Information about data privacy

The use of this website may involve the processing of personal data. To help you understand the way your data is used, we have provided an overview of the processes involved with the information below. In order to ensure the correct processing of your data, we would also like to inform you of your rights under the European Union’s General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).
Data processing will be handled by ROY ROBSON FASHION GmbH & Co. KG Bleckeder Landstraße 18-20, 21337 Lüneburg, Germany (hereinafter “we” or “us”). 

General information

Contact

If you have any questions or comments regarding this information, or would like to contact us in order to assert your rights, please address your enquiry to: 

ROY ROBSON FASHION GmbH & Co. KG 
Bleckeder Landstraße 18-20 
21337 Lüneburg, Germany
Tel.: +49 (0)4131 8870
Email: dataprotection@royrobson.com

General information about data processing

The use of this website may involve the processing of personal data. The term “personal data” refers to all information relating to a specific or identifiable person. An IP address may therefore also be termed personal data. An IP address is assigned to the device connected to the Internet by the Internet service provider so that the device can send and receive data. During the use of the website, we record information that you yourself provide. Additionally, specific information about your use of the website is recorded automatically by us during your visit to the site.
We process personal data in compliance with the relevant data protection legislation, most notably GDPR and BDSG. We only process your data in accordance with the law. During the use of this website, we only process your personal data in order to fulfil a contract to which you are a party, or in order to carry out preliminary contractual measures at your request (Section 6 Para. 1 clause 1b) GDPR), to fulfil a legal obligation (Section 6 Para.1 clause 1c) GDPR) or if it is necessary in order to protect our legitimate interests or the legitimate interests of a third party, provided that these interests are not superseded by your interests, basic rights and freedoms requiring the protection of your personal data (Section 6 Para. 1 clause 1f) GDPR). Where you have provided the information yourself, we also use your personal data in order to decide on the justification for an employment contract (Section 26 Para. 1 clause 1 BDSG). Otherwise, we only process your personal data if you have specifically consented for us to do so (Section 6 Para. 1 clause 1a) GDPR).

Duration of data storage

Unless otherwise indicated in the information below, we will only store your data for as long as it takes to achieve the purpose of processing or to fulfil our contractual and legal obligations. Such statutory data storage requirements are often the result of commercial or tax law.

Technical service providers

Unless otherwise indicated in the information below, your data is processed on the servers of technical service providers within the European Union that have been commissioned by us to do so. These service providers will only process your data as explicitly instructed and are contractually bound to guarantee the protection of your data via appropriate technical and organisational measures.

Processing server log files

For the purely informative use of our website, general information is transmitted by your browser to our server and saved automatically (i.e. not via a registration). This information includes: browser type/version, operating system, page requested, previous page visited (referrer URL), IP address, date and time of the server request and HTTP status code.

The data is processed in order to protect our legitimate interests and its legal basis is Section 6 Para. 1 clause 1f) GDPR. This use of your data helps us to maintain our website and ensure its security. The data is deleted after seven days, provided there are no concrete indications giving rise to a justified suspicion of unlawful use that requires the further analysis and processing of the information.

Contact form

Our website contains a contact form for you to send us messages and enquiries. The transfer of your data is encrypted using the https + TSL protocol.
The legal basis for this is Section 6 Para. 1 clause 1b) GDPR. All fields marked as mandatory must be filled in in order to process your enquiry. If you do not provide this information, we will not be able to process it. All other data is provided voluntarily. Alternatively, you can also send us a message via the contact email address.

Retailer area

If you would like to use our retailer area in order to download image and movie material for our collections, for example, you need to register as a retailer on the website. You can see which information is required for registration from the input screen. It is essential to provide the information marked as mandatory in order to complete your registration. The data you provide will be used for the purpose of providing a service. The legal basis for this is Section 6 Para. 1 clause 1b) GDPR. 

Job applications

It is possible to apply for vacancies within our company via our website. If you do so, we will collect personal information from you, including in particular your name, CV, cover letter and any other information you provide. The transmission of your application data via this form to us is encrypted via the https + TSL protocol. You can also apply via email or in writing to the contact details provided.

