1. INTRODUCTION
Your privacy is important to us. This Privacy and Cookie Policy (“Policy”) describes how we handle your personal data. We comply with the applicable laws and regulations, including the General Data Protection Regulation (GDPR). Your personal data will be used solely for the purposes stated in this Policy unless the further processing of your data is compatible with the purposes for which the data were originally processed.
2. PERSONAL DATA WE COLLECT
We collect personal data via our website.
Personal data are any information (data) that relate to an identified or identifiable individual. We collect the following information:
when placing an order on our website, we ask you for your name, address, contact and invoicing details in order to process and deliver your order.
If you create an account on our website, we ask for your name, e-mail address and password so that you can log in and use our services. We request your billing information and delivery address for practical reasons as well; you do not have to re-enter these when placing your next order.
If you write a review expressing your dissatisfaction, we will ask for your details (address, e-mail address and/or telephone number) so we can contact you.
If you contact our customer service by using the chat function, the web form, via phone or by sending an e-mail, we ask for your name, telephone number and/or e-mail address in order to be able to answer your question.
If you wish to receive our newsletter, we ask you for your e-mail address.
When you visit our website, we may ask you to fill in a survey. The main purpose of this inquiry is to improve our services in general. It is not mandatory to fill in a survey in order to be able to order products from our web shop.
When you visit our website, we collect information about your activity on our website in order to personalise your website visits. This information concerns the IP address of your computer, your username, the time of retrieval, and any other data your browser sends to us. We anonymise these data as much as possible. We collect visitor data via the use of cookies. Please refer to the cookie section below (section 5) for more information on the use of cookies.
We collect technical data from our website visitors in order to analyse and improve our services. This includes the measurement and analysis of statistical data and the generation of user statistics. We anonymise these data as much as possible. We collect technical data via the use of cookies. Please refer to the cookie section below (section 5) for more information on the use of cookies.
3. WHY WE COLLECT YOUR PERSONAL DATA: PURPOSES
We only process your personal data for the purposes described above.
We shall ask for your consent before using your personal data for other purposes, unless the further processing of the personal data is compatible with the purposes for which these data were originally processed. If we wish to process your personal data for other purposes, we shall inform you in advance.
We shall not use your personal data to take a decision based on automated processing only, including profiling.
4. LEGAL BASES FOR PROCESSING
Contract
When you place an order, you enter into a contract with us. In order to provide you with our services, we require certain information, such as your name, delivery address, e-mail address and billing information.
Legitimate interests
We may process your data if we have certain legitimate interests in processing your personal data, except if your interest in not having the data processed, is greater.
Optimising our marketing campaigns, personalising our website, and answering your questions are part of our regular business activities. In addition, we would like to keep you informed of our products via a newsletter. We also have an interest in a website with good functionalities tailored to the wishes of the visitors thereof.
The first time you place an order via our website, we ask you to create a user account. We have a legitimate interest to do so, because this will speed up the order process and delivery.
You have the right to object to these processing operations. If so, please contact us. You can reach us by using through the chat function on our website or via e-mail:
[email protected]
In case of an objection, we shall cease processing your personal data unless there are compelling, justifiable reasons because of which our interest in this processing is greater than your interest in stopping the processing. Please note that you may not be able to make the best use of our services if you request us to cease processing.
Consent
In some cases, we ask your consent for processing your data namely
before you write a review or contact our customer service
before we send you a newsletter
You have the right to withdraw your consent at any time. In that case, we will stop processing your data for that purpose. Your personal data shall be deleted unless there are compelling reasons requiring us to retain these data.
You can unsubscribe and/or delete your data by the following means:
Each newsletter contains a link that allows you to unsubscribe with one click.
Contacting us through the chat function on our website or by sending an e-mail to : [email protected]
Please also refer to section 13 below.
Legal obligation
We process personal data by virtue of the law. For example, the storage of personal data in our financial records is required by reason of tax legislation.
5. COOKIES
We use so-called cookies. Cookies are small text files that are stored on a computer or other device such as a tablet or telephone when a visitor views or uses our website.
The purpose of the use of cookies is:
to allow the website to function properly or better by, for example, recognising the visitor and thus providing a better service.
Traffic analysis on a website with the aim of identifying potential improvements.
Recording visitor surfing behaviour in order to provide our visitors with targeted offers.
You can choose either to accept or to refuse marketing cookies. Your settings can be managed via our cookie banner.
Some internet browsers are set to accept cookies by default. You can change the settings of your browser to prevent this. The “Help” function of your browser shows how to block cookies. When you choose this option, it is possible that certain parts of our website do not function optimally or are not accessible anymore. Please note that you can also adjust the settings before saving a cookie.
