Privacy Policy

RADIACODE LTD (“we”, “us”, “our”) value your privacy and are committed to transparency in how we handle your personal data. This Privacy Policy lets you know how and for what purposes we are processing your information. We pledge that we will take reasonable steps to ensure that your personal data will only be used in ways that comply with this Privacy Policy and applicable regulations.

This Privacy Policy governs the processing of personal data in your interactions with us, including when you: (1) visit (use) our website located at: https://www.radiacode.com/ (the “Website”), (2) communicate with us and as otherwise described in this Privacy Policy.

Before you share any personal data with us, please review this Privacy Policy and our Terms and Conditions (the “Terms”).

When you choose to use our Radiacode App or the RadiaVerse interactive radiation portal including the Interactive map, please, see the Privacy Policy for the Radiacode App and Interactive map, which describes how your personal information is collected and used.

1. Who we are?

RADIACODE LTD, duly incorporated in and registered under the laws of the Republic of Cyprus, with a registered office at 10 Spyrou Kyprianou, Germasogeia, 4040 Limassol, Cyprus acts as a data controller. It means we determine the purposes and means of the processing of personal data.

Since we are registered under the law of the Republic of Cyprus, the personal data authority overseeing us regarding the personal data processing is the Commissioner for Personal Data Protection. You always have the right to make a data protection-related complaint at any time to a supervisory authority. You may also contact your local data protection authority. A list of local data protection authorities is available here.

You can exercise your data protection rights and contact us with any privacy-related questions without creating an account on the Website. You can reach us by sending an email to security@radiacode.com or by writing to us at our postal address above, addressed to the “Privacy team”.

2. How do we collect personal data?

We process personal data in the following ways:

  1. when you provide us with personal data. You provide us with your personal data in order to realize the purposes of the processing. For example, in order to create an account on the Website, and carry out marketing or informational mailings, we need the personal data we receive from you;
  2. when personal data is collected automatically. There are tools that allow us to collect technical personal data about you when you use the Website. For certain purposes (e.g. to enable you to technically use the Website, to track and fix bugs on the Website), we automatically collect your personal data where there is a legal basis to do so.
  3. when information is provided from other sources: we may receive information from Shopify and other service providers that operate checkout, payments, communications, analytics and delivery integrations on our behalf.

3. How do we process personal data?

We process your personal data only when and to the extent necessary for the purposes described in this Privacy Policy. When the applicable retention period expires, we delete or irreversibly anonymise the personal data, unless continued retention is required or permitted by law, including for backups, legal claims, tax, accounting, fraud-prevention or security purposes.

Is it mandatory to provide personal data? What happens if you do not provide it?

In most cases, you are free to decide whether to provide us with your personal data. However, for some purposes we cannot provide you with certain features or services without specific information:

  • Account registration and use of your account on the Website. To create and use an account, you need to provide at least your email address. If you do not provide this information, you will not be able to create an account and use the related functionality.
  • Placing an order and receiving a device. To process your order and deliver the device, we need information such as your full name, delivery address, email address and phone number. If you decide not to provide this information, we will not be able to process your order or deliver the device to you.
  • Essential technical and usage data. Certain session, checkout, security and device information is necessary to operate the Shopify-powered Website, authenticate accounts, maintain the shopping cart, process checkout and protect the Website against fraud and abuse. Optional analytics, personalisation and advertising technologies are not necessary to use the Website and are activated only where the required consent has been obtained. Blocking strictly necessary technologies may prevent some requested features from working.

Providing your personal data for marketing communications and for analytics / preference cookies is not required by law or by contract. If you do not provide your consent for these purposes, this will not affect your ability to use the Website or place orders, but you may receive a less personalized experience and will not receive our marketing updates.

Below we describe the processing purposes relating to Website visitors, customers and account holders, the categories of personal data involved, the applicable legal bases and the relevant retention periods.

