Privacy Policy
The security of personal information is, above all, a matter of trust, and at greendrev.com the protection of user data is given the highest priority. This document describes in detail what information is collected, why it is needed, how it is used and what measures are taken to keep it from falling into the wrong hands. It is worth reviewing before leaving your contact details on the site or placing an order.
This Privacy Policy applies to all information that the site may obtain about a user while they use the resource, its services and its sections. Processing is carried out in strict compliance with the applicable data-protection law. Use of the site signifies full consent to the rules described herein. If any of the provisions appear unacceptable, it is better to refrain from using the resource’s services.
The accuracy of the personal data provided is not verified. It is assumed that the information is up to date and belongs to the person entering it. The user bears responsibility for the consequences of providing inaccurate information.
What data is collected
When interacting with the site, certain information may be requested — at the moments when a user fills in a feedback form, subscribes to the newsletter or places an order. Such information includes:
- Surname, first name and patronymic. Required for identification and to address you personally.
- Contact telephone number. Used to confirm orders and to clarify details of enquiries.
- Email address. Notifications about order status, answers to questions and, where consent has been given, site news are sent to it.
- Delivery address. Required when ordering goods or services that involve a specialist visit or courier delivery.
In addition to the data the user enters manually, technical information is collected automatically. It does not allow a person to be directly identified, but it helps to understand how the site works and where it slows down. Such data includes:
- IP address.
- Browser type and operating system.
- Date and time of access to the site.
- Addresses of the pages the visitor opened.
- The source of the visit to the site (for example, from a search engine or an advertisement).
Purposes of collecting information
Data is collected not for the sake of the process itself, but in order to accomplish specific tasks that make interaction with greendrev.com more convenient and clear. The main purposes are as follows:
- User identification. It is important to know whom the dialogue is being conducted with in order to prepare documents correctly and fulfil the order.
- Feedback. Answering questions and processing the requests and enquiries submitted through the forms on the site.
- Fulfilment of obligations. When products or services are ordered, the data is used to arrange delivery, installation and other work.
- Improving the quality of service. Analysis of technical information helps to identify errors, make the interface clearer and speed up page loading.
- Providing information. Where the relevant consent has been given, messages about new products, promotions or changes to the working schedule are sent to the specified email address.
Principles of personal data processing
The handling of personal data on the site is built on several fundamental principles, and these are not a declaration for show but working rules. The first is lawfulness: any action with data relies on a specific legal basis, be it the user’s consent or the need to perform a contract. The second is purpose limitation: information is used only for the tasks for which it was collected and is not diverted to extraneous needs.
The third principle is minimisation. Exactly as much information is requested as is needed for a specific operation, without excessive fields kept “just in case”. The fourth is accuracy and relevance: outdated or erroneous data is corrected or deleted at the user’s request. The fifth is storage limitation: as soon as the purpose has been achieved and the lawful grounds for further storage cease to exist, the data is deleted or anonymised. And, finally, security — at every stage technical and organisational measures are applied that reduce the risk of a leak.
Legal grounds for processing
Data is processed only where there is a lawful basis. In most cases that basis is the user’s consent. Clicking the “Submit” button in any form on the site confirms that the person has read this policy and permits the use of the information provided.
Processing may also be necessary in order to perform a contract to which the user is a party. For example, when a product is purchased, the address and telephone number are processed in order to fulfil delivery obligations. In certain cases processing is required to comply with the requirements of the law or to protect the legitimate interests of the operator, provided this does not infringe the rights and freedoms of the user.
How data is handled
The processing of personal information includes collection, recording, systematisation, accumulation, storage, refinement (updating or modification), retrieval, use, transfer, anonymisation, blocking, deletion and destruction. Both automated systems and manual processing by the responsible staff are applied.
The period of data processing is not limited in advance. Information is stored for exactly as long as it is necessary in order to achieve the purposes for which it was collected, or until the moment the user withdraws consent.
The risks associated with storing information on the internet are well understood, and therefore a set of security measures is applied:
- Use of a secure data-transfer protocol (HTTPS).
- Regular updating of the server software.
- Restricted access to the databases — the information is seen only by those staff who need it for their work.
- Antivirus protection and firewalls.
Data retention periods
The retention period depends on why the data was collected. Contact details left for processing a specific order are stored for as long as is required to fulfil it and to provide the subsequent warranty support, as well as for the period stipulated by law for accounting and contractual documents. Data collected for the newsletter is stored until the user unsubscribes from it.
Technical information from the server logs and the analytics systems is usually stored for a limited time and is used in anonymised form for statistics and diagnostics. When the grounds for storage cease to exist, the data is deleted or anonymised in such a way that it becomes impossible to re-establish a link to a specific person. If a user withdraws consent, their personal data is deleted, with the exception of information that must be retained by law.
Transfer of information to third parties
Personal data is neither sold nor transferred to outside organisations for their commercial benefit. However, in certain situations the involvement of partners is unavoidable. Data may be transferred to third parties in the following cases:
- Delivery services and transport companies. They need the address and telephone number in order to deliver the order.
- Payment systems. In the case of online payment, the data is transferred to banking services in order to carry out the transaction. Bank card details are not stored on the site’s side.
- Analytics services. Web-analytics tools, for example Yandex.Metrica, are used to analyse traffic. Such services receive anonymised data by which a specific person cannot be identified.
- Requirements of the law. Information may be disclosed to state authorities upon receipt of an official request within the framework of the applicable legislation.
In all other cases, should a need arise to transfer data to anyone else, the user’s explicit consent is requested in advance. Partners who are granted access to data in order to perform their functions are obliged to ensure its confidentiality and not to use it for their own purposes.
