You acknowledge and agree that your personal data may be processed in accordance with this Notice. Processing your personal data is, amongst others, necessary in order for us to be able to fulfil a contract with you, communicate with you and send you newsletters.
1 About us
1.1 We are the data controller in respect of any personal data that we process about you pursuant to the Danish Data Protection Act, Regulation (EU) 2016/679 of 27 April 2016 (“GDPR”) and all other applicable law from time to time relating to the processing of personal data.
1.2 If you have any comments or enquires related to this Notice, please do not hesitate to contact us at:
Shamballa Jewels A/S
Ny Østergade 7, 1
1101 København K
+45 33 36 59 59
2 Personal Data Collected
2.1 We collect and process certain personal data about you for the purposes specified in section 3 below.
2.2 We collect any personal information that you provide to us directly, including when you subscribe to the Shamballa platform.
2.3 In addition, we collect certain information about you from the third parties. We may receive information about you if you use any of other websites we (or any member of the brand within our group) operate or other services we provide. In this case we will have informed you when we collected that data that it may be shared internally and combined with data collected on this site. We are also working closely with third parties (including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers) and may receive information about you from them.
3.1 Use made of your personal data
Information you give to us. We will use this information in relation to:
• Administration of our Site and performance of our contract with you: The information you give us is necessary to enable us to (i) fulfil your order (including acknowledging your order and communicating with you if there is any issue regarding the fulfilment of your order); (ii) make sure your order is delivered correctly; (iii) maintain your account; (iv)accounting, billing, reporting and audit; (v) authentication and identity checks; (vi) credit, debit or other payment verification; (vii) debt collection; (viii) safety, security, health, training, legal and administrative purposes.
• Providing customer service in pursuit of our legitimate interest as a retailer: We ask for your contact details, such as your email address and telephone number and order details to enable us to answer any questions you have about using our Site and to notify you about the status of your order and other customer care services such as identifying your requirements and shopping preferences. To provide those customer care services we may use your data for statistical and market analysis; case studies, research and development by us, or a third party we appoint as a data processor but in doing so your personal data will be anonymised for the use of it by these parties. They will not receive your name, address, email address or telephone number.
• Direct Marketing: We want to keep you up to date on our latest products, promotional offers and events in order to improve your shopping experience with us. We may use the information you provide and the information we collect about you to build a picture of your interests so that we may tailor our communications to you to ensure they are relevant and of interest to you and so that when you visit our site we can tailor your experience so that it is easier to shop with us.
Electronic Marketing. If you are an existing customer, we will only contact you by electronic means (email or text) about goods and services analogous to those which were the subject of a previous sale. Otherwise, we will contact you by electronic means only if you have explicitly consented to this. If you are a new customer, and where we permit selected third parties to use your data, we (or they) will contact you by electronic means only if you have explicitly consented to this.
• Our service: To notify you about changes to our service.
• Our Site: To ensure that content from our Site is presented in the most effective manner for you and for your computer, and so that we can enhance your experience of using our Site.
4 How we use your personal data
4.1 We may use your personal data for the following purposes:
a. to fulfil our contract with you, including delivery of the products and services requested by you;
b. to communicate with you about special offers, promotions, and other news about our services, including via email, but always subject to your explicit consent;
c. to generate statistics and analyses to maximize user-friendliness and improve functionality of our website,
- to comply with our legal obligations
- to provide you with customer service and to communicate with you
- where necessary for the establishment, exercise or defence of legal claims
5 Legal basis for processing your personal data
5.1 We will process your personal data in because it is necessary: (i) for entering into or performing under a contract entered into with you, including in order to provide our services to you register and process claims and to respond to enquires made by you, cf. GDPR, article 6(1)(b); (ii) for the purpose of furthering our legitimate interests, including in respect of correspondence with you regarding your products, complaints, event etc., cf. GDPR, article 6(1)(f);
(iii) for compliance with our legal obligations, including in respect of section 5 of the Danish Bookkeeping Act, cf. GDPR, article 6(1)(c); and
(iv) for the establishment, exercise or defence of legal claims, cf. GDPR, article 6(1)(b).
5.2 We will also process your personal data on the basis of any consents provided by you, for example to communicate with you about special offers, promotions, events and other news about our services, cf. GDPR, article 6(1)(a).
You can withdraw your consent at any time by contacting us using the contact details specified in section 1.2 above.
6 Protection and storage of your personal data
6.1 We take your privacy serious and will accordingly ensure that appropriate technical and organisational safeguards are in place at all times in order to protect your personal data against unauthorised or unlawful processing and against accidental loss, damage, destruction, alteration or disclosure.
6.2 The personal data we collect about you will only be stored as stated below:
Purpose of processing
Entering into or performing under a contract entered into with you.
Until it is established that no contract will be entered into, or if a contract is entered into, up to 3 years after the contract has ended or as long as storage is required by applicable law (e.g. to comply with the Danish Bookkeeping Act) or storage is necessary to establish, exercise or defend legal claims.
7 Transfer of your personal data to third parties
7.1 We may if relevant share your personal data with the below categories of third parties:
(i) affiliated companies in the group of undertakings;
(ii) service providers assisting with our business activities such as our payment services providers, hosting providers, providers of IT support, web analytics service and CRM-systems;
(iii) our advisors, including accounting firms and law firms; and
(iv) public authorities such as the tax authorities.
7.2 You can rest assured that any such transfer of your personal data will take place in accordance with applicable data protection legislation and subject to appropriate security measures.
8 Transfer of your personal data outside the European Economic Area (EEA)
8.1 Some of the third parties to whom we may transfer your personal data may be located outside of the EEA. If we transfer any of your personal data to countries outside of the EEA which do not provide an adequate level of protection according to applicable data protection legislation we will always ensure that appropriate safeguards to protect your data are in place. In this respect, we will only transfer your personal data if the third party:
(i) is established in a country which, according to a decision of the European Commission, offers an adequate level of data protection;
(ii) has entered into a contract with us in accordance with the European Commission’s model contracts for the transfer of personal data to third countries; or
(iii) has been certified in accordance with the ’EU-US Privacy Shield Framework’ (only relevant for recipients in the U.S.).
8.2 We may transfer your personal data to the following third parties outside of the EEA:
Google Analytics / USA and MailChimp / USA
8.3 If you would like more information about our transfer of personal data to countries outside of the EEA, please contact us using the contact details specified in section 1.2 above. Do not hesitate to contact us if you would like more information about the security measures in place to protect your data, or copies of relevant documents, including the European Commission’s model contracts.
9 Your rights
9.1 Subject to certain conditions set out in data protection legislation, you have the following rights in respect of your personal data:
(i) the right to insight to the personal data, which we store and process about you, as well as a number of additional information regarding the processing;
(ii) the right to obtain a copy of the personal data we have collected about you, in a structured, commonly used and machine-readable format, and to transmit those data to another controller;
(iii) the right to update or amend the personal data we have collected about you if it is inaccurate or incomplete, or in certain cases, erased prior to the end of the retention period listed in section 5.2;
(iv) the right to object to the processing of the personal data we have collected about you, including in respect of any data processed for direct marketing purposes; and
(v) in certain cases, you have the right to restrict the processing of the personal data we have collected about you.
9.2 Where our processing of your personal data has been restricted, such personal data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.
9.3 If you have any questions regarding the processing of your personal data or wish to carry out any of your rights, please contact us by using the contact information in section 1.2 above.
9.4 You have the right to lodge a complaint with the Danish Data Protection Agency (www.datatilsynet.dk).