Processing of customer support inquiries for analysis, issue resolution, and routing to relevant internal departments to ensure high-quality service
Processed personal data
  • Email address
  • Category of the issue
  • Other data that you provide in the issue and further correspondence
Recipients of personal data

Help Scout PBC (Help Scout, USA) — processor

Legal basis for the processing

Legitimate interest (GDPR Art. 6(1)(f)) in ensuring high-quality customer service and efficient handling of your inquiries.

Data retention period

Retained for the duration of the inquiry and up to 6 years thereafter to establish or defend potential legal claims within applicable Cypriot limitation periods.

Handling customer support cases related to problematic or delayed orders
Processed personal data
  • Full name
  • email address
  • order ID
  • phone number
  • postal address
Recipients of personal data

Help Scout PBC (Help Scout, USA) — processor; Shopify International Ltd. (Shopify, Ireland) — processor for the underlying order records

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Retained for the duration of the inquiry and up to 6 years thereafter to establish or defend potential legal claims within applicable Cypriot limitation periods.

Warranty and after-sales service
Processed personal data
  • Full name
  • email address
  • order ID
  • phone number
  • postal address
  • device serial number
  • reason of return or repair
Recipients of personal data

Help Scout PBC (Help Scout, USA) — processor; Shopify International Ltd. (Shopify, Ireland) — processor for the underlying order records; couriers and postal operators, including but not limited to FedEx, ACS air couriers Cyprus and Cyprus Post — independent data controllers where a return, replacement or repair shipment is carried out

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Up to 6 years after resolution of the warranty or repair request within applicable Cypriot limitation periods.

Issuing compensation (e.g., voucher or refund) to customers
Processed personal data
  • Full name
  • email address
  • order ID
  • postal address
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor; the applicable payment provider — processor or independent controller, depending on the provider and the payment method, where a refund is made

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Up to 6 years from the end of the tax year in which the compensation was issued, extendable up to 12 years in cases of suspected deceit or deliberate omission under Cypriot tax and VAT law.

Registration and authentication of a customer account using Shopify
Processed personal data
  • email address
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Until the user deletes the account and up to 6 years thereafter to establish or defend potential legal claims within applicable Cypriot limitation periods.

Operating the Shopify storefront, shopping cart and checkout
Processed personal data
  • session, cart and checkout identifiers
  • products viewed and added to the cart
  • selected language and shipping country
  • customer/account identifier, if logged in
  • IP address, device, browser and network information
  • order and transaction information
  • consent and privacy preferences
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor

Legal basis for the processing

Contract (GDPR Art. 6(1)(b)) for functionality requested by the user; legitimate interests (GDPR Art. 6(1)(f)) in operating and securing the storefront. Optional analytics, personalisation and advertising are based on consent (GDPR Art. 6(1)(a)).

Data retention period

Session and cart data are retained for the period necessary to provide the requested functionality. Essential cookie and consent identifiers may remain for the durations stated in the Cookie Policy. Order records are retained under the applicable transaction-retention periods below.

Account, transaction and storefront security and fraud prevention using Shopify
Processed personal data
  • IP address
  • device, browser and network information
  • session and account identifiers
  • authentication and login events
  • checkout and transaction information
  • fraud and security signals
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor; the applicable payment providers — processor or independent controller, depending on the provider and the payment method

Legal basis for the processing

Legitimate interests (GDPR Art. 6(1)(f)) in protecting users, transactions and the Website against fraud, abuse, unauthorised access and malicious activity; compliance with legal obligations (GDPR Art. 6(1)(c)) where applicable.

Data retention period

For no longer than necessary to investigate and prevent security incidents and fraud, comply with applicable obligations and establish or defend legal claims.

Placing an order for a device and making payments
Processed personal data
  • Order details
  • full name
  • phone number
  • IP address
  • email address
  • billing information
  • shipping information
  • updates on status of transactions
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor, which operates the checkout and transmits payment data to the payment provider selected by you; and the payment provider corresponding to the payment method selected at checkout. Depending on the provider and the payment method, a payment provider may act either as our processor or as an independent data controller for its own regulatory and anti-fraud purposes. Full payment credentials are collected directly by the applicable payment provider.

