INFORMATION NOTICE ON THE PROCESSING OF PERSONAL DATA PURSUANT TO ARTICLES 13 AND 14 OF EU REGULATION 679/2016 (“GDPR”)
Your privacy is extremely important to us, please read this Privacy Statement carefully.
We wish to inform you in a complete and transparent manner about the personal data processing that the companies listed in paragraph 1 below will carry out on your personal data provided by you and/or collected in the context of the contacts you will possibly have with us, including for example the following:
When we collect your personal data, we differentiate between active and passive users, depending on how you use our Site or services.
You are an active user (“User”) when you:
You are a passive user (“Passive User”) when you visit any and all websites and applications without registering.
1. WHO COLLECT YOUR PERSONAL DATA
The companies collecting and processing personal data as autonomous data controllers (hereinafter the “Data Controllers” or the “Companies”) or as joint controllers are:
OTB (Parent company of Jil Sander and Jil Sander Affiliate) and Jil Sander carry out some activities as joint controllers, taking jointly the decisions regarding the purposes and means of personal data processing. Hereafter, the term “Joint Controllers” means Jil Sander and OTB jointly considered when they process data as Joint Controllers.
To facilitate your understanding of the processing activities carried out by the above-mentioned subjects as Controllers or Joint Controllers, we have prepared this document explaining which processing activities are carried out autonomously by each company.
By using our Site or visiting our shops, you agree and intend to be legally bound by this Privacy Statement and Terms and Conditions. This Privacy Statement is incorporated into our Terms and Conditions available at .
Please note that this Privacy Statement is subject to an arbitration provision, requiring you to arbitrate any claims you may have against us on an individual basis.
Arbitration on an individual basis means that you will not have, and you waive, the right for a judge or jury to decide your claims, if any, and that you may not proceed in a class, consolidated or representative capacity.
2. WHAT PERSONAL DATA WE PROCESS
Each Company collects different categories of personal data according to the purpose for which it processes them.
Herein below we specify which categories of personal data are collected; in the following paragraph we will explain for what purposes each category of data is processed by each Data Controller or by the Joint Controllers as appropriate. “Personal Data” is information that identifies, relates to, describes, can be associated with, or could reasonably be linked, directly or indirectly, with a particular individual, device, or household.
3. FOR WHAT PURPOSES WE PROCESS YOUR PERSONAL DATA
In this paragraph we further explain for what purposes each category of data is processed by each Data Controller or Joint Controller.
3.1 PURPOSES OF JIL SANDER S.p.A.
Jil Sander is the company that manages the e-commerce via the Site and the shop where you purchased a product and to which you have requested assistance services. In some cases, it may be necessary for Jil Sander to become aware of some information concerning you, to process specific requests you may have. Jil Sander will process Personal Data for the following purposes.
Jil Sander will process your identifiers, contact data, biographical data, and purchase data for marketing purposes, that is for advertising on social networks to which you are registered or sending advertising or direct sales material, carrying out market research, commercial communication with automated contact methods (email, newsletter, SMS, MMS, online messaging platforms, etc.) and traditional contact methods (mail), asking for your consent, where required by applicable law.
Legal basis: this processing is based, where required by applicable law, on the consent you have given via the appropriate opt-in disclosure.
You can at any time withdraw your consent, when required by applicable law, or you opt out to receive the above-mentioned communications by clicking on the appropriate option in each marketing email received, as well as by writing to the address email@example.com, or otherwise by contacting the Company at the addresses indicated in paragraph 1.
b. Sales activities and response to other requests made by customers
If you purchase Jil Sander’s products through the e-commerce service on the Site, Jil Sander will process your identifiers, contact data, biographical data, and purchase data to conclude the sale, as well as for all activities strictly connected and related to it, such as delivery or other administrative and accounting obligations. These data will be requested also in case of purchases performed without registration. In this case the personal data will be stored exclusively for the time necessary to complete the purchase activity.
Similarly, Jil Sander may need to process your identifiers, contact data, and biographical data to respond to any further requests that you may formulate through the Site or through the Customer Service, through telephone or chat, such as information or assistance requests.
Legal basis: this processing is based on the performance of a purchase contract to which you are a party; the provision of the Personal Data listed above is necessary for this purpose, since otherwise Jil Sander will not be able to process your request.