The data collected by means of cookies will be treated confidentially.
6. META-PIXEL
We use Meta pixels for gathering information that allows us to identify specific target groups.
For more information please refer to the Meta privacy policy: https://www.facebook.com/privacy/policy.
7. GOOGLE ANALYTICS
We use Google analytics for gathering statistical information about our website use with the purpose of creating targeted marketing campaigns.
8. HOW LONG WE STORE YOUR DATA
We store your personal data no longer than necessary for the purpose of data processing.
Newsletter: your name and contact details will be kept for as long as you are interested in receiving our newsletter.
Answering your question(s): your name and contact details are kept for as long as necessary to answer your question(s). Details are stored for a maximum period of 1 year, unless there are other (legal) reasons for retaining the data.
Delivery of our products: we store your data no longer than necessary to deliver the product, to collect the invoice and other administrative purposes. The data for collecting the invoice shall be stored no longer than 2 years, unless there are other (legal) reasons for retaining the data.
Technical reasons, such as website optimisation: if possible, technical data are stored in an anonymous form. The data are used for as long as necessary to optimise the website, but no longer than 6 months.
Surveys: we keep this information – for monitoring the quality of our services - no longer than necessary.
9. HOW WE SECURE YOUR DATA
We have taken technical and organisational measures to protect your personal data against unlawful processing or loss.
These include, inter alia, the following measures:
All persons working with us are bound by confidentiality with regard to your personal data.
We ensure that third parties who have access to your personal data, comply with our security requirements. For this purpose we have entered into contracts with these parties.
Where possible, we pseudonymise your data and encrypt your personal data.
We have created a secure backup environment in order to restore personal data in the event of physical or technical incidents.
We test and evaluate the measures regularly.
Although we cannot prevent third parties from accessing your data or prevent a loss of your data through a breach of our security measures, we shall take all appropriate measures to ensure your personal data are not accessible to unauthorised persons.
10. WHERE YOUR PERSONAL DATA ARE PROCESSED
We process your personal data in the European Union. Any transfer of personal data to countries outside the European Union, will be done in accordance with the provisions of the GDPR. We will take appropriate measures to ensure that the data are protected properly.
11. WHO HAS ACCESS TO YOUR DATA
We shall not provide your personal data to third parties, unless we are required to do so by law or if you have given permission for this.
We use ICT and marketing service suppliers with whom we will conclude a data processing agreement, including confidentially clauses. These parties process personal data upon our explicit instructions only.
12. CHANGES TO OUR POLICY
This Policy may be amended in the event of changes of our products and/or services and/or changes of the law. Any amendment will be published on this website.
In case of substantial amendments that apply to you directly, we shall inform you personally, for example by e-mail. In case of substantial changes of the purposes of our processing and if the processing is subject to your consent, we will ask your consent for these new purposes.
13. HOW CAN YOU EXERCISE YOUR RIGHTS?
You have the following rights under GDPR (articles 15 – 21) and other relevant data protection laws:
Right to request access to your personal data
Right to request the correction of your personal data if these are incorrect (rectification)
Right to request removal of your personal data
Right to request restriction of the processing of your personal data
If we have processed your personal data on basis of our legitimate interests: the right to object to the (further) processing of your personal data (opposition)
If we have processed your data on basis of your consent or the performance of our contract with you: the right to receive data in machine-readable form so that you can transmit those data to another processing controller (data portability)
If you want to receive more information or if you want to exercise one or more of these rights, you can contact us through the chat function on our website or by sending an e-mail to [email protected].
14. OBJECTION AND RIGHT OF COMPLAINT
We process certain personal data based on our legitimate interests (section 4). You have the right to object to the processing of your personal data on this basis at all times. In that case, we shall cease processing your personal data unless there are compelling, justified reasons because of which our processing interest is greater than your interest to stop the processing.
What should you do if you disagree with a decision by us, for example, when we decide not to delete your personal data? In that case you can use one or more of the following options:
Contact us: we shall do our utmost to find a joint solution. You can find our contact information at the bottom of this Policy.
Lodge a complaint: you have the right to lodge a complaint with the Dutch Data Protection Authority: https://www.autoriteitpersoonsgegevens.nl/ or, if you are located in another EU member state, the Data Protection Authority in your country.
Litigate: you have the right to apply to the competent court.
15. CONTACT
The responsibility for processing personal data lies with:
XD Design
Lange Kleiweg 6-28
2288 GK Rijswijk, the Netherlands
February 2023
Privacy Policy Website
1.
Introduction
2.
Personal data we collect
3.
Why we collect your personal data: purposes
4.
Legal bases for processing
5.
Personal data of minors
6.
Cookies
7.
Facebook-pixel
8.
Google analytics
9.
