Eccotemp Systems Europe, B.V. Herengracht 282, Paleis op de dam 1425, 1016 BX Amsterdam, Niederlande is the controller of your personal data according to the EU General Data Protection Regulation (“GDPR) and other applicable data protection laws.
CATEGORIES OF PERSONAL DATA
We process the following categories of personal data:
Master data such as first name, surname, mailing address, , date and place of birth or customer number;
Payment data such as credit card number or bank account information;
Communication data such as e-mail address, telephone number or communication content (e.g., e-mails);
Service- and contract data such as information concerning the goods and/or services you purchase from us;
Device and usage data such as your IP address.
PURPOSE OF PROCESSING, LEGAL BASIS AND ORIGIN
We use the personal data you provide to us for the specific purposes for which you provide the information, as stated at the time of collection, and as otherwise permitted by law. The information we collect from you may in particular be used in the following ways:
To enter into contracts and process transactions including executing your payments and delivering the purchased products or services requested. The legal basis for the processing is Article 6 para. 1 sentence 1 lit. b) GDPR, which permits data processing that is necessary for the performance of a contract with the affected individual or in order to take steps at the request of the individual prior to entering into a contract.
To improve customer service (your information helps us to more effectively respond to your customer service requests and support needs). In this case, we process your data on basis of our legitimate interest to answer to the needs of our customers pursuant to Article 6 para. 1 sentence 1 lit. f) GDPR).
With your consent, to send you important information and updates pertaining to your order, in addition to receiving occasional company news, updates, related product or service information, etc.
When you access our Website, the Website may automatically collect, process and store certain personal data in a pseudonymized form. Such device and usage information may include (i) specific information about the device used to access the Website (including model, operating system, IP address, language and similar information) and (ii) information about the use of features, functions or notifications on the device to recognize you and to analyze trends. The legal basis for this is our legitimate interest (Art. 6 para. 1 lit. f) GDPR) to monitor and maintain the performance of the Website and to analyze uses, activities and trends in connection with our Website.
We will share your data (whether or not anonymized) with:
Google Analytics: anonymized data is shared for the purpose of compiling statistics on the use of our website.
JustUno: displays popups and logs ip addresses that have been shown popups to mitigate redundancy.
BigCommerce: our website and store is hosted through Big Commerce who records various data from tracking of orders to site visit statistics.
UPS and DHL: your address and contact details will be shared for the purpose of delivering your order.
Our website uses the following cookies:
Various cookies from external suppliers: Google Analytics. Data collected through these cookies does not contain any personal data.
Various functional cookies. E.g., to remember the active language or currency of the website or your authorization token when you are logged in. These cookies expire automatically at the end of your session.
RECIPIENT OF DATA
We may hire third parties to provide certain services to us as a processor whereby the third party may gain access to your personal data. In particular, this includes IT-, e-mail- and marketing-services. The service providers used are contractually obliged to us to take appropriate technical and organizational security measures to protect your personal data and to process these only in accordance with our instructions.
We may disclose your personal data to payment services providers, legal, tax and other advisors as well as enforcement and government agencies in accordance with applicable data protection laws. Such processing is legally based on the necessity of the processing for the performance of the individual purchase agreement (Article 6 para. 1 sentence 1 lit. b GDPR), the compliance with legal obligations (Article 6 para. 1 sentence 1 lit. c) GDPR) which we are subject to or our legitimate interests (Article 6 para. 1 sentence 1 lit. f) GDPR), such as exercising or defending legal claims.
TRANSFER OF PERSONAL DATA TO THIRD COUNTRIES
Your personal data may be transferred to and processed by recipients in third countries outside the European Economic Area (EEA) that, from the perspective of the European Union, do not provide an adequate level of data protection. Where such a transfer is made, it will be based on appropriate safeguards, such as the standard contractual clauses adopted by the European Commission. You may request a copy of the appropriate safeguards by contacting us at the contact details provided in section 7. Access is limited to recipients who need the respective data to perform their tasks.
STORAGE PERIOD OF YOUR PERSONAL DATA, CRITERIA FOR STORAGE PERIOD
We store your personal data for as long as this is necessary for the purposes of the data processing described in section 2 above. If we no longer require your personal data for the described purposes, we will erase the data from our systems and records or make the data completely anonymous so that you can no longer be identified from it. Your data will not be erased or completely made anonymous if and as long as we need to store the data in order to fulfil legal or regulatory obligations or if we need the data to preserve evidence within the statutory limitation period.
YOUR RIGHTS AS A DATA SUBJECT AND HOW TO ASSERT THEM
If you have declared your consent to the processing of your personal data, you can withdraw this consent at any time with future effect. Such withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal. If you lodge an objection, we will no longer process your personal data unless any other (legal) basis permits this. However, if the consent is withdrawn and no other legal basis exists, we must delete the personal data immediately.
According to applicable data protection laws, as a data subject you may have the right of access (Article 15 GDPR), the right to rectification (Article 16 GDPR), the right to erasure (Article 17 GDPR), the right to restriction of processing (Article 18 GDPR) and the right to data portability (Article 20 GDPR). The right to access and the right to erasure may be restricted under certain circumstances in accordance with applicable local data protection laws. In addition, you are entitled to lodge a complaint with a data protection supervisory authority (Article 77 GDPR).
Under certain circumstances, on grounds relating to your particular situation, you have the right to object at any time to the processing of your personal data that are processed on the basis of our legitimate interests (Article 21 para. 1 GDPR). Furthermore, if your personal data is processed for the purpose of direct marketing, you have the right to object at any time to the processing of your personal data for these purposes, to the extent that it is related to such direct marketing (Article 21 para. 2 GDPR). In this case, we will no longer process your personal data for these purposes.
In order to exercise your rights, please contact us under the contact details provided in section 7
No part of this website or any of its contents may be reproduced and/or made public by printing, photocopying, faxing, retyping, storage in an automated system without the written approval of Eccotemp Systems Europe B.V. or otherwise as is applicable to all or part of the operation. Requests for approval or further information should be addressed to firstname.lastname@example.org.
Data Protection Authority
You always have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or another competent data protection authority. Of course, we would appreciate it when you first contact us so that we can solve the problem for you.