Privacy policy

Miilo’s privacy notice

Last policy update: August 2026

Miilo Entreprise OÜ (the "Site", "Miilo", "we", "us", or "our") is a company registered in Estonia, under the company registry number 17572775 and act under the brand Miilo.

We committed to protecting your personal data and respecting your privacy in accordance with applicable European data protection laws, including the General Data Protection Regulation (GDPR) (EU) 2016/679.

Please read this Privacy Policy carefully to acknowledge the treatment of your personal data, understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services.

If you have any questions about our Privacy Notice, or if you would like to contact us for any other reason you can get in touch:

  • email info@miilostudio.com.

1. General provisions

1.1. This privacy policy regulates the principles regarding the collection, processing and storage of personal data. Personal data is collected, processed and stored by Miilo Entreprise OÜ, the controller of personal data (hereinafter referred to as the data processor).

Company Name: Miilo Entreprise OÜ

Registered Address: Harju maakond, Tallinn, Põhja-Tallinna linnaosa, Puuvilla tn 8, 10314

Registration Number: 17572775

Email: info@miilostudio.com.

1.2. A data subject for the purposes of this privacy policy is a customer or other natural person whose personal data is processed by the data processor.

1.3. A customer for the purposes of the privacy policy is anyone who purchases goods or services from the data processor's website.

1.4. The data processor complies with the principles of data processing set out in legislation, including the processing of personal data lawfully, fairly and securely. The data processor is able to confirm that personal data has been processed in accordance with the provisions of legislation.

2. Reasons of collection

2.1. To deliver our services to you, fulfill an order, enter in contract or in contact, we will process your personal data in order to enter contracts with you, when an order is placed, a service required or to enter in contact under marketing purposes. We process information you give us willingly.

3. Collection, processing and storage of personal data

3.1. The personal data that the data processor collects, processes and stores is collected electronically, mainly via the website and e-mail.

3.2. By sharing their personal data, the data subject grants the data processor the right to collect, organize, use and manage the personal data that the data subject shares with the data processor directly or indirectly when purchasing goods or services on the website, for the purposes specified in the privacy policy.

3.3. The data subject is responsible for ensuring that the data provided by him/her is accurate, correct and complete. Knowingly providing false data is considered a violation of the privacy policy. The data subject is obliged to immediately notify the data processor of any changes to the data provided.

3.4. The data processor is not liable for any damage caused to the data subject or third parties due to the provision of false information by the data subject.

3.5. Type of data collected

  • Information You Provide Directly - name, email address, phone number…
  • Information Collected Automatically - IP Address, device information, cookies and similar technologies…
  • Information from Third Parties - Analytics providers, Advertising partners, Social media platforms, Payment service providers…

4.  Processing of customers' personal data

4.1. The data processor may process the following personal data of the data subject. It includes, among others:

  • First and last name;
  • Date of birth;
  • Telephone number;
  • Email address;
  • Postal and delivery addresses;
  • Current account number;
  • Payment card details;
  • Information submitted through contact forms;

4.2. In addition to the above, the data processor has the right to collect data about the client that is available in public registers.

4.3. The legal basis for the processing of personal data is Section 6(1)(a), (b), (c) and (f) of the General Data Protection Regulation:

(a) the data subject has given consent to the processing of his or her personal data for one or more specific purposes;

b) the processing of personal data is necessary for the performance of a contract concluded with the data subject or in order to take steps prior to entering into a contract at the request of the data subject;

(c) the processing of personal data is necessary for compliance with a legal obligation to which the controller is subject;

(f) the processing of personal data is necessary for the legitimate interests pursued by the controller or by a third party, unless such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require the protection of personal data, in particular where the data subject is a child.

4.4. Processing of personal data according to the purpose of processing:

4.4.1.The data processor may process the personal data to the following purposes:

  • Newsletter
  • Registering and using a user account on the website
  • Processing an order
  • Payments
  • Deliveries
  • Get in contact - through phone, email, mail and webforms
  • Support services
  • Offer personalized products and services of interest to the user
  • Share data with third parties (e.g. courier / delivery companies)
  • Verify compliance and analyze website statistics, performance to improvements
  • Comply with legal obligations.

4.4.2. Purpose of processing – security and safety

Maximum period of retention of personal data – in accordance with the deadlines specified in the law

4.4.3. Purpose of processing – order processing

Personal data is processed for the performance of a contract and retained for up to 10 years after completion of the order to establish, exercise, or defend legal claims.

