GDPR Policy


1. Introduction and Scope

Uvenoraurel (“we,” “our,” or “us”) respects your privacy and is committed to handling personal data responsibly. This GDPR Policy explains how we may collect, use, store, share, and protect personal data when you visit https://uvenoraurel.com or interact with our services.

The General Data Protection Regulation (GDPR), Regulation (EU) 2016/679, applies where its territorial scope requirements are met. Depending on the circumstances, this may include processing carried out in the context of an establishment in the European Union or processing by an organization outside the EU that relates to offering goods or services to individuals in the EU or monitoring their behavior there.

Uvenoraurel primarily serves customers in the United States. Our U.S. operations and shipping coverage do not, by themselves, determine whether the GDPR applies. Applicability depends on the relevant legal requirements and our actual data processing activities.

This policy should be read together with our Privacy Policy and Cookies Policy, which provide additional information about our privacy practices.

2. Personal Data We May Collect

Depending on how you interact with our website, we may process the following categories of personal data:

  • Identity and Contact Information: Name, email address, and telephone number.
  • Order and Transaction Information: Order numbers, purchase records, transaction status, and refund-related information.
  • Delivery Information: Shipping addresses, billing addresses, and delivery-related details.
  • Payment-Related Information: Payment method, transaction status, and information required to process payments. Payment information may be handled directly by third-party payment providers.
  • Account Information: Account settings and login-related information, where account functionality is available.
  • Customer Service Information: Inquiries, feedback, support communications, and attachments you voluntarily provide.
  • Technical and Usage Information: IP address, browser type, device information, access logs, and website interaction data, where collected.
  • Cookie and Tracking Data: Information collected through cookies and similar technologies, depending on the technologies deployed and your preferences.

We collect personal data directly from you, automatically through your use of the website, or from service providers where applicable and legally permitted.

3. Purposes of Processing

We may process personal data for the following purposes, where applicable:

  • To process and manage orders and related transactions.
  • To facilitate payments, refunds, and transaction reconciliation.
  • To arrange deliveries and provide order updates.
  • To respond to inquiries and handle customer service requests.
  • To maintain website functionality, security, and performance.
  • To detect and prevent fraud, unauthorized activities, and misuse.
  • To analyze website usage and improve the shopping experience, where applicable.
  • To manage marketing communications and preferences, where permitted.
  • To comply with legal obligations, resolve disputes, and establish, exercise, or defend legal claims.

We process personal data only for purposes supported by an applicable legal basis and handle any further processing in accordance with applicable law.

4. Legal Bases for Processing

Where the GDPR applies, we rely on the legal basis appropriate to the relevant processing activity under Article 6.

Consent: We may process personal data based on your freely given, specific, informed, and unambiguous consent when consent is required or otherwise relied upon.

Performance of a Contract: Processing may be necessary to fulfill an order or take steps at your request before entering into a contract.

Legal Obligation: We may process personal data when necessary to comply with applicable legal requirements.

Legitimate Interests: We may process personal data when necessary for our legitimate interests or those of a third party, provided those interests are not overridden by your rights and freedoms. Depending on the circumstances, these interests may include website security, fraud prevention, and the defense of legal claims.

Vital Interests: This basis may apply where processing is necessary to protect the vital interests of you or another individual.

Public Task: This basis applies only where processing is necessary for a task carried out in the public interest or under official authority and the required legal basis exists.

Not every legal basis will apply to every activity. We determine the appropriate basis according to the purpose and circumstances of the processing.

Where processing relies on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal. Certain processing may continue where another valid legal basis applies.

5. Cookies and Similar Technologies

We may use cookies and similar technologies to support essential website functions, maintain shopping cart activity, remember preferences, analyze website performance, or support marketing activities, depending on the technologies deployed.

Where required by applicable law, nonessential cookies and similar tracking technologies will be subject to appropriate notice and consent mechanisms. Where available, you may manage your preferences or withdraw consent through the relevant settings.

For additional details about cookie categories and their use, please refer to our Cookies Policy.

6. Sharing and Disclosure of Personal Data

We may disclose necessary personal data to third parties when required to operate our website, provide services, or fulfill a lawful purpose. Depending on our actual arrangements, recipients may include:

  • Payment processors that facilitate transactions and refunds.
  • Shipping and delivery providers that fulfill orders.
  • Website hosting, technical support, and information security providers.
  • Customer service and order management providers.
  • Analytics or marketing service providers, where applicable.
  • Legal, regulatory, or judicial authorities when disclosure is required or permitted by law.

Service providers may process personal data on our behalf to the extent necessary to perform their services. Where required by the GDPR, appropriate data processing agreements and safeguards must be established.

We do not treat personal data as unrestricted for third-party use. Disclosures must have an appropriate purpose and legal basis, and applicable data protection requirements must be followed.

7. Data Retention

We retain personal data only for as long as reasonably necessary to fulfill the purposes for which it was collected, including providing services, meeting legal obligations, maintaining relevant transaction records, resolving disputes, and protecting legitimate interests.

Retention periods depend on the type of data, the processing purpose, applicable legal requirements, and operational needs. We do not apply a single retention period to all personal data.