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Up to 6 years from the end of the tax year in which the transaction occurred, extendable up to 12 years in cases of suspected deceit or deliberate omission under Cypriot tax and VAT law.

Issuing and managing invoices
Processed personal data
  • Full name
  • email address
  • phone number
  • postal address
  • user’s country and province/state level
  • IP address
  • browser info and operating system
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor; Shop Circle Ltd (Order Printer Pro, UK) — processor.

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Up to 6 years from the end of the tax year in which the invoice was issued, extendable up to 12 years in cases of suspected deceit or deliberate omission under Cypriot tax and VAT law.

Informing about transactions and other service-related communication
Processed personal data
  • email address
  • transaction data
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor

Legal basis for the processing

Legitimate interest (GDPR Art. 6(1)(f)) in providing reliable and efficient service communication.

Data retention period

Up to 6 years from the end of the tax year in which the related transaction occurred, extendable up to 12 years in cases of suspected deceit or deliberate omission under Cypriot tax and VAT law.

Delivery of devices
Processed personal data
  • Full name
  • phone number
  • delivery postal address
  • email address
  • order ID
Recipients of personal data

couriers and postal operators, including but not limited to FedEx, ACS air couriers Cyprus and Cyprus Post — independent data controllers for delivery, transport, customs clearance and their own legal obligations. Depending on the destination country and the shipping option selected, other couriers or postal operators may be involved. Shopify International Ltd. (Shopify, Ireland) and Ecwid by Lightspeed — processors supporting the transmission of shipment information to the relevant delivery provider.

Legal basis for the processing

Contract (GDPR Art. 6(1)(b))

Data retention period

Up to 6 years from the end of the tax year in which the delivery occurred, extendable up to 12 years in cases of suspected deceit or deliberate omission under Cypriot tax and VAT law. FedEx and other courier providers, acting as independent data controllers, may retain shipment and customs-related data for longer under their own retention policies and applicable statutory obligations.

Managing a customer account using Shopify
Processed personal data
  • email address and contact details
  • customer/account identifier
  • account settings and preferences
  • delivery addresses
  • order and transaction history
  • account activity and security logs
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor

Legal basis for the processing

Contract (GDPR Art. 6(1)(b)); legitimate interests (GDPR Art. 6(1)(f)) in maintaining account security and protecting legal rights.

Data retention period

Until the account is deleted, with transaction records and limited security or legal-claims records retained for the applicable periods stated in this Policy.

Collecting feedback via Trustpilot
Processed personal data
  • Email address
  • full name
  • date of the order
  • order number
Recipients of personal data

Trustpilot A/S (Trustpilot, Denmark), which sends review invitations on our behalf and acts as our processor for this purpose.

Legal basis for the processing

Legitimate interest (GDPR Art. 6(1)(f)) in enhancing our services and customer satisfaction

Data retention period

30 days from the date the feedback was submitted. If no feedback is submitted, the retention period is 30 days from the date the feedback invitation was sent.

Sending forgotten basket notifications
Processed personal data
  • email address
  • full name
  • products added to the shopping cart
  • cart and checkout identifier and the time of the abandoned checkout
  • country
  • marketing consent status and consent record
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor

Legal basis for the processing

Consent (GDPR Art. 6(1)(a)), as these reminders are sent only to users who have given their consent to receive marketing communications. You may withdraw your consent at any time using the unsubscribe link in the message or by contacting us.

Data retention period

60 days from the user’s last activity related to the shopping cart (creation, update, or attempt to check out)

Email marketing and promotional communications using Shopify Messaging
Processed personal data
  • full name
  • email address
  • phone number
  • physical address
  • device and activity data
  • geolocation
  • IP address
  • browser and operating system
  • marketing consent status and consent record
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor, via Shopify Messaging.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a))

Data retention period

Until consent is withdrawn or the data are no longer necessary for the purpose. Marketing consent is reviewed every 3 years to ensure it remains valid and up to date.

