Privacy Policy

Privacy Policy

Individual Goda Narijauskaite (“Supernormal”, “we”, “our”, “us”), is the owner of the website www.supernormalpeople.com (hereinafter referred to as the "Website”). We are committed to protecting the privacy of our customers’ and online users’ (“you”, “your”). This Privacy Policy describes how we deal with the personal data that we process via our Website, our stores and/or applications managed by us and the services offered thereon (hereinafter referred to as the "Services”). This Privacy Policy applies to your use of our Website and Services, along with any use of our retail studio location at Kraziu 19, Vilnius, Lithuania.

By visiting our Website or providing us your personal data, you are accepting and consenting to the provisions of this Privacy Policy. All personal data processed by us, is handled in strict compliance with the European General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”).

  1. Controller

The data controller who processes all of the personal data we process is:

Goda Narijauskaite, individual working under an economic business certificate, located at Tauro street 8-33, 01113 Vilnius, Lithuania and registered at State Tax Inspectorate in Lithuania with the identification number 56577710.

If you have any questions, please contact our customer experience department at (hello@supernormalpeople.com).

  1. Personal Data Collected
  • Registration or information requests through our website

We process information from visitors of our store and Website, including when you buy products or receive information from us through email or phone with your request for information. We process personal data based on: consent according to art. 6(1)(a) GDPR, contract according to art. 6(1)(b) GDPR, compliance with a legal obligation according to art. 6(1)(c) GDPR and legitimate interests according to art. 6(1)(f) GDPR.

You may contact us at any time through email to request information. If you send us such an email, we may process the personal data and information provided in your email.

We may combine the information you have provided with other information we have processed about you, both online and in person (including but not limited to your purchase history, your address, prescription details and/or purchase date), along with information that we receive from public information sources and external parties (e.g. Google, Facebook, etc.)

If you provide us with personal data about another person, you hereby declare that you are authorized to do so and that you allow us to use that information in accordance with this Privacy Policy.

  • Automatically generated data

When you use our Website, we may process and register your IP address. Your IP address will be stored in a temporary log file. We may share information regarding your use of our Website with our trusted subsidiaries, affiliates, and partners, as described further in Articles 3.2 and 3.3 below.

Additionally, like many other websites, we use cookies. A cookie is a small file that is sent along with pages of a website and stored by your browser on your computer’s hard drive. For example, cookie-related techniques are the use of fingerprints and scripts such as Google Analytics. Cookies allow personal data to be stored or consulted so that you can be recognised if you visit the Website again. For more detailed information on our use of cookies and similar technologies, please see our Cookie Policy.

  1. Purpose of Data Processing
  • We process your personal data, as described in Article 2.1, for the following purposes:
  • to fulfil our obligations to provide you with our Services or products (such as shipping and invoicing) or other requests you may make (such as contacting opticians) (based on contract according to art. 6(1)(b) GDPR);
  • to contact you regarding follow-up Services (such as communicating the results of nuances of processed custom orders), to answer your questions, and provide requested information or advice (based on consent according to art. 6(1)(a) GDPR);
  • to secure our business goals (based on legitimate interest according to art. 6(1)(f) GDPR):
    1. for data analysist to improve the efficiency of Services;
    2. for audits to check whether our internal processes function as intended and to comply with legal or contractual requirements;
    3. for fraud and security checks, such as to detect and prevent identity theft or cyberattacks;
    4. for the development of new products and services;
    5. to supplement, improve or change our Website, products, and services;
    6. to identify trends in the use of Services, to get insight on which parts of our Services are most interesting for our users; and
    7. to determine the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users;
  • analysis of personal data (e.g. purchase history, prescription details, shipping country and/or city, language) to provide personalised services offers (based on consent and legitimate interest according to art. 6(1)(a) and (f) GDPR):
    1. to understand you better so that we can personalise our interactions with you and provide you with information and / or offers that are tailored to your interests; and
    2. to better understand your preferences so that we can deliver content through the Services that we believe will be relevant and interesting to you.
  • to send you an email newsletter with offers and information about similar products and Services, only if you have specifically opted in for this. Please note that you can always object to such use, via the ‘unsubscribe’ link in our email newsletters (based on consent according to art. 6(1)(a) GDPR);
  • to comply with various legal obligations, including tax obligations (based on compliance with a legal obligation according to art. 6(1)(c) GDPR; and
  • if you respond to an action or contest, we use the information to carry out the action, to announce the prize winner(s), and to measure the response to our marketing campaigns (based on contract according to art. 6(1)(b) GDPR).
  • We will only make personal data available to third parties that are involved in the execution of your order (i.e. lens prescription for custom orders). These third parties process personal data according to our instructions and any such use shall be our full responsibility. Any such data made available is recorded, and any such third parties are also made parties to data processing agreements. We do not pass on your personal data to other third parties unless we are legally obliged to do so.
  • We use the automatically generated information, as described in Article 2.2, and your company data and personal data, as described in Article 2.1, to conduct aggregated analyses for internal research and statistical and strategic purposes ("Aggregated Information"). This Aggregated Information does not identify you or your company. We use the Aggregated Information to optimise our Website, Services and products and learn more about the use of our Website and products so we can improve them. 
  1. Use by Minors

The Services are not intended for use by persons under the age of 16. If you are younger than 16 years of age, you cannot make use of the Services and you must refrain from providing personal data. If your child has unexpectedly submitted personal information to us and you wish to request that the same personal data be removed, please contact us. Article 8 (Your rights with respect to your personal data) of this Privacy Policy describes the process through which you can contact us for any such requests.

