GDPR Notice
GDPR information for EU/EEA residents interacting with Galore De Teddies, including your rights and how we handle your personal data.
This GDPR Notice applies to individuals in the European Union (EU) and European Economic Area (EEA) who interact with Galore De Teddies. While we are a South African business, we respect and uphold the rights of EU/EEA data subjects under the General Data Protection Regulation (EU) 2016/679 (GDPR) where it applies to our activities.
1. Data Controller
Galore De Teddies acts as the Data Controller for the personal data described in this notice. We determine the purposes and means of processing your personal data.
- Contact: info@galoredeteddies.co.za
- Country of establishment: South Africa
2. Personal Data We Collect and Our Lawful Basis
| Category | Examples | Lawful Basis (GDPR Art. 6) |
|---|---|---|
| Identity & Contact Data | Name, email address, phone number, delivery address | Art. 6(1)(b) Contract performance |
| Financial Data | Payment information (processed via PayFast) | Art. 6(1)(b) Contract performance |
| Technical Data | IP address, cookies, browser and device data | Art. 6(1)(f) Legitimate interests (security, analytics) |
| Usage & Creative Data | Canvas drawings, designs, order history | Art. 6(1)(b) Contract performance |
| Marketing Preferences | Communication opt-ins and preferences | Art. 6(1)(a) Consent (freely given, withdrawable) |
3. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights, exercisable free of charge:
- Right of Access (Art. 15): Request a copy of the personal data we hold about you and information about how we use it.
- Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data.
- Right to Erasure / Right to be Forgotten (Art. 17): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Restriction of Processing (Art. 18): Request that we temporarily limit processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): Receive the personal data you provided to us in a structured, machine-readable format and transmit it to another controller.
- Right to Object (Art. 21): Object to processing based on legitimate interests, or to processing for direct marketing at any time.
- Rights re Automated Decision-Making (Art. 22): Right not to be subject to a decision based solely on automated processing that produces significant legal effects.
To exercise any of these rights, please contact us. We will acknowledge your request within 72 hours and respond fully within 30 days (extendable to 60 days for complex requests, with prior notice).
4. Recipients of Your Personal Data
We do not sell your personal data. We may share it with:
- PayFast payment processing (PCI-DSS compliant)
- Courier / delivery partners order fulfilment within South Africa
- Technology service providers hosting, email, analytics (bound by data processing agreements)
- Legal and regulatory authorities where required by applicable law
5. International Data Transfers
As a South African business, your personal data will be processed outside the EU/EEA. We ensure appropriate safeguards are in place, relying on one or more of the following mechanisms:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
- Binding Corporate Rules where applicable
You may request a copy of the transfer safeguards we rely on by contacting us.
6. Retention Periods
- Account data: Duration of your account plus 3 years after closure.
- Order and transaction records: 5 years (legal and tax compliance obligations).
- Marketing consent records: Until consent is withdrawn, then promptly deleted.
- Technical / log data: Up to 12 months for security and diagnostic purposes.
7. Security Measures
We implement appropriate technical and organisational measures to protect your personal data, including SSL/TLS encryption, access controls, secure payment processing, and regular security reviews. See our POPI Act Compliance page for further detail.
8. Right to Lodge a Complaint
If you believe we have not handled your personal data in accordance with GDPR, you have the right to lodge a complaint with your local EU/EEA supervisory authority. A list of national data protection authorities is available on the European Data Protection Board website at edpb.europa.eu.
We would appreciate the opportunity to address your concerns first please contact us before approaching your supervisory authority.
9. Updates to This Notice
We may update this GDPR Notice from time to time. We will post the revised notice on this page with an updated effective date. Registered users will be notified of material changes by email.