Privacy Policy
We respect your privacy and are committed to protecting your data.
Last updated: March 26, 2026
The merchant (store owner) acts as Data Controller for store customer data and business decisions.
Kordiva acts as Data Processor for platform hosting, security, and operational processing on behalf of the merchant.
We collect information you provide when creating an account or placing an order.
We use your data to process orders, provide support, and improve services.
We share data only with trusted service providers necessary to fulfill orders.
We implement security measures to protect your personal information.
You can request access, updates, or deletion of your data.
Contact us if you have questions about our privacy practices.
- This store policy framework is prepared for MK, EU/EEA, UK, US, and Canada operations.
- Platform-level policy templates are locked and owner-facing editors cannot override required legal clauses.
- Controller identity is injected from verified organization legal profile data.
- Access, rectification, deletion/anonymization, restriction, portability, and objection rights are supported.
- DSAR requests are handled via dashboard tools and support channels with 30-day SLA workflow.
- Rights requests and privacy complaints can be sent to: store legal contact (/contact)
- Contract performance, legal obligation, legitimate interest, and consent are used as applicable legal bases.
- Retention categories: accounting/order records (up to 10 years, where required), support records (up to 3 years), marketing consent records (up to 24 months), security/operational logs (up to 12 months), subject to applicable law.
- Deletion requests apply anonymization where legal retention is required.
- For transfers outside EU/EEA/UK, contractual and organizational safeguards are applied.
- Subprocessors and transfer safeguards are maintained by platform compliance records.
- You have the right to lodge a complaint with the competent data protection supervisory authority in your jurisdiction.
- For first-line support and rights handling, contact: store legal contact (/contact)
Compliance checks include legal identity data, certificate metadata, and readiness for UJP-related reporting workflows.
Order billing data is retained for statutory accounting/UJP requirements under applicable law.
This privacy notice is auto-generated by platform compliance policy from the organization legal profile and is not editable by the organization.