Due to the legislation on personal data protection, we undertake to provide you with and you have the opportunity to exercise the following rights related to personal data protection:
1. Right to receive information about whether we process your personal data and, if we do, what personal data is processed
You have the right to receive our confirmation as to whether we are processing your personal data, as well as the right to access your processed personal data, information on the purposes of data processing, the category of data being processed, the category of data recipient, the period of data processing, data sources, automated decision-making, including profiling, as well as about their meaning and consequences. The above information is provided to you in this policy and we believe it is useful to you. If you are a user of an app account or have linked your app account to a THANK YOU account (with an existing THANK YOU card) or created a new virtual THANK YOU card, you can view your personal data that we process in your app account, for example to check your current information, data, consents you have given, cancel consents already given or give new ones, review valid individual offers, get an overview of your purchase history of at least the last 2 years (adding and using MAXIMA money) using the app or THANK YOU card, check the balance of your MAXIMA money. Please note that the app and your THANK YOU account are linked to a specific THANK YOU card, so only the usage history of your valid THANK YOU card is shown on the account. If you exchange your THANK YOU card, your app account will not display the usage history of your old card, even if you have connected the cards. If the information provided in this policy and your app account is not sufficient for you, you can always contact us in the manner provided in this policy.
2. Right to request correction of your personal data
If the data provided by you has changed or you see that the information being processed about you is inaccurate or incorrect, you have the right to request that this information be changed, clarified or corrected.
You may self-correct your data in your app account or provide us with updated data by contacting us as described in this policy and requesting correction or clarification of your data.
3. Right to withdraw consent
If we process your data based on your consent, you have the right to withdraw your consent at any time and the processing of data based on your consent will be terminated.
For example, at any time you may withdraw your consent to receive commercial offers and information from the app, as well as your consent to profiling in order to provide you with personalized offers. Withdrawal of these consents does not limit your further use of the app or participation in the THANK YOU loyalty program or the ability to use its other benefits, but it means that we cannot make you good individual offers, etc.
You may correct your consent by revoking it or re-granting your previously revoked consent by providing the app with updated information in your app account or smart device, by changing the terms of the consent, or by contacting us as described in this policy.
If your consent expires or is withdrawn or revoked, we will delete the data processed with your consent, unless there is another basis for processing it to achieve other data processing purposes set out in the policy - but in the cases set out in the policy, we will anonymize the data permanently.
In any situation, we can keep your consent and its proof for a longer period of time, if it is necessary to protect our rights in connection with any demands and claims made against us.
4. Right to appeal
If it seems to you that we are processing your data in violation of the requirements of the legislation on the processing of personal data, we recommend that you immediately contact us directly. We believe that we can dispel all your doubts, satisfy your requests and correct errors, if any.
If you are not satisfied with the solutions we offer or if, in your opinion, we do not take the necessary measures, you have the right to file a complaint with the supervisory authority, which in the Republic of Estonia is the Data Protection Inspectorate (more information available at https://www.aki.ee/et)
5. Right to object to data processing if it is based on a legitimate interest
You have the right to object to the processing of your personal data if it is processed on the basis of our legitimate interest. However, considering the purposes and operating principle described in the terms and policies of your app account and the THANK YOU loyalty program, as well as the balance of the legitimate interests of both parties - you as a data subject and us as a data processor, it should be noted that your objections may mean that we will be unable to guarantee you the opportunity to use an app account and participate in the THANK YOU loyalty program in the future.
If you wish to exercise a right set out in this section, please send a written request to our data protection officer using the contact details provided in the policy.
6. Right to request deletion of data (right to be forgotten)
If there are important circumstances specified in the legislation governing the processing of personal data (in particular, the grounds specified in Article 17 of the General Data Protection Regulation), such as if personal data is processed illegally or the legal basis for data processing has disappeared, you have the right to demand that we delete your personal data. If you wish to exercise a right set out in this section, please send a written request to our data protection officer using the contact details provided in the policy.
You can also delete your personal data at any time. In order to delete your account, you must submit a corresponding application to klienditugi@maxima.ee following the instructions given in the Terms of Use of the App. When you delete your account, all personal data that is necessary for your app account to function will be permanently deleted. If your personal data processed while being a user of the app are used for other purposes specified in this policy and the legal basis for their processing is not consent, we may retain the relevant information to ensure the achievement of those purposes, such as to comply with the requirements arising from legislation governing the circulation of accounting documents, if you have paid for purchases through the app, or to ensure evidence is available in case you file a claim that may be related to your experience as a user of the app.
7. Right to request restriction of data processing
If the legislation on data processing refers to important circumstances, such as if personal data is processed illegally, you dispute the accuracy of the data or object to data processing based on our legitimate interests, you have the right to restrict the processing of your data. Please note, however, that due to data processing restrictions and while such restrictions are in effect, we may not be able to provide you with all the conveniences and benefits of a user of the app.
If you wish to exercise a right set out in this section, please send a written request to our data protection officer using the contact details provided in the policy.
8. Right to transfer data
You have the right to request the transfer of such data that you have provided to us in digital form. After receiving your data transfer request, we will ensure the realization of your right by issuing the data in a common and computer-readable format or by sending the data you want in digital form to the recipient of your choice, taking into account the information provided in your request.
If you wish to exercise a right set out in this section, please send a written request to our data protection officer using the contact details provided in the policy.
9. Application processing procedure
In an effort to protect the data of all users and customers of our app from illegal disclosure, when we receive a data request from you or to ensure your other rights, we must make sure that you are the actual user of the app and/or that the THANK YOU card has been issued to you. For this purpose, we may ask you to submit up-to-date data provided in your app account or THANK YOU account (such as first name, last name, date of birth, e-mail address or mobile phone number) and compare whether the data you provide corresponds to the data in the app account or THANK YOU account. During this verification, we may send a verification notification on the contact details you have provided, by text message or e-mail requesting authorization. If the verification fails, such as if the data you provide does not match the data in your app account or if you do not authorize after receiving a text message or e-mail, we are forced to state that you are not the data subject of the requested data and reject your request.
If we have received your request to ensure one of your rights and have successfully completed the above verification, we undertake to provide you with information on the progress of your request without delay, but in any case no later than one month after receiving your request and completing the verification. Considering the complexity of the application and the number of applications, we have the right to extend the one-month period by another two months, but we will inform you of this before the end of the first month and give reasons for such an extension.
If your request is submitted digitally, we will also send you a response using digital means, unless this is not possible due to the large volume of information, or if you ask us to respond in another way, or if you cannot be identified.
If we are forced to reject your request due to circumstances stipulated in the legislation, we will inform you of the refusal in writing and justify the refusal in accordance with the requirements stipulated in the legislation.
Data subjects may submit an application to exercise the above-mentioned rights (including withdrawing consent or prohibiting the use of your data), as well as complaints, notices or requests by e-mail at dpo@maxima.ee. The rights are exercised according to the conditions, restrictions and exceptions set forth in the legislation.
You can stop using the app at any time by deleting it from your smart device. In this case, we will stop collecting data related to your use of the app. In order to delete the data collected during your use of the app, you must submit an application in accordance with the terms and policies.
Deletion/removal of the app does not eliminate your app account or THANK YOU account or block your THANK YOU card, which means that even after deleting the app, we will continue to collect and process the personal data contained in your THANK YOU loyalty program privacy statement according to the procedures and conditions set out in the THANK YOU loyalty program.