PRIVACY POLICY

PRIVACY POLICY

In ECCO we respect your privacy and therefore all companies within the ECCO group of companies (“ECCO Affiliates”) are committed to protect information that identifies or is capable of identifying an individual (“personal data”), which it collects, uses and/or has access to.

How personal data is collected, used and shared depends on which ECCO Affiliates you interact with, and how.

With this Privacy Policy we want to ensure that you receive adequate information about our collecting and processing of your personal data, including such information we are obliged to inform you about according to applicable personal data protection regulation incl. the EU Regulation No. 2016/679 the General Data Protection Regulation (“GDPR”).

This Privacy Policy may be supplemented by other information received from us or another ECCO Affiliate and other terms and conditions applicable to our websites, or which you have agreed to as part of interacting with us or another ECCO Affiliate.

Your comments and feedback are always welcome.

List of Content

1. OUR CONTACT DETAILS
1.1. Identity of the Controller(s)
1.2. Our Contact Details
1.3. Contact details for the Data Protection Officer

2. HOW TO USE YOUR PERSONAL DATA
2.1. When signed up for Newsletters
2.2. When visiting our ECCO Stores
2.3. When contacting us through Customer Care etc.
2.4. When participating in competitions and surveys etc.
2.5. Profiling for marketing purposes

3. HOW WE SHARE YOUR PERSONAL DATA WITH OTHERS
3.1. Categories of Recipients
3.2. Transfer of data to third countries

4. HOW WE RETAIN AND DELETE YOUR DATA

5. YOUR RIGHTS AND HOW TO WITHDRAW CONSENTS AND UNSUBSCRIBE
5.1. The right to access
5.2. The right to rectification
5.3. The right to erasure
5.4. The right to restriction of processing
5.5. The right to data portability
5.6. The right to object
5.7. The right withdraw consents
5.8. The right to complaint to data protection supervisory authority

6. LINKS TO OTHER WEBSITES

7. CHANGES TO THIS PRIVACY POLICY

PLEASE READ THIS PRIVACY POLICY CAREFULLY 

1. OUR CONTACT DETAILS

1.1. Identity of the Controller(s)

Unless otherwise specified elsewhere, the legal entity being responsible for the collection and processing of your personal data under this Privacy Policy (the “Controller”) is:

ECCO Distributors DAC
Unit 8 Blarney Business Park
Blarney
Co. Cork
Ireland

(In this Privacy Policy referred to as “we”, “us” and “our”)

1.2. Our Contact Details

If you have any questions or need to get in contact with us we urge you to contact us through our Customer Care representatives by; 

E-mail: info@eccoirl.com 
Phone: 00353214382382
Letter: ECCO Distributors DAC, Unit 8 Blarney Business Park, Blarney Co. Cork, Ireland attn. Customer Care

1.3. Contact details for the Data Protection Officer

Our appointed Data Protection Officer can be contacted either by;

E-mail: legal@ecco.com
Phone: +45 7491 1733
Letter: ECCO Holding A/S, Legal Department, Industrivej 5, 6261 Bredebro, Denmark attn.: DPO

2. HOW WE USE YOUR PERSONAL DATA

When you interact with us we will collect personal data about you, and use it for various purposes, such as enabling you to make use of our various services, including signing up for Newsletters, contacting our Customer Care representatives etc. We also use your personal data to evaluate and assess your personal interests and preferences in order improve our services and offer you services better customized to your interests and preferences.

If you are asked to provide information, then it is optional for you to disclose such information. The information might, however, be needed for statutory, contractual or practical reasons. We will always clearly indicate whether the information is mandatory. If you refrain from disclosing information which we deem as mandatory, as a consequence it may be that we will not be able to provide you with the services you have requested (e.g. signing up for a newsletter).

To help personalise and continuously improve our services and communication with you, for instance through our newsletters, we may upon occasion ask you for information on your personal interests, demographic data or your experience of our products and services. This supplementary information is always voluntary, but we appreciate your support in providing it.

How we collect and use your personal data depends on how you interact with us, and which services you make use of.