Sales analysis based on completed orders
Processed personal data
  • Full name
  • email address
  • phone number
  • postal address
  • order details
  • amount purchased
  • delivery status
  • communication channel
  • geolocation
Recipients of personal data

Shopify International Ltd. (Shopify, Ireland) — processor.

Legal basis for the processing

Legitimate interest (GDPR Art. 6(1)(f)) in improving our offering, plan stock and resources, and ensuring our business operates efficiently.

Data retention period

For analytics purposes, personal data is retained for up to 3 years based on legitimate interest in improving our offering, plan stock and resources, and ensuring our business operates efficiently.

Displaying embedded video content using YouTube
Processed personal data
  • IP address and cookie/online identifiers
  • device and browser information
  • video viewing and interaction data
  • consent state
Recipients of personal data

Google Ireland Limited (YouTube, Ireland) — controller for its own purposes.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a)) for non-essential YouTube technologies.

Data retention period

For the durations stated in the Cookie Policy or until consent is withdrawn for future collection.

Server-side tag management and event routing using Stape
Processed personal data
  • IP address and device/browser information
  • Website interaction and event data
  • page and conversion identifiers
  • data routed to the analytics or advertising services selected by the user
Recipients of personal data

Stape Europe OÜ (Stape, Estonia) — processor.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a)) where Stape routes optional analytics or advertising events

Data retention period

The currently listed cee identifier remains for 3 months.

Website traffic, conversion and remarketing analytics using Google Analytics
Processed personal data
  • Online identifiers (IP address, cookies, device ID)
  • browsing data
  • timestamps
  • referral source
  • conversion events
Recipients of personal data

Google Ireland Limited (Google Analytics, Ireland) — processor for the measurement services provided to us; Google may act as a controller for its own purposes where the relevant data-sharing settings are enabled.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a))

Data retention period

Up to 1 year, 1 month and 4 days from the date the data was collected, or until consent is withdrawn, whichever occurs first

Product usage and funnel analytics using Amplitude
Processed personal data
  • Country
  • device information (browser, OS, device type)
  • session data and session replay recordings
  • page views
  • user actions
  • clicks
  • navigation events
  • marketing data (UTM parameters, referrers, campaign identifiers)
Recipients of personal data

Amplitude, Inc. (Amplitude, USA) — processor

Legal basis for the processing

Consent (GDPR Art. 6(1)(a))

Data retention period

Up to 1 year or until consent is withdrawn, whichever occurs first; Session replay data: stored for a maximum of 30 days or until consent is withdrawn, whichever occurs first

Online advertising using Google Ads
Processed personal data
  • IP address
  • device information (device type, features used, access times)
  • browser information
  • cookies
  • events (incl. clicks)
  • advertising ID
  • item purchased
  • transaction ID
  • amount purchased
  • currency
Recipients of personal data

Google Ireland Limited (Google Ads, Ireland) — controller, and joint controller with us in respect of the collection and transmission of conversion and audience data.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a))

Data retention period

Up to 1 year and 24 days from the date the data was collected, or until consent is withdrawn, whichever occurs first.

Website behaviour and preference analytics using Microsoft Clarity
Processed personal data
  • Device information (device type, features used, access times, IP)
  • usage information (manufacturer, model, OS, time zone, language, region)
  • customer preferences signals, including CMS
  • customer activity, including products viewed and/or included in shopping carts
Recipients of personal data

Microsoft Ireland Operations Limited (Microsoft Clarity, Ireland) — processor.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a))

Data retention period

Up to 1 year from the date the data was collected, or until consent is withdrawn, whichever occurs first

Marketing and advertising using Meta Pixel
Processed personal data
  • IP address
  • referrer URL
  • device information (device type, features used, access times, IP)
  • browser information
  • user interactions (pseudonymised)
  • email (pseudonymised)
  • first name (pseudonymised)
  • last name (pseudonymised)
  • city (pseudonymised)
  • ZIP (pseudonymised)
  • country (pseudonymised)
Recipients of personal data

Meta Platforms Ireland Limited (Meta, Ireland) — joint controller with us in respect of the collection and transmission of event data through the Meta Pixel, and independent controller for its own subsequent processing.

