LAST UPDATED – March 4, 2022
We are pleased that you have visited our online shop and about your interest in our products. Esprit would like you to feel comfortable when using our websites, and that you do not worry about the confidentiality of your data. Data protection is part of the corporate philosophy of Esprit. Therefore, we consider transparency in the handling of the data of our customers to be extremely important. We would like to inform you below on which personal data we collect, for which purposes we process your personal data and which rights you are entitled to.
Please note that the Esprit’s website is intended for use by adults. If you are under the age of 18, please seek the prior consent from a person with parental responsibility for you for the services on our website. No one under the age of 18 should provide with us any personal data, and we confirm that we do not intend to collect any personal data from those under the age of 18.
The data controllers are:-
· Esprit Retail (Hong Kong) Limited
o Postal Address: 27/F, China United Centre, No. 28 Marble Road, North Point, Hong Kong
· Esprit Retail B.V. & Co. KG
o Postal Address: Esprit Allee 1, 40882 Ratingen, Germany
Our Data Protection Officer can be contacted at email@example.com.
1. HOW WE COLLECT PERSONAL DATA FROM USERS
When you visit our Website, you are not obligated to provide any information to us. Under the PDPO we are the data user for the processing of your Personal Data. We collect Personal Data that you disclose to us when you use the Website or our services through the Website. For example, you may submit information when you make purchases; when you request information; when you register/sign up for our newsletter; when you create and/or log in your online account. Such Personal Data may include your name, address, telephone number, email address, gender, date of birth, credit card information, username and password (for account holder), and other information about you (collectively, "Personal Data"). We then use the Personal Data to create a user profile. In this context we may combine the Personal Data you give us online with other information we hold, as regards transactions and communications collected or processed by any member of the Esprit Group and authorized third party service provider or subcontractors. We also automatically collect certain data about your use of the Website such as log files, cookies, browser type and other computer or device information as described below.
2. PURPOSE OF PROCESSING PERSONAL DATA
We may use data from you for a number of purposes:
· If you decide to become a registered user of our Website, we need to process your data to identify you as a user of the Website and grant you access to its various functionalities, products and services available to you as a registered user. You may cancel your registered user account by contacting us through Customer Service. We hereby inform you that the data we gather regarding your activity, which have been collected through the different channels of the Website and which include your purchases, shall remain linked to your account so that all the information can be accessed together.
· When you place an order via our Website, your Personal Data may be collected, processed and used for the performance and execution of the purchase contract that you executed with us or authorized third party fulfilment service provider Global-e Hong Kong Limited (“Global-e”) on the Website.
o To contact you for updates or informative notices related to the contracted functionalities, products or services, including quality surveys and to be able to establish the degree of customer satisfaction with the provided service.
o To manage payment of the products that you purchase, regardless of the payment procedure used. For example: If on purchasing any of our products through the Website, you opt to activate the functionality of save your payment data and your shipment address for future purchases, where this functionality is available, we need to process the indicated data for activation and development of that functionality. Consent to the activation of this functionality enables your autocompleted payment data to appear in subsequent purchases so that you do not need to introduce them in each new process, and these data will be deemed valid and effective for subsequent purchases. You may change or cancel your payment data at any time through the section on payment information of your Website registered user account.
o To activate the mechanisms necessary to prevent and detect unauthorised uses of the Website (for example, during the purchase and returns process) as well as potential fraud being committed against you and/or against us. If we consider that the transaction may be fraudulent or we detect abnormal behaviour which indicates attempted fraudulent use of our features, products or services, this processing may result in consequences such as the blocking of the transaction or the deletion of your user account.
o To manage potential exchanges or returns after you have purchased and manage requests of availability information for articles, reservations of products through the Website, depending on the availability of such options from time to time.
o For invoicing purposes and to make available to you the tickets and invoices of the purchases you have made through the Website.
o To ensure that you are able to use other available functionalities or services, such as the purchase, receipt, management and use of the Gift Card or of the Gift Voucher.
· Your Personal Data will also be processed to meet requests or applications that you make through the Customer Service channels. We only process the Personal Data that are strictly necessary to manage or resolve your request or application. If you contact us via telephone, the call may be recorded for quality purposes and so that we can respond to your request. If it is available and you choose to communicate with our Customer Service through the chat service of a social network or another collaborator, some of your Personal Data such as your name or username, will be imported from your social network or collaborator account. Also, bear in mind that the data you submit on this service will be available to your social network or collaborator and subject to their privacy policies, therefore we recommend you to review your privacy settings and to read the social network or collaborator privacy policies to obtain more detailed information about their use of your Personal Data when using their services.
