Privacy Policy
This Privacy Policy describes the rules for processing the personal data of persons using the Estelvio platform (estelvio.com), in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (GDPR) and applicable national law.
1. General provisions and definitions
Wherever this document refers to:
- GDPR - means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data,
- personal data - means information about an identified or identifiable natural person,
- processing - means an operation or set of operations performed on personal data, in particular collection, recording, storage, adaptation, disclosure and erasure,
- the Platform - means the website available at estelvio.com together with all its features (catalog, Customer account, admin panel, Estelvio Academy, blog),
- User - means any natural person visiting the Platform or using its features, including a person acting on behalf of a Customer (Terms of Service, §1).
2. Data controller
The data controller within the meaning of Art. 4(7) GDPR is Global Bridge Solutions LLC, with its registered address at 30 N Gould St Ste N, Sheridan, WY 82801, USA, operating the Platform under the Estelvio™ brand (the "Controller").
For all matters relating to the processing of personal data and the exercise of the rights described in this document, you can contact the Controller at contact@estelvio.com.
3. Scope of data processed
In connection with operating the Platform, the Controller processes the following categories of data:
- registration and Account data - the contact person's name, company name and address, tax ID (if provided), email address, phone number, sign-in history,
- Order data - the contents of the Order, delivery address, billing details, the selected currency, payment status, and the history of correspondence relating to a given Order,
- data from contact forms - name, email address, the content of the message and other data voluntarily provided in the inquiry,
- Estelvio Academy training data - course progress, test results, and the data entered on an issued certificate (name, optionally company name),
- anonymized statistical data - information about visits to the Platform (traffic source, country, pages visited, device and browser type), collected without using cookies. A visitor is identified only by a one-way cryptographic hash (computed from the IP address, browser identifier and a random daily "salt" deleted after 2 days) - it is not possible to reconstruct the IP address or identify a specific person from such a hash.
4. Purposes and legal bases for processing
Personal data is processed for the following purposes and on the following legal bases:
- to set up and operate the Account and to conclude and perform the sales contract (fulfil the Order) - pursuant to Art. 6(1)(b) GDPR (necessary for the performance of a contract to which the data subject is party, or to take steps prior to entering into a contract),
- to issue billing documents and comply with legal obligations (including tax and accounting obligations) - pursuant to Art. 6(1)(c) GDPR (necessary for compliance with a legal obligation to which the Controller is subject),
- to respond to an inquiry sent through the contact form or by email - pursuant to Art. 6(1)(f) GDPR (the Controller's legitimate interest in handling correspondence),
- to carry out statistical analysis of traffic on the Platform in anonymized form - pursuant to Art. 6(1)(f) GDPR (the Controller's legitimate interest in developing and optimizing the Platform),
- to provide training under Estelvio Academy and to issue a certificate of completion - pursuant to Art. 6(1)(b) GDPR,
- to establish, pursue or defend against potential claims - pursuant to Art. 6(1)(f) GDPR (the Controller's legitimate interest).
5. Data retention period
Personal data is stored for the following periods:
- Account data - for as long as the Account exists and until it is deleted at the Customer's request, unless applicable law or the need to settle obligations requires a longer retention period,
- Order data and billing documents - for the period required by tax and accounting law (as a rule, 5 years, counted from the end of the year in which the tax payment deadline relating to a given document fell),
- data from contact forms and correspondence - for as long as needed to provide a response and for the limitation period of any claims related to the content of the correspondence,
- statistical data - is anonymized (via a one-way cryptographic hash with a rotating daily salt) from the moment it is collected, so it is never linked to an identifiable person for longer than the lifetime of a given daily salt.
6. Data recipients
Personal data may be disclosed to entities that, on the Controller's instructions, participate in fulfilling Orders or operating the Platform, in particular:
- providers handling payments and the bank accounts used for settlements,
- carriers and courier companies delivering the Goods,
- providers of hosting, email and IT infrastructure services for the Platform,
- providers of accounting services, where necessary to correctly settle an Order,
- public authorities entitled to obtain data under applicable law.
The Controller does not sell personal data to third parties and does not disclose it for marketing purposes to entities unrelated to fulfilling Orders.
7. Transfers of data outside the European Economic Area
The Controller is based outside the European Economic Area (in the United States), which means that personal data processed in connection with operating the Platform may be transferred to the Controller outside the EEA.
In such cases, the Controller applies the appropriate safeguards required by the GDPR to ensure an adequate level of data protection, in particular standard contractual clauses approved by the European Commission or other mechanisms provided for in Chapter V of the GDPR, to the extent applicable to the given situation.
8. Data security
The Controller applies technical and organizational measures to protect personal data appropriate to the risks and the categories of data covered, including in particular:
- an encrypted connection (HTTPS) between the User's browser and the Platform's server,
- Account passwords stored in encrypted form, not readable in plain text,
- restricted access to data - only persons authorized by the Controller have access to Customer data, to the extent necessary to perform their duties,
- regular database backups.
9. Rights of the data subject
The data subject has the following rights:
- right of access (Art. 15 GDPR) - to obtain confirmation of whether the Controller processes their data, and if so, to obtain a copy of it,
- right to rectification (Art. 16 GDPR) - to request correction of inaccurate data or completion of incomplete data,
- right to erasure (Art. 17 GDPR) - to request deletion of data, unless grounds exist that exclude this right (e.g. an obligation to retain it under law),
- right to restriction of processing (Art. 18 GDPR),
- right to data portability (Art. 20 GDPR) - to receive data in a structured, commonly used, machine-readable format, to the extent the data is processed on the basis of a contract or consent and in an automated manner,
- right to object (Art. 21 GDPR) - to processing based on the Controller's legitimate interest, on grounds relating to the data subject's particular situation,
- right to lodge a complaint with the supervisory authority competent for the protection of personal data, if the data subject considers that the processing of their data infringes the GDPR.
To exercise the rights above, please contact contact@estelvio.com. Providing personal data is voluntary, but necessary to create an Account, place an Order, or receive a response to an inquiry.
10. Automated decision-making
The Controller does not make decisions about Users based solely on automated processing, including profiling, that would produce legal effects concerning them or similarly significantly affect them, within the meaning of Art. 22 GDPR.
11. Cookies
Detailed information about the cookies used on the Platform - their types, purpose and how to manage them - can be found in a separate document: Cookie policy.
12. Changes to the Privacy Policy
This Privacy Policy may be updated periodically, in particular in connection with changes in the law or the development of the Platform's features. The current version of this document is always available at this address, and its amendment does not affect rights acquired by Users before it was introduced.
13. Contact
For matters relating to the protection of personal data and this Privacy Policy, please contact contact@estelvio.com.
See also the Platform Terms of Service and the Cookie Policy.