Legal basis for the processing

Consent (GDPR Art. 6(1)(a))

Data retention period

Up to 180 days from the date the data was collected, or until consent is withdrawn, whichever occurs first

We do not receive or store full payment card numbers, card security codes or other full payment credentials. These data are collected directly by Shopify and the applicable payment provider. We may receive limited transaction information, such as the payment method, payment status, transaction identifier, billing details and limited card information made available by the payment provider.

4. How long do we keep your personal data?

We keep your personal data for as long as necessary to fulfill the purpose of the processing. Specific timeframes are specified in Section 3.

Under certain circumstances, we may be required to retain your personal data for a longer period of time in accordance with applicable law or regulatory requirements. This may include but is not limited to, situations involving legal proceedings, investigations, or government inquiries. We will only retain your personal data for as long as necessary to comply with these legal obligations, and we will take appropriate measures to ensure its security and confidentiality during this period.

5. Sharing your data with third parties

Your privacy is of utmost importance to us, and we handle your personal data with the highest level of care and responsibility. We only share your personal data when this is necessary and lawful, and we always remain responsible for such sharing as a data controller.

We may share your personal data in the following situations:

  • To comply with applicable law. We may disclose your personal data where this is necessary to comply with legal obligations, such as to respond to subpoenas, court orders, or other lawful government requests. We may also share your personal data if we believe in good faith that such disclosure is necessary to protect our rights, enforce our Terms, investigate fraud, or protect the safety of you or others.
  • To accomplish the purposes set forth above. To provide our services and operate the Website, we work with carefully selected service providers. Most of them act as processors on our instructions and only process personal data on our behalf; we do not allow these providers to use your personal data for their own purposes. We choose our service providers with care and require them to implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure or misuse. Certain recipients, however, act as independent data controllers of your personal data, as further described below.

Depending on the specific service you use, we may share different categories of personal data with our service providers. In particular:

  • E-commerce and platform providers, including Shopify, receive the data necessary to host and operate the Website, customer accounts, shopping cart, checkout, orders, consent settings and related security functions.
  • Hosting providers receive data that are necessary to store and operate the Website (for example, account data, order data and technical logs).
  • Analytics, advertising, video and tag-management providers receive technical, usage, cookie and event data only for the purposes and subject to the consent settings described in Sections 3 and 7. These providers may include Google, Microsoft, Meta, YouTube, Amplitude and Stape.
  • Payment service providers receive the data necessary to process your payments (for example, information about your order, full name, email address and other payment-related identifiers). Depending on the payment method and the provider concerned, a payment service provider may act either as our processor or as an independent data controller for its own regulatory, anti-fraud and financial-crime obligations. The payment options currently offered at checkout are card payments (Visa, Mastercard, Maestro, American Express and UnionPay) and Klarna as a “buy now, pay later” option, PayPal, Google Pay, Apple Pay; the available options may vary depending on your country, currency and device. We do not receive or store your full bank card details.
  • Customer support and communication tools receive the data you provide when contacting us or placing orders (for example, your name, email address, order details and the content of your messages). These include Help Scout PBC (Help Scout, USA), which provides the shared support inbox, help centre and related support functionality and acts as our processor.
  • Delivery and logistics providers (e.g. couriers and postal operators) receive the data necessary to deliver your order or to handle a return, replacement or repair shipment (for example, your full name, delivery address, phone number, email address and order reference). Unlike our processors, couriers and postal operators act as independent data controllers: they determine their own purposes and means of processing for transport, customs clearance and declaration, and compliance with their own legal obligations, and they retain shipment data in accordance with their own privacy policies and statutory retention requirements.
  • Professional consultants, lawyers, and notaries. In certain situations, we may share your personal data with professional advisers such as legal counsel, regulatory consultants, auditors, or notaries. We disclose your personal data to such advisers only when this is necessary and justified, for example to protect or exercise our legal rights and interests or to obtain legal or regulatory advice and support regarding contractual, corporate, compliance or other matters. We share with these professionals only the minimum amount of personal data necessary for them to provide their services. All such advisers are bound by confidentiality obligations and are required to protect personal data in accordance with applicable laws, professional ethical standards, and—where applicable—contractual data protection obligations.