Your personal application information will only be collected, saved, processed and used for purposes linked to your interest in a current or future position with our company and for processing your application. Your application will only be processed and viewed by the relevant contact partners within our company. All staff involved in data processing are required to maintain the confidentiality of your data. 

If we are not able to offer you a position, we will archive your data for up to six months after the rejection for the purpose of answering any questions that may arise in connection to your application and rejection. This does not apply if legal provisions prevent the deletion of your data, if the information has to be retained in order to serve as evidence, or if you have expressly consented to a longer archiving period.

The legal basis for this is Section 26 Para. 1 clause 1 BDSG. If your application data is archived for longer than six months and you have expressly consented to this, we would like to indicate that you may revoke your consent at any time in accordance with Section 7 Para. 3 GDPR. Revoking your consent does not affect the legality of the processing that has taken place until the time of the revocation. 

Cookies

We use cookies on our website. Cookies are small text files that are saved by your browser when you visit a website. This makes it possible to identify your browser and enables our server to recognise it again in future. If this use of cookies leads to the processing of your personal data, it is done on the legal basis provided in Section 6 Para. 1 clause 1f) GDPR. In such cases, this processing serves our legitimate interest of making our website more user-friendly, effective and secure.
Most of the cookies we use are known as ‘session cookies’, which are deleted at the end of your visit. Other cookies (‘persistent cookies’) are automatically deleted after a specific period of time, which may vary depending on the cookie. You can delete cookies at any time by accessing your browser’s security settings. You can also completely reject the use of cookies by selecting the relevant option in your browser settings. The Federal Office for Information Security provides more information on cookies at https://www.bsi-fuer-buerger.de/BSIFB/DE/Empfehlungen/EinrichtungSoftware/EinrichtungBrowser/Sicherheitsmassnahmen/Cookies/cookies_node.html.

Google Analytics

To analyse visits to our website, we use the Google Analytics service provided by Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”) . Google uses cookies to analyse your use of our website. The information generated by the cookie with regard to the use of our website is generally transmitted to a Google server in the US and saved there. Google is authorised by us to use this information to analyse the use of our website by the user, to compile reports on activity within our website and to provide additional services associated with the use of our website and the Internet. When doing so, the data processed may be used to create pseudonymous user profiles of the website’s users. We only use Google Analytics with activated IP anonymisation. This means that the user’s IP address is shortened by Google within the European Union’s member states or in other states that are party to the contract outside of the European Economic Area. The IP address transmitted by the user’s browser is not matched with other data by Google.

The legal basis for the data processing in connection with Google Analytics is Section 6 Para. 1 clause 1f) GDPR and it serves the legitimate interest of analysing user behaviour on our website, which enables us to optimise our website design for the user. 
You can prevent cookies from being saved by selecting the relevant setting in your browser software. You can also prevent the information generated by the cookie from being saved by downloading and installing the browser plug-in available from the following link:  http://tools.google.com/dlpage/gaoptout?hl=de. If you are using our website via a mobile device, you can deactivate Google Analytics by clicking on the following link.
Google is certified under the Privacy Shield agreement and therefore guarantees compliance with European data privacy law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). 

Hotjar

Our website uses a plug-in offered by Hotjar Ltd. (St Julians Business Centre,
3, Elia Zammit Street, St Julians STJ 1000, Malta, “Hotjar”), which enables us to analyse movement on our website using heatmaps. This makes it possible to detect how far users scroll down and which buttons the user clicks on, and how often. The tool also enables us to obtain feedback directly from the user. In this way, we are able to collect valuable information to help us make our website even faster and more user-friendly.
Hotjar only enables us to track which buttons are pressed, how the mouse is used, how far the user scrolls, the size of the device’s screen, the type of device and browser information. We also receive information about your geographical location (country) and the preferred language for our website. Areas of the website displaying your personal data or data from third parties are automatically hidden by Hotjar and therefore cannot be traced by the tool at any time. For more information about Hotjar and data privacy, please visit the following website: https://www.hotjar.com/legal/policies/privacy.
The legal basis for the use of this service is Section 6 Para. 1 clause 1f) GDPR. The information processing serves the legitimate interest of analysing user behaviour on our website, which enables us to optimise our website design for the user. You can prevent the collection of your data by Hotjar when visiting a Hotjar-based website by visiting this website: https://www.hotjar.com/opt-out and clicking on “Deactivate Hotjar”. Alternatively, you can activate “Do Not Track (DNT)” in your browser.

