or doctor, which may be a symbol that uniquely identifies a person.

What is not considered Personal Data

- company registration number
- email address such as info@company.com
- anonymous data

Other changes to the law now include the right to:

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Right to your portability

The data subject, “customer”, becomes able to request access to the data existing on our website and it is done by request.Horta da Maria has no way to import any data from another site.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Right to be forgotten

It becomes the data subject, “customer”, to be able to request that their personal data be removed.

Horta da Maria will have to provide customers with information about what data they retain and for what purpose, if requested.

You will also have to create and implement technology that can give users the right to Opt-Out / Opt-In in the transmission of these data (NewsLetters / Notifications)

All customers can request, with Horta da Maria, the deletion of all their customer data. This measure applies only to customers and is made by request within 20 days of ordering.

The data to be deleted depends on the customer's use of the Horta da Maria website, that is, if he placed orders, comments, used coupons, etc. and taking into account whether they are considered personal data or not (in the case of Companies).

Note: If you placed orders, all promos associated with your account are deleted equally.

Note: Invoicing is not done online, but in a Management software, which under national law, must keep the invoices. This data includes mandatory data such as Name and Address, and optional data, Telephone and NIF if the customer provided them.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Right of access

The holder of personal data has the right to obtain from Horta da Maria confirmation that the data concerning him or her are or are not subject to processing and, if applicable, to access their personal data and access the information provided for by law .

If you want more than one copy of your personal data in the process of being processed, Horta da Maria may subject this service to a fee for administrative costs.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Right of Rectification

The holder of personal data has the right to obtain from Horta da Maria, without undue delay, the rectification of inaccurate or incomplete data concerning him.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Right to Limitation of Treatment

The data subject has the right to obtain from Horta da Maria the limitation of the treatment, if one of the following situations applies:

a) Dispute the accuracy of personal data, for a period that allows Horta da Maria to verify its accuracy;

b) The processing of data is lawful and the data subject opposes the deletion of their personal data and requests, in return, the limitation of their use;

c) Horta da Maria no longer needs personal data for processing purposes, but these data are required by the holder for the purposes of declaration, exercise or defense of a right in a legal proceeding;

d) If you have opposed the processing, until it is verified that the legitimate reasons of the data controller prevail over those of the data subject.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Right of opposition

1. In cases where data processing is carried out for the purpose of legitimate interests pursued by Horta da Maria;

2. When data processing is carried out for direct marketing purposes

3. The data subject may also, at any time, object to the processing of their personal data.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Registration Data

We remind you that the entire site is encrypted by a Security Certificate, so that the data sent between the server and the user is safe.

We start by providing information about what personal data a user provides and which is collected when registering at Horta da Maria:

Required fields

- Name and surname
- Address
- City
- District
- Postal Code
- Country
- Email address
- Telephone
- Password (encrypted)
- Privacy Policy Acknowledgment Visa.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Optional Fields:

- Tax Information (Name, TIN)
- Receive NewsLetter

The Mandatory Fields collected on the registration page are intended for sending orders and contacting the customer.Your data will be kept for this purpose for 2 years of inactivity.During registration at Horta da Maria, it is now mandatory to indicate that you have become aware of our privacy policy.

This visa is associated with the created account.

The Name / NIF Optional Fields are for billing purposes.

These data provided to Horta da Maria are limited to internal use, not being shared with any outside service, except for email, first and last names if you choose to subscribe to the newsletter (see section on data shared with third parties).

Other information collected

your IP

The date of registration on the website / last access to the website.

Data from your device / Browser.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Why We Need This Data

This data collected by our website is key both for its operation and for its security, including a cookie with the session ID, IP and device. Allow the online store to create / know / analyze if a customer:

Used a discount coupon

How many points you have accumulated on your card.

Placed Orders.

Contact requests or messages.

Location (IP – allows us to detect intrusions to reserved areas).

Device (Lets us know what kind of view to show (smartphone, tablet, computer)

All these data are processed only by Horta da Maria (Data Controller and Processor), and for the functioning of the Online Store. They have the duration of the session started when you visit the site.

They also allow to improve the navigability of the site, knowing the type of devices / Operating System / screen resolution, in order to make the site visible on them.

Note: The IP Allows us to detect intrusion attempts by IP's to reserved areas of the website, in order to block them.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Data shared with third party websites

According to the regulation (RGPD), Horda da Maria has a data controller and if connected to third party services, these are the real data processors.