We transfer your personal data to third parties only in accordance with the requirements of the GDPR. With each service provider that processes personal data on our behalf as a processor, we conclude a written data processing agreement or rely on an equivalent contractual mechanism. These agreements require our service providers to:

  • process personal data only on our documented instructions;
  • protect personal data with appropriate technical and organisational measures;
  • keep personal data confidential; and
  • assist us in fulfilling our obligations towards data subjects.

Where our partner offers its own GDPR-compliant data processing agreement, we may adhere to such agreement. In such cases, our relationship with that partner – including the transfer of personal data – is governed by those data processing terms.

Some recipients of your personal data – in particular couriers and postal operators, and, depending on the payment method, certain payment service providers – act as independent data controllers rather than as our processors. When we share your personal data with such recipients, we share only the data necessary for the relevant purpose (for example, delivering your order), and their processing of your personal data is governed by their own privacy policies and applicable law.

INTERNATIONAL DATA TRANSFERS

Some of our service providers and other recipients of your personal data are located outside the European Economic Area (EEA) or may store your personal data on servers located outside the EEA. This includes, for example, Shopify International Ltd. (Ireland), which operates the Website, customer accounts, cart, checkout and related services and may transfer personal data to Shopify group companies and its sub-processors located outside the EEA, including in Canada and Singapore, and Help Scout PBC (USA), which operates our customer-support platform and stores support correspondence in the United States, as well as certain other hosting and payment providers, and couriers and postal operators involved in delivering your order or handling a return, replacement or repair shipment to or from countries outside the EEA (for example, the United States and the United Kingdom).

When we transfer your personal data to a country outside the EEA that does not provide an adequate level of data protection, we ensure that appropriate safeguards are in place as required by the GDPR. These safeguards may include:

  • relying on a decision of the European Commission that the country provides an adequate level of protection (for example, for transfers to the United Kingdom or to recipients in the United States certified under the EU-U.S. Data Privacy Framework); and/or
  • entering into Standard Contractual Clauses adopted by the European Commission with the relevant recipient; and, where necessary,
  • implementing additional contractual, technical and organisational measures to protect your personal data.

For example, our customer-support provider Help Scout PBC is located in the United States and participates in the EU-U.S. Data Privacy Framework, including its UK Extension. In addition, our data processing agreement with Help Scout incorporates the Standard Contractual Clauses adopted by the European Commission (together with the UK Addendum and Swiss modifications) as a further transfer safeguard.

For transfers carried out by Shopify, the Shopify Data Processing Addendum provides that transfers from the EEA and Switzerland to other Shopify group companies are made under Shopify’s Binding Corporate Rules, that transfers from the United Kingdom rely on Standard Contractual Clauses concluded between Shopify entities together with the International Data Transfer Addendum issued by the UK Information Commissioner’s Office, and that transfers from Shopify International Ltd. to its Canadian parent company Shopify Inc. may also rely on the European Commission’s adequacy decision for Canada. Transfers to countries that do not ensure an adequate level of protection are subject to the 2021 Standard Contractual Clauses (Commission Decision 2021/914/EC), the UK International Data Transfer Addendum, the Standard Contractual Clauses as amended for Swiss law, or any successor transfer mechanism.

In addition, in limited cases – such as international deliveries or return shipments carried out by couriers and postal operators – we may rely on the derogation under GDPR Art. 49(1)(b), where the transfer is necessary for the performance of our contract with you (for example, to deliver your order or process a return or repair).

