Privacy Policy

Controller.
Registered business name: BaKaTa 
KvK number: 42050053
Contact: hello@bakata.nl

Personal data we process

We only process personal data that is necessary to operate our website, handle orders, provide customer service, and communicate with you

Orders & delivery: We process your name, email address, phone number, billing address, shipping address, order details, payment status, and delivery information.
Purpose: to process and deliver your order, provide customer service, send order updates, handle returns, and comply with invoicing and tax obligations.
Legal basis: performance of a contract, Article 6(1)(b) GDPR; legal obligation, Article 6(1)(c) GDPR.

Customer account: If you create an account, we process your login details, account details, saved addresses, and order history.
Purpose: to provide account functionality and make future purchases easier.
Legal basis: performance of a contract, Article 6(1)(b) GDPR

Support & contact forms: When you contact us, we process your name, email address, message content, and any information you choose to include. Purpose: to respond to your request and provide support.
Legal basis: legitimate interest, Article 6(1)(f) GDPR, or performance of a contract, Article 6(1)(b) GDPR, when your request relates to an order

Newsletter and marketing emails: If you subscribe to our newsletter or choose to receive marketing emails, we process your email address and, where relevant, your name and preferences.
Purpose: to send brand updates, collection launches, event invitations, and other marketing communications.
Legal basis: consent, Article 6(1)(a) GDPR.
At this stage, we manage email communication through our email hosting provider, Hostinger. If we start using a dedicated email marketing platform in the future, this Privacy Policy will be updated.
You can unsubscribe at any time by using the unsubscribe link in our emails, when available, or by contacting us at hello@bakata.nl.

Analytics: We may use Google Analytics 4 to understand how visitors use our website, such as pages visited, device type, browser, approximate location, and website interactions.
Purpose: to improve our website and customer experience.
Legal basis: consent, Article 6(1)(a) GDPR, unless analytics are configured in a way that does not require consent under applicable cookie rules.

Advertising and measurement: We may use tools such as Meta Pixel and Meta Conversions API to measure and improve advertising on Facebook and Instagram. This may include pseudonymous identifiers and event data, such as viewed products, items added to cart, and purchases.
Purpose: to measure ad performance and improve our advertising.
Legal basis: consent, Article 6(1)(a) GDPR.

Cookies and consent

We use essential cookies to make our website work properly. These cookies are always active. For analytics and marketing cookies, we ask for your consent through our cookie banner before placing these cookies or using similar technologies. You can accept, reject, or change your choices at any time through “Cookie settings” in the website footer.

Processors and recipients

We only share personal data with service providers that are necessary to run our store and provide our services. These may include:

  • Website and store platform: WordPress and WooCommerce
  • Hosting provider: Hostinger
  • Email and email hosting provider: Hostinger
  • Payment providers: Stripe
  • Shipping providers: PostNL and other delivery partners where applicable
  • Analytics provider: Google Analytics 4
  • Advertising and measurement providers: Meta, including Facebook and Instagram

Where required, we enter into data-processing agreements with these providers. Payment providers may also act as independent controllers for certain payment-related processing. Please refer to their own privacy policies for more information.

International transfers

Some of our service providers may process personal data outside the European Economic Area. Where this happens, we rely on appropriate safeguards, such as adequacy decisions, Standard Contractual Clauses, and additional technical and organisational measures where required.

Retention periods

We do not keep personal data longer than necessary.

Orders, invoices, and tax records: 7 years, in line with Dutch tax and administration obligations.
Customer accounts: as long as the account remains active. Inactive accounts may be deleted after 24 months.
Support requests: up to 12 months after resolution, unless a longer period is needed for legal or business reasons.
Newsletter data: until you unsubscribe or withdraw consent.
Marketing and advertising data: until you withdraw consent, or after 24 months of inactivity where applicable.
Cookie consent records: for as long as needed to demonstrate consent and manage your preferences.

Your rights.

Under the GDPR, you have the right to request:

access to your personal data;
rectification of incorrect or incomplete data;
deletion of your personal data;
restriction of processing;
data portability;
objection to processing based on legitimate interest;
withdrawal of consent at any time.

To exercise your rights, contact us at hello@bakata.nl.

We may need to verify your identity before responding to your request. You also have the right to lodge a complaint with the Dutch Data Protection Authority, the Autoriteit Persoonsgegevens.

Security

We take appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, disclosure, alteration, or destruction. Access to personal data is limited to people and providers who need it to perform their work.

Children

Our website and products are intended for adults. We do not knowingly collect data from children. If you believe that a child has provided us with personal data, please contact us so we can delete it where appropriate.

Updates

We may update this policy from time to time. The latest version will always be available on this page.

Shopping Cart
Scroll to Top