We, like all other ECCO Affiliates, strongly believe in the protection of the personal data in our custody and control, and thus we have implemented what we believe are appropriate technical and organisational security measures to protect this personal data against unauthorized or unlawful processing and against accidental loss, destruction or damage.

Below you can read more about how we collect and process your personal data in different situations, including the general categories of personal data being processed; the source of the personal data that we do not directly obtain from you; the purposes for which personal data is being processed; and the legal basis for the processing.

2.1. When signed up for newsletters.

You have the opportunity to sign up to receive information by e-mail about ECCO’s products (shoes, bags and related accessories) services, contests and promotions from us and other ECCO Affiliates (“Newsletters”).

We will only send you newsletters and other marketing material, if you have specifically consented to receive newsletters from us.

If you sign up to receive Newsletters from us then you will be asked to provide certain basic information about yourself. The mandatory personal data includes your first and last name and e-mail address (“Newsletter Registration Data”), which will be used for the purpose of your registration, checking the validity of the e-mail and providing you with relevant Newsletters. We cannot sign you up for Newsletters, unless you provide us with the mandatory information.

We may also give you the opportunity to provide us with other supplementary data other than the data, which we clearly have indicated as mandatory such as gender, shoe size and phone number. It is your own choice whether you provide such supplementary data to us. If you provide us with the supplementary data, it will help us improve our services and offerings to you.

The Legal basis for sending you Newsletters is GDPR art. 6(1) a) namely the consent you have granted, when signing up to receive Newsletters.

You can always withdraw from a consent to receive Newsletters and unsubscribe from an e-mail or SMS list by following the instructions in any e-mail, SMS or other communication you receive from us. Please also refer to SECTION 5 (YOUR RIGHTS AND HOW TO WITHDRAW CONSENTS AND UNSUBSCRIBE).

Our Newsletters contain so-called tracking pixels. A tracking pixel is a miniature graphic embedded in such e-mails, which are sent in HTML format to enable log file recording and analysis. This allows a statistical analysis of the success or failure of online marketing campaigns. Based on the embedded tracking pixel, we may see if and when an e-mail was opened by the recipient, and which links in the e-mail were called up by the recipient (“Newsletter-Tracking Data”). Such Newsletter-Tracking Data are used by us to perform general marketing research and to optimize the distribution and use of Newsletters. The legal basis for this is GDPR art. 6(1) f) our legitimate interest namely in understanding customer behaviour and interests and ensuring effective marketing and advertisement of ECCO product and services.

We will also use the Newsletter Registration Data, supplementary data and Newsletter-Tracking Data to perform general marketing research and to tailor or improve our websites and our service offerings. We may also link this data to other personal data about you for profiling purposes in order to be able to personalize your website experiences, adapt the content of future Newsletters to better suit to your interests and to provide you with personalized offerings. Please also refer to SECTION 2.5 (PROFILING FOR MARKETING PURPOSES).

2.2. When visiting our ECCO Stores

You can visit ECCO Stores operated by us without disclosing any information about yourself.

Electronic Receipt: We offer to provide you with an electronic copy of your invoice by e-mail, when you make a purchase in one of our ECCO Stores. If you make use of this service, then we will keep your e-mail address together with a copy of the invoice to provide you with this service, and later on be able to retrieve a copy hereof in case you need to document a purchase. The legal basis for this is GDPR art. 6(1) f) our legitimate interest namely in providing customers services.

We will not use your e-mail to send you newsletters or other marketing material, unless you specifically have signed up to receive Newsletters.

Having signed up to receive Newsletters: If you have signed up to receive Newsletters, and have chosen to identify yourself in an ECCO Store, e.g. by giving your name, e-mail or phone number then the ECCO Store may on our behalf register information about your visit, such as the date of the visit, details about your purchases, returns etc. (“Offline Transactional Data”). Please also refer to SECTION 2.1 (WHEN SIGNED UP FOR NEWSLETTERS) and SECTION 2.5 (PROFILING FOR MARKETING PURPOSES).