3.2 PURPOSES OF THE JOINT CONTROLLERS (JIL SANDER AND OTB)
Jil Sander and OTB operate as Joint Controllers on the basis of a specific agreement for the purpose indicated below.
a. Customer profiling
With your consent, the Joint Controllers will be entitled to process identifiers, biographical data, contact data, sales data, purchase data, the data collected in the shop, navigation data, and other similar network activity for profiling purposes and for business analysis, that is for analysis on your purchase preferences consisting of automated processing of the above mentioned Personal Data. This processing is aimed at analytically knowing or predicting your purchasing preferences, and also in order to create customer profiles and customize the commercial offer so that it is more in line with your preferences.
Legal basis: this processing is based on the consent you have given.
You will be entitled at any time to withdraw your consent to be subject to profiling by writing to firstname.lastname@example.org or otherwise by contacting the Joint Controllers at the addresses indicated in paragraph 1.
3.3 PURPOSES OF JIL SANDER AFFILIATE
Jil Sander Affiliate is the company that manages the shop where you have purchased a product, possibly by phone or other methods provided for by Jil Sander Affiliate and to which you have requested assistance services. In some cases, it may be necessary for Jil Sander Affiliate to become aware of some information concerning you, to process specific requests you may have. Jil Sander Affiliate will process Personal Data for the following purposes.
a. Sales related services
Jil Sander Affiliate may need to process your identifiers/contact data/biographical data and certain sales data (tax code and/or VAT number, passport number and Global Blue card number) to manage your purchase when concluded by phone or other methods provided by Jil Sander Affiliate, or issue an invoice, should you request it.
Legal basis: this processing is based on the performance of a contract to which you are a party; the provision of the Personal Data listed above is necessary for this purpose, since otherwise Jil Sander Affiliate will not be able to process your request.
b. After-sales services
Jil Sander Affiliate may collect your identifiers/contact data/biographical data to process specific requests that you may formulate in the shop, during post-sales; for example, to arrange a repair, a customization, a home delivery or to manage a return.
Legal basis: this processing is based on the performance of a contract of which you are a party; the provision of the Personal Data listed above is necessary for this purpose, since otherwise Jil Sander Affiliate will not be able to process your request.
3.4 PURPOSES OF ALL DATA CONTROLLERS OR JOINT CONTROLLERS
Finally, each Data Controller or Joint Controller may need to comply with a specific legal provision to which it is subject or to defend its own right in court.
a. Purposes related to the obligations established by laws or regulations, by decisions/requests of competent authorities or by supervisory and control bodies
Each Data Controller or Joint Controller may process your Personal Data to comply with a legal obligation to which it is subject.
Legal basis: compliance with a legal obligation.
The provision of data for this purpose is mandatory because in the absence of data the Data Controller or the Joint Controller will not be in a position to comply with their legal obligations.
b. Defence of rights during judicial, administrative or extra-judicial proceedings and in disputes arising in connection with the services offered
Your Personal Data may be processed by each Data Controller or Joint Controller to defend their rights or take legal action or make claims against you or third parties.
Legal basis: this processing is based on the legitimate interest pursued by the Data Controller or Joint Controller to protect their rights.
4. COOKIES; WHAT PROCESSING ACTIVITIES WE CARRY OUT IF YOU’RE USING OUR WEBSITE AND YOU NAVIGATE WITHOUT BEING LOGGED IN
The Site is managed by Jil Sander. It is possible to browse the Site without having to actively communicate your Personal Data if you are not logged in. In this case, while browsing the Site, we inform you that the computer systems and software procedures used to operate the Site acquire, during their normal operation, some data whose transmission is implicit in the use of Internet communication protocols.
This is information that is not directly associated with identified users, but which by its very nature could, through processing and association with data held by third parties, allow these users to be identified.
This category of data includes the IP addresses or domain names of the computers used by users who connect to the Site, the addresses in URI (Uniform Resource Identifier) notation of the requested resources, information regarding access, information regarding location, the method used to submit the request to the server, the size of the file obtained in response, the numerical code indicating the status of the response given by the server (successful, error, etc.), the information regarding the user’s visit including data clickstream of the URL, within and from the Site, the duration of the visit on some pages and the interaction on these pages and other parameters relating to the operating system and the user’s IT environment.
The data collected while browsing the Site will be processed to (i) manage the Site and resolve any operating problems, (ii) make sure that the content of the Site is presented in the most effective way for its devices, developing, testing and making improvements to the Site, (iii) as far as possible, to keep the Site safe and secure, (iv) to obtain anonymous statistical information on the use of the Site and to check its correct functioning, (v) identify anomalies and/or abuses in the use of the Site. The data could also be used to ascertain responsibility in case of possible computer crimes committed against the Site or third parties and may be presented to the Judicial Authority, if this makes an explicit request.