· If you have elected to receive direct marketing communications from us, your Personal Data may be used by us to send you information about us, and/or to receive the latest news on Esprit branded promotions and products. We will send you such information by means of e-newsletters, e-mails and by mails or posts. For this purpose, we may process your name, email address, mobile phone number, gender, date of birth and shipping address, and an overview of communications we have sent you. We retain your Personal Data for as long as you wish to receive direct marketing communication from us. You can decide not to receive such communications or updates from us at any time by contacting us or by using the unsubscribe option included in each email.
Your Personal Data may also be used for the following purposes:
· Providing you with customer service and related service in the course of our business, including but not limited to services relating to order, delivery, payment, products change or return and product preference;
· Providing you with the technical and functional management of the Website;
· Providing you with our marketing materials and information related to products, latest offers, sales promotion, upcoming events and discounts;
· Conducting researches, surveys, audits, reviews and analyses of your experience with our services and products;
· Gathering users’ statistics for the purpose of future marketing and promotion and future development of our services and website;
· Meeting disclosure obligations and other requirements imposed by or for the purposes of any laws, regulations, rules, regulations, codes of practice or guidelines (whether applicable in or outside Hong Kong) binding on us including making disclosure to any legal, regulatory, governmental, tax, law enforcement or other authorities;
· Investigating, preventing or stopping fraud and abuse; and
· Book keeping.
3. HOW ARE WE LEGALLY PERMITTED TO PROCESS YOUR DATA
· We process your Personal Data because this is necessary on the terms regulating the use of the Website. In other words, for you to be able to register as a user on the Website, we need to process your personal data, since we would otherwise be unable to manage your registration. We consider we have a legitimate interest to link to your account your purchases and the data collected through different channels of the Website about your activity.
· We process your Personal Data because their processing is necessary for us to make the purchase or services contract with you. Certain processing of data related to the purchase process is activated only because you request or authorise it, as is the case of the storage of payment data for future purchases, where these features are available. In these cases, our processing of your data is supported by your own consent. In addition to this, we process your location data when you provide us your consent in order to offer you specific services through the Website. We consider that we have a legitimate interest to carry out the necessary verifications to detect and prevent potential fraud or fraudulent uses of the Website, for example when you make a purchase or return. We understand that the processing of these data is positive for all the parties involved: for you, as it allows us to put in place measures to protect you against attempted fraud perpetrated by third parties; for us, as it allows us to avoid unauthorised uses of the Website; for all our customers and society, as it also protects their interest by ensuring that fraudulent activities are prohibited and detected when they do occur.
· We consider that we have legitimate interest in answering the requests or queries raised by you through the existing different contact channels. We understand that the processing of these data is also beneficial to you to the extent that it enables us to assist you adequately and answer to the queries you raised. When you get in touch with us, in particular, for the management of incidents related to your order or the product or service acquired through the Website, the processing of your data is necessary to perform the purchase contract. When your request is related to the exercise of your rights on which we inform you below, or to claims on our products or services, we are legally permitted to process your data for compliance with our legal obligations.
· We are legally permitted to process your data for marketing purposes due to the consent that you give us, for example when you accept receiving customized information through multiple channels, when you participate in our customer survey, or when you accept the legal terms and conditions to participate in a promotional action. To offer you personalised services or to show you customised information, whether on our Website or those of third parties, as well as to engage in data enrichment, we consider that we have a legitimate interest to conduct a profiling with the information that we have about you (such as your browsing, preferences or purchase history) and the Personal Data that you have provided us, such as the age range or language, since we understand that the data processing of these data is also beneficial to you because it allows you to improve your user experience and access the information in accordance with your preferences.
· We consider that we have a legitimate interest in analysing the Website usability and the user's satisfaction degree, since we understand that the processing of these data is also beneficial for you because the purpose is to improve the user experience and provide a higher quality service.
4. WHO HAS ACCESS TO YOUR PERSONAL DATA
· You acknowledge and agree that we may engage third-party payment processors (including but not limited to Global-e) for the purpose of processing your payments made via the Website from time to time. The Personal Data, which contains your payment information including but not limited to your credit/debit card number, holder's name and CCV that we collected, will be passed to such payment processors, their affiliates and/or their agents (if necessary) solely for the aforesaid purpose.
