Privacy policy
PRIVACY POLICY OF PAGWeb OÜ
Effective from 20.06.2025
-
General Provisions
The data controller of the online store PAGWOOD.EE (hereinafter the Online Store) is PAGWeb OÜ (registration code 16800837), located at Mäealuse 9, 12618 Tallinn, Harjumaa.
By using the Online Store and making purchases, the user of the Online Store (hereinafter the Client) confirms their agreement with the provisions set out in the Online Store’s privacy policy.
The purpose of this privacy policy is to describe to the Client, whether a natural or legal person, how PAGWeb OÜ processes the Client’s personal data. PAGWeb OÜ may update this document as necessary. The valid version is always available in the Online Store.
-
Data We Process
Natural person Client:
Personal data enabling client identification, such as first and last name, and personal ID code or date of birth;
Contact details, including email address and phone number;
Delivery information - address and chosen delivery method;
Payment-related data, such as bank account number, payment details, and purchase history;
Customer support data, including client inquiries, responses provided, complaints, and communication history;
Data about the use of the online store, including information about concluded contracts;
Statistical data and information related to customer surveys or marketing offers;
Other data voluntarily shared by the client, such as feedback or comments.
Legal person Client:
Contact details of the legal representative - first and last name, email address, and phone number;
Company’s official identification data - company name, address, and registration code;
Data related to the company’s contact person — name, email, and phone number;
Payment-related information - bank account number, payment details, and purchase history;
Delivery-related data - delivery address and method;
Authorized persons’ data - contact information and identification details;
Customer support data - client inquiries, responses, complaints, and communication logs;
Data related to the use of the online store - information about website usage and contract details;
Statistical and survey-related data - including survey results and offer-related information;
Other data voluntarily shared by the client - such as feedback and comments.
Client personal data is retained as long as the Client has not requested termination of processing or until their account has been deleted. If required by law, for example for accounting or other legal obligations, data may be retained for a longer period.
-
Reasons for Collecting and Processing Data
PAGWeb OÜ processes personal data to provide its clients with reliable, smooth, and high-quality service. Processing personal data of natural persons is primarily necessary for fulfilling the contract concluded with the client — including accepting, managing, and delivering orders. Certain data may also be required for fulfilling legal obligations, such as accounting or consumer dispute resolution.
Data of representatives of legal entities is processed mainly on the basis of legitimate interest, to identify the right of representation and enable appropriate business cooperation.
Personal data of natural person clients is used for the following purposes:
Identification data - required to conclude and properly fulfill purchase and sales contracts;
Contact data - used to communicate with the client, provide order status, and delivery information;
Delivery data - ensures timely and accurate delivery of ordered goods;
Payment data - processed to execute payments, manage refunds, and handle orders;
Customer support data - allows responding to inquiries, resolving issues, and handling complaints;
Online store usage data - collected to ensure site stability and improve user experience;
Analysis and feedback information - used to develop services and personalize offers;
Additionally, the client may voluntarily share extra information (such as comments or feedback) that helps us improve our service further.
Personal data of legal person clients is processed for the following purposes:
Company data and contact info — necessary for managing customer relations, proper order handling, and contract fulfillment;
Payment data - used to arrange payments and, if necessary, provide refunds related to orders;
Delivery data - information required for order delivery according to the agreement;
Purchase history - tracked for previous purchases and personalized services;
Authorized persons’ data - information about individuals authorized to act on behalf of the company;
Customer support - data for managing inquiries and feedback to respond quickly and effectively;
Online store usage data - collected to improve website functionality and optimize user experience;
Analysis and feedback - used for compiling statistical reports and enhancing services;
Voluntary information - additional info shared by the client, helping us better understand their needs and expectations.
-
Lawfulness of Data Processing
The main basis for personal data processing is the performance of a contract between the client and the online store - meaning data is used for managing orders, deliveries, and handling goods and payment returns.
Personal data is also processed according to legal obligations, such as accounting and financial reporting requirements.
Additionally, data processing may be based on the company’s legitimate interests, especially when resolving potential consumer disputes or analyzing purchase history to improve quality.
-
Data Sharing
Client names, phone numbers, and email addresses are forwarded only to delivery service providers chosen by the client when placing an order. For couriers, the delivery address is also included, which is necessary for proper and timely delivery of goods.
To ensure reliability and functionality of the online store, personal data is also shared with IT service providers managing web hosting and technical solutions.
-
Data Security and Access Restriction
Personal data is stored on secure servers located in countries of the European Union or European Economic Area. If necessary, data may also be transferred to countries recognized by the European Commission as having adequate data protection, and in certain cases to US companies that comply with Privacy Shield standards.
Access to personal data is strictly limited and allowed only to online store employees responsible for solving technical issues and providing customer support.
The online store applies diverse security measures - both technical and organizational - to prevent data loss, unauthorized access, or modification.
Data sharing with authorized processors takes place under specific contractual agreements ensuring sufficient protection and data accuracy. For example:
Data is shared with payment service providers to process payments;
Courier and logistics companies receive necessary contact information for delivering orders;
IT service providers are given data for managing and developing online systems.
-
Client’s Right to Access and Correct Their Data
Personal data can be accessed and corrected by contacting our customer support at info@pagwood.ee. Since our online store does not have a user profile system, personal data management and information provision take place through customer support.
Upon electronic request, necessary information is also provided via common electronic channels. Every individual has the right to access data collected about them, request correction of inaccurate data, demand termination of personal data processing, and obtain information about data usage.
-
Modification or Withdrawal of Consent
If personal data processing is based on the client’s consent, the client has the right to withdraw their consent at any time by notifying customer support via email.
-
Retention
Personal data related to payments or disputes is retained until the claim is fully settled or until the statute of limitations has expired.
Personal data contained in accounting-related documents is retained according to law for up to seven years.
-
Closing User Account and Deleting Personal Data
If you wish to delete your personal data, please contact our customer support at info@pagwood.ee. Your request will be reviewed within 30 days and you will be informed about the deletion process timeline. Please note that some data required to fulfill legal obligations (e.g., for accounting purposes) cannot be deleted.
For legal person clients, the account cannot be deleted until all outstanding debts to PAGWeb OÜ have been fully paid. This procedure is necessary to ensure fulfillment of contractual and financial obligations. The account can only be permanently closed once no unpaid invoices or other obligations remain.
To protect personal data and prevent misuse, deletion requests are accepted only if the applicant’s identity can be reliably verified - for example, through a digitally signed application.
-
Marketing Communication Preferences
The client’s email address and phone number may be used to send direct marketing messages only if the client has given explicit consent. If the client wishes to unsubscribe from such messages, they can do so at any time by clicking the link at the bottom of the email or by contacting customer support.
If personal data is used for direct marketing purposes, including creating customer profiles, the client has the right to object to such processing at any time. The request must be sent to our customer support via email.
-
Procedure for Handling Disputes
All questions and possible disputes related to personal data processing are resolved primarily through our customer support at info@pagwood.ee.
If the issue cannot be resolved satisfactorily, the Client has the right to contact the supervisory authority — the Estonian Data Protection Inspectorate (email: info@aki.ee).