5. WHAT HAPPENS IF YOU DO NOT PROVIDE PERSONAL DATA
Some Personal Data that we will indicate you from time to time during the registration are necessary for the completion of the purchase contract and for administrative and accounting purposes.
In the description of the purposes in paragraph 3, we have specified when it is necessary to provide Personal Data. Where not expressly indicated as mandatory, therefore, the provision of Personal Data is optional and there will be no consequences if you do not provide them, unless it is impossible for the Data Controllers or Joint Controllers to act as described (for example, the impossibility to carry out marketing activities).
6. HOW AND HOW LONG WE WILL PROCESS PERSONAL DATA
The Personal Data provided to and/or collected by the Data Controllers or the Joint Controllers are processed and stored with automated tools and, in some cases, may be processed and stored on a paper backing. In particular, the Personal Data processed for purposes of marketing and Customer profiling will be entered and stored in the CRM systems (Customer Relationship Management) that allow the processing of Personal Data for these purposes.
The Personal Data will be stored for the time necessary to achieve the purposes for which they were collected. In particular, the following rules will apply:
In any case, for technical reasons, the termination of the processing and the consequent cancellation or irreversible anonymization of the related Personal Data will be definitive within thirty days from the terms indicated above.
With particular reference to the judicial protection of our rights or in case of requests from the authority, the data processed will be stored for the time necessary to process the request or to protect the right.
7. WHERE PERSONAL DATA MAY BE TRANSFERRED
For the purposes indicated above, we may also transfer your Personal Data to Europe, in particular to Italy where OTB and Jil Sander are seated.
We may also transfer your Personal Data to third countries, not belonging to the European Union, which may possibly do not guarantee the same level of protection. The transfer to third countries will always take place in accordance with the provisions of the GDPR, adopting any other measures necessary to ensure the security of the Personal Data being transferred. These measures possibly include agreements incorporating the so-called “standard contractual clauses” issued by the European Commission or your consent. You can ask for information regarding these third countries and how to obtain a copy of the appropriate safeguards using the following email: email@example.com or the contact details indicated in paragraph 1.
8. WHO WILL PROCESS PERSONAL DATA
Personal Data will be processed by:
Personal Data may also be disclosed to third-party service providers, independent data controllers, in particular to freelancers or companies providing legal or tax advice and assistance and to companies managing payments made by debit or credit cards or for fraud prevention and management activities.
Our third-party service providers may also have access to the Personal Data of people who are not users of the Site based on information that you directly disclosed on the Site, in the following instances:
In all of the above cases, you must make sure you receive the consent from third parties prior to disclosing their Personal Data and inform them about our Privacy Statement. We will treat this Personal Data in accordance with this Privacy Statement, just as we treat your Personal Data. However, you will be responsible in connection with the disclosure of third-parties’ Personal Data, if you failed to obtain the third parties’ express consent to disclose their Personal Data or for any improper or unlawful use of that data.
Lastly, we may share your information with third parties, unrelated to the services provided on the Site, when we believe it is necessary or appropriate, including: (a) as required or necessary in order to comply with applicable law (including laws outside your country of residence); (b) to protect us against liability; (c) to respond to subpoenas, judicial processes, or legitimate requests by law enforcement officials; (d) to purchasers in connection with any sale, assignment, or other transfer of all or a part of our business or company; (e) to protect our operations; (f) to protect our rights, privacy, safety or property; and (g) to allow us to pursue available remedies or limit the damages we may sustain.
Personal Data will not be disseminated in any way.
9. COLLECTION FROM CHILDREN
The Site is not intended for children under the age of 13 and we do not knowingly collect Personal Data from such children. Children under the age of 13 should not use or attempt to use our Site or send Personal Data to us. In the event that we learn that we have inadvertently gathered Personal Data from a child under the age of 13, we will take reasonable measures to erase such information from our records. Parents who believe that we might have any information from or about a child under 13, may submit a request to firstname.lastname@example.org and request that such data be removed.
10. EXERCISING YOUR RIGHTS
Pursuant to Chapter III of the GDPR, you have the right to ask each Data Controller or Joint Controller:
Right to object: in addition to the rights listed above, you always have the right to object at any time to the processing of your Personal Data carried out by the Data Controller or Joint Controller for the pursuit of its legitimate interest. You have the right to object to direct marketing, which includes profiling. If you prefer that the processing of your Personal Data is carried out solely through traditional contact methods, you can object to the processing of your Personal Data carried out through automated contact methods.
You also have the right to withdraw, in whole or in part, the consent, when requested by applicable law, to the processing of Personal Data concerning you for the purpose of sending advertisements or direct selling or for carrying out market research or commercial communication with automated contact methods (email, other remote communication systems via communication networks such as, for instance: SMS, MMS, messaging platforms, etc.) and traditional contact methods (mail).
