This Privacy Policy explains how Govora, UAB, trading as Averel, collects, uses, stores and protects personal data when you visit averelhome.com, create an account, place an order, contact us or otherwise interact with our online store.
We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and other applicable data protection laws.
1. Who We Are
The controller responsible for your personal data is:
Govora, UAB
Trading as: Averel
Company code: 305789638
VAT number: LT100014376412
Registered office: Forto g. 29, Akademija, Kauno r. Lithuania
Email: support@averelhome.com
If you have any questions concerning this Privacy Policy or the use of your personal data, you may contact us using the details above.
2. What Personal Data We Collect
Depending on how you interact with our website, we may collect the following categories of personal data:
Identification and contact information
Your name, surname, email address, telephone number, billing address and delivery address.
Order and transaction information
Products purchased, order number, order value, delivery method, payment status, returns, refunds and correspondence relating to your order.
Account information
Where you create a customer account, we may process your account details, order history, saved addresses and other information associated with your account.
Payment information
Payments are processed through our selected payment service providers. We may receive information such as payment status, transaction reference and payment method. Full payment-card details are generally handled directly by the relevant payment provider rather than stored by us.
Customer service information
Information you provide when contacting us through our contact form, email, telephone or other customer-support channel.
Returns and withdrawal information
Where you submit a return, complaint or withdrawal request, we may process your name, email address, order number, products concerned, information contained in your request and the date and time of submission.
Technical and website information
Depending on your cookie choices and website configuration, this may include IP address, browser type, device information, website activity, security logs and cookie identifiers.
Under GDPR principles, only data reasonably necessary for a stated purpose should be collected.
3. Why We Process Your Personal Data
Processing Orders
We process your name, contact information, billing and delivery information, order details and related transaction information to:
process your purchase, arrange payment, fulfil your order, arrange delivery, communicate about the order and deal with returns or refunds.
Legal basis: performance of a contract or taking steps at your request before entering into a contract.
Customer Accounts
Where you choose to create an account, we use your information to provide and maintain your account, display order history and provide account-related functionality.
Legal basis: performance of our contract with you and, where appropriate, our legitimate interest in operating the customer account functionality requested by you.
Delivery
We use your name, telephone number, email address, delivery address and relevant order information to arrange delivery of your purchases.
Relevant information may be provided to couriers, furniture carriers or other logistics providers responsible for delivering your order.
Legal basis: performance of the sales contract.
Customer Service
When you contact us, we use the information you provide to respond to enquiries about products, orders, delivery, returns or other customer-service matters.
Legal basis: performance of a contract, steps taken before entering into a contract or our legitimate interest in responding to customer enquiries, depending on the nature of your request.
Returns, Complaints and Withdrawal Requests
We process information submitted through our return or withdrawal procedures to process your request, comply with consumer-law obligations and maintain appropriate records of the request.
Legal basis: compliance with legal obligations and, where relevant, performance of our contractual obligations.
Accounting, Tax and Legal Obligations
Certain order, transaction, invoice and customer information may need to be retained to comply with accounting, tax, consumer-protection and other legal requirements.
Legal basis: compliance with a legal obligation.
Website Security and Fraud Prevention
We may process technical information, logs and transaction-related information where necessary to protect our website, customer accounts and transactions against fraud, misuse, unauthorised access and other security risks.
Legal basis: our legitimate interest in maintaining the security and integrity of our website and business, and where applicable compliance with legal obligations.
4. Marketing Communications
If you choose to subscribe to marketing communications, we may use your email address and other information you voluntarily provide to send you information about products, collections, news or offers.
Where consent is required, marketing communications will only be sent after you have provided that consent.
Legal basis: consent, where required by law.
You may withdraw your consent at any time by clicking the unsubscribe link in a marketing email or by contacting us.
Withdrawing consent does not affect the lawfulness of processing carried out before consent was withdrawn.
5. Cookies and Similar Technologies
Our website uses cookies and similar technologies.
Some cookies are strictly necessary for the operation of the website, including functionality relating to shopping carts, checkout, customer sessions and security.
Other technologies may be used for analytics, personalisation or marketing only where permitted and, where required, after you have provided consent.
6. Who We Share Personal Data With
We do not sell your personal data.
Where necessary for the purposes described in this Policy, personal data may be shared with categories of service providers such as:
Hosting and IT providers – for website hosting, maintenance, email and technical infrastructure.