2.3. When contacting us through Customer Care etc.

When you contact us either through one of our Customer Care representatives, or e-mail us with a comment or questions we will retain and use such information in order to respond to your request. You may be asked for further information that identifies you, such as your name, e-mail address, telephone number and country for the purpose of being able to answer your questions etc. We might also request other information, which might be needed to reply to your request. It is always optional for you what information you chose to provide us with. However, please note that in case we do not have sufficient information to process your request, then it might have as a consequence, that we will not be able to accommodate your request. The Legal basis for this processing is GDPR art. 6(1) f) our legitimate interests namely in providing customer services, understanding customer behaviour and interests and establishing, exercising and/or defending legal claims.

We might also request other information including health data, biometric data or special categories of data, if you have made a claim against us, and the information is needed for establishing, exercising or defending the claim. The legal basis for this is GDPR art. 9(1) f) namely that the processing is necessary for establishing, exercising or defending legal claims.

2.4. When participating in competitions and surveys etc.

Occasionally we may give you the opportunity to participate in competitions, surveys etc. If you choose to participate, then we will be asking you to provide us with certain data. Such data depends on the specific competition or survey etc., but might include your name, e-mail, age, gender, family information, shoe size, other demographic information or information about your interests and purchasing preferences. We use this information for running competitions or surveys etc., but we also use it for general market research purposes and to tailor or improve our service offerings. The Legal basis for this is GDPR art. 6(1) a) namely the consent you have granted, when choosing to participate in the competition or survey etc.

We may also link the personal data obtained through your participation in a competition or survey etc. to other personal data about you for profiling purposes as described in SECTION 2.5 (PROFILING FOR MARKETING PURPOSES)

2.5. Profiling for marketing purposes

If you have identified yourself to us, for example by giving us your name, e-mail address or phone number, then we may link the personal data we have collected about you as per above sections, including data collected through the use of the ECCO Groups websites, Newsletter-Tracking Data, names, e-mail, phone number, addresses, information from you concerning demographics, interests and preferences (e.g. gender, birth date, shoe size, family information, product preferences etc.), transactional data, returns and Customer Care interactions. The purpose for this is to perform general marketing research incl. customer analysis and customer segmentation and statistics. Furthermore, we may use the information to evaluate and assess your individual interests and preferences in order to personalize your shopping experiences and optimizing the service you receive from us. The legal basis for this is GDPR art. 6(1) f) our legitimate interests namely in understanding customer behaviour and interests and ensuring effective marketing and advertisement of ECCO product and services.

If you have signed up to receive Newsletters, then we will also use your personal data in order to adapt the content of Newsletters to better suit your interests and to provide you with personalized offerings. The Legal basis for this is GDPR art. 6(1) a) namely the consent you have granted, when signing up to receive Newsletters.

If you disagree and want to object to this, please contact us in accordance with the SECTION 1 (OUR CONTACT DETAILS), and we will then cease to use your personal data for profiling for marketing purposes.

3. HOW WE SHARE YOUR PERSONAL DATA WITH OTHERS

In order to make our services available to you, provide you with requested services and support and in general to operate our business, we will have to disclose and transfer your personal data to other ECCO Affiliates and third parties, such as IT suppliers, marketing agencies, logistics service providers, payment service providers etc.

Please be ensured that we will not sell or rent your personal data to third parties for them to be able to use your personal data for their own direct marketing purposes, unless we have your consent to do so.

When using data processors to process your personal data on our behalf we require, that they only process your personal data in accordance with our instructions. We also require that the data processors signs relevant contracts providing sufficient guarantees to implement appropriate technical and organisational measures in such a manner that the data processing will meet the requirements of the applicable data protection regulation and ensures an appropriate protection of your rights.

In case we disclose your personal data to third parties, who will not be acting as a data processor under our instructions, but as independent data controllers, then we do our best to ensure that they are trustworthy and have implemented appropriate technical and organisational measure to protect your data, and provides us with clear commitments to comply with applicable data protection regulation and not to use the personal data received from us for other purposes, than providing agreed services and making statistical analysis in an anonymised manner.