Facebook Custom Audiences

Our website uses Facebook Custom Audiences for websites, a service provided by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”). This service integrates a Facebook remarketing pixel on our website, which enables Facebook to record the visitors to our site and use their data to provide targeted advertising (Facebook Ads). The pixel transmits general information about the browser session to Facebook, as well as a non-reversible and non-personal checksum (hash value), which is generated from your Facebook ID. For information on how Facebook handles your data, and on your rights and settings available to protect your personal data, please read the Facebook data privacy statement at https://www.facebook.com/privacy/explanation
The legal basis for this type of data processing is Section 6 Para. 1 clause 1f) GDPR and it serves our legitimate economic interests. 
If you would like to opt out of the use of Facebook Website Custom Audiences for the future, please visit https://www.facebook.com/ads/website_custom_audiences.
Facebook is certified under the Privacy Shield agreement and therefore guarantees compliance with European data privacy law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). 

Integrated services and third-party content

Our website uses services and content provided by third parties (hereinafter summarised as “content”). In order to integrate this information, it is technically necessary to process your IP address so that the content can be sent to your browser. Your IP address is therefore transmitted to the relevant third-party provider. 
This type of data processing is done in order to protect our legitimate interests in terms of the optimisation and cost-effective operation of our website, and its legal basis is Section 6 Para. 1 clause 1f) GDPR. 
The programming language JavaScript is often used to integrate third-party content. You can therefore prevent your data from being processed in this way by deactivating JavaScript in your browser or by installing a JavaScript blocker. Please note that this may limit the functionality of the website.
We have integrated content from the following third parties on our website:
Google LLC (1600 Amphitheatre Parkway, Mountain View, CA 94043, USA; “Google”):

  • Google Maps for displaying maps;
  • Google Web Fonts for displaying fonts.

Google is certified under the Privacy Shield agreement and therefore guarantees compliance with European data privacy law (https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active). 
In order to display videos, we use the service provided by YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066, USA (“YouTube”). As a Google subsidiary, YouTube is also covered by Google’s Privacy Shield certification.  
We also use fonts provided by Monotype, 600 Unicorn Park Drive, Woburn, MA 01801, USA (fonts.com). Please note that the level of data protection in the US is not considered adequate under GDPR.

Your rights

As the person affected, you have the right to assert your rights as an affected individual. This includes, in particular, the following rights:

  • Under Section 15 GDPR and Section 34 BDSG, you have the right to request information about whether, and the extent to which, we have processed personal data about your person. 
  • Under Section 16 GDPR, you have the right to request the correction of your data.
  • Under Section 17 GDPR and Section 35 BDSG, you have the right to request the deletion of your personal data.
  • Under Section 18 GDPR, you have the right to request the restricted processing of your personal data.
  • Under Section 20 GDPR, you have the right to receive the personal data that you have provided us in a structured, standard and machine-readable, and to transmit this data to another person responsible.

Right of objection

Under Section 21 GDPR, you have the right to object to any processing of your data with a legal basis in Section 6 Para. 1 clause 1e) or f). If we use personal data for direct marketing purposes, you may object to this use of your data in accordance with Section 21 Paras. 2 and 3 GDPR.

Data Protection Officer

Please see below for the contact details for our Data Protection Officer:
datenschutzbeauftragter@royrobson.com

Appeal to a supervisory authority

If you are of the opinion that the use of your personal data has been in breach of the provisions of the GDPR, you have the right to appeal to a supervisory authority under Section 77 GDPR.