  1. Data Retention
    • We shall process the personal data for a period of two (2) years after your last order, or for as long as legally required or necessary and allowed for the purpose(s) for which it was obtained. Immediately after these periods we will destroy the personal data and/or anonymise them.
    • The criteria used to determine our retention periods include, but may not be limited to: (i) the duration of our ongoing relationship with you and the Services we offer you; (ii) whether or not we are subject to any legal obligation(s); and (iii) any other legal necessity (such as applicable limitation period(s), litigation, or internal or external investigations).
    • Notwithstanding Article 5.1, we may process the personal data for a longer period (i) if you ask us to retain data for another two (2) year period, (ii) in order to comply with statutory retention periods (such as those required by tax legislation), or (iii) in order to prove compliance with applicable statutory obligations (such as the GDPR or email marketing legislation).
    • If you request deletion of your personal information by contacting us through the process described in Article 8, all of your personal information processed through our Website shall be deleted, as required by applicable law, unless we are obligated to retain such information, whether by law, to complete the transaction for which the information was processed, or for internal use.
  2. Data Protection

Any personal information we process is treated as confidential. As such, we shall take appropriate technical and organisational measures to safeguard and protect the personal data against any accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access or against any other unlawful or unauthorised processing of such personal data. These measures guarantee an appropriate level of security given the risks related to processing and the nature of the data. For example, we use Security Socket Layer encryptions during your order process and completion of our registration form.

  1. Sharing the Personal Data
  • Without prejudice to Articles 3, 7.1, and 7.2, we don’t transfer any personal information or personal data to any third party without your explicit permission, unless we are obliged to do so under applicable legislation or by order of the competent supervisory authority.
  • However, please note that we may transfer your personal data and the information to our local retail stores, as set out in Article 3.2.
  • Furthermore, we may employ other data processing companies to process personal data solely on our behalf. Such data processor companies are only entitled to process the data needed to perform their services and activities and in accordance with our explicit written instructions. The processor guarantees that it has implemented appropriate technical and organisational measures in such a manner that its processing meets the requirements of this Privacy Policy and the GDPR, and ensures the protection of the rights of all data subjects. The processing of personal data by a processor shall always be governed by a written data processing agreement between us and the processor. For additional information regarding these data processing companies, please contact us according to the process as described in Article 8, below.
  1. Your Rights
    • You have the right to obtain our confirmation as to whether or not we process your personal data, on request. The personal details you provide when registering with us a client can be viewed and altered at anytime by yourself through your account on the Website. You are also entitled to send our customer experience department (hello@supernormalpeople.com) a request to receive such information. Furthermore, you are entitled to send our customer experience department at hello@supernormalpeople.com a request to access, receive, transfer, rectify, erase or completely withdraw your consent for processing your personal data. We will process your request immediately and in accordance with the GDPR and we will send you a response without undue delay, at least within one month after the receipt of your written request.
    • You are entitled to object to our processing of your personal data at any time. Upon any such objection, we shall no longer process your personal data, unless we demonstrate 1) compelling legitimate grounds for the processing which override your interests, rights and freedoms, or 2) to establish, exercise, or defend any legal claim(s). We will send you a response without undue delay, not to exceed one month after the receipt of your written request.
    • If you have any complaints regarding our data processing or your previous requests, you can contact our customer experience department at hello@supernormalpeople.com. You also have the right to file a complaint with the relevant Data Protection Authority.
    • If you have any further questions or comments, please contact our customer experience department at hello@supernormalpeople.com
  2. Cross-border Transfer
  • Because Goda’s Narijauskaite’s individual economic activity is a global business activity, your personal data may be stored and processed in every country where we have facilities or service providers. By using our Services or by giving us permission (where required by law), you hereby agree that your information may be transferred to countries other than the country where you live, where other data protection laws may apply than in your own country. Appropriate contractual and other measures have been taken to protect personal data when sent to our subsidiaries or third parties in other countries.
  • Some countries outside the European Economic Area (EEA) are recognised by the European Commission as countries where an appropriate level of data protection applies according to the EEA standards (the full list of these countries is available here). For transfers from the EEA to countries that in the opinion of the European Commission do not offer sufficient protection, we have ensured that adequate measures have been taken, among other things by ensuring that the recipient is bound to EU standard data protection provisions, EU-US Privacy Shield certification, or an EU-approved code of conduct or certification to protect your personal data.

 

  1. Third-party Websites

Our Website may contain hyperlinks that lead to outside websites that are maintained by third parties. We cannot accept any responsibility for the content of these websites and for the way in which these websites deal with your data. Please be sure to read the applicable privacy policy, if present, of the website you are visiting.

  1. Revisions of This Privacy Policy

Please note that this Privacy Policy might be revised from time to time. Any revised Policy will be published on our Website, where the most current version is available at all times. We recommend checking our Website and the Privacy Policy on a regular basis. If we make a material change to this Privacy Policy that would lessen your privacy rights, we will either continue to honour our prior Policy for information that we processed when it was in force, or we will ask for your consent to the change. The last revision was made in August 2020

Vilnius, Lithuania, August 2020

Search