You can obtain a list of third parties (our processors and other recipients), more information about transfers of your personal data by contacting us at: security@radiacode.com.

6. Use of Shopify for the Website, customer accounts, shopping cart and checkout

Our Website, online store, customer accounts, shopping cart and checkout are hosted and operated using Shopify services (“Shopify”). Shopify provides the technical platform used to display products, maintain sessions and carts, authenticate customer accounts, process checkout and orders, integrate payment methods, record privacy preferences and support related communications and security functions.

For these core merchant services, Shopify International Ltd. or the applicable Shopify contracting entity generally processes customer personal data on our behalf as a processor under Shopify’s Data Processing Addendum. The categories of data may include contact and account information, cart and order data, transaction status, device and usage information, session and checkout identifiers, security signals and privacy preferences.

Shopify Network Intelligence and Enhanced Services

Where Shopify Network Intelligence is enabled, Shopify may use data about interactions with our Store, other merchants and Shopify to provide Enhanced Services, including analytics, product and store customisation, fraud prevention, advertising and more relevant experiences. For this separate processing, Shopify may act as an independent controller and is responsible for responding to requests concerning its own processing.

For users in the EEA, the United Kingdom and Switzerland, non-essential Shopify analytics, personalisation and advertising technologies are activated only where the consent required by applicable law has been obtained. Consent preferences are synchronised between our consent-management platform and the Shopify Customer Privacy API.

More information about Shopify’s processing and available privacy choices is available in the Shopify Consumer Privacy Policy and through the Shopify Privacy Portal.

7. How we process cookies

In order to operate the Website and, with your consent where required, analyse usage, personalise content and measure advertising, we use cookies and similar technologies such as pixels, local storage, consent identifiers, server-side event routing and session-replay technologies. A cookie is a piece of data that can be stored on the browser of your computer or mobile device you use to access the Website. It enables the Website to “remember” your activity or preferences for a certain period or during a specific session. Information collected through these technologies may identify you directly or indirectly, including by distinguishing your browser or device, and may be used to provide a more personalised experience.

For information about the specific cookies and tracking technologies we use, their providers, retention periods, and how you can manage your preferences, see our Cookie Notice.

8. Rights under GDPR

As a data subject, you have certain rights regarding your personal information. We are committed to upholding these rights and ensuring that you can exercise them effectively.

Below, you can find the information regarding your rights as a data subject under EU legislation:

Right of access

This right allows you to request access to the personal data we hold about you.

To exercise this right, please contact us at the e-mail indicated above. Upon receiving your request, we will provide you with a copy of the personal data we process in the form in which you have requested the provision of this information. Please note that in some cases we may charge you a reasonable fee for providing this information. If we are unable to fulfil your request for any reason, we will provide you with an explanation and inform you of your rights to appeal the decision.

Right to rectification

This right enables you to request the correction or updating of any inaccurate or incomplete personal data we hold about you.

You can exercise this right in two ways:

1. by yourself by following these steps:

  • log in to your account on the Website
  • open a personal profile on the Website
  • locate personal data you wish to correct and edit it
  • save the changes to update your data instantly

2. by contacting us at e-mail indicated above. Upon receiving your request for rectification, we will review the accuracy and completeness of your personal data and make any necessary corrections or updates.

Right to erasure

This right allows you to request the deletion or destruction of your personal data in certain circumstances, such as when the data is no longer necessary for the purposes for which it was collected or processed (or, as we all know, the “right to be forgotten”).

You can exercise this right by contacting us at e-mail indicated above. Upon receiving your request for erasure, we will assess whether the applicable conditions are met and, where required, delete or anonymise the relevant personal data. Where GDPR Article 19 applies, we will communicate the erasure to recipients to whom the personal data were disclosed, unless this proves impossible or involves disproportionate effort.

Right to restrict processing

This right allows you to request the restriction of processing of your personal data in certain circumstances, such as when the processing is unlawful, when we no longer need the personal data, or when you have objected to the processing.