3.1. Categories of Recipients

The main categories of potential recipients of your personal data are:

A. Service Providers
We may share your personal data with our trusted third party service providers, who, on our behalf, operate, maintain, and/or support our IT systems and IT infrastructure, our websites, perform statistical analysis, sending newsletters, deliver goods you have purchased from us, provide customer support and perform other important services for us.

B. Other ECCO Affiliates
We may disclose your personal data to ECCO Sko A/S with its registered address at Industrivej 5, 6261 Bredebro, Denmark and other companies, which are owned or controlled by ECCO Sko A/S or owns or controls ECCO Sko A/S (“ECCO Affiliates”) in order for them to provide us with relevant services.

C. Legal Successors
A transfer of your personal data to another legal entity may occur as part of a transfer of our business or parts thereof in form of a reorganization, sale of assets, consolidation, merger or similar.

D. Other disclosures
In addition to where you have consented to a disclosure of the personal data or where disclosure is necessary to achieve the purpose(s) for which, it was collected, personal data may also be disclosed in special situations, where we have reason to believe that doing so is necessary to identify, contact or bring legal action against anyone damaging, injuring, or interfering (intentionally or unintentionally) with our rights or property, users, or anyone else who could be harmed by such activities, or otherwise where necessary for the establishment, exercise or defence of legal claims.

3.2. Transfer of data to third countries

The use of service providers and disclosure of your personal data to other ECCO Affiliates and other recipients might imply a transfer of your personal data to countries, which might not have data protection regulation as protective as in your jurisdiction and might not be considered ensuring an adequate level of protection of personal data by the EU Commission or a national data protection authority (so called “unsafe Third Countries”). Such countries include, but is not limited to, the United States, Canada, China, Hong Kong, Macau, Taiwan, Vietnam, Singapore, Thailand, Malaysia, Japan, South Korea, Indonesia, Australia and New Zealand.

We require that all recipients of your personal data provide appropriate safeguards to protect your personal data, when it is transferred to “unsafe Third Countries”, through the adherence to standard data protection clauses adopted by the EU Commission cf. the GDPR article 46(2). Please click here to obtain more information about the standard data protection clauses we use. If the recipient is certified under the US Privacy Shield this is also considered as providing appropriate safeguards to protect your personal data cf. the EU General Data Protection Regulation article 46(2). Please click here to obtain more information about the US Privacy Shield.

If you have any questions, please contact our Customer Care representatives in accordance with SECTION 1 (OUR CONTACT DETAILS).

4. HOW WE RETAIN AND DELETE YOUR DATA

Your personal data will be held by us and kept in a form, which permits identification of you for no longer than is necessary for the purposes for which the personal data is collected and legitimately processed. This implies that we will keep and process your personal data as long as we are providing services to you and also keep it afterwards for as long as would be needed for the settlement of any potential disputes that may be raised afterwards or as long as the law otherwise provides for. Thereafter, we will either delete your personal data or anonymise it so that it no longer can be used to identify you.

We will delete any information, which according to our reasonable assessment seems to be inaccurate or out of date by reason of the time elapsed since it was collected or by reason of any other information in our possession.

If you provide us with a written request, we will also erase or anonymize your personal data without undue delay, unless we have a valid legal ground to continue to keep your personal data. Please also refer to SECTION 5 (YOUR RIGHTS AND HOW TO WITHDRAW CONSENTS AND UNSUBSCRIBE).

5. YOUR RIGHTS AND HOW TO WITHDRAW CONSENTS AND UNSUBSCRIBE

You have certain rights according to the applicable data protection regulation. Some of the rights are rather complex and include exemptions, accordingly you are recommended to read relevant laws and guidance from the regulatory authorities for full explanation of these rights. However, you can find a summary of your rights below in this section.

Summary of your rights:

5.1. The right to access

You have a right to obtain the confirmation as to whether or not your personal data are being processed by us. In addition, you have a right to obtain more detailed information about the personal data kept and the processing undertaken by us and under certain circumstances the right to receive a copy of this personal data.

5.2. The right to rectification

You have the right to have inaccurate personal data about you rectified, and, taking into account the purpose of the processing, to have incomplete personal data completed.

