This Policy explains how your Personal Data is collected, used, and disclosed by Mabsut Life D.o.o LTD (“ Mabsut ”, “ We ”, “ Us ”). It also tells you how you can access and update your Personal Data and make certain choices about how your Personal Data is used.
This Policy covers both our online and offline data collection activities, including Personal Data that We collect through our various channels such as websites, apps, third-party social networks, points of sales and events. Please note that We combine Personal Data that We collect via one method (e.g. Mabsut website) with Personal Data that We collect via another method (e.g. a Mabsut’s offline event).
If you fail to provide necessary Personal Data to us, We may not be able to provide you with our goods and/or services.
Mabsut has appointed a Data Protection Officer (DPO) to ensure compliance with the requirements as per data Protection Regulation 679/2016/EU. The DPO at Mabsut has direct and immediate connections with the top-level management of Mabsut and remains in an independent position within the corporate structure of Mabsut. Visitors to the corporate Website of Mabsut as well as our perspective and/or existing clients can get in touch with our DPO by electronic mail service to dpo@Mabsutlife.com .
This Policy applies to Personal Data that We collect from or about you, from the following sources:
Mabsut websites . Consumer-directed websites operated by Mabsut, including sites that We operate under our own domains/URLs and mini-sites that We run on third party social networks such as Facebook (“ Websites ”).
E-mail, text and other electronic messages . Electronic communications between you and Mabsut.
Points of Sales . Demonstrators present in third-party physical stores to assist you with the registering of your ordering.
Data from other sources . Third party social networks (e.g. such as Facebook, Google) or market researchers (if feedback not provided on an anonymous basis).
Masbust Customer Relationship Centers . Calls to our Customer Relationship Centers (“ CRC ”).
Depending on how you interact with Mabsut (online, offline, over the phone, etc.), We collect various types of information from you, as described below.
Personal contact information . This includes any information you provide to Us that would allow Us to contact you, such as your name, postal address, e-mail address, social network details, or phone number.
Account login information . Any information that is required to give you access to your specific account profile. Examples include your login ID/email address, screen name, password in an unrecoverable form, and/or security question and answer.
Demographic information & interests . Any information that describes your demographic or behavioral characteristics. Examples include your date of birth, age or age range, gender, geographic location (e.g. postcode/zip code), favorite products, hobbies and interests, and household or lifestyle information.
Technical information about computer/mobile device . Any information about the computer system or other technological device that you use to access one of our Websites or apps, such as the Internet protocol (IP) address used to connect your computer or device to the Internet, operating system type, and web browser type and version. If you access a Mabsut website or app via a mobile device such as a smartphone, the collected information will also include, where permitted, your phone’s unique device ID, advertising ID, geo-location, and other similar mobile device data.
Websites/communication usage information . As you navigate through and interact with our Websites or newsletters, We use automatic data collection technologies to collect certain information about your actions. This includes information such as which links you click on, which pages or content you view and for how long, and other similar information and statistics about your interactions, such as content response times, download errors and length of visits to certain pages. This information is captured using automated technologies such as cookies (browser cookies, flash cookies) and web beacons, and is also collected through the use of third-party tracking. You have the right to object to the use of such technologies, for further details please see Section 3.
Market research & consumer feedback . This includes information that you voluntarily share with Us about your experience of using our products and services.
Consumer-generated content . This refers to any content that you create and then share with Us on third party social networks or by uploading it to one of our Websites or apps, including the use of third-party social network apps such as Facebook. Examples include photos, videos, personal stories, or other similar media or content. Where permitted, We collect and publish consumer-generated content in connection with a variety of activities, including contests and other promotions, website community features, consumer engagement, and third-party social networking.
Third party social network information . This refers to any information that you share publicly on a third party social network or information that is part of your profile on a third party social network (such as Facebook) and that you allow the third party social network to share with Us. Examples include your basic account information (e.g. name, email address, gender, birthday, current city, profile picture, user ID, list of friends, etc.) and any other additional information or activities that you permit the third party social network to share. We receive your third-party social network profile information (or parts of it) every time you download or interact with Mabsut web application on a third party social network such as Facebook, every time you use a social networking feature that is integrated within Mabsut site (such as Facebook Connect) or every time you interact with Us through a third party social network. To learn more about how your information from a third party social network is obtained by Mabsut, or to opt-out of sharing such social network information, please visit the website of the relevant third party social network.
Payment and Financial information . Any information that We need in order to fulfill an order, or that you use to make a purchase, such as your debit or credit card details (cardholder name, card number, expiration date, etc.) or other forms of payment (if such are made available). In any case, We or our payment processing provider(s) handle payment and financial information in a manner compliant with applicable laws, regulations and security standards such as PCI DSS.
