Privacy Policy

General Provisions

This privacy policy (hereinafter – the Privacy Policy) is intended to explain what data UAB “Konfesta”, legal entity code 303444860, J. Basanavičiaus g. 15, Vilnius (hereinafter – the Service Provider) collects on the website www.candypop.fi (hereinafter – the Website), why it collects it, and what it does with it.

It is considered that the Buyer has read and agrees to comply with the Privacy Policy and the processing of their data for order fulfillment purposes by checking the box "I agree with the privacy policy and the processing of my data for order fulfillment purposes". By checking the box, the Buyer agrees that personal data (name, surname, email address, phone number, delivery address) will be processed for the purpose of selling goods and services in the online store. The Buyer consents to receive CandyPOP direct marketing messages by checking the box "Yes, I would like to receive a newsletter about your products" in the pop-up or cart.

When processing your personal data, the Service Provider follows the Law on Legal Protection of Personal Data of the Republic of Lithuania, and as of May 25, 2018 – General Data Protection Regulation No. 2016/679 (GDPR) and other directly applicable legislation regulating personal data protection.

Personal Data

Personal data includes the client's name, surname, email address, phone number, delivery address, IP address, payment data (bank account number, payment method, etc.), purchase history, VAT invoice details, information about failed payments, browsing history on the website, and other information related to contract conclusion and execution.

Data Processing Purposes and Retention Period

The Service Provider collects the client’s personal data for the following purposes:

  1. For registration – name, surname, email address. This data is retained for 2 years from your last purchase on our website.
  2. For contract conclusion and execution – name, surname, email address, mobile phone number, delivery address, payment data (bank account number, payment method, etc.), purchase history (purchased items, prices, etc.), and other contract-related information. This data is processed and retained for 2 years from your last purchase on our website.
  3. For direct marketing – if the user expresses a desire by giving consent, the following data is collected: name, surname, email address, phone number, and information about your computer and visits to and use of the website, including your IP address, login time and date. The Service Provider uses this data to contact you and inform you about news and offers via email. Each direct marketing message will include an option to opt out, by notifying us via the email or other means listed in this Privacy Policy.

Cookies

What is a cookie and what is its purpose?

A cookie is a text file sent by a server to a browser and stored in the browser. This information is sent back to the server every time the browser requests a page. This allows the server to remember browser settings or track visits.

Cookies help websites operate more efficiently and improve services, as well as provide information to administrators for statistics or advertising purposes—primarily to personalize your browsing experience (e.g., recognizing you when logging in, hiding irrelevant ads, etc.).

More information about the cookies used on this website can be found here:

How can I delete/disable cookies?

Most browsers allow you to disable cookies in their settings. However, please note that disabling navigation or functional cookies may affect website functionality and/or limit our ability to provide services. Below are browser-specific instructions for managing cookies:

For more information about cookies, cookie management, and your preferences regarding third-party profiling, visit youronlinechoices.com/lt/. To disable analytics cookies and prevent Google Analytics from collecting data, you can install this browser add-on: tools.google.com/dlpage/gaoptout

Data Recipients

We may disclose your data to our employees, managers, agents, suppliers, or subcontractors if necessary, e.g., payment transactions may be processed by our payment service providers, or specific services may require us to transfer your data to service providers such as hosting providers, couriers, server maintenance providers, email service providers, etc.

We may also disclose information about you (aside from what's described here, we do not share your data with any third parties):

  • if we are required to do so by law;
  • to defend our rights or interests (including providing your data to third parties for debt recovery).

Your Rights as a Client

You have the right to:

1. Submit a written request to us to confirm whether your data is being processed and, if so, to access your data and related information: processing purposes; data categories; recipients or categories of recipients; data retention period or its criteria.

1.2. Request correction or completion of inaccurate or incomplete personal data;   
1.3. Request deletion of your personal data. This right may be limited and applies when at least one of these reasons exists: the data is no longer needed for the purposes collected; you withdraw consent where it was the sole basis; the data was processed unlawfully; we are legally required to delete it;   
1.4. Withdraw consent for processing your data where it's processed solely on that basis;   
1.5. Request transfer of your data to another controller where technically possible;   
1.6. File a complaint with us or the State Data Protection Inspectorate if you believe your rights may be violated.

Third-Party Websites

Our website may contain links to other websites. We are not responsible for their privacy policies or practices.

Customer Responsibility

You are responsible for ensuring the accuracy, truthfulness, and completeness of the data you provide. If your data changes, you must update it via the registration form or notify us by email. We are not liable for damages caused by inaccurate or incomplete data or failure to update it.

Loyalty Program Privacy Policy

The controller of the personal data submitted in the CANDY POP LOYALTY PROGRAM CUSTOMER FORM is UAB “Konfesta” (J. Basanavičiaus g. 15, LT-03108 Vilnius). Your data is processed only based on your consent and only for the purposes you agreed to in the form. The data is accessible only to UAB “Konfesta” and its processors performing specific tasks and services.

You have the right to: request access, correction, or deletion of your data, restrict processing, object to processing, and the right to data portability, in accordance with legal requirements.

Requests must be submitted in writing (including electronic format) and allow identification of the requester. Identity must be verified by document or electronic means. If sent by mail or courier, a copy of the identity document must be included. Representatives must provide proof of representation and identification documents.

For exercising your rights, please contact UAB “Konfesta” director Dominykas Juškis (phone: +37062055456, [email protected]) or use the company's contact details above.

You can withdraw your consent to data processing at any time. Withdrawal does not affect the legality of processing based on consent before withdrawal. Contact UAB “Konfesta” to withdraw.

Please note: providing your personal data is necessary to participate in the loyalty program. Without consent, you cannot be included. However, agreeing or refusing direct marketing does not affect participation in the loyalty program.

Data in the form and system is retained while you are a participant and for 2 years after you leave. If consent for direct marketing is given, data is kept for 3 years from withdrawal, expiration, or company decision to stop processing. This period may be extended if the data is needed in legal proceedings or investigations.

You have the right to appeal actions (or inactions) to the State Data Protection Inspectorate or court as per the law.

UAB “Konfesta” commits to lawful, fair, and transparent processing, ensuring security and implementing measures to protect data from unlawful destruction, accidental changes, disclosure, or other unauthorized processing.

Privacy Policy Updates

The Privacy Policy is effective as of September 1, 2019. If we make changes, the updated version will be posted on this page. The last update was on February 2, 2022.

Contact Information

If you have any questions regarding this Privacy Policy, please contact us using the information below:

UAB “Konfesta” 
Company code:303444860 
Registered address: J. BasanaviÄŤiaus g. 15, Vilnius 
Correspondence address: J. BasanaviÄŤiaus g. 15, Vilnius 
Email: [email protected] 
Phone: +370 66 555000