Privacy Policy
Last updated: March 13, 2025
1. Data controller and contact details
The data controller responsible for the processing of your personal data in connection with this website and our services is:
Vunarexxsmyx
5872 Oxford Ave
Philadelphia, PA 19149
United States
Email: welcome@vunarexxsmyx.world
Phone: +1 215 613 7900
You may contact us at any time with questions about this Privacy Policy or to exercise your data protection rights.
2. Scope and applicability
This Privacy Policy applies to the website https://vunarexxsmyx.world and all related subpages, as well as to the processing of personal data in the context of orders, customer support, and marketing activities carried out by Vunarexxsmyx. It describes what personal data we collect, for what purposes we use it, on what legal basis we process it, how long we retain it, and what rights you have under applicable data protection law, including the General Data Protection Regulation (GDPR) where applicable, and U.S. federal and state privacy laws.
3. Personal data we collect
We may collect the following categories of personal data:
- Identification and contact data: name, email address, telephone number, and postal address when you place an order, contact us, or subscribe to communications.
- Order and transaction data: order details, payment-related information (we do not store full card numbers; payment processing may be handled by third-party payment providers), delivery address, and order history.
- Technical and usage data: IP address, browser type and version, device type, operating system, referring URL, pages visited, date and time of access, and similar technical data when you use our website. This may be collected through cookies and similar technologies as described in our Cookie Policy.
- Communication data: content of messages you send to us (e.g. via contact form or email) and records of our correspondence.
We do not collect special categories of personal data (e.g. health data) unless you voluntarily provide it in a message and we need it to respond to your request. In that case, we will use it only for the purpose you indicated and in accordance with applicable law.
4. Purposes and legal basis for processing
We process your personal data for the following purposes and on the following legal bases:
- Performance of a contract: To process and fulfil your orders, manage deliveries, handle returns, and provide customer support. Legal basis: performance of a contract (Art. 6(1)(b) GDPR where applicable) or equivalent under U.S. law.
- Legitimate interests: To operate and improve our website, prevent fraud, ensure security, and defend our legal rights. Legal basis: legitimate interests (Art. 6(1)(f) GDPR where applicable), balanced against your rights.
- Consent: Where we use cookies or process data for analytics or marketing beyond strictly necessary purposes, we do so on the basis of your consent where required by law (Art. 6(1)(a) GDPR where applicable). You may withdraw consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Legal obligation: To comply with tax, accounting, and other legal obligations (e.g. retention of invoices). Legal basis: legal obligation (Art. 6(1)(c) GDPR where applicable).
5. Recipients and international transfers
Your data may be shared with:
- Service providers who assist us with hosting, payment processing, shipping, email delivery, and analytics, subject to contractual safeguards and only to the extent necessary for the stated purposes.
- Public authorities when required by law (e.g. tax authorities, courts).
Some of these recipients may be located outside the European Economic Area or your country of residence. Where we transfer personal data to such countries, we ensure appropriate safeguards are in place (e.g. standard contractual clauses approved by the European Commission, or equivalent mechanisms under U.S. or other applicable law) and that your rights remain protected.
6. Retention periods
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal obligations:
- Contract and order data: For the duration of the contractual relationship and thereafter for the period required by applicable tax and commercial law (typically 6–10 years for invoices and related records, depending on jurisdiction).
- Customer support and correspondence: For the time needed to resolve your request and, where relevant, for a reasonable period thereafter for evidence and quality purposes (e.g. 3 years), unless longer retention is required by law.
- Marketing and analytics data processed on the basis of consent: Until you withdraw consent or object, or for the period stated at the time of collection; thereafter we delete or anonymize the data in accordance with our retention schedule.
- Technical and access logs: For a limited period necessary for security and troubleshooting (e.g. 12–24 months), unless a longer period is required for legal or regulatory reasons.
After the retention period expires, we delete or anonymize your data so that it can no longer be attributed to you.
7. Security measures
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction, including:
- Use of HTTPS and encryption in transit for all data exchanged with our website.
- Access controls and authentication so that only authorized personnel can access personal data where necessary for their role.
- Secure storage and processing environments, regular updates, and security assessments.
- Contractual obligations with processors to maintain confidentiality and security.
Despite these measures, no method of transmission or storage over the Internet is completely secure. We encourage you to use strong passwords and to contact us immediately if you suspect any unauthorized use of your data.
8. Your rights
Depending on your place of residence, you may have the following rights in relation to your personal data:
- Right of access: To obtain confirmation as to whether we process your data and, if so, to receive a copy and information about the processing (Art. 15 GDPR where applicable).
- Right to rectification: To have inaccurate or incomplete data corrected (Art. 16 GDPR where applicable).
- Right to erasure: To request deletion of your data in certain circumstances (e.g. where it is no longer necessary, you withdraw consent, or you object and there are no overriding legitimate grounds) (Art. 17 GDPR where applicable).
- Right to restriction of processing: To request that we limit the processing in certain situations (Art. 18 GDPR where applicable).
- Right to data portability: To receive your data in a structured, commonly used, machine-readable format and, where technically feasible, to have it transmitted to another controller (Art. 20 GDPR where applicable).
- Right to object: To object to processing based on legitimate interests or for direct marketing; we will cease processing unless we demonstrate compelling legitimate grounds (Art. 21 GDPR where applicable).
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority in the country of your residence, place of work, or place of the alleged infringement. In the United States, you may also have rights under state laws (e.g. CCPA) and can contact us or the relevant state attorney general.
To exercise any of these rights, please contact us using the details in section 1. We will respond within the time limits set by applicable law (e.g. one month under the GDPR, subject to extension where necessary). We may need to verify your identity before processing your request.
9. Children
Our website and services are not directed at individuals under the age of 18. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us and we will take steps to delete such information.
10. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the way we operate. The "Last updated" date at the top will be revised when we make material changes. We encourage you to review this page periodically. Where required by law, we will seek your consent or notify you of significant changes before they take effect.
11. Additional information for specific jurisdictions
European Economic Area (EEA): Our processing of personal data of individuals in the EEA is governed by the GDPR. The legal bases and rights set out above apply. Our representative in the EEA (if we appoint one) will be indicated here or on request.
United States: We comply with applicable U.S. federal and state privacy laws. Residents of California and other states with specific privacy laws may have additional rights (e.g. to know, delete, correct, opt out of sale, non-discrimination). We do not sell personal information as defined under the CCPA. To exercise your rights, contact us at the details above.
For any questions about this Privacy Policy or our data practices, please contact us at welcome@vunarexxsmyx.world or by mail at the address above.