Calls to CRC . Communications with a CRC will be recorded or listened into, in accordance with applicable laws, for local operational needs (e.g. for quality or training purposes). Payment card details are not recorded. Where required by law, you will be informed about such recording at the beginning of your call.
Cookies/Similar Technologies . Please see our Cookie Notice to learn how you can manage your cookie settings and for detailed information on the cookies We use and the purposes for which We use them.
Log Files . We collect information in the form of log files that record website activity and gather statistics about your browsing habits. These entries are generated automatically, and help Us to troubleshoot errors, improve performance and maintain the security of our Websites.
Web Beacons . Web beacons (also known as “web bugs”) are small strings of code that deliver a graphic image on a web page or in an email for the purpose of transferring data back to Us. The information collected via web beacons will include information such as IP Address, as well as information about how you respond to an email campaign (e.g. at what time the email was opened, which links you click on in the email, etc.). We will use web beacons on our Websites or include them in e-mails that We send to you. We use web beacon information for a variety of purposes, including but not limited to, site traffic reporting, unique visitor counts, advertising, email auditing and reporting, and personalization.
The following paragraphs describe the various purposes for which We collect and use your Personal Data, and the different types of Personal Data that are collected for each purpose with your consent (where required) . Please note that not all of the uses below will be relevant to every individual.
Our interest and reasons to collect such Personal Data are as follows:
5. DISCLOSURE OF YOUR PERSONAL DATA
In addition to Mabsut or ad-hoc in-country partners (in charge of Mabsut’s operations ) mentioned in the data controllers & contact section (see Section 11), We share your Personal Data with the following types of third-party organization:
Service providers . These are external companies that We use to help Us run our business (e.g. order fulfillment, payment processing, fraud detection and identity verification, website operation, market research companies, support services, promotions, website development, data analysis, CRC, etc.). Service providers, and their selected staff, are only allowed to access and use your Personal Data on Our behalf for the specific tasks that they’ve been requested to carry out, based on our instructions, and are required to keep your Personal Data confidential and secure. Where required by applicable law, you can obtain a list of the providers processing your Personal Data (see Section 11 to contact us).
Credit reporting agencies/debt collectors . To the extent permitted by applicable law, credit reporting agencies and debt collectors are external companies that We use to help Us to verify your creditworthiness (in particular for orders with invoice) or to collect outstanding invoices.
Third party companies using Personal Data for their own marketing purposes . Except in situations where you have given your consent, We do not license or sell your Personal Data to third party companies for their own marketing purposes. Their identity will be disclosed at the time your consent is sought.
In accordance with applicable laws, We will use your Personal Data for as long as necessary to satisfy the purposes for which your Personal Data was collected (as described in Section 4 above) or to comply with applicable legal requirements.
Personal data used to provide you with a personalized experience (see Section 4 above for details) will be kept for a duration permitted by applicable laws.
7. DISCLOSURE, STORAGE AND/OR TRANSFER OF YOUR PERSONAL DATA
We use a variety of reasonable measures (described below) to keep your Personal Data confidential and secure. Please note, however, that these protections do not apply to information you choose to share in public areas such as third-party social networks.
People who can access your Personal Data . Your Personal Data will be processed by our authorized staff or agents, on a need to know basis, depending on the specific purposes for which your Personal Data have been collected (e.g. our staff in charge of customer care matters will have access to your customer record).
Measures were taken in operating environments . We store your Personal Data in operating environments that use reasonable security measures to prevent unauthorized access. We follow reasonable standards to protect Personal Data. The transmission of information via the Internet is, unfortunately, not completely secure and although We will do our best to protect your Personal Data, We cannot guarantee the security of the data during transmission through our Websites/apps.
Measures We expect you to take . It is important that you also play a role in keeping your Personal Data safe and secure. When signing up for an online account, please be sure to choose an account password that would be difficult for others to guess and never reveal your password to anyone else. You are responsible for keeping this password confidential and for any use of your account. If you use a shared or public computer, never choose to have your login ID/email address or password remembered and make sure to log out of your account every time you leave the computer. You should also make use of any privacy settings or controls We provide you in our Website/app.
Transfer of your Personal Data . The storage as well as the processing of your Personal Data as described above require that your Personal Data are ultimately transferred/transmitted to, and/or stored at, a destination outside of your country of residence. We will also transfer your Personal Data to countries outside the European Economic Area (“ EEA ”) including to countries which have different data protection standards to those which apply in the EEA. We (i) have put in place European Commission approved standard contractual clauses to protect your Personal Data (and you have a right to ask Us for a copy of these clauses (by contacting Us as set out below) and/or (ii) will rely on your consent (where permitted by law).
