PRIVACY POLICY

The CONVOTIS GmbH and its affiliates (collectively, the “Company,” “we,” or “us”) wants you to be familiar with how we collect, use and disclose information. This Privacy Policy describes our practices in connection with information that we collect through:

  • Websites operated by us from which you are accessing this Privacy Policy (the “Websites”);
  • Software applications made available by us for use on or through computers and mobile devices (the “Apps”);
  • HTML-formatted email messages that we send to you that link to this Privacy Policy or other communications with you; and
  • Offline business interactions you have with us.

Collectively, we refer to the Websites, Apps, emails, and offline business interactions as the “Services.”

PERSONAL INFORMATION

Personal Information” is information that identifies you as an individual or relates to an identifiable individual. The Services collect Personal Information, including:

  • Name
  • Postal address (including billing and shipping addresses)
  • Telephone number
  • Email address
  • IP address (we may also derive your approximate location from your IP address)

Collection of Personal Information

We and our service providers collect Personal Information in a variety of ways, including:

  • Through the Services.
    • We collect Personal Information through the Services, for example, when you sign up for a newsletter, register an account to access the Services, visit our stores, attend one of our events, place an order over the phone, contact customer service, or make a purchase.
  • From Other Sources.
    • We receive your Personal Information from other sources, for example:
    • publicly available databases;
    • joint marketing partners, when they share the information with us.

We need to collect Personal Information in order to provide the requested Services to you. If you do not provide the information requested, we may not be able to provide the Services. If you disclose any Personal Information relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.

Use of Personal Information

We and our service providers use Personal Information for the following purposes:

  • Providing the functionality of the Services and fulfilling your requests.
    • To provide the Services’ functionality to you, such as arranging access to your registered account, and providing you with related benefits, special promotions, or customer service.
    • To respond to your inquiries and fulfill your requests, when you contact us via one of our online contact forms or otherwise, for example, when you send us questions, suggestions, compliments or complaints, or when you request a quote for or other information about our Services.
    • To operate the Apps, as well as customer portals and ticket systems.
    • To complete your transactions, verify your information, and provide you with related benefits, special promotions, or customer service.
    • To send administrative information to you, such as changes to our terms, conditions, and policies.
    • To allow you to send messages to another person through the Services if you choose to do so.

We will engage in these activities to manage our contractual relationship with you and/or to comply with a legal obligation.

  • Providing you with our newsletter and/or other marketing materials and facilitating social sharing.
    • To send you marketing related emails, with information about our services, new products and other news about our company.
    • To facilitate social sharing functionality that you choose to use.

We will engage in this activity with your consent or where we have a legitimate interest.

  • Analyzing Personal Information for business reporting and providing personalized services.
    • To analyze or predict our users’ preferences in order to prepare aggregated trend reports on how our digital content is used, so we can improve our Services.
    • To better understand your interests and preferences, so that we can personalize our interactions with you and provide you with information and/or offers tailored to your interests.
    • To better understand your preferences so that we can deliver content via our Services that we believe will be relevant and interesting to you.

We will provide personalized services based on our legitimate interests, and with your consent to the extent required by applicable law.

  • Allowing you to participate in sweepstakes, contests or other promotions.
    • We may offer you the opportunity to participate in a sweepstakes, contest or other promotion.
    • Some of these promotions have additional rules containing information about how we will use and disclose your Personal Information. Please read those additional rules before choosing to participate.

We use this information to manage our contractual relationship with you.

  • Aggregating and/or anonymizing Personal Information.
    • We may aggregate and/or anonymize Personal Information so that it will no longer be considered Personal Information. We do so to generate other data for our use, which we may use and disclose for any purpose, as it no longer identifies you or any other individual.
  • Accomplishing our business purposes.
    • For data analysis, for example, to improve the efficiency of our Services;
    • For audits, to verify that our internal processes function as intended and to address legal, regulatory, or contractual requirements;
    • For fraud prevention and fraud security monitoring purposes, for example, to detect and prevent cyberattacks or attempts to commit identity theft;
    • For developing new products and services;
    • For enhancing, improving, repairing, maintaining, or modifying our current products and services, as well as undertaking quality and safety assurance measures;
    • For identifying usage trends, for example, understanding which parts of our Services are of most interest to users;
    • For determining the effectiveness of our promotional campaigns, so that we can adapt our campaigns to the needs and interests of our users; and
    • For operating and expanding our business activities, for example, understanding which parts of our Services are of most interest to our users so we can focus our energies on meeting our users’ interests.

We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation, and/or based on our legitimate interest.

Disclosure of Personal Information

We disclose Personal Information:

  • To our affiliates for the purposes described in this Privacy Policy.
  • To our third party service providers, to facilitate services they provide to us.
    • These can include providers of services such as website hosting, data analysis, payment processing, order fulfillment, return authorization, fraud prevention, information technology and related infrastructure provision, customer service or related benefits (including special promotions), email delivery, auditing, and other services.
  • To third party sponsors of sweepstakes, contests, and similar promotions.
  • By using the Services, you may elect to disclose Personal Information.
    • On message boards, chat, profile pages, blogs, and other services to which you are able to post information and content. Please note that any information you post or disclose through these services will become public and may be available to other users and the general public.

Other Uses and Disclosures

We also use and disclose your Personal Information as necessary or appropriate, in particular when we have a legal obligation or legitimate interest to do so:

  • To comply with applicable law and regulations.
    • This may include laws outside your country of residence.
  • To cooperate with public and government authorities.
    • To respond to a request or to provide information we believe is necessary or appropriate.
    • These can include authorities outside your country of residence.
  • To cooperate with law enforcement.
    • For example, when we respond to law enforcement requests and orders or provide information we believe is important.
  • For other legal reasons.
    • To enforce our terms and conditions; and
    • To protect our rights, privacy, safety or property, and/or that of our affiliates, you or others.
  • In connection with a sale or business transaction.
    • We have a legitimate interest in disclosing or transferring your Personal Information to a third party in the event of any reorganization, merger, sale, joint venture, assignment, transfer, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings).