4.4.4. Purpose of processing – ensuring the functioning of the e-shop services.

Technical and account-related data is retained for as long as the customer account remains active and for up to 3 years thereafter unless a longer retention period is required by law.

4.4.5. Purpose of processing – customer management

Customer communication records are retained for up to 5 years after the last interaction.

4.4.6. Purpose of processing – financial activities, accounting

Accounting data is retained for the period required by applicable accounting and tax legislation.

4.4.7. Purpose of processing – marketing

Until consent is withdrawn and for a limited period afterward to demonstrate compliance.

5. Marketing Communications

If you subscribe to our newsletter or marketing communications, we may use your email address to send updates and promotional information.

You may withdraw your consent at any time by:

  • Clicking the unsubscribe link in emails;
  • Contacting us;

NB: Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.

6. Cookies and Tracking Technologies

We use cookies and similar technologies to operate and improve our website.

Cookies may include:

  • Strictly necessary cookies
  • Functional cookies
  • Analytics cookies
  • Advertising and marketing cookies

Where required by law, we obtain your consent before placing non-essential cookies on your device.

For more information, please see our Cookie Policy.

7. Sharing of Personal Data

7.1. We may share personal data with third parties,including:

  • Hosting providers
  • IT service providers
  • Analytics providers
  • Payment processors
  • Marketing service providers
  • Professional advisors
  • Public authorities where legally required

7.2. E-commerce Platform

  • Shopify Inc. — store hosting, order processing, customer data

7.3. Analytics

  • Google Analytics (Google LLC) — website usage tracking
  • Meta Pixel (Meta Platforms Inc.) — ad performance tracking
  • TikTok Pixel (TikTok Inc.) — ad performance tracking

7.4. Advertising

  • Google Ads (Google LLC) — paid advertising
  • Meta Ads (Meta Platforms Inc.) — paid advertising
  • TikTok Ads (TikTok Inc.) — paid advertising

7.5. Payments

  • Shopify Payments (powered by Stripe) — payment processing
  • PayPal Inc. — payment processing
  • Visa / Mastercard — card network processing
  • Bank and financial institutions - payment processing

7.6. Delivery & Shipping

  • Shipping carriers (e.g. DHL, DPD, Omniva, Unisend etc.)

7.7. Reviews

  • Reviews platform can include Trustpilot, Google Reviews etc.)

All third-party processors are required to process personal data in accordance with applicable data protection laws and our instructions.

8. International Data Transfers

Where personal data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, including:

  • European Commission adequacy decisions
  • Standard Contractual Clauses (SCCs)
  • Other lawful transfer mechanisms recognized under GDPR

You may request further information regarding such safeguards by contacting us.

9. Data Retention

We retain personal data only for as long as necessary to fulfill the purposes described in this Privacy Policy, including:

  • Compliance with legal obligations
  • Resolution of disputes
  • Enforcement of agreements
  • Business and operational needs

Retention periods may vary depending on the nature of the data and applicable legal requirements.

10. Data subject rights

10.1. The data subject has the right to access and review their personal data.

10.2. The data subject has the right to receive information about the processing of his or her personal data.

10.3. The data subject has the right to supplement or correct inaccurate data.

10.4. If the data processor processes the personal data of the data subject based on the data subject's consent, the data subject has the right to withdraw consent at any time.

10.5. The data subject has the right to restrict the processing of the personal data or ask for its erasure ("Right to be Forgotten")

10.6. The data subject has the possibility to file a complaint with the Data Protection Inspectorate to protect his or her rights.

Know more about GDPR

11. Security Measures

We implement appropriate technical and organizational measures to protect personal data against:

  • Unauthorized access
  • Loss
  • Destruction
  • Alteration
  • Disclosure

However, no internet transmission or electronic storage method can be guaranteed to be completely secure.

12. Final provisions

12.1. These data protection conditions have been drawn up in accordance with Regulation (EU) No 2016/679 of the European Parliament and of the Council on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation), the Personal Data Protection Act of the Republic of Estonia, and the legislation of the Republic of Estonia and the European Union.

12.2. The data processor has the right to partially or completely change the data protection conditions by informing data subjects of the changes via the website www.miilostudio.com.