Payment service providers – to securely process payments and prevent payment fraud.
Delivery and logistics providers – to deliver your orders.
Accounting and professional advisers – where required for accounting, tax, legal or professional services.
Website and communication service providers – where used to operate customer forms, transactional emails or other website services.
Public authorities – where disclosure is required by law or necessary to establish, exercise or defend legal claims.
Service providers acting on our behalf are required to process personal data only as permitted by applicable law and relevant contractual arrangements.
7. International Data Transfers
Some service providers may process personal data outside the European Economic Area (“EEA”).
Where personal data is transferred outside the EEA, we will ensure that an appropriate legal mechanism is used where required, such as an adequacy decision issued by the European Commission or appropriate contractual safeguards including Standard Contractual Clauses.
GDPR requires users to be informed where their information may be transferred outside the EU/EEA and of the applicable safeguards.
8. How Long We Keep Personal Data
We retain personal data only for as long as necessary for the purpose for which it was collected and to comply with applicable legal obligations.
The applicable retention period depends on the type of information.
Order, invoice and transaction records are retained for the period required by applicable accounting, tax and other legal obligations.
Customer account information is generally retained while the account remains active and may subsequently be retained where required for legal, accounting, fraud-prevention or dispute-resolution purposes.
Customer service enquiries are retained for a reasonable period after the enquiry has been resolved where necessary for customer service, record keeping or potential legal claims.
Returns, complaints and withdrawal records may be retained for the period necessary to demonstrate compliance with consumer-law obligations and handle potential disputes or legal claims.
Marketing information is retained until consent is withdrawn or the information is no longer required, subject to keeping limited information where necessary to record an opt-out.
Technical and security logs are retained only for an appropriate period based on security and operational requirements.
GDPR permits stating either an exact retention period or, where that is not possible, the criteria used to determine it. Data should not be retained indefinitely without a purpose.
9. Your Data Protection Rights
Subject to the conditions provided by applicable law, you may have the right to:
Access the personal data we hold about you.
Rectify inaccurate or incomplete personal data.
Request erasure of personal data where the legal requirements for erasure are met.
Restrict processing in certain circumstances.
Object to processing, particularly where processing is based on legitimate interests or is carried out for direct marketing.
Data portability where applicable.
Withdraw consent at any time where processing is based on consent.
Lodge a complaint with a competent data protection supervisory authority.
These are the principal rights recognised under the GDPR.
To exercise your rights, contact us.
We may need to request reasonable information to confirm your identity before acting on a request.
10. Right to Lodge a Complaint
If you believe that your personal data has been processed in breach of applicable data protection law, you have the right to lodge a complaint with a supervisory authority.
For a business established in Lithuania, the supervisory authority is:
State Data Protection Inspectorate
Valstybinė duomenų apsaugos inspekcija (VDAI)
L. Sapiegos g. 17
LT-10312 Vilnius
Lithuania
Further information, including complaint procedures, is available through the official VDAI website.
You may contact us first if you would like us to investigate a privacy concern directly.
11. Security
We use appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction.
Such measures may include encrypted website connections, restricted administrative access, authentication controls, backups, software updates and appropriate access controls.
However, no internet-based service can guarantee absolute security.
GDPR requires controllers to protect personal data using appropriate technical and organisational measures and to be able to demonstrate compliance with data-protection principles.
12. Payment Security
Payments through our website are processed using approved third-party payment providers.
Depending on the payment method selected, payment information may be processed directly by the relevant payment service provider.
We do not intend to store complete payment-card details on our own website infrastructure unless expressly stated otherwise.
For information about how a payment provider processes personal data, please refer to that provider’s privacy information.
13. Automated Decision-Making
Unless otherwise specifically disclosed, we do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significantly affect you.
Our payment or fraud-prevention providers may use automated systems as part of their own services. Where applicable, their own privacy information explains such processing.
GDPR privacy information must disclose relevant automated decision-making and profiling where applicable.
14. Third-Party Websites
Our website may contain links to third-party websites.
We are not responsible for the privacy practices of independent third-party websites. We recommend reviewing their privacy policies before providing personal information to them.
15. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to our business, website functionality, service providers or applicable law.
The latest version will always be published on this page and the Last updated date will be amended accordingly.
Where a change materially affects how personal data is processed, we will provide additional notice where required by law.