Type of website: Ecommerce
Effective date: 1st day of January 2019
Casalivingdesign.com (the "Site") is owned and operated by Casa Living Design. Casa Living Design is the data controller and can be contacted at:
1350 Castlefield Ave, York, ON M6B 4C4
1. The personal data we will collect;
2. Use of collected data;
3. Who has access to the data collected;
4. The rights of Site users; and
For users in the European Union, we adhere to the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, known as the General Data Protection Regulation (the "GDPR"). For users in the United Kingdom, we adhere to the GDPR as enshrined in the Data Protection Act 2018.
We have not appointed a Data Protection Officer as we do not fall within the categories of controllers and processors required to appoint a Data Protection Officer under Article 37 of the GDPR.
By using our Site, users agree that they consent to:
When the legal basis for us processing your data is that you have provided your consent to that processing, you may withdraw your consent at any time. If you withdraw your consent, it will not make processing that we completed before you withdrew your consent unlawful.
You can withdraw your consent by: "Asking us to remove their account."
Legal Basis for Processing
We collect and process personal data about users in the EU only when we have a legal basis under Article 6 of the GDPR.
We rely on the following legal bases to collect and process the personal data of users in the EU:
1. Users have provided their consent to the processing of their data for one or more specific purposes; and
2. Processing personal user data is necessary for us to take steps before entering a contract or for the performance of a contract to which a user is a party at the request of a user. If a user does not provide the personal data necessary to perform a contract, the consequences are as follows: An order can not be placed without the appropriate customer information.
Personal Data We Collect
Data Collected Automatically
When you visit and use our Site, we may automatically collect and store the following information:
1. Hardware and software details;
2. Clicked links; and
3. Content viewed.
Data Collected in a Non-Automatic Way
We may also collect the following data when you perform certain functions on our Site:
1. First and last name;
2. Email address;
3. Phone number;
4. Address; and
5. Payment information.
This data may be collected using the following methods:
1. Creating an account; and
2. Accepting an order.
How We Use Personal Data
The data we collect automatically is used for the following purposes:
The data we collect when the user performs certain functions may be used for the following purposes:
1. To process orders.
Who We Share Personal Data With Employees
We will not sell or share your data with other third parties, except in the following cases:
1. If the law requires it;
2. If it is required for any legal proceeding;
3. To prove or protect our legal rights; and
4. To buyers or potential buyers of this company if we seek to sell the company.
If you follow hyperlinks from our Site to another Site, please note that we are not responsible for and have no control over their privacy policies and practices.
How Long We Store Personal Data
User data will be stored for ten years from order.
You will be notified if your data is kept longer than this period.
How We Protect Your Personal Data
While we take all reasonable precautions to ensure that user data is secure and protected, there always remains the risk of harm. The Internet as a whole can be insecure at times, and therefore we are unable to guarantee the security of user data beyond what is reasonably practical.
Your Rights as a User
Under the GDPR, you have the following rights:
1. Right to be informed;
2. Right of access;
3. Right to rectification;
4. Right to erasure;
5. Right to restrict processing;
6. Right to data portability; and
7. Right to object.
We do not knowingly collect or use personal data from children under 16. If we learn that we have collected personal data from a child under 16 years of age, the personal data will be deleted as soon as possible. If a child under 16 years of age has provided us with personal data, their parent or guardian may contact our privacy officer.
How to Access, Modify, Delete, or Challenge the Data Collected
If you would like to know if we have collected your personal data, how we have used your personal data, if we have disclosed your personal data and to who we disclosed your personal data, if you would like your data to be deleted or modified in any way, or if you would like to exercise any of your other rights under the GDPR, please get in touch with us here:
Do Not Track Notice
Do Not Track ("DNT") is a privacy preference you can set in specific web browsers. We do not track the users of our Site over time.