All of these services are reviewing and improving their privacy policies to comply with the RGPD.

Horta da Maria can process your data to send you information about its products and services.

This data processing will only be carried out with your consent, given at the time of registration of the customer account on our website.

If you consent, you will receive marketing communications via email and/or SMS. Horta da Maria will also be able to share your data with third parties that manage social networks, such as Facebook, for the purposes of carrying out marketing campaigns through social networks.

Consent to the processing of personal data for direct marketing purposes may be revoked at any time.

Your data will be kept for this purpose for 2 years of inactivity.

Horta da Maria's website is linked to the services of MailChimp, Google, Facebook, Hipay, Compra Fácil, Paypal and Stripe, which use their technologies as tools for data analysis or payment gateway.

Horta da Maria uses the PayPal platform as a gateway for payments also with Credit Card, to generate ATM references, MB Way and payment by Credit Card we use the platform provided by HiPay.

No personal or sensitive data is sent by Horta da Maria to the PayPal, Hipay or Stripe payment platform.

Payment is made outside the Horta da Maria website, on a secure platform duly accredited for this purpose.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

MailChimp

If you choose to subscribe to Horta da Maria's newsletter, your email is accessed by the MailChimp service. First and Last Name are optional.

Horta da Maria uses MailChimp's service and technology to send a weekly NewsLetter with News / Promotions / Discount Coupons, as the investment in a newsletter system with MailChimp's capacity would be extremely costly.

As a visitor, if you have subscribed to our NewsLetter, you can always unsubscribe.

MailChimp is an internationally recognized service. To learn more about MailChimp's privacy policy: Learn More

https://mailchimp.com/legal/privacy/?_ga=2.29855484.2107600803.1522925657-695328312.1522925657

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Google Analytics

We are connected to Google services. Horta da Maria's website does not track tags such as User ID or Emails, that is, we do not provide this data to any data processor (except at the option of the user / client in NewsLetters), and to some extent, there is a character of anonymity, but according to the regulation (RGPD), it is not true, as the IP is now considered a personal data.

As such, we have implemented a Cookies setting that allows the Customer / Visitor the decision to accept them or not, as well as the possibility of revoking that same decision at any time.

The information we have access to from these services includes data such as:
 - Demographic data
 - interests
 - Geographic data

This data is collected, whether from visitors or customers, who for example use Google services.

However, Horta da Maria does not use traces like the User Id , or other tags, such as emails, which would allow a deeper analysis of user data. Thus, there is no direct relationship, or we do not have access, to concrete information, between a customer (his name or email) and the data we obtain from Google, but rather a more abstract data relationship via IP : for example: if visitors to our site are mostly male or female.

This data is important for any e-commerce website.

They allow the analysis of data both for promotional purposes in advertising campaigns, that is, to advertise our products to those who are interested in books, but also for the simple maintenance and improvement of the website itself, making it possible to notice if a certain page on the website is slow , if images are missing, which pages are most visited, etc.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Cookies

Consult ON HERE our Cookies policy

We advise you to clear cookies and configure them.

When browsing the Horta da Maria website, you must consent or not to the use of these cookies, which presupposes the acceptance of this Privacy Agreement.

Horta da Maria reserves the right to change this agreement without prior notice, and is obliged to notify its customers of the changes made.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Communication with the Customer

At Horta da Maria, communication with customers is preferably done by e-mail, using e-mails from the Online store.

Exchanged emails are saved until the subject is raised and then deleted from both the server and email clients.

If the phone number is provided, we may use this data for faster contact, such as a stockout of an ordered product, activate or help finalize the customer's payment for the product or to speed up the shipment of your product. order.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Customer Notifications

Emails of non-promotional content may be sent from us, related to, for example, new website features, changes to the privacy policy, changes in order status, "abandoned" cart reminders, among other promotional campaigns related to the abandoned carts.

‎‎‏‏‎ ‎‏‏‎ ‎‏‏‎ ‎

Responsible for the Processing and Protection of Personal Data

organizational structure, who will be available to provide you with any information regarding the processing of your personal data by Horta da Maria, including the list of our subcontractors in matters of personal data protection. It is possible to contact the DPO by sending an email to dpo@hortadamaria.pt, with the subject DPO.

The computerized processing of data collected by Horta da Maria is carried out in compliance with Law No. 67/98 of 26 October (Personal Data Protection Law), and authorized by the National Data Protection Commission.

For any further questions or further clarification contact: dpo@hortadamaria.pt