Privacy Policy

1. General Provisions1.1. This Privacy Policy describes how Sualua (hereinafter referred to as the “Data Controller”) collects, processes, and stores personal data obtained through the website https://sualua.com/ (hereinafter referred to as the “Website”) from its customers and visitors (hereinafter referred to as the “Data Subject” or “You”).

1.2. Personal data means any information relating to an identified or identifiable natural person. Processing means any operation performed on personal data, such as collection, recording, organization, storage, use, viewing, deletion, or destruction.
1.3. The Data Controller processes personal data in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR) and applicable European Union data protection legislation.

2. Collection, Processing, and Storage of Personal Data2.1. Personally identifiable information is collected, processed, and stored by the Data Controller primarily through the Website https://sualua.com/ and via electronic communication (e-mail, contact forms, or checkout forms).

2.2. By visiting and using the services offered on the Website, you agree that any information you provide will be used and processed in accordance with this Privacy Policy.

2.3. The Data Subject is responsible for ensuring that the submitted personal data is accurate, complete, and up to date. Knowingly providing false information constitutes a violation of this Privacy Policy. The Data Subject must promptly notify the Data Controller of any changes to their personal data.

2.4. The Data Controller is not responsible for any losses incurred by the Data Subject or third parties due to the submission of false or inaccurate personal data.
3. Processing of Personal Data3.1. The Data Controller may process the following categories of personal data:

  • Name and surname
  • Contact information (e-mail address and/or phone number)
  • Delivery or billing address
  • Order and transaction data (purchased products, prices, payment status)
  • Any other information voluntarily submitted via the Website or during communication with the Data Controller
3.2. The Data Controller may verify the accuracy of the provided data using publicly available sources where legally permitted.

3.3. The legal basis for processing personal data is Article 6(1)(a), (b), (c), and (f) of the GDPR, including:

  • Consent of the Data Subject
  • Performance of a contract
  • Compliance with legal obligations
  • Legitimate interests of the Data Controller
3.4. Personal data is stored only as long as at least one of the following conditions applies:
  • The data is necessary for the purpose for which it was collected;
  • The Data Controller or the Data Subject may exercise legitimate rights or interests;
  • The Data Controller has a legal obligation to retain the data (e.g. accounting or tax regulations);
  • The Data Subject’s consent remains valid.
When none of these conditions apply, personal data is permanently deleted or anonymized.
3.5. To fulfill its obligations, the Data Controller may transfer personal data to third-party service providers acting on behalf of the Data Controller, such as:
  • Payment service providers
  • Courier and logistics services
  • Accounting or IT service providers
Personal data may also be disclosed to public authorities if required by law.
3.6. The Data Controller implements appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, disclosure, or unlawful processing.
4. Rights of the Data Subject4.1. In accordance with the GDPR, you have the right to:
  • Access your personal data and receive information about its processing;
  • Request correction of inaccurate or incomplete personal data;
  • Request deletion of your personal data (“right to be forgotten”), where legally permissible;
  • Withdraw consent at any time (without affecting prior lawful processing);
  • Restrict or object to the processing of your personal data;
  • File a complaint with a supervisory data protection authority in your EU country of residence.
4.2. Requests regarding personal data and Data Subject rights can be submitted by contacting the Data Controller at:
E-mail: [insert official Sualua contact email]
5. Final Provisions5.1. This Privacy Policy is governed by Regulation (EU) 2016/679 (GDPR) and applicable European Union data protection laws.
5.2. The Data Controller reserves the right to amend this Privacy Policy at any time. Changes take effect upon publication on https://sualua.com/.
Made on
Tilda