How long we store your data
10.
How we secure your data
11.
Where your personal data is processed
12.
Who has access to your data
13.
Changes to our policy
14.
How can you exercise your rights?
15.
Contact
1.Introduction
Your privacy is important to XD Design® (XD Connects). This Privacy Policy describes how we handle your personal data.
XD Design® (XD Connects) complies with all applicable laws and regulations, including the General Data Protection Regulation (GDPR).
We shall only use your personal data for the purposes stated in this Privacy Policy and for no other purposes unless the further processing of the personal data is compatible with the purposes for which this data was originally processed.
2. Personal data we collect
We collect personal data via our websites www.xindao.com and www.xd-design.com, when you contact us and/or when we send a newsletter.
Personal data is data that can be used to identify your identity. We collect the following information from you in the following way:
- When you place an order on our website, we ask you for your name, address, contact details and invoicing details in order to process the order and deliver your order.
- If you create an account on our website, we ask you for your name, e-mail address and password so that you can log in and use our services. We request your billing information and delivery address so that you do not have to enter it again for your next order.
- If you write a review, we will ask for your e-mail address to contact you if you are not satisfied with your purchase.
- If you contact our customer service by means of the chat function, filling in the web form, or sending us an e-mail, we ask you for your name and e-mail address in order to be able to answer your question.
- If you wish to receive our newsletter, we ask you for your e-mail address in order to be able to send you this newsletter.
- When you visit our website, we will request you if you want to fill in a survey. The main purpose of this inquiry is to improve our services in general. It is not mandatory to fill in this survey to be able to order products from our webshop.
- When you visit our website, we collect information about your visit and click behaviour on our website in order to bring our products to your attention and to personalise your website visit. This concerns the IP address of your computer, your username, the time of retrieval, and any other data your browser sends to us. We try to anonymise this data as much as possible.
- We collect technical data from our website visitors in order to analyse and improve our services. This includes the measurement and analysis of statistical data and the generation of user statistics. We try to anonymise this data as much as possible. We use technical data through the use of cookies.
We only process your personal data for the purposes described above.
We shall ask you for your consent before we use your personal data for other purposes, unless the further processing of the personal data is compatible with the purposes for which this data was originally processed. If we wish to process your personal data for other purposes, we shall inform you in advance.
We may have to share your personal data with authorities or other third parties, for example when there are legal obligations.
We shall not use your personal data to take a decision based solely on automated processing, including profiling.
4. Legal bases for processing
Contract
When you place an order, you enter into a contract with us, which means we require certain information from you, such as your name, e-mail address and billing information.
Justified interests
We may process your data if we have certain legitimate interests in processing your personal data, except if your interest in not having the data processed is greater.
Optimising our marketing campaign, personalising our website, and answering your questions is part of our regular business activities. In addition, we would like to keep you informed about our products via the newsletter as part of our regular business activities. XD Connects also has an interest in a website with good functionality that is tailored to the wishes of the visitors of the website.
You have the right to object to these processing operations. If you wish to object, please contact us. You can reach us via e-mail: [email protected] or call : +31 (0) 70 319 99 85. In that case, we shall cease processing your personal data unless there are compelling, justifiable reasons why our interest in the processing is greater than your interest in stopping the processing. You may not be able to make the best use of our services if you request us to cease processing.
In certain cases, we ask you for permission before we process your data. This concerns the following processing:
- Before you create an account on our website
- Before you write a review or contact our customer service
- Before we send you a newsletter
You have the right to withdraw your consent at any time. In that case your personal data shall be deleted unless there are compelling reasons why we cannot delete your personal data.
You can withdraw your consent in the following way:
- Newsletter: each newsletter contains a link that allows you to unsubscribe with one click.
- Account: you can unsubscribe by sending an e-mail to [email protected]
- Contact customer service: you can contact us to withdraw your consent via tel. no.: +31 (0) 70 319 99 00.
5. Personal data of minors
We only process the personal data of minors if written permission is given by the parent, caregiver or legal representative.
6. Cookies
We use so-called “cookies”. Cookies are small text files that are stored on a computer or other device such as a tablet or telephone when a visitor views or uses our website. Because some cookies can be traced to personal preferences, they fall under personal data.
The purpose of the use of cookies by XD Design® (XD Connects) is:
- To allow the website to function properly or better by, for example, recognising the visitor and thus providing a better service.
- Traffic analysis on a website with the aim of identifying potential improvements.
- Recording visitor surfing behaviour with the aim of being able to make more targeted offers.
You can decide yourself whether to accept or refuse cookies. Most internet browsers are set to accept cookies automatically by default. You can, however, change the settings of your browser to prevent this. The Help function of your internet browser shows how you can block cookies. When you choose this, it is possible that certain parts of the website do not function optimally or are not accessible. It is also possible to adjust the settings so you receive a notification before a cookie is saved.
