WHAT PERSONAL DATA WE COLLECT AND WHY AND LEGAL BASIS
We collect personal data in the following ways:
a. Active collection
Active collection means personal data you provide to us when you sign up for an account with us. We may ask you to provide us with your name, your surname, your email address and other limited amounts of personal data. We process such personal data for the purpose of providing our services to you and to communicate with you regarding the services. Providing such personal data is voluntary. However, without providing such personal data, you will not be able to sign up for an account. We will further use this personal data to optimize our products, learn more about our customers, including to build a database of interested consumers who can help us finalize and customize our products, and identify potential early adopters.
We do not collect any credit card or other payment card data directly from you via the Platform. Instead we have arrangements with a number of third party payment gateway providers to process your payments on our behalf. Any card data you provide through interacting with the Platform is submitted to the payment gateway provider you select to make your payment through.
For EEA data subjects: The legal basis for the processing of the above personal data relating to active collection in some cases will be the contract on the use of the Platform concluded with you. The legal basis for the processing of the above personal data in some cases will be our legitimate interest, which is the use of personal data to develop our products and our business. We have assessed in a balancing test that the processing is necessary to achieve our aforementioned legitimate interests and that our legitimate interests are not overridden by your interests or your fundamental rights and freedoms.
We will also use your personal data to send you email and other marketing messages about our products. The personal data we collect allows us to keep you posted on our latest product announcements. If the law requires us to do so, we will first seek your consent before sending you marketing messages.
For EEA data subjects: We will only send you marketing messages when you have consented to receive them. The legal basis for the processing of such personal data is consent.
b. Passive collection
Passive collection means : information, which may include personal data, which is automatically collected as you navigate through and interact with the content on the Platform, as well as install information on your Device (such as cookies).
The purpose of passively collecting your information is to understand the visitors’ behavior and engagement to different areas of the Platform, along with to improve the overall customer experience.
Through the tracking code embedded in our Platform, the information, which may include personal data, collected includes:
i. Device-specific data
The following information may be collected through your Device and browser:
- Your Device’s IP address (collected and stored in an anonymized format)
- Device screen size
- Device type (unique device identifiers) and browser information
- Geographic location (country location only)
- Preferred language used to display the web page
ii. Log data
Our servers automatically record information that includes:
- Referring domain
- Pages visited
- Geographic location
- Preferred language used to display the web page
- Date and time when platform pages were accessed
We do not currently respond to “do not track” signals in browsers; we are trying to provide a customized experience. The Platform uses “cookies“ to collect information, which may include personal data including standard internet log information and details of your behavioral patterns upon visiting our Platform. We do this to provide you with a better experience, identify preferences, diagnose technical problems, analyze trends and to improve the Platform. “Cookies” are small data files transferred onto computers or devices by websites for record-keeping purposes and to enhance functionality on the Platform.
For EEA data subjects: The legal basis for the automatic collection of personal data listed above are our legitimate interests which are the following: to monitor and maintain the performance of the Platform and to analyze trends, usage and activities in connection with our Platform, to provide a better experience for you, to identify preferences, to diagnose technical problems and to analyze trends and to improve the Platform. We have assessed in a balancing test that the processing is necessary to achieve our aforementioned legitimate interests and that our legitimate interests are not overridden by your interests or your fundamental rights and freedoms. Providing such personal data is voluntary.
iv.Third Party Services
We use a variety of services hosted by third parties, such as Google Analytics, Clicky and Hotjar. The cookies that we use on our platform are detailed in the following link. Please click here to read.
WHAT WE COLLECT FROM OTHER INTERACTIONS WE HAVE WITH YOU AND FROM THIRD PARTIES
To the extent you have consented to us doing so, we may combine personal data you give us with other personal data we hold about you from other sources, transactions and communications. This may include personal data obtained from our stores, direct mail, catalogs, events, products and applications, or other interactions. To the extent you have consented, we may also combine that personal data with data that is publicly available and data from third parties. We also collect personal data about gift recipients provided by the giver.
For EEA data subjects: The legal basis for the combination of such personal data is your consent.
SHARING PERSONAL DATA
a. Corporate Group
We may provide your personal data to our holding company and affiliates, some of which may be outside the European Union. The access is limited to colleagues with a need to know.
For EEA data subjects: The legal basis for the respective transfer of your personal data is our legitimate interests. Our legitimate interests are the transmission of personal data within the group of companies for internal administrative and support purposes. We have assessed in a balancing test that the processing is necessary to achieve our aforementioned legitimate interests and that our legitimate interests are not overridden by your interests or your fundamental rights and freedoms.
b. Service Providers
We may transfer your personal data to service providers to conduct our business. For example, they may handle data management, email distribution, market research, information analysis, and promotions management, acting as data processor. We may also share your personal data to administer features (e.g. music download, race registration, or workout routine). Those external service providers will be subject to contractual obligations to implement appropriate technical and organizational security measures to safeguard your personal data and to process the personal data only as instructed. All credit card or other payment card data you supply through the Platform is transmitted to the third party payment gateway provider you select.
c. By Law Or To Protect Rights
For EEA data subjects: The legal basis for such processing is compliance with a legal obligation to which we are subject or our legitimate interests, such as exercise or defense of legal claims. We have assessed in a balancing test that the processing is necessary to achieve our aforementioned legitimate interests and that our legitimate interests are not overridden by your interests or your fundamental rights and freedoms.
d. Business Transfers
Your personal data may be transferred to a third party as a part of our business assets in a sale of a part or all of our business. If this should happen, notice of the transfer will be provided by posting to the Platform or other form of communication.