· We may share your Personal Data with entities which belong to the Esprit Group (for details on the companies within the Esprit group, please refer to our annual report which may be found at hkexnews.hk), which may reside outside Hong Kong or your home country.
· To facilitate the purposes set out in this Section 4, we may transfer, disclose, grant access to or share your Personal Data with the third parties set out in this Section 4 and you acknowledge that those parties may be based outside Hong Kong and your home country (including in the United States and within the European Union) and that your Personal Data may be transferred to places where the data protection laws are substantially different to, or do not serve the same purposes as the PDPO.
· Where your Personal Data is transferred pursuant to this Section 4, we take steps to ensure that the third party recipient residing outside of Hong Kong or your home country use and process your Personal Data with a standard of protection at least equivalent to the PDPO and, as required, the laws of the jurisdiction where you reside. We also require that such third parties keep your Personal Data confidential.
5. LOG FILES
As with most online websites, we automatically gather non-personally identifiable information and store it in log files through the Website. This information includes IP address (as appropriate, in an anonymous, shortened form), date and time of the request, time zone difference to Greenwich Mean Time (GMT), content of the request (actual page), access status/HTTP status code, data volumes transmitted, website from which the request emanates, browser type or app used, operating system and its interface, language and version of the browser software. We use these information, which does not identify users, to analyse trends, to administer the Website and to gather demographic information about our user base as a whole. We do not link this automatically-collected information to personally identifiable information.
6. SOCIAL MEDIA WEBSITES, PLATFORMS OR CHANNELS
7. PRODUCT REVIEW AND CUSTOMER SATISFACTION SURVEYS
Your opinion is important to us, whether it is about your satisfaction with your shopping experience with us, our products and services overall, or your views and impressions around the fashion world. Therefore, from time to time, we provide customer surveys via our Website where you can express your opinion on various topics. In principle, we allow you to participate anonymously in our customer surveys. Insofar as this is necessary within the framework of the customer survey or you wish us to do so, we will collect your name, surname, telephone number and e-mail address. If you wish, we will use this data so that we can subsequently contact you personally. In any case, we process your IP address when conducting the customer satisfaction survey to enable the connection between your terminal device and the server on which the customer survey is hosted. We also collect data about which end device, operating system and browser you used in order to understand how high the participation rates of the different end devices are and to be able to further optimize our surveys for the respective end devices and browser types. We also collect data on how you interact with our surveys, i.e. how long you stay on individual question pages and on which survey page you end a survey. We use this data to make future surveys even more customer-friendly. For these analyses, we use the collected device data in aggregated form, so that you can no longer be identified as an individual person. Customer satisfaction surveys are carried out by way of order processing via the service provider Qualtrics, which is a subsidiary of SAP.
8. COOKIES ON THE WEBSITE
· Generally, transient cookies – including, in particular, “session cookies” – are automatically deleted when you close your internet browser, or when a session has expired. These cookies store a so-called session ID, with which various enquiries of your internet browser can be allocated to the joint session. In this way, your computer can be recognised again if you return to our Website. The session cookies are as a rule deleted when you log out or close the internet browser. The following data is stored and transmitted via session cookies:
o Language settings;
o Any log-in information;
o Visitor ID; and
o Time stamp with the start and end of the current session.
Each internet browser differs in the type, how it manages the cookie-settings. This is described in the help menu of each internet browser, it is explained to you how you can change your cookie-settings.
You can set your browser so that it does not accept cookies or to notify you when you are sent a cookie so that you have the opportunity to decide whether or not to accept it. However, please note that in the case of the non-acceptance of cookies, the functionality of our Website may be restricted.
· We use the Facebook tag by Meta Platforms, Inc. (formerly known as “Facebook Inc.”) on our Website. Firstly, this tag is for the purpose of conversion tracking, which allows us to understand how our marketing activities work, which serves the purpose of presenting you product information that is even more relevant in future using the social media network Facebook. We also use the “Custom Audiences” remarketing function of the Facebook Tag on our Website. This remarketing function serves the purpose of targeting visitors to the Website with interest-based advertising on the social media network Facebook. This tag creates a direct connection to the Facebook server when the website is visited. This tells the Facebook server which of our pages you have visited. Facebook allocates this information to your personal Facebook user account, if you have one. When you visit the social media network Facebook, you will subsequently be shown personalised, interest-based Facebook ads.
