Privacy statement - Embrosa

Version March 2019

Introduction

Embrosa takes your privacy very seriously and shall process and use your personal data in a secure way. In this Privacy Statement we will explain which data we process, with whom we share the data, and why we share the data. In addition, the Privacy Statement provides more information about your rights with regard to our processing of your personal data. Please read this Privacy Statement carefully. Should you have any questions, please contact us at support@embrosa.com.

Who is Embrosa?

Embrosa is the private limited company (besloten vennootschap) Embrosa, with its registered office in (3584 BN) Utrecht at Euclideslaan 60, listed in the Commercial Register of the Dutch Chamber of Commerce under number 66026334. Embrosa is the controller with regard to the processing of your personal data by Embrosa.

Privacy

Our database is in the European Union. However, please take into account that your personal data is shared with Brands which send content or information to you. Processors of these Brands may also have access to your data. Many Brands for which we deliver content are located outside the European Union. We cannot check if every Brand complies with the GDPR. If you want to make sure that your personal data is processed according to the GDPR or similar regulations, you need to check the privacy policy of the Brands that you want to receive information from, before selecting these Brands in our App. By selecting Brands in our App you explicitly consent to sharing your personal data with these Brands, even if these Brands are located outside the European Union or if their data processing takes place outside the European Union.

Sharing your data with third parties and for commercial purposes

We give Brands (brands, suppliers and/or distributors of brands) access to personal data such as your name, the name of your company, and your location. This enables us to offer you the App at a low price. If you select a Brand in the App and indicate that you wish to receive messages from that Brand, please be aware that we share personal data with this company. If you click on an Advertisement in the App, please be aware that we share personal data with this company. By selecting Brands or clicking on Advertisement in the App you explicitly consent to sharing your personal data with these Brands. We may use your personal data for commercial purposes, e.g., to inform you about our services or relevant products and services of carefully selected organizations. In this case you will be informed either via the App or your registered email address. Your personal data are also used for market research and for the optimization of our services. In this context, your personal data is anonymized and cannot be traced back to you.

Accessing, changing or deleting your personal data

At any time you may request us to give access to your personal data or to delete your personal data. It is possible that you only want to stop using the App. If this is the case, you may choose for certain Brands to keep your data because you sell their products. Since we cannot be certain about this, you are responsible for the deletion of your data stored by Brands. You will need to request the individual Brands to delete your personal data.

How does Embrosa use your personal data?

Underneath you will find an overview of the purposes for the processing of your personal data. You will also find a specification of which data Embrosa uses for that specific purpose, the legal justification, and the amount of time Embrosa keeps this data. For clarity’s sake, we have categorized the purposes.

Services, customer management and financial administration

Purpose
Financial administration

Information
Company name, Billing address, Bank details, Outstanding balance

Legal basis
Legal obligation

Storage period
As long as necessary for this purpose


Purpose
Services

Information
Home address, Email, Customer file data, Data necessary to provide the service, Data generated by the service

Legal basis
Necessary for the performance of a contract

Storage period
As long as necessary for this purpose


Purpose
Handling complaints

Information
Home address, Email, Customer file data, Data necessary to provide the service, Data generated by the service

Legal basis
Necessary for the performance of a contract

Storage period
As long as necessary for this purpose


Purpose
Invoicing

Information
Home address, Email, Customer file data, Data necessary to provide the service, Data generated by the service

Legal basis
Necessary for the performance of a contract

Storage period
As long as necessary for this purpose


Purpose
CRM

Information
Name, Username, Email, Location, Order history, Social media account, Browser, OS, User ID, Phone, Profile photo

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Job application

Information
Name, Username, Email, Location, Order history, Social media account, Browser, OS, User ID, Phone, Profile photo

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Marketing

Purpose
Direct marketing

Information
Name, Email, Phone, Online behaviour, Interest in a product, Social media account, User ID, Order history, Billing address

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Affiliate marketing

Information
Name, Email, Phone, Online behaviour, Interest in a product, Social media account, User ID, Order history, Billing address

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Newsletter

Information
Name, Email

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Retargeting

Information
Name, Email, Phone, Online behaviour, Interest in a product, Social media account, User ID, Order history, Billing address

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Social media marketing

Information
Name, Email, Phone, Online behaviour, Interest in a product, Social media account, User ID, Order history, Billing address