Data processing when placing an order
Particular attention should be paid to the scenario in which a user places an order for a product or a service. Here the data is processed along the entire chain: from the initial request and the agreement of details through to manufacture, delivery and, if necessary, installation. The name and telephone number are needed to stay in contact as the work proceeds, the address for delivery, and the information about the order itself for precise fulfilment. Without this information it is simply impossible to meet the obligations, and so its processing is inseparable from the service itself.
Once the order has been completed, part of the data is retained in the volume that is required for warranty obligations and accounting. This is normal practice: if, after some time, a repeat order or a warranty enquiry is needed, the history of the interaction helps to resolve the matter more quickly. At the same time, information that is no longer needed for any of the purposes is withdrawn from active use.
Handling cookies
Cookies are small text files that are saved on the device when the site is visited. They help the resource to “remember” the user, their settings and their preferences. Thanks to them there is no need to enter the same data several times, and it is easier for the site to understand which sections are more popular.
The site uses several types of cookies:
- Technical. They ensure the stable operation of the site’s core functions.
- Analytical. They help to gather statistics: how many people visited the site and which pages were opened most often.
- Functional. They remember the user’s choices — for example, the interface language or the region.
The use of cookies can be disabled at any time in the browser settings. It should be borne in mind that, after this, certain site functions may work incorrectly or become unavailable. For comfortable use of the resource it is better to leave cookies enabled.
Web analytics and statistics
In order to understand how visitors use the site, web-analytics systems are employed. They show a generalised picture: how many people visit, from which devices, which sections they read for longer, and where they close the page. All of this is anonymised statistics from which a specific person cannot be worked out. It is needed not for surveillance, but in order to make the site more convenient: to remove elements that do not work, to speed up slow pages and to refine the navigation.
Analytics services use their own cookies and may record the fact that pages have been visited. You can opt out of such collection by disabling cookies in your browser or by using the privacy settings of the relevant services. This does not affect access to the site’s main content — only the completeness of the statistics changes.
User rights
As a personal data subject, the user retains full control over the information provided. In particular, there is the right to:
- Find out exactly what data about them is stored.
- Request that information be corrected if it is outdated or contains errors.
- Demand the deletion of the data (the “right to be forgotten”) if it is no longer needed for the stated purposes or if consent has been withdrawn.
- Restrict the processing of data in certain cases.
- Withdraw consent to the processing of personal data at any time.
To exercise any of these rights it is enough to send a message in free form via the feedback form or to the email address given in the contacts section. The request is processed within the periods established by law, and the user is informed of the outcome separately.
How to withdraw consent
Consent to the processing of personal data is given voluntarily and is withdrawn just as voluntarily. To withdraw it, it is enough to send a request by any convenient means from the contacts section — indicating which data is concerned. Once such a request has been processed, the personal data is deleted or anonymised, with the exception of information that must be retained by law, for example for the accounting records of orders already fulfilled.
The withdrawal of consent affects only further processing and does not cancel actions that were carried out on a lawful basis before the moment of withdrawal. It should be borne in mind that, without some of the data, certain services cannot be provided — for example, it is impossible to deliver an order without an address. The user is warned of this in advance so that the decision can be an informed one.
Links to other resources
The pages of greendrev.com may contain links to third-party sites — partners, information resources or social networks. The operator bears no responsibility for the content of these sites or for their privacy policies. Before leaving any information on a third-party resource, it is worth reviewing that resource’s own data-protection rules.
Protection of children’s privacy
The site is intended for an adult audience, and data about persons who have not reached the age of majority is deliberately not collected. If it emerges that a child’s personal information has ended up on the site without the consent of parents or guardians, such information is immediately deleted from the databases. A parent who discovers that a child has left their data should get in touch via the site’s contacts.
Changes to the Privacy Policy
Legislation and the site itself change over time, and so the document is periodically updated. The current version is always posted on this page. Notifications are not sent for every minor amendment, and so it is worth looking into this section from time to time in order to stay aware of the current rules.
If the changes prove to be significant — for example, if the purposes of data collection change — the notification is placed in a more noticeable way: through an announcement on the home page or by email for those who are subscribed to the news.
Liability of the parties
The operator undertakes to store the user’s information securely and to prevent its disclosure, except in the cases described in this policy. In the event of loss or disclosure of data through the operator’s fault, liability arises in accordance with the legislation.
At the same time, no liability arises in respect of information if it:
- Became public knowledge before the moment of its loss or disclosure.
- Was received from a third party before it reached the site.
- Was disclosed with the consent of the user themselves.
- Became known as a result of the hacking of the user’s personal device or account through their own carelessness.
The user, in turn, should take a responsible attitude towards their own information security: use strong passwords, not give access to their devices to outsiders and keep antivirus programs up to date. A significant proportion of leaks occur not on the sites’ side but precisely because of careless handling of personal devices and passwords.
How to get in touch about data matters
If you still have questions about data protection, have found an inaccuracy in the text or need to withdraw consent to the processing of information, you can let us know. The feedback form on the site or a message to the email address indicated in the contacts section is suitable for this. Enquiries on the subject of confidentiality are considered within a reasonable time, and the details of the request are clarified where necessary.
The operator is open to dialogue and is ready to explain any points concerning confidentiality. The user’s peace of mind and their confidence in the security of their personal information are the foundation of a long and predictable cooperation.
This version of the policy comes into force from the moment of its publication on the site and remains valid until a new version appears. Users’ personal data is processed with due diligence and is protected by the technical and organisational measures that have been adopted.