5.3. The right to erasure

In some cases, you have the right to erasure of your personal data without undue delay. Those circumstances include; i) the personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed; ii) you withdraw consent to consent-based processing; iii) the processing is for direct marketing purposes and iv) the personal data has been unlawfully processed. However, there are certain general exclusions of the right to erasure. Those general exclusions include where processing is necessary; i) for the exercising the right of freedom of expression and information; ii) for compliance with legal obligation; or iii) for the establishment, exercise or defence of legal claims.

5.4. The right to restriction of processing

In some cases, you have the right to restrict the processing of your personal data. Where processing has been restricted, we may continue to store your personal data. However, we will only otherwise process it i) with your consent; ii) for the establishment, exercise or defence of legal claims; iii) for the protection of the rights of another natural or legal person; or iv) for reasons of important public interest.

5.5. The right to data portability

To the extent the legal basis for the processing is your consent, and such processing is carried out by automated means, you have the right to receive your personal data in a structured, commonly used and machine-readable format. However, this right does not apply where it would adversely affect the rights and freedoms of others.

5.6. The right to object

You have the right to object to the processing of your personal data on grounds relating to your particular situation, but only to the extent that the legal basis for the processing is that the processing is necessary for i) the performance of a task carried out in the public interest or in the exercise of any official authority vested in ECCO; or ii) the purpose of legitimate interests pursued by us or a third party. In such case we will cease processing the personal data, unless we can demonstrate compelling legitimate grounds for the processing, which override your interests, rights and freedoms or the processing is for the establishment, exercise or defence of legal claims.

You also have the right to object to our processing of your personal data for direct marketing purposes (including profiling for direct marketing purposes). If you make such an objection, we will cease to process your personal data for this purpose.

5.7. The right to withdraw consents

To the extent that the legal basis for the processing is your consent, you have the right to withdraw from that consent at any time.

In case you withdraw from a consent given, then we will cease to process your personal data, unless and to the extent the continued processing is permitted or required according to the applicable personal data regulation or other applicable laws and regulations. The withdrawal from your consent will in no event effect the lawfulness of processing based on consent before its withdrawal.

If you refrain from providing required consents, or later on withdraw from the consents, it might have as a consequence that you may not be able to benefit from some of the service offerings provided by us.

5.8. The right to complaint to data protection supervisory authority

You may always lodge a complaint with your local data protection supervisory authority. The data protection supervisory authority in Ireland is

Data Protection Commissioner
Canal House
Station Road
Portarlington
Co. Laois
R32 AP23
Ireland
www.dataprotection.ie

We do our best to ensure that we protect your personal data, keep you informed about how we process your personal data and comply with the applicable data protection regulation. In case you are not satisfied with the processing and protection of your personal data or the information you have received from us, then we urge you to inform us in order for us to improve. Please also do not hesitate to contact us, if you want to make use of your rights.

Please contact us through the points of contact listed in SECTION 1 (OUR CONTACT DETAILS). Please also provide us with relevant information to take care of your request, including your full name and email address so that we can identify you. We will respond to your request without undue delay.

You can always withdraw from a consent to receive newsletters etc. and unsubscribe from an e-mail list by following the instructions in any e-mail or other communication you receive from us.

6. LINKS TO OTHER WEBSITES

We may provide links to third party websites. These linked websites are not under our control, and we therefore cannot accept responsibility or liability for the conduct of third parties linked to our websites. Before disclosing your personal data on any other website, we advise you to examine the terms and conditions of using that website and its privacy policies.

7. CHANGES TO THIS PRIVACY POLICY

We reserve the right, at our discretion, to add, modify or remove portions of this Privacy Policy in the future to ensure that the information herein provides relevant and adequate information about our collecting and processing of your personal data.

This Privacy Policy may be supplemented by other information received from us or another ECCO Affiliates and other terms and conditions applicable to this website or which you have agreed to as part of interacting with us or another ECCO Affiliate.

If you have consented to receive newsletters and other information from us, we will inform you about any updates to this Privacy Policy through e-mail.

Version 05/2018