Privacy Policy
Last updated:
This Privacy Policy provides a comprehensive description of how Tloxoreliecholul.world ("we," "us," or "our") collects, uses, stores, discloses, and protects your personal data when you access our website, place orders, or interact with our services. We are committed to transparency and comply fully with the General Data Protection Regulation (GDPR), the ePrivacy Directive, and applicable New Zealand privacy legislation, including the Privacy Act 2020 and its amendments.
Data Controller
Tloxoreliecholul.world acts as the data controller for all personal data processed through our website and services. You may contact us at any time regarding your data.
Tloxoreliecholul.world
143 Lake Road, Devonport, Auckland 0622, New Zealand
Email: admin@tloxoreliecholul.world
Scope and Application
This policy applies to all visitors of our website, customers who purchase our products, individuals who subscribe to our communications, and anyone who contacts us through our forms or email. It covers data collected through our website, email correspondence, customer service channels, and any third-party services we use to facilitate our operations.
Data We Collect
We may collect the following categories of personal data:
- Identity data: Full name, title, and in certain cases date of birth when required for age verification or compliance purposes.
- Contact data: Email address, telephone number, billing and shipping address, and alternative contact details you provide.
- Technical data: IP address, browser type and version, time zone, operating system, device information, unique device identifiers, and referring URLs.
- Usage data: How you navigate our website, pages viewed, time spent, click patterns, and interaction with our content and features.
- Communication data: Messages, inquiries, and feedback you send via our contact forms, email, or customer service channels.
- Transaction data: Order details, payment information (processed securely by payment providers), purchase history, and delivery preferences.
- Marketing preferences: Your choices regarding newsletters, promotional communications, and cookie consent.
Purposes of Processing
We process your data for the following purposes, always in line with applicable law:
- To respond to inquiries, process orders, and provide customer support.
- To improve our website, products, and services based on user feedback and analytics.
- To send transactional communications such as order confirmations and shipping updates.
- To comply with legal and regulatory obligations, including tax and consumer protection requirements.
- To prevent fraud, ensure security, and protect against unauthorized access or misuse.
- To send marketing communications where you have consented or where we have a legitimate interest, with the ability to opt out at any time.
- To conduct surveys and research to better understand our customer base and improve our offerings.
Legal Basis Under GDPR
We process your data only when we have a valid legal basis:
- Consent: When you tick our consent checkbox, subscribe to newsletters, or accept non-essential cookies.
- Contract performance: To fulfil orders, process payments, and deliver products you have purchased.
- Legitimate interests: For website operation, analytics, fraud prevention, and marketing to existing customers, where such interests are not overridden by your rights.
- Legal obligation: To meet regulatory requirements such as tax reporting and consumer protection.
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected. Specific retention periods include:
- Order and transaction data: 7 years for legal and tax compliance.
- Contact form submissions and customer inquiries: 2 years from last contact.
- Analytics and usage data: Up to 26 months, after which it is anonymized or deleted.
- Marketing preferences: Until you withdraw consent or unsubscribe.
- Technical logs: Up to 12 months for security and debugging purposes.
After the retention period expires, data is securely deleted or anonymized so it can no longer identify you.
Your Rights
Under GDPR and the New Zealand Privacy Act, you have the following rights:
- Right of access: Request a copy of the personal data we hold about you.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request deletion of your data in certain circumstances ("right to be forgotten").
- Right to restrict processing: Request that we limit how we use your data in certain situations.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interests or for direct marketing.
- Right to withdraw consent: Withdraw consent at any time where processing is based on consent.
- Right to lodge a complaint: Lodge a complaint with a supervisory authority such as the Office of the Privacy Commissioner (New Zealand) or your local data protection authority.
To exercise any of these rights, contact us at admin@tloxoreliecholul.world. We will respond within 30 days. There is no charge for exercising your rights unless the request is manifestly unfounded or excessive.
Data Security
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure. These measures include:
- Encryption in transit (HTTPS/TLS) and at rest where applicable.
- Access controls limiting data access to authorized personnel only.
- Regular security assessments and vulnerability testing.
- Secure password policies and multi-factor authentication for administrative access.
- Employee training on data protection and confidentiality.
- Incident response procedures to address any breach promptly.
While we strive to protect your data, no method of transmission over the internet is 100% secure. We encourage you to use strong passwords and keep your account credentials confidential.
International Transfers
If we transfer your data outside the European Economic Area (EEA) or New Zealand, we ensure that adequate safeguards are in place. This may include Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other mechanisms recognized under applicable law. You may request details of these safeguards by contacting us.
Third-Party Sharing
We may share your data with trusted third parties who assist us in operating our business, such as payment processors, shipping providers, and analytics services. These parties are contractually required to protect your data and use it only for the purposes we specify. We do not sell your personal data to third parties for their marketing purposes.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or business operations. When we make material changes, we will update the "Last updated" date at the top of this page and, where appropriate, notify you by email or through a notice on our website. We encourage you to review this policy periodically.
Contact Us
For privacy-related inquiries, to exercise your rights, or to report a concern:
Email: admin@tloxoreliecholul.world
Address: 143 Lake Road, Devonport, Auckland 0622, New Zealand