8. ACCESS TO YOUR PERSONAL DATA
Access to Personal Data . Where provided by law, you, your successors, representatives and/or proxies have the right to access, review and request a physical or electronic copy of the information held about you. You also have the right to request information on the source of your Personal Data.
These rights can be exercised by sending Us an e-mail: DPO@mabsutlife.com , attaching a copy of your ID or equivalent details (where requested by Us and permitted by law). If the request is submitted by a person other than you, without providing evidence that the request is legitimately made on your behalf, the request will be rejected.
Please note that any identifying information provided to Us will only be processed in accordance with, and to the extent permitted by applicable laws.
Additional rights (e.g. modification, deletion of Personal Data) . Where provided by law, you, your successors, representatives and/or proxies can (i) request deletion, the portability, correction or revision of your Personal Data; (ii) oppose the data processing; (iii) limit the use and disclosure of your Personal Data; and (iv) revoke consent to any of our data processing activities.
Please note that, in certain circumstances, We will not be able to delete your Personal Data without also deleting your user account. We may be required to retain some of your Personal Data after you have requested deletion, to satisfy our legal or contractual obligations. We may also be permitted by applicable laws to retain some of your Personal Data to satisfy our business needs.
Where available, our Websites have a dedicated feature through which you can review and edit the Personal Data that you have provided. Please note that We require our registered consumers to verify their identity (e.g. login ID/email address, password) before they can access or make changes to their account information. This helps prevent unauthorized access to your account.
We hope that We can satisfy queries you may have about the way we process your Personal Data. However, if you have unresolved concerns you also have the right to complain to competent data protection authorities.
9. YOUR CHOICES ABOUT HOW WE USE AND DISCLOSE YOUR PERSONAL DATA
We strive to provide you with choices regarding the Personal Data that you provide to Us. The following mechanisms give you the following control over your Personal Data:
Cookies/Similar Technologies . You manage your consent via (i) our consent management solution or (ii) your browser so as to refuse all or some cookies/similar technologies, or to alert you when they are being used. Please see Section 3 above.
Advertising, marketing and promotions . If you wish to have your Personal Data used by Mabsut to promote its products or services, you can indicate so through the relevant tick box(es) located on the registration form or by answering the question(s) presented by our Trade demonstrators, CRC or boutique representatives. If you decide that you no longer wish to receive such communications, you can subsequently unsubscribe from receiving marketing-related communications at any time, by following the instructions provided in each such communication. To opt-out of marketing communications sent by any medium, including third-party social networks, you can opt-out at any time by logging into the Websites/apps or third-party social networks and adjusting your user preferences in your account profile by unchecking the relevant boxes or by calling our CRC. Please note that, even if you opt-out from receiving marketing communications, you will still receive administrative communications from Us, such as order or other transaction confirmations, notifications about your account activities (e.g. account confirmations, password changes, etc.), and other important non marketing related announcements.
Personalization (offline and online) : Where required by law, if you wish to have your Personal Data used by Mabsut to provide you with a personalized experience/targeted advertising & content, you can indicate so through the relevant tick box(es) located on the registration form or by answering the question(s) presented by our Trade demonstrators, CRC or boutique representatives. If you decide that you no longer wish to benefit from this, you can opt-out at any time by logging into the Websites/apps and adjusting your user preferences in your account profile by unchecking the relevant boxes or by calling our CRC.
10. CHANGES TO OUR NOTICE
If We change the way We handle your Personal Data, We will update this Notice. We reserve the right to make changes to our practices and this Notice at any time, please check back frequently to see any updates or changes to our Notice.
We are not responsible for events beyond our direct control. We cannot guarantee nor do we represent that there will be error-free performance regarding the privacy of the Information, and we will not be liable for any direct, indirect, incidental, consequential or punitive damages relating to the use or release of the Information.
12. YOUR ACCEPTANCE OF THIS POLICY
By agreeing to the Terms and Conditions during the registration process on the Website, or by continued use of the services, you agree to this Policy and to any changes we may make to this Policy from time to time. We will notify you of any such changes to the Policy by posting the changes on the Website, and you will be required to confirm such changes. Failure to confirm such change will prevent you from continuing using the Website and/or Services. Your only remedy in case in which you do not wish to be bound by such change is to stop using the Website and/or Services and to close your Account.
If you feel the rights to personal data related to you had been infringed by Mabsut Life D.o.o LTD, please get in touch with our DPO at: DPO@mabsutlife.com .
This privacy statement was last revised in May 2018.