GDPR Policy

This GDPR Policy explains how personal data is processed, protected, and managed in accordance with the General Data Protection Regulation.
It is intended to be read together with our Privacy Policy, which describes how information is collected and used in day-to-day operations.


1. Relationship With the Privacy Policy

This policy complements our Privacy Policy and focuses specifically on data protection principles, legal processing grounds, and user rights under GDPR.
Where the two policies overlap, they are intended to work together rather than replace one another.


2. Categories of Personal Data

Depending on how users interact with the website, we may process:

  • Identification and contact details provided during checkout or communication

  • Order and transaction-related records

  • Technical data related to website access and usage

  • Information shared voluntarily through customer inquiries

Data is limited to what is relevant for operational purposes.


3. Legal Basis for Data Processing

Personal data is processed based on one or more of the following GDPR legal grounds:

  • Performance of a contract: to process orders, manage payments, and arrange delivery

  • Explicit consent: when users choose to receive informational updates

  • Legal obligations: for tax, accounting, or regulatory compliance

  • Legitimate interests: to improve services, maintain platform security, and prevent misuse

Each processing activity is aligned with its appropriate legal basis.


4. Data Storage and Management

Personal data is stored in secure systems with access controls in place.
Retention periods depend on the purpose of processing and applicable record-keeping requirements.
Data is not retained longer than reasonably necessary.


5. Data Sharing and Transfers

Personal data may be shared only when required for:

  • Order fulfillment and operational support

  • Compliance with legal or regulatory requests

Data is not transferred for unrelated commercial purposes.


6. User Rights Under GDPR

Users have the right to:

  • Request access to their personal data

  • Ask for corrections or updates

  • Request deletion where applicable

  • Restrict or object to certain processing activities

  • Withdraw consent previously given

Requests are handled in line with applicable data protection standards.


7. Data Security Measures

Appropriate technical and organizational measures are used to reduce risks such as unauthorized access, loss, or misuse of personal data.
Security practices are reviewed as part of ongoing operations.


8. Policy Updates

This GDPR Policy may be revised to reflect regulatory or operational changes.
Any updated version will replace previous versions once published.


9. Contact Details

For GDPR-related questions or data requests, users may contact us using the details below:

Address: 6118 N 14th St, Phoenix, AZ,85014-1740, US
Phone: +1(928)382-1756
Email: eurohelp@roomtimber.com
Business Hours (Australian Time): 08:30–12:00 & 14:00–17:30

Cart

loading