Privacy Policy 
This privacy policy for Lemons And Yarn OÜ (doing business as Lemons And Yarn) describes how and why we might collect and store your information when you use our website, such as when you:
Sign up for newsletters
Sign up for workshops
Order through the website www.lemonsandyarn.com


Data We Are Processing
We are processing data which might include customer's:
First and last name
Physical or email address
Website logins IP address
Credit card details


Purpose and Usage of Register
We only collect and use your data for the purposes written in this privacy policy or for purposes to which you have separately consented. We collect data so we can process your orders, workshop registrations, and offer newsletter marketing. We process your personal data in compliance with GDPR requirements and based on one or more of the following legal grounds:
Consent: We may process your data when you have explicitly given us permission to do so, such as subscribing to our newsletter or accepting cookies on our website. You can withdraw your consent at any time. 
Contractual necessity: We process your data when it's necessary to fulfill a contract with you, such as processing your order or providing customer support. 
Legitimate interest: We may process your data when it serves our legitimate business interests, such as improving our services, maintaining website security, or conducting market research, provided that such processing does not outweigh your rights and freedoms. 
Our aim is to collect as little personal data about you as possible.

Name of Register
The name of the register is Lemons And Yarn’s customer and contact person register.

Register Controller
The controller is Heli Savila, owner of Lemons And Yarn OÜ
Business ID: 2997285-8
Email: lemonsandyarn@gmail.com
Phone: +372 5691 2868
Company’s legal address: Lõõtsa 4 11415 Tallinn Estonia 


Privacy Policies of Other Websites
Lemons And Yarn’s website contains links to other websites. Our privacy policy applies only to our website, so if you click on another website, their privacy policy will apply.

Adobe Portfolio
This website is hosted by Adobe Portfolio, a platform by Adobe. If you want to know more about how Adobe deals with data, please refer to their privacy policy at https://www.adobe.com/privacy/policy.html

Stripe
By making a purchase on our website through Stripe, the data collected will be passed to the respective third party, including information required to process or support the payment, such as the purchase total and billing information. Stripe’s privacy policy is available at https://stripe.com/en-fi/privacy

Newsletter
We use MailerLite to manage our email marketing subscriber list and to send emails to our subscribers. MailerLite is a third-party provider, which may process your data using industry-standard technologies to help us monitor and improve our newsletter. MailerLite’s privacy policy is available at https://www.mailerlite.com/legal/privacy-policy
You can unsubscribe from our newsletter anytime by clicking on the unsubscribe link provided at the end of each newsletter.

GDPR-Compliant Data Processing Agreements with Third-Party Providers
We acknowledge that we have entered into GDPR-compliant data processing agreements with our third-party providers, including Stripe, MailerLite, and Adobe. This ensures that they maintain the same high standards of data protection and security that we adhere to when processing your personal data on our behalf.

Data Storage and Retention Periods 
In accordance with the GDPR's storage limitation principle, we have implemented data retention policies to ensure that personal data is stored for no longer than necessary for the purposes for which it was collected and processed. The data retention periods we apply depend on various factors, including legal obligations, contractual requirements, and our legitimate business interests. Below is a summary of our data retention periods for different categories of personal data:
Transaction data: Purchase and payment history, including order details and billing information, are retained for a period of 7 years in accordance with local tax laws and regulations.
Newsletter subscriptions: If you subscribe to our newsletter, we will store your email address and any other relevant personal data for as long as you remain subscribed. You may unsubscribe at any time, after which we will delete your personal data related to the subscription within 30 days.
Support inquiries: Personal data collected through support inquiries, such as name, email address, and the content of the inquiry, will be retained for 2 years to ensure proper follow-up, address any recurring issues, and improve our services.
Website analytics: We retain anonymized website usage data, such as IP addresses and browsing history, for a period of 1 year to analyze website performance and improve user experience.
Upon the expiration of the applicable data retention period or when the purpose for which the data was collected has been fulfilled, we will either delete or anonymize the personal data, as required by the GDPR. In certain circumstances, we may retain your personal data for a longer period if necessary for legal, regulatory, or other legitimate reasons.

Rights to change or delete your data
We would like to make sure you are fully aware of all your data protection rights. Every user is entitled to the following: 
The right to access, correct and delete data. You have the right to request for copies of your personal data, request us to make changes or erase your personal data from our register.
You have a right to data portability and to restrict the processing of your data. Please note that if you decline the processing of your personal data we may not be able to offer you our services, such as online orders and payments.
You also have a right to object to processing, the right to withdraw consent (where applicable), and the right to lodge a complaint with a supervisory authority.

Data Protection Measures
We are committed to protecting your personal data and have implemented appropriate technical and organizational measures to ensure its security. We work with GDPR-compliant providers that maintain high data protection standards.

Matters related to register
For all matters related to the register, if you have any queries, comments or requests regarding your data, please contact Heli Savila by email: lemonsandyarn@gmail.com

Changes to privacy policy
Lemons And Yarn keeps its privacy policy under regular review and places any updates on this website. 

Last updated: March 25, 2023
Back to Top