Free Delivery for orders over €20 in Malta and over €40 in Gozo.

Hit enter to search or ESC to close

Privacy Policy

1. About Us

1.1 Introduction

This privacy and cookie policy (‘the Privacy Policy’) sets out the ways in which Whimsy Castle may use your personal data.

 

1.2 Our Contact Details

You can contact us:

  1. by post, using the postal address below:
    Whimsy Castle
    The Penthouse
    58, Main Street
    St Julian’s
    Malta
  2. using our website contact form – https://whimsycastle.mt/contact/; or
  3. by email, on [email protected].

2. About Your Data

2.1 Data We Process

The personal data we collect/process in Your regard is the following:

DATA CATEGORY TYPE OF DATA WHAT IT’S USED FOR OUR LEGAL BASIS
Tracking Data

Data about Your use of the Website

IP address, geographical location, browser type and version, operating system, referral source, length of visit, page views, website navigation paths, and information about the timing, frequency and pattern of Your use. For functionality, for security purposes, to analyse the use of the Website and to personalise and optimize content available to You on the Website. Legitimate interest
Communications Data

Data provided to us when You complete a ‘Contact Us’ Form or when You use the ‘chat’ function provided Our Website.

Name and surname, email address, IP address, and other information You may enter into the form. To reply to Your queries about the products and services available through the Website. Legitimate interest
Registration Data

Data provided to us when you register an account with us. This information includes your

 

Name & surname, email address, IP address, postal address, phone number, username and password, lens prescription, brand preference. To provide You with an account which will enable You to make purchases on the Website. Legitimate interest
Guest Purchase Data

Data provided to us when you purchase products from the Website without registering an account with Us.

Name & surname, email address, IP address, postal address, phone number, username and password, lens prescription, brand preference. To provide You with products You have purchased. Contractual performance
Financial Data

Payment details provided when you purchase products from the Website. Financial data is processed through our chosen payment gateway or through Paypal.

Credit card or other bank details. To provide You with products You have purchased. Contractual performance
Recommend a Friend

Data provided to us when a friend recommends us to You by giving Us Your email address.

Name & surname, email address, IP address. To provide You with an initial notification which will enable You to know more about our products and services available on the Website. Legitimate interest
Account History

All Data relating to Your purchasing activity and patterns.

Purchase history, returns To process Your purchase transactions for products and services, and to ensure any transaction issues can be dealt with.

For accounting and taxation purposes.

Contractual performance

Legal obligation

Subscription Data

Information that You provide to us for the purpose of subscribing to our email notifications and/or newsletters.

Name and surname, email address, IP address To send You information about our products, services, offers, discounts and news. Consent

NOTE that you have the right to withdraw Your consent, at any time by clicking on the ‘unsubscribe’ link found in any marketing communications. You may also send an email to [email protected].

2.2 Personal information we collect

A cookie is a small file of letters and numbers that are stored on your browser or the hard drive of your computer and contain information that is transferred to your computer’s hard drive. We use cookies on the Website to improve it functionality, and to allow Us to better the site. When You continue to browse the Website, You are agreeing to our use of cookies.

Please note that You can block cookies at any time by activating the setting on Your browser that allows You to refuse the setting of all or some cookies. Keep in mind, however, that blocking all cookies, or even some of them, will have a negative impact on the usability and possibly the rendering of many websites, including ours. If You block cookies You will not be able to use all the features on the Website and might not be able to view it correctly or in the way it was originally intended to be displayed. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them visit: www.allaboutcookies.org.

We use cookies as follows:

NAME FUNCTION
Google Analytics We use this cookie to be able to optimize our website designs, gain insight on popular features, identify usage trends, track the delivery of our promotional content and, more generally, to know our market better.

Google Privacy Policy: https://policies.google.com/privacy?hl=en

 

WordPress Stats We use this cookie to be able to optimize our website designs, gain insight on popular features, identify usage trends, track the delivery of our promotional content and, more generally, to know our market better.

WordPress Privacy Policy:

https://automattic.com/privacy/

 

Double Click

 

We use this cookie to track the effectiveness of our marketing campaigns. It enables Google to serve our adverts on other sites based on your browsing history on our page and engagement with our adverts.

Google Privacy Policy: https://policies.google.com/privacy?hl=en

Double Click Ad Exchange

 

We use this cookie to log when users view specific pages or take specific actions on our Website. This allows us to provide targeted advertising in the future.

Google Privacy Policy: https://policies.google.com/privacy?hl=en

 

GA Audiences

 

We use this cookie to re-engage visitors that are likely to convert to customers based on the visitor’s on-line behaviour across web sites.

Google Privacy Policy: https://policies.google.com/privacy?hl=en

 

Hotjar We collect data on how you interact with our website through heat maps showing clicks, taps and scroll behaviour on web and mobile in addition to screen recordings, form analysis and conversion funnels.

You can read more about Hotjar through the following links:

 

Facebook Pixel We use Facebook Pixel to understand how users interact with our Facebook ads across devices, allowing us to optimise delivery to our intended target audience and drive more traffic to our website.

Privacy Policy: https://www.facebook.com/privacy/

YouTube Our website uses plugins from YouTube, which is operated by Google. The operator of the pages is YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA.

If you visit one of our pages featuring a YouTube plugin, a connection to the YouTube servers is established. Here the YouTube server is informed about which of our pages you have visited.