OTHER INFORMATION

Other Information” is any information that does not reveal your specific identity or does not directly relate to an identifiable individual. The Services collect Other Information such as:

  • Browser and device information
  • App usage data
  • Information collected through cookies, pixel tags and other technologies
  • Demographic information and other information provided by you that does not reveal your specific identity
  • Information that has been aggregated in a manner such that it no longer reveals your specific identity

The processing of Other Information is described in the separate Cookie Policy, which is available at https://www.convotis.com/en/cookie-policy/. If we are required to treat Other Information as Personal Information under applicable law, we may use and disclose it for the purposes for which we use and disclose Personal Information as detailed in this Policy. In some instances, we may combine Other Information with Personal Information. If we do, we will treat the combined information as Personal Information as long as it is combined.

SECURITY

We seek to use reasonable organizational, technical and administrative measures to protect Personal Information within our organization. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “Contacting Us” section below.

CHOICES AND ACCESS

If you would like to request to access, correct, update, suppress, restrict, or delete Personal Information, object to or opt out of the processing of Personal Information, or if you would like to request to receive a copy of your Personal Information for purposes of transmitting it to another company (to the extent these rights are provided to you by applicable law), you may contact us in accordance with the “Contacting Us” section below. We will respond to your request consistent with applicable law.

In your request, please make clear what Personal Information you would like to have changed or whether you would like to have your Personal Information suppressed from our database. For your protection, we may only implement requests with respect to the Personal Information associated with the particular email address that you use to send us your request, and we may need to verify your identity before implementing your request. We will try to comply with your request as soon as reasonably practicable.

Please note that we may need to retain certain information for recordkeeping purposes and/or to complete any transactions that you began prior to requesting a change or deletion (e.g., when you make a purchase or enter a promotion, you may not be able to change or delete the Personal Information provided until after the completion of such purchase or promotion).

ADDITIONAL INFORMATION REGARDING the European Economic Area (the “EEA”):

As a data subject you have the following rights under the statutory conditions:

  • to check whether and what kind of personal data we hold about you and to request copies of such data (right of access)
  • to request correction, supplementation or deletion of your personal data that is inaccurate or processed in non-compliance with applicable requirements (right to rectification and erasure)
  • to request us to restrict the processing of your personal data (right to restriction)
  • in certain circumstances, to object for legitimate reasons to the processing of your personal data or to revoke consent previously granted for the processing (right to object or withdraw consent)
  • to receive the personal data you provided to us in a structured, commonly used and machine-readable format and to transmit those data to another controller (right to data portability)

We do not process your personal data for the purpose of taking decisions based solely on automated processing, including profiling, which produce legal effects concerning you (Art 22 GDPR).

You also have the right to lodge a complaint with an EU/EEA data protection authority for your country or region where you have your habitual residence or place of work or where an alleged infringement of applicable data protection law occurs. A list of data protection authorities is available at http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080.

RETENTION PERIOD

We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law.

The criteria used to determine our retention periods include:

  • The length of time we have an ongoing relationship with you and provide the Services to you (for example, for as long as you have an account with us or keep using the Services);
  • Whether there is a legal obligation to which we are subject (for example, certain laws require us to keep records of your transactions for a certain period of time before we can delete them); or
  • Whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation or regulatory investigations).

THIRD PARTY SERVICES

This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.

In addition, we are not responsible for the information collection, use, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, RIM, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider, or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with the Apps.

USE OF SERVICES BY MINORS

The Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Information from individuals under 16.

JURISDICTION AND CROSS-BORDER TRANSFER

Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Services you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Information.

ADDITIONAL INFORMATION REGARDING THE EEA:

Some non-EEA countries are recognized by the European Commission as providing an adequate level of data protection according to EEA standards (the full list of these countries is available here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en. For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place adequate measures, such as standard contractual clauses adopted by the European Commission to protect your Personal Information. You may obtain a copy of these measures by contacting us in accordance with the “Contact Us” section below.

SENSITIVE INFORMATION

Unless we request it, we ask that you not send us, and you not disclose, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership) on or through the Services or otherwise to us.

THIRD PARTY PAYMENT SERVICE

The Services may provide functionality allowing you to make payments to the Company using third-party payment services with which you have created your own account. When you use such a service to make a payment to us, your Personal Information will be collected by such third party and not by us, and will be subject to the third party’s privacy policy, rather than this Privacy Policy. We have no control over, and are not responsible for, this third party’s collection, use, and disclosure of your Personal Information.

UPDATES TO THIS PRIVACY POLICY

The “Last Updated” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.

CONTACTING US

CONVOTIS GmbH, located at Neuer Zollhof 3, 40221 Düsseldorf, Germany, is the company responsible for collection, use, and disclosure of your Personal Information under this Privacy Policy.

If you have any questions about this Privacy Policy, please contact us at [email protected], or:

  • CONVOTIS GmbH attn. Data protection officer
  • CONVOTIS Münster GmbH, att: Rüdiger Niemeier, Robert-Bosch-Straße 17a, 48161 Münster, Germany, or telephone: +49 (2533) 28 118 08 100
  • CONVOTIS Services GmbH, att: Katarzyna Umerle, Guglgasse 15/4A/4.OG, 1110 Wien, Austria, or telephone: +43 (1) 7985012

You may also contact our Data Protection Officer (DPO) responsible for your country or region, if applicable:

Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.