Skip to content

GDPR Privacy Policy – Your Data Protection Rights

GDPR Privacy Policy

Last updated: January 23, 2025

This GDPR Privacy Policy explains how ToTintor (“Company”, “we”, “us”) collects, uses, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). By using https://totintor.com, you agree to this policy.

Definitions

  • Data Controller: ToTintor, as the entity responsible for determining purposes and means of data processing.
  • Personal Data: Any information relating to an identified or identifiable natural person (e.g., name, email, address, IP).
  • Data Subject: You, the individual whose data is being processed.
  • Processor: Third-party services used to process data on our behalf (e.g., Shopify, payment gateways, analytics providers).

Types of Data Collected

  • Personal Data: name, email, phone, billing and shipping addresses.
  • Usage Data: IP address, browser type, pages visited, time spent on site, device identifiers.
  • Cookies & Tracking: session cookies, functionality cookies, analytics cookies.

Legal Basis for Processing

  • Consent: when you subscribe to newsletters or marketing.
  • Contract: to process your orders and deliver products.
  • Legal obligation: to comply with tax or accounting laws.
  • Legitimate interest: to improve our services, prevent fraud, and ensure security.

Your Rights Under GDPR

  • Right to Access – request a copy of your personal data.
  • Right to Rectification – correct inaccurate or incomplete data.
  • Right to Erasure – request deletion of your data (“right to be forgotten”).
  • Right to Restrict Processing – limit how your data is used.
  • Right to Data Portability – receive your data in a machine-readable format.
  • Right to Object – object to processing, including for direct marketing.
  • Right to Withdraw Consent – opt-out of data uses where consent is the legal basis.

Data Transfers & Security

Your data may be transferred outside the EEA. In such cases, we ensure appropriate safeguards (e.g., Standard Contractual Clauses). We use SSL encryption, secure servers, and restricted access to protect your data.

Data Retention

We retain personal data only as long as necessary to fulfill business, legal, or compliance purposes. Usage data may be retained for shorter periods unless required for security or improvement.

Contact & Complaints

If you have questions about this Privacy Policy or would like to exercise your GDPR rights, contact us at:

If you are in the EU, you may also lodge a complaint with your local Data Protection Authority.

Back to top

Shopping Cart

Your cart is currently empty

Shop now