For EEA data subjects: The legal basis for the transfer may be your consent, the performance of a contract, the pursuit of legitimate interests, or other applicable legal bases.
SHARING – YOU CHOOSE
For EEA data subjects: The legal basis for sharing this personal data is your consent.
PROTECTING THE PERSONAL DATA
Security Measures: We use a variety of security measures, including encryption and authentication tools, to help protect your personal data. All credit card or other payment card data you supply through the Platform is transmitted to the selected third party payment gateway provider on an SSL encrypted basis.
GENERAL DATA PROTECTION REGULATION
DISCLOSURES FOR EEA DATA SUBJECTS
The below sections set out rights and other matters specific to EEA data subjects.
INTERNATIONAL DATA TRANSFER
The personal data that we collect or receive about you may be transferred to and processed by recipients who are located inside or outside the European Economic Area and which do not provide for an adequate level of data protection. The countries that are recognized to provide for an adequate level of data protection from an EU law perspective are Andorra, Argentina, Canada, Switzerland, Faeroe Islands, Guernsey, the State of Israel, Isle of Man, Jersey, New Zealand and the Eastern Republic of Uruguay. Recipients in the US may partially be certified under the EU-U.S. Privacy Shield and thereby deemed to provide for an adequate level of data protection from an EU law perspective. To the extent your personal data is transferred to countries that do not provide for an adequate level of data protection from an EU law perspective, we will base the respective transfer on appropriate safeguards, such as standard data protection clauses adopted by the European Commission. You can ask for a copy of such appropriate safeguards by contacting us as set out in Section “CONTACT US”. The access is limited to recipients with a need to know.
KEEPING YOUR PERSONAL DATA
You can modify or delete your profile within certain of our services, through your account. Your information previously posted may still be publicly viewable. We may keep information and content in our backup files and archives. Your personal data will be retained as long as necessary to provide you with the services requested. When we no longer needs to use your personal data to comply with contractual or statutory obligations, we will remove it from our systems and records and/or take steps to properly anonymize it so that you can no longer be identified from it, unless we need to keep your personal data, including if we need to keep your personal data to comply with legal or regulatory obligations to which we are subject, e.g. statutory retention periods and usually contain retention periods, or if we need it to preserve evidence within the statutes of limitation.
If you have declared your consent for any personal data processing activities, you can withdraw this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal.
Pursuant to applicable data protection law you may have the right to: request access to your personal data, request rectification of your personal data; request erasure of your personal data, request restriction of processing of your personal data; request data portability, and object to the processing of your personal data. Please note that these aforementioned rights might be limited under the applicable national data protection law. For further information on these rights, please refer to Section “YOUR RIGHTS IN DETAIL”.
You also have the right to lodge a complaint with a data protection supervisory authority. To exercise your rights please contact us as stated in Section “CONTACT US”.
YOUR RIGHTS IN DETAIL
a. Right of access
You may have the right to obtain from us confirmation as to whether or not personal data concerning you is processed, and, where that is the case, to request access to the personal data. The access information includes – inter alia – the purposes of the processing, the categories of personal data concerned, and the recipients or categories of recipients to whom the personal data have been or will be disclosed. However, this is not an absolute right and the interests of other individuals may restrict your right of access.
You may have the right to obtain a copy of the personal data undergoing processing. For further copies requested by you, we may charge a reasonable fee based on administrative costs.
b. Right to rectification
You may have the right to obtain from us the rectification of inaccurate personal data concerning you. Depending on the purposes of the processing, you may have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
c. Right to erasure (“right to be forgotten”)
Under certain circumstances, you may have the right to obtain from us the erasure of personal data concerning you and we may be obliged to erase such personal data.
d. Right to restriction of processing
Under certain circumstances, you may have the right to obtain from us restriction of processing your personal data. In this case, the respective data will be marked and may only be processed by us for certain purposes.
e. Right to data portability
Under certain circumstances, you may have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you may have the right to transmit those data to another entity without hindrance from us.
f. Right to object
If the processing of your personal data is based on legitimate interests, you may have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data by us and we can be required to no longer process your personal data.
Moreover, if your personal data is processed for direct marketing purposes, you have the right to object at any time to the processing of personal data concerning you for such marketing, which includes profiling to the extent that it is related to such direct marketing. In this case, your personal data will no longer be processed for such purposes by us.