We do not keep unique personal data. Visitors to our website remain anonymous. Therefore, no information is included in our cookies that can be traced back to individual persons. We deal with the data collected by means of cookies confidentially.
7. Facebook-pixel
We use Facebook pixels for gathering information that allows us to identify specific target groups. For more information about what Facebook is doing with your personal data we refer to the Facebook privacypolicy which can be found at: https://www.facebook.com/about/privacy
8. Google analytics
We use Google analytics for gathering statistic information about our website-use with the purpose of creating targeted marketing campaigns.
9. How long we store your data
We do not store your personal data longer than is necessary for the purpose for which we process the data.
- Newsletter: your name and contact details will be kept for as long as you are interested in receiving our newsletter.
- Answering your questions: your name and contact details are kept for as long as necessary for us to answer your questions.
- Delivery of our products: we do not store your data longer than is necessary to deliver the product, to collect the invoice and for other administrative purposes. We shall not store the data we need to collect the invoice for more than two years, unless there are other (legal) reasons for retaining the data.
- Technical reasons, such as website optimisation: technical data is stored in an anonymous form as far as possible and used as long as necessary to optimise the website, but not longer than six months.
- Survey’s : we keep this information no longer than necessary to monitor our quality of service.
10. How we secure your data
We have taken technical and organisational measures to protect your personal data against unlawful processing or loss.
The security measures we have taken include, but are not limited to, the following measures:
- All persons working with us are bound to maintain confidentiality of your personal data.
- We ensure third parties who have access to your personal data comply with the requirements we set for security. We have entered into contracts with these third parties to protect your data.
- We have created a secure backup environment in order to be able to restore personal data in the event of physical or technical incidents.
- We test and evaluate the set measures regularly.
We cannot completely prevent third parties from accessing your data or prevent a loss of your data through a breach of our security measures, but we shall take all appropriate measures to ensure your personal data is not accessible to unauthorised persons.
11. Where your personal data is processed
We process your personal data in the European Union. Your personal data will not be processed or transmitted to other countries.
12. Who has access to your data
We shall not provide your personal data to third parties, except to the parties described below or if you have given permission for this.
We work with the following external parties who have access to your personal data:
- Maintaining our financial administration via our ERP system (Microsoft Dynamics)
- Facebook, for creating user profiles with the purpose of target marketing.
- Copernica for direct mailings
- Active Ants, for executing all order activities
- Channel Advisor, as a Sales management system
We have entered into a processing agreement with those parties that process your personal data in order to protect your personal data.
We reserve the right to share your personal data with third parties when this is required by law or when this is necessary to protect the interests of you, us or third parties.
13. Changes to our policy
This Privacy Policy may be amended in the event of changes to our products or services, or changes in privacy legislation. We shall publish every amendment on this website. In the case of substantial amendments that apply to you, we shall inform you personally about this by sending you an e-mail for example.
14. How can you exercise your rights?
You have a number of rights under the privacy legislation (including the GDPR). These rights are described in articles 12 - 23 of the GDPR and in related legislation. In any case, you have the following rights with regard to your personal data:
- Right to request access to your personal data
- Right to request the correction of your personal data if it is incorrect (rectification)
- Right to request the removal of your personal data
- Right to request restriction of your personal data
- If we have processed your personal data on the basis of our legitimate interests: the right to object to the (further) processing of your personal data (opposition)
- If we have processed your data on the basis of your permission: right to request the transfer of personal data (data portability)
If you want to receive more information about this or if you want to use one or more of these rights, you can contact us via [email protected]
Objection and right of complaint
We process certain personal data about you based on our justified interests. You have the right to object to the processing of your personal data on this basis at all times. In that case, we shall cease processing your personal data unless there are compelling, justified reasons why our processing interest is greater than your interest to stop the processing.
What should you do if you disagree with a decision by us, for example when we decide not to delete your personal data? You can use one or more of the following options:
- Contact us: in that case we shall try to work with you to find a solution. You can find our contact information at the bottom of this Privacy Policy.
- File a complaint: you have the right to file a complaint with the Data Protection Authority: https://www.autoriteitpersoonsgegevens.nl/
- Request for mediation: you can ask the Data Protection Authority to mediate between you and us: https://www.autoriteitpersoonsgegevens.nl/
- Litigate: you have the right to turn to the competent court to settle the dispute.
15. Contact
The responsibility for processing personal data lies with:
XD Connects B.V.
Verrijn Stuartlaan 1D
2288 EK Rijswijk
E-mail: [email protected]
Telephone: +31 (0)70 319 99 00