Privacy Policy
1. General Information
This Privacy Policy explains how Biokaup OÜ (registration code 16519951, contact: info@itsbio.ee, phone +372 5667 5471) processes the personal data of its customers and website visitors on itsbio.ee.
Biokaup OÜ acts as the data controller in accordance with the EU General Data Protection Regulation (GDPR) and the laws of the Republic of Estonia.
By using our website and online store, you confirm that you have read and agreed to this Privacy Policy.
2. Personal Data We Process
Biokaup OÜ collects and processes personal data only to the extent necessary for providing services and maintaining customer relationships.
The personal data we may collect includes:
-
First and last name
-
Contact information (address, email address, phone number)
-
Order and payment details (including billing and delivery information)
-
Customer preferences (e.g. preferred contact method, language)
-
Website usage information (IP address, device and browser information, visit history)
Biokaup OÜ does not collect or process special categories of personal data (such as health data, political opinions, or religious beliefs).
3. Purposes and Legal Bases for Processing
Biokaup OÜ processes personal data for the following purposes and based on the following legal grounds:
Purpose of Processing | Legal Basis |
---|---|
Fulfilling online store orders and customer communication | Performance of a contract (GDPR Art. 6(1)(b)) |
Product delivery and payment processing | Contract performance and legal obligation |
Accounting and financial reporting | Legal obligation (Accounting Act) |
Marketing communications and newsletters | Customer consent (GDPR Art. 6(1)(a)) |
Website improvement and analytics | Legitimate interest (GDPR Art. 6(1)(f)) |
Customers can withdraw their consent for marketing communications at any time by using the unsubscribe link in our emails or by contacting info@itsbio.ee.
4. Disclosure of Personal Data to Third Parties
Biokaup OÜ may share personal data only when necessary for fulfilling an order or complying with legal obligations.
Third parties who may receive personal data include:
-
Delivery partners (e.g. Omniva, Smartposti, DPD) for shipping and delivery;
-
Payment service providers (Maksekeskus AS) for processing payments;
-
IT and marketing service providers assisting in managing the online store or sending newsletters;
-
Accounting service providers for fulfilling legal obligations.
All third parties are bound by confidentiality agreements and process data only in accordance with Biokaup OÜ’s instructions.
Personal data is not transferred outside the European Union or the European Economic Area, unless adequate data protection safeguards are in place in accordance with GDPR (such as an EU Commission adequacy decision or standard contractual clauses).
5. Data Retention
Biokaup OÜ retains personal data only as long as necessary to achieve the purpose for which it was collected or to comply with legal obligations:
-
Customer and order data – up to 3 years after the last purchase;
-
Accounting data – at least 7 years, in accordance with the Accounting Act;
-
Marketing consent data – until the consent is withdrawn.
After the retention period expires, data is securely deleted or anonymized.
6. Cookies and Web Analytics
The website itsbio.ee uses cookies to improve the user experience and analyze site usage.
Cookies are small text files stored on your device.
We may use the following types of cookies:
-
Essential cookies – required for the website and online store to function;
-
Analytical cookies – help us understand how visitors use our website (e.g. Google Analytics);
-
Marketing cookies – enable us to display relevant advertisements (e.g. Meta Pixel).
Users can manage or disable cookies at any time in their browser settings, except for technically necessary cookies.
7. Customer Rights
Under GDPR, customers have the following rights regarding their personal data:
-
To request access to their personal data held by Biokaup OÜ;
-
To request correction or completion of inaccurate data;
-
To request deletion of data (“right to be forgotten”) where permitted by law;
-
To restrict or object to the processing of personal data;
-
To withdraw consent for marketing communications;
-
To receive their data in a structured format and transmit it to another controller (data portability);
-
To lodge a complaint with the Estonian Data Protection Inspectorate (www.aki.ee) if they believe their rights have been violated.
All data requests and inquiries can be sent to info@itsbio.ee.
Biokaup OÜ will respond within a reasonable timeframe, but no later than 30 days from receipt of the request.
8. Data Security
Biokaup OÜ applies appropriate administrative, technical, and physical security measures to protect personal data from accidental or unlawful destruction, alteration, disclosure, or unauthorized access.
All communication between customers and the online store is protected through encrypted SSL connection.
Access to personal data is limited to authorized employees and partners who need it to perform their work duties.
9. Changes to the Privacy Policy
Biokaup OÜ may update this Privacy Policy periodically to reflect changes in legal requirements or business practices.
The latest version will always be available at itsbio.ee.
In case of significant updates, customers will be notified via email or newsletter.
This version is effective as of 3 October 2025.
10. Contact Information
Biokaup OÜ
Registration code: 16519951
Address: Pärnu, Estonia
Email: info@itsbio.ee
Phone: +372 5667 5471
Website: www.itsbio.ee