· In order to collect statistical data about the use of our Website, and to optimise our advertising so that it is tailored to your interests and with special offers for you, we use technology from Light Reaction. Light Reaction is part of the Xaxis programmatic media group; Xaxis is a company operating globally as part of the GroupM media investment group; GroupM is part of the WPP plc. group.
· We use advertising services belonging to the social media network Pinterest, which is operated by Pinterest Europe Ltd.. In doing so, we book advertisements via what are called pins within Pinterest. If you arrive at one of our advertisements via one of the pins that we have booked, this information will be processed by Pinterest and transferred to us as statistics (conversion). This enables us to obtain a rough idea of how many users have clicked on our pins. However, we do not receive any information that could personally identify the user.
· We use the online advertising program “Google Adwords” and conversion tracking. Google conversion tracking is an analysis service developed by Google. When you click on an ad shown by Google, a conversion tracking cookie is saved on your computer. These cookies have limited validity periods, do not contain personal information and cannot be used to identify you. If you visit certain pages on our Website and the cookie has not yet expired, Google and we can see that you have clicked on the ad and were redirected to this page. Each Google AdWords client receives a different cookie. It is thus ensured that no cookies can be tracked via the websites of AdWords clients.
9. HOW WE PROTECT PERSONAL DATA
We treat the security of your Personal Data seriously. We utilize appropriate administrative, technical and physical safeguards and security measures to protect the Personal Data you provide on this Website against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure or use and any other unlawful forms of processing. The data you enter is automatically encrypted before it is sent. All the data is protected and only available to authorized personnel and subcontractors. However, no method of transmission over the Internet, or method of electronic storage, is 100% secure. Therefore, while we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
10. TIME FOR WHICH THE DATA ARE KEPT
· To manage your user registration – We will process and retain your data for the time during which you remain a registered account user of our Website (i.e. until you decide to unsubscribe) or as required by law.
· Development, performance and execution of the purchase contract – We will process your data for the time necessary to manage the purchase of the products that you buy, including potential returns, complaints or claims related to the purchase of the products in question. Sometimes, we will only process the data until the time when you decide, as is the case of payment data that you requested us to store for future purchases (where this feature is available).
· Customer Service – We will process your data for the time necessary to meet your request or application.
· Marketing – We will process your data until you unsubscribe or cancel your subscription to the newsletter. Likewise, we will show you personalized ads until you change your device, browser and/or cookies settings so that permission to do so is revoked.
· Analysis of usability and quality – We will process your data occasionally for the time during which we proceed to carry out a specific quality action or survey or until we anonymize your browsing data.
Notwithstanding the fact that we will process your Personal Data for the time strictly necessary to achieve the purpose in question, we will subsequently keep them duly stored and protected for the time during which liability may arise for their procession, in compliance with legislation in force from time to time. Once each of the potential actions is time-barred we will proceed to delete the Personal Data. In addition, should we transfer your Personal Data to any third party (including but not limited to Global-e), we will use reasonable efforts to direct the transferee to delete your Personal Data in a manner which is consistent with the foregoing requirements.
11. WHEN YOU PROVIDE US WITH DATA OF THIRD PARTIES OR VICE VERSA
13. CONTACT – RIGHT TO ACCESS, CORRECT AND REMOVE PERSONAL DATA
· If you have any questions, comments or complaints about us or how we process your Personal Data, or in case you wish not to be contacted by us for direct marketing purposes anymore, please contact us at the email below. Also, upon request, we will provide you with a summary of any personally identifiable information collected and retained by us regarding you. You may modify, correct, or update your Personal Data or request to have your Personal Data removed from our database.
· At your request, we will remove your personal data to the extent that they are no longer necessary for the purpose for which we need to keep processing them, or when we are no longer legally permitted to process them.
· We will only send copies of Personal Data to the email address on file for the visitor name associated with it and if we consider this necessary to be able to identify you, we may request you to provide a copy of a document evidencing your identity.
· Our contact details are:
Tel no.: 22804829
Attn: Data Protection Officer
· If you contact us via telephone, the call may be recorded for quality purposes and so that we can respond to your request.
· Where the processing of your data is based on our legitimate interest, you will also have the right to object to the processing of your data.
· Finally, we inform you that you have the right to lodge a complaint with any competent data protection regulatory authority. However, we recommend that a complaint is always lodged first with our Data Protection Officer, so that we can address your concerns as quickly and in the most customer-focused manner possible.