If you’re logged in to your YouTube account, YouTube allows you to associate your browsing behaviour directly with your personal profile. You can prevent this by logging out of your YouTube account.

YouTube is used to help make our website appealing. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

Further information about handling user data, can be found in the data protection declaration of YouTube under https://www.google.de/intl/de/policies/privacy.

Vimeo Our website uses features provided by the Vimeo video portal. This service is provided by Vimeo Inc., 555 West 18th Street, New York, New York 10011, USA.

If you visit one of our pages featuring a Vimeo plugin, a connection to the Vimeo servers is established. Here the Vimeo server is informed about which of our pages you have visited. In addition, Vimeo will receive your IP address. This also applies if you are not logged in to Vimeo when you visit our plugin or do not have a Vimeo account. The information is transmitted to a Vimeo server in the US, where it is stored.

If you are logged in to your Vimeo account, Vimeo allows you to associate your browsing behavior directly with your personal profile. You can prevent this by logging out of your Vimeo account.

For more information on how to handle user data, please refer to the Vimeo Privacy Policy at https://vimeo.com/privacy.

Google Web Fonts For uniform representation of fonts, this page uses web fonts provided by Google. When you open a page, your browser loads the required web fonts into your browser cache to display texts and fonts correctly.

For this purpose your browser has to establish a direct connection to Google servers. Google thus becomes aware that our web page was accessed via your IP address. The use of Google Web fonts is done in the interest of a uniform and attractive presentation of our plugin. This constitutes a justified interest pursuant to Art. 6 (1) (f) DSGVO.

If your browser does not support web fonts, a standard font is used by your computer.

Further information about handling user data, can be found at https://developers.google.com/fonts/faq and in Google’s privacy policy at https://www.google.com/policies/privacy/.

2.3 Personal information we collect

We retain Your personal data no longer than strictly necessary i) to realize the purpose for which your personal data was originally collected ii) as required by a specific law to which we may be subject and iii) to manage any legal claims in relation to which such data may be required in evidence. Transactional records may be kept for up to 10 years from the performance of a contract for accounting and VAT record purposes. Data offered when a friend is referred is only kept until first communication to the ‘friend’ is sent, after which we will delete the data, unless the ‘friend’ subscribes to our newsletter or marketing communications. Should You need to know the complete list of the retention periods we adhere to with respect to the indicated categories of personal data, please contact us on [email protected].

 

2.4 Who has Access to Your Data

Whimsy Castle is a partnership with a head office in Malta. The majority of the service providers who are able to access the Website or any of the personal information collected from or relating thereto are located within the EEA, and we have data processing agreements in place with these parties. These include customer relationship management, online review service provider, email service provider, web developers, affiliates, payment gateway, SEO agents, product suppliers, delivery and logistics, providers of professional advice (accounting and legal). Personal data that we hold is at all times on a strict ‘need to know’ basis.

The Website whimsycastle.mt is hosted in the United States. We also work with web maintenance providers located outside the EEA. We have appropriate legal and security relationships with these parties and have taken steps to ensure that they are complying with the General Data Protection Regulation, including, as necessary, execution of contracts based on the European Union’s Standard Contractual Clauses for cross-border data transfers.

 

2.5 Automated Decision-Making

Other than ‘profiling’ activities carried out in order to display advertisements that will be relevant to You as explained in Paragraph 2.3 above, we do not engage in any automated decision-making.

 

2.6 Personal Data relating to Children

The Website should only accessible by individuals over the age of 16. It is a parent’s or legal guardian’s responsibility to ensure that persons under 16 do not complete any registration forms or make any purchases on/through Our Website. If We have reason to believe that We hold Personal Data of a person under that age, We will delete it immediately.

3. ABOUT YOUR RIGHTS

At any point in time during Our processing of Your data, You have the following rights. All requests in this regard may be made by sending an email to [email protected]. We will also forward Your request to the relevant 3rd Parties mentioned above as required.

  • Right of access – You can request a copy of the information that We hold about You.
  • Right of rectification – You can ask Us to correct data that We hold about You if it’s inaccurate or incomplete.
  • Right to be forgotten – in some situations, You may ask Us to delete certain data We hold about You and We will always comply to the extent allowed or required by any applicable law.
  • Right to restriction of processing – in some situations, You may ask Us to restrict the processing of Your data.
  • Right of portability – You may ask Us to transfer certain data We hold about You to another organization.
  • Right to object – You have the right to object to certain types of processing such as direct marketing.
  • Right to object to automated processing, including profiling – You also have the right to object to the legal effects of automated processing or profiling.
  • Right to complain about how your Personal Data is being processed by Us (or third parties), or about how Your complaint has been handled, – You can lodge a complaint directly with the Office of the Information and Data Protection Commissioner (https://idpc.org.mt/) and with Us ([email protected]).
  • RIGHT TO WIRHDRAW – you have the right to withdraw Your consent, where given, at any time. This applies in particular to receiving marketing communications, where You are able to opt-out of receiving further notifications by clicking on the ‘unsubscribe’ link found in all such communications. You may also send an email to [email protected].

The version of this Privacy Policy is currently Version 2.1 and was last updated on 6th July 2021. It is valid and applies to You until a new version uploaded on the Website and is accepted by You.

Product Categories
Wishlist 0
Continue Shopping