FREE SHIPPING TO EU & UK || FREE HOME VIEWING || GLOBAL SHIPPING

Privacybeleid

Last updated: 19 August 2026. This policy explains how we handle your personal data under Regulation (EU) 2016/679 (GDPR).

1. Data controller

[COMPANY LEGAL NAME], [REGISTERED ADDRESS], company number (KBO/BCE) [KBO NUMBER], VAT [BE VAT NUMBER], is the controller of the personal data collected through yamilcraft.be. For any question about this policy or your rights, write to info@yamilcraft.com.

2. What we collect and why

  • Order data (name, billing and delivery address, email, phone, order contents, payment status) — to conclude and perform the sales contract with you. Legal basis: performance of a contract (Art. 6(1)(b) GDPR).
  • Account data (email, password hash, order history) if you create an account — to give you access to your orders. Legal basis: contract.
  • Invoicing and accounting records — to comply with Belgian tax and accounting obligations. Legal basis: legal obligation (Art. 6(1)(c)).
  • Newsletter address, if you subscribe — to send you offers and news. Legal basis: consent (Art. 6(1)(a)), withdrawable at any time via the unsubscribe link in every message.
  • Support messages you send through our contact forms — to answer your enquiry. Legal basis: contract or legitimate interest.
  • Technical and usage data (IP address, browser, pages viewed) — to keep the site secure and working, and, where you consent, to measure and improve it. Legal basis: legitimate interest (Art. 6(1)(f)) or consent for non-essential cookies.

3. Payment data

Card details are entered on the secure page of our payment service provider and are processed by them as an independent controller. We never receive or store your full card number, expiry date or security code. We only receive the result of the transaction and a masked reference.

4. Who we share data with

We share personal data only with parties that need it to deliver the service: our hosting provider, our payment service provider, carriers and logistics partners, our email and newsletter provider, our accountant, and analytics or advertising partners where you have consented. All processors act on our documented instructions under a data processing agreement. We never sell your personal data.

5. International transfers

Some of our providers are established outside the European Economic Area. Where that is the case, the transfer is covered by an adequacy decision of the European Commission or by the European Commission’s Standard Contractual Clauses together with additional safeguards. You may request a copy of the relevant safeguards at info@yamilcraft.com.

6. How long we keep it

  • Order, invoicing and accounting records: 7 years, as required by Belgian law.
  • Account data: for as long as your account is open, then deleted or anonymised.
  • Newsletter subscription: until you unsubscribe.
  • Support correspondence: up to 3 years after the enquiry is closed.
  • Cookies and technical logs: as set out in our cookie notice.

7. Your rights

You have the right to access your data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, to data portability, and to withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal. To exercise any of these rights, email info@yamilcraft.com. We respond within one month.

If you believe we are not handling your data correctly, you may lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit / Autorité de protection des données), Drukpersstraat 35, 1000 Brussels — dataprotectionauthority.be — or with the supervisory authority of your country of residence.

8. Cookies

We use strictly necessary cookies to run the shop (session, basket, language and currency preference, security). Analytics, marketing and social media cookies are only placed after you consent through our cookie banner, and you can change or withdraw your choice at any time from the cookie settings link.

9. Security

The site runs over TLS encryption. We apply access controls, keep our software up to date and limit access to personal data to staff who need it. Should a personal data breach be likely to result in a high risk to your rights, we will inform you and the supervisory authority as required by Articles 33 and 34 GDPR.

10. Changes

We may update this policy to reflect changes in our processing or in the law. The version published on this page, with its “last updated” date, is the one that applies.

nl_BEDutch
Kies uw valuta