1.1. This policy on the processing of personal data ("Personal Data Policy") describes how LS retail ApS ("Kasia Lilja Studio", "us", "our", "we") collects and processes information about you.
1.2. The personal data policy applies to personal information that you provide to us or that we collect via Kasia Lilja's website, www.kasialilja.dk (the "Website").
1.3 Kasia Lilja Studio is the data controller for your personal information. All inquiries to Kasia Lilja Studio can be made via the contact information listed under pkt. 7.
- What personal information do we collect, for what purposes and the legal basis for the processing
2.1. When you visit the Website, we automatically collect information about you and your use of the Website, such as the type of browser you use, the search terms you use on the Website, your IP address, including your network location, and information about your computer.
2.1.1 the purpose is to optimize the user experience and the function of the Website, as well as carry out targeted marketing, including retargeting via Facebook and Google. This processing of information is necessary for us to safeguard our interests in improving the Website as well as show you relevant offers.
2.1.2 The legal basis for processing is Article 6 (1) of the EU Personal Data Regulation. XNUMX, letter f.
2.2. When you buy a product or communicate with us on the Website, we collect the information you provide, such as name, address, e-mail address, telephone number, payment method, information about which products you buy and possibly have returned, delivery requests, and information about the IP address from which ordering was made.
2.2.1 the purpose is that we can deliver the products you have ordered and otherwise fulfill our agreement with you, including to be able to manage your rights to return and advertise. We may also process information about your purchases in order to comply with legal requirements, including for bookkeeping and accounting. When purchasing, the IP address is collected for that purpose and to take care of our interest in being able to prevent fraud.
2.2.2 The legal basis for processing is Article 6 (1) of the EU Personal Data Regulation. XNUMX, letters b, c and f.
2.3. When you sign up for our newsletter, we collect information about your name and email address.
2.3.1 the purpose is to take care of our interest in being able to deliver newsletters to you.
2.3.2 The legal basis for processing is Article 6 (1) of the EU Personal Data Regulation. XNUMX, letter f.
2.4 When you sign up for our customer club (My account), you will be asked to provide eg name, address, date of birth, e-mail address and telephone number, your preferences and interests, etc. In addition to name, address and e-mail address, you choose which information you will give us. In addition, we collect information under your membership about your use of the customer club's benefits, contests you participate in, etc. We compare this information with other information we have about you, including information about what you have purchased and possibly returned.
2.4.1 the purpose is to be able to manage your membership and provide you with the services and offer you the benefits associated with the membership of the customer club, as well as to take care of our interest in being able to send newsletters and carry out targeted marketing.
2.4.2 The legal basis for processing is Article 6 (1) of the EU Personal Data Regulation. XNUMX, letters b and f. At registration, you will be asked to give separate consent to electronic marketing.
- Recipients of Personal Information
3.1 Information about your name, address, e-mail, telephone number and order number and specific delivery requests are passed on to GLS or a carrier who delivers the purchased goods to you. When purchasing non-stocked goods, the mentioned information can be passed on to the manufacturer or seller of the product in question, who in that case will be responsible for the delivery.
3.2 Information may be left to external partners who process the information on our behalf. We use external partners for, among other things, technical operation and improvements of the Website, distribution of newsletters and targeted marketing, including retargeting, as well as for your assessment of our company and products. These companies are data processors and under our instruction and process data for which we are data responsible. The data processors may not use the information for any purpose other than fulfilling the agreement with us, and are subject to confidentiality about this. We have entered into written data processor agreements with all data processors that process personal data on our behalf.
3.3 Two of these data processors, Google Analytics v / Google LLC. And Facebook Inc. is established in the United States. The necessary guarantees for the transfer of information to the USA are secured through the data processor's certification under the EU-US Privacy Shield, cf. EU Personal Data Regulation Art. 45.
3.3.1 copy of Google LLC certification can be found here: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active.
3.3.2 copy of Facebook Inc.'s certification can be found here: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active.
- Your rights
4.1 In order to create transparency regarding the processing of your information, we, as the data controller, must inform you of your rights.