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Behavioural targeting

Information
Name, Email, Phone, Online behaviour, Interest in a product, Social media account, User ID, Order history, Billing address

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Loyalty program

Information
Name, Email, Phone, Online behaviour, Interest in a product, Social media account, User ID, Order history, Billing address Legitimate interests

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Website

Purpose
Website analytics

Information
Online behaviour, Location

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
A/B testing

Information
Online behaviour, Location

Legal basis
Legitimate interests

Interest concerned
Commercial interests

Storage period
As long as necessary for this purpose


Purpose
Account

Information
Name, Email, Username, User ID, Message content

Legal basis
Necessary for the performance of a contract

Storage period
As long as necessary for this purpose


Purpose
Chat feature

Information
Name, Email, Username, User ID, Message content

Legal basis
Necessary for the performance of a contract

Storage period
As long as necessary for this purpose


Security and fraud prevention

Purpose
Data security

Information
Name

Legal basis
Necessary for the performance of a contract

Storage period
As long as necessary for this purpose


How did we obtain your personal data?

Embrosa has obtained your data because you have provided this data to us, and because Embrosa has obtained your information from third parties. These third parties are: common sources like the commercial register and others.

What are your rights?

Under the European General Data Protection Regulation you have a number of rights with regard to your data and the processing thereof:

Access

You may access your personal information and make any necessary changes in your account. If you would like to see which personal data Embrosa has obtained about you, you may exercise your right of access by submitting a request to Embrosa.

Making changes

If you wish to make changes to the personal information that you have seen as a result of a request for access and you are unable to make the changes yourself in your account, you may request that Embrosa makes these changes for you. You may request that Embrosa modifies, corrects, supplements, erases or shields your information.

Restriction of processing of personal data

You also have the right, under certain conditions, to ask Embrosa to restrict the processing of your personal data.

Right to object

If processing of your data takes place on the grounds of ‘legitimate interest’ by Embrosa or a third party, you have the right to object to that processing.

Portability of data

You have the right to obtain your personal data from Embrosa. Embrosa will provide this in a structured and commonly used format, which can easily be opened using commonly used digital systems.

When the legal basis for a particular processing is your explicit consent, you have the right to withdraw that consent. This does not affect past processing, but does mean that we will no longer be allowed to process this data in the future. It may also result in Embrosa no longer being able to provide you with certain services.

Response from Embrosa

A request can be sent to support@embrosa.com. Embrosa will comply with your request as soon as possible and in any case no later than one (1) month after Embrosa has received such a request. If Embrosa rejects your request, we will indicate in our reply why the request was rejected.

Recipients of your personal data

Your data may be transmitted to:

  • Data processors
  • Parties that are involved in the execution or fulfilment of an agreement between you and Embrosa
  • Brand owners, distributors, suppliers and resellers of products our users sell

It is possible that Embrosa is required to submit your data to a third party, for example to fulfil a legal obligation.

Transfer to third countries or international organisations

It may be necessary, for instance for technical and operational reasons, to transfer your (personal) data to affiliates of Embrosa located outside the European Economic Area. Due to the possibility that the regulations in the area of privacy protection do not offer the same protection as within the European Economic Area, Embrosa will use the Privacy Shield or the EU Model Clauses to protect your privacy as much as possible. If that is not possible, Embrosa will ask your consent to transfer your (personal) data to countries that do not maintain an adequate protection level. You may withdraw your consent at any time.

Wat zijn cookies en hoe gebruikt Embrosa ze?

Cookies are small pieces of (text) information that are sent to your browser when you visit the website of Embrosa and then stored on the hard disk or in the memory of your device. The cookies placed via Embrosa’s website cannot damage your device or the files stored on it. With ‘cookies’, we also mean comparable techniques collecting information, such as device fingerprinting. You can read our Cookie Statement here.

Can changes be made to this Privacy Statement?

This Privacy Statement is subject to changes. We therefore advise you to regularly read the Privacy Statement for any such changes.

Questions, remarks, and complaints

If you have any questions regarding this Privacy Statement or the way in which Embrosa uses your data, you can send an e-mail to support@embrosa.com. If you have a complaint about the way your data is processed, please send an e-mail to support@embrosa.com. Furthermore, you always have the right to contact the competent national data protection authority. In The Netherlands, this is the ‘Autoriteit Persoonsgegevens’.