When personal data is no longer necessary, we will delete it, anonymize it, or otherwise handle it in accordance with applicable law, subject to any lawful retention requirements.

8. Data Security and Personal Data Breaches

We seek to implement reasonable technical and organizational measures appropriate to the circumstances to protect personal data against unauthorized access, accidental loss, alteration, or disclosure.

No method of internet transmission or electronic storage can be guaranteed to be completely secure. We therefore cannot promise absolute security.

Where the GDPR applies, personal data breaches will be assessed and handled in accordance with applicable legal requirements. Under Article 33, a supervisory authority must generally be notified without undue delay and, where feasible, within 72 hours after the controller becomes aware of a breach, unless the breach is unlikely to result in a risk to individuals' rights and freedoms.

Under Article 34, affected individuals must also be informed without undue delay when the breach is likely to result in a high risk to their rights and freedoms, subject to applicable exceptions.

Notification obligations depend on the circumstances of the incident and the relevant legal requirements. Not every incident requires notification to a supervisory authority or affected individuals.

9. International Data Transfers

Uvenoraurel's listed business address is in the United States. Depending on our actual operations and service provider arrangements, personal data may be processed or accessed across national borders.

Where the GDPR applies and personal data is transferred to a country outside the European Economic Area that does not benefit from an applicable adequacy decision, the transfer must satisfy the requirements of Chapter V of the GDPR.

Depending on the circumstances, lawful transfer mechanisms may include:

  • An applicable European Commission adequacy decision.
  • Standard Contractual Clauses (SCCs), where appropriate, together with any necessary supplementary safeguards.
  • Another transfer mechanism permitted by the GDPR.

The mechanism required depends on the destination, the parties involved, and the specific data transfer. We do not represent that any particular transfer mechanism has been implemented unless the relevant arrangements have been verified.

10. Your Rights Under GDPR

Where the GDPR applies, you may have the following rights, subject to applicable conditions, exceptions, and limitations:

  • Right to Be Informed: To receive information about how your personal data is processed.
  • Right of Access: To request access to your personal data and obtain a copy where legally required.
  • Right to Rectification: To request correction of inaccurate or incomplete personal data.
  • Right to Erasure: To request deletion of personal data when the legal requirements are met.
  • Right to Restriction of Processing: To request that processing be restricted in certain circumstances.
  • Right to Data Portability: To receive certain personal data in a structured, commonly used, machine-readable format and, where legally applicable, transmit it to another controller.
  • Right to Object: To object to processing based on legitimate interests or a public task where the relevant conditions apply. You also have an absolute right to object to processing for direct marketing, including related profiling.
  • Rights Related to Automated Decision-Making: Where Article 22 applies, to benefit from protections concerning decisions based solely on automated processing that produce legal effects or similarly significant effects, subject to the GDPR's conditions and exceptions.
  • Right to Withdraw Consent: To withdraw consent at any time when processing is based on consent, without affecting the lawfulness of prior processing.
  • Right to Lodge a Complaint: To lodge a complaint with a competent data protection supervisory authority.

These rights are not unconditional and may be subject to legal requirements and exceptions. The GDPR does not automatically provide every right in every situation.

To exercise a right, contact us using the details provided below. We may take reasonable steps to verify your identity where necessary to protect your personal data.

We will respond to qualifying requests within the time limits required by applicable law. Under the GDPR, responses are generally due within one month of receiving a request. This period may be extended by up to two additional months where permitted because of the complexity or number of requests. If an extension is necessary, we will inform you within the applicable initial period.

11. Data Controller and Contact

The identity of the data controller depends on the actual legal and operational arrangements for the website. Uvenoraurel is the website brand name; this policy does not establish that the brand is a separately registered legal entity.

Where required by the GDPR, the responsible operator must identify the appropriate controller and provide any legally required representative or Data Protection Officer information. Such details should be confirmed according to the actual business structure and applicable law.

For privacy-related questions or requests concerning access, correction, deletion, restriction, objection, or withdrawal of consent, you may contact us using the information below.

12. Complaints and Supervisory Authorities

If the GDPR applies to the relevant processing, you may lodge a complaint with a competent data protection supervisory authority, particularly in the EU Member State where you live, work, or where an alleged infringement occurred, as permitted under applicable law.

The appropriate authority depends on the circumstances of the processing and the applicable supervisory jurisdiction. We do not designate a specific EU supervisory authority or representative in this policy because the relevant arrangements have not been independently confirmed.

You may also contact us directly so we can review your privacy concern. Contacting us does not limit your statutory right to lodge a complaint with a competent authority.

13. Policy Updates

We may update this GDPR Policy to reflect changes in our business operations, website technologies, data processing practices, or applicable legal requirements.

When changes are made, we will update this page and revise the date shown at the beginning of the policy. Where applicable law requires additional notice or renewed consent, we will take the required steps.

Contact Information

Phone: +1 (314) 427-6813
Email: contact@uvenoraurel.com
Address: 4507 Fair Ave #A, Saint Louis Missouri 63115, United States
Opening hours: Monday to Friday, 9:00 AM – 6:00 PM (EST)