To exercise this right, please contact us at the email address indicated above. While processing is restricted, we will generally store the personal data but will not otherwise process it without your consent, except for the establishment, exercise or defence of legal claims, the protection of the rights of another natural or legal person, or reasons of important public interest.

Right to data portability

This right allows you to receive a copy of your personal data in a structured, commonly used, and machine-readable format if it is technically possible to do so and to transmit those data to another controller.

To exercise this right, please contact us at the e-mail indicated above. Upon receiving your request for data portability, we will provide you with a copy of your personal data in the requested format, where technically feasible.

Right to object

This right enables you to object to the processing of your personal data in certain circumstances, such as where the processing is based on legitimate interests or for direct marketing purposes.

To exercise this right, please contact us at the e-mail indicated above. Upon receiving your objection to processing, we will assess the validity of your objection and, if valid, cease processing your personal data for the purposes to which you have objected.

You have the right to withdraw your consent to the processing of your personal data at any time. This means that if we are processing your personal data based on your consent, you have the right to revoke that consent.

To withdraw consent for cookies and similar technologies, use the “Change Cookie Settings” control described in Section 7. For other consent-based processing, contact us at the email address indicated above or use the unsubscribe mechanism provided in the relevant communication. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. If no other legal basis applies, we will stop the relevant processing.

Right to lodge a complaint

You have the right to lodge a complaint with a data protection supervisory authority if you believe that the processing of your personal data violates the GDPR.

Since we are established in Cyprus, our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of Cyprus. However, you are free to contact any EU or EEA data protection authority that is competent under Article 77 GDPR.

If you believe that our processing of your personal data violates applicable legislation, you have the right to lodge a complaint with a supervisory authority in your country of residence, place of work, or where the alleged breach took place. A list of EU supervisory authorities and their contact details is available here.

Automated decision-making and profiling

Under the GDPR, you have the right not to be subject to automated decisions that significantly affect you, unless specific conditions apply. You also have the right to obtain meaningful information about the logic involved, the potential consequences, and to request human review of such decisions.

We do not make decisions about you based solely on automated processing, including profiling, which produce legal effects concerning you or similarly significantly affect you within the meaning of the GDPR. We may use profiling in a limited way in the context of performance and targeting cookies to better understand how users interact with the Website and to show you more relevant content or advertisements. Such profiling does not produce legal or similarly significant effects for you. You can disable such cookies at any time through the cookie settings described in Section 7, or you can object to such processing by contacting us at security@radiacode.com.

Please note that these rights are subject to certain limitations and exceptions as provided by law. To exercise any of these rights or for further inquiries, please contact us using the provided contact information.

We will review your request as soon as possible, but not more than within one (1) month. Please keep in mind that this period may be extended for an additional two (2) months, if necessary, based on the complexity and number of your requests. In that case, we will tell you about the extension within one (1) month of receipt of your request and explain the reasons for the delay.

9. Children’s privacy

We do not knowingly collect or solicit your personal data from anyone under eighteen (18) years of age or knowingly allow such persons to use our Website. If you are under eighteen (18) years of age, please do not provide any personal data to us. If we learn that we have collected personal data about a child under eighteen (18) years of age, we will delete that personal data as soon as possible. If you believe that we might have any personal data from or about a child under eighteen (18) years of age, please contact us at the e-mail indicated above.

10. Changes to the privacy policy

This Privacy Policy may be changed from time to time due to the implementation of new technologies, changes in applicable laws or for other purposes.

When we make changes, we will update the “Last update” date at the top of this Privacy Policy. For material changes that significantly affect your rights or the way we process your personal data, we will take additional steps to inform you, such as:

  • displaying a prominent notice on the Website; and/or
  • sending you an email notification if we have your email address and the changes are relevant to your relationship with us.

Your continued use of the Website after the effective date of the updated Privacy Policy will be subject to the new Privacy Policy. If we make any changes that require your explicit consent for further processing of your personal data, we will request your consent or renewed consent (in case it was obtained previously).