4.2 The right of access
4.2.1 You are at all times entitled to request information from us about, among other things, what information we have registered about you, what purpose the registration serves, what categories of personal information and recipients of information that may. may be, as well as information on where the information comes from.
4.2.2 You have the right to receive a copy of the personal data that we process about you. If you want a copy of your personal information, you must send a written request to firstname.lastname@example.org. You may be asked to document that you are who you pretend to be.
4.3 The right to rectification
4.3.1 You have the right to have incorrect personal information about yourself corrected by us. If you become aware that there are errors in the information that we have registered about you, you are encouraged to contact us in writing so that the information can be corrected.
4.3.2 Information that we have collected in connection with your registration with our customer club, you have the opportunity to correct via log-in to your user profile.
4.4 The right to delete
4.41 In certain cases, you have the right to have all or some of your personal data deleted by us, eg if you revoke your consent and we have no other legal basis for continuing the processing. To the extent that continued processing of your information is necessary, eg for us to comply with our legal obligations, or for legal claims to be established, asserted or defended, we are not obliged to delete your personal information.
4.5 The right to limit the treatment to storage
4.5.1 In certain cases, you have the right to have the processing of your personal data limited to only storage, eg if you believe that the information we process about you is incorrect.
4.6 The right to data portability
4.6.1 In certain cases, you have the right to have personal information that you have provided to us provided in a structured, commonly used and machine-readable format and have the right to transfer this information to another data controller.
4.7 Right of objection
4.7.1 You have the right at any time to object to our processing of your personal data, with a view to direct marketing, including the profiling carried out in order to be able to target our direct marketing.
4.7.2 You also have the right at any time, for reasons relating to your personal situation, to object to the processing of your personal data, which we carry out on the basis of our legitimate interests, cf. pkt. 2.1 and 2.3.
4.8 The right to withdraw consent
4.8.1 You have the right at any time to revoke a consent you have given us for a given processing of personal data, including the profiling carried out by you as a member of the customer club. If you wish to revoke your consent, please contact us at email@example.com.
4.9 The right to complain
4.9.1 You have at all times the right to submit a complaint to the Danish Data Protection Agency, Borgergade 28, 5, 1300 Copenhagen K about our processing of your personal data. 45 33.
- Deletion of personal data
5.1 Information collected about your use of the Website, cf. pkt. 2.1. deleted at the latest when you have not used the Website for 1 year.
5.2 Information collected in connection with your subscription to our newsletter will be deleted when your consent to the newsletter is withdrawn, unless we have another basis for processing the information.
5.3 Information collected in connection with purchases you have made on the Website, cf. pkt. 2.2 will in principle be deleted 3 years after the end of the calendar year in which you have made your purchase. However, information can be stored for a longer period of time if we have a legitimate need for longer storage, eg if it is necessary for legal claims to be established, asserted or defended, or if storage is necessary for us to meet legal requirements. Accounting material is stored for 5 years until the end of a financial year to meet the requirements of the Accounting Act.
5.4 Information that we have collected in connection with your registration to and during your membership of our customer club, cf. pkt. 2.4, we will automatically delete: a) if you have not logged in to your user profile for 3 years, b) if you deactivate (suspend) your membership to our customer club and do not reactivate it within the next 3 years, or c) if you unsubscribe you your membership to our customer club.
6.1 We have implemented appropriate technical and organizational security measures against the accidental or unlawful destruction, loss, alteration or deterioration of personal data and against the disclosure or misuse of unauthorized persons.
6.2 Only employees who have a real need to access your personal information in order to perform their work have access to it.
7.1 LS Retail ApS is data responsible for the personal data collected via the Website.
7.2 If you have any questions or comments about this Personal Data Policy or would like to make use of one or more of your rights described in section 4, you can contact:
LS Retail ApS
Tel. no .: 3699 7946
- Changes in the Personal Data Policy
8.1 If we make changes to the Personal Data Policy, you will be informed of this on your next visit to the Website.
8.2 If you have signed up for our customer club, you will be informed of the changes in the policy by sending information to your registered e-mail address.
9.1 This is version 1.00 of Kasia Lilja Studio's personal data policy dated 22 / 5-2018