The exercise of these rights, which can be done through the contact details indicated in paragraph 1, is not subject to formal constraints. In the event that you exercise any of the above mentioned rights, it will be the responsibility of the Data Controller or Joint Controller that you contacted to verify if you are entitled to exercise the right and to provide you with an answer, normally within a month.
As regards the Joint Controllers relationship, please note that OTB and Jil Sander entered into a specific agreement pursuant to article 26 of the GDPR, an extract of which is available for consultation contacting each of the Joint Data Controllers using the contact details indicated under paragraph 1.
If you believe that the processing of your Personal Data is carried out in breach of the provisions of the GDPR, you have the right to lodge a complaint with the Supervisory Authority or to start the appropriate legal actions before the competent courts.
To exercise your rights, you can send a request to the Data Controllers or Joint Controllers by writing to the addresses indicated in paragraph 1. The OTB’s Data Protection Officer can be contacted at the email address email@example.com.
11. YOUR CALIFORNIA PRIVACY RIGHTS & HOW WE RESPOND TO “DO NOT TRACK” SIGNALS
If you are a California resident, you may have the right to request and receive certain information about a company’s disclosure of your Personal Data to third parties for their own direct marketing use, and your choices with respect to such disclosures. Because we do not share your Personal Data with third parties for their own direct marketing use unless you are first given the opportunity to opt in or out, we are exempt from this requirement. If you still wish to learn more about our compliance with this requirement, please contact us at the address listed in paragraph 1.
As of January 1, 2020, you may be entitled to the below rights:
You can exercise your rights by contacting us using the details set out in paragraph 1. Whenever feasible for verification, we will match the identifying information provided by you to the Personal Data already maintained by us. If, however, we cannot verify your identity from the information already maintained by us, we may request additional information. You may designate an authorized agent to make a request on your behalf. Such authorized agent must be registered with the California Secretary of State and must have permission to submit requests on your behalf. We may deny a request from an agent that does not submit proof that they have been authorized by you to act on your behalf.
12. HOW WE RESPOND TO DO NOT TRACK SIGNALS
The “Do Not Track” (“DNT”) privacy preference is an option that may be made in some web browsers allowing you to opt-out of tracking by websites and online services. At this time, global standard DNT technology is not yet finalized and not all browsers support DNT. We therefore do not recognize DNT signals and do not respond to them.
13. THIRD-PARTY ADVERTISING
We may use advertisers, third-party ad platform, tracking technologies and other advertising companies to serve advertisements on the Site and to improve the performance of our advertising across the Internet.
Please be advised that such advertising companies may gather Personal Data about your visit to our Site or other websites (such as through cookies, web beacons, and other technologies) to enable such advertising companies to market products or services to you, to monitor which ads have been served to your browser and which webpages you were viewing when such ads were delivered. You can also generally opt-out of receiving personalized ads from third-party advertisers and ad networks who are members of the Network Advertising Initiative (NAI) or who follow the Digital Advertising Alliance’s Self-Regulatory Principles for Online Behavioral Advertising by visiting the opt-out pages on the NAI website https://optout.networkadvertising.org/?c=1 here and DAA website here https://optout.aboutads.info/?c=2&lang=EN
14. LINKS TO THIRD-PARTY WEBSITES
Again, please note that this privacy statement does not cover the collection and use of information by such third-party websites and advertisers.
We have adopted commercially reasonable security measures to protect your Personal Data against accidental or unlawful destruction, loss, alteration, or unauthorized disclosure or access. We may use third-party products and services to secure or store your information. We encrypt credit card numbers from e-commerce transactions conducted on our Site. However, no method of Internet transmission or electronic storage is 100% secure or error free. Consequently, we cannot ensure or warrant the security of any information you transmit to us. If we learn of a data security systems breach we may attempt to notify you electronically so that you can take appropriate protective steps. By using the Site or providing Personal Data to us, you agree that we can communicate with you electronically regarding security, privacy, and administrative issues relating to your use of the Site. We may post a notice via the Site if a security breach occurs. We may also send an email to you at the email address you have provided to us in these circumstances. Depending on where you live, you may have a legal right to receive written notice of a data privacy or security breach. If you have any reason to believe that your interactions with the Site are no longer secure, please notify us immediately at the addresses provided above.
Additionally, please do not forget that it is essential for the safety of your data that your device is equipped with tools such as constant antivirus updates and that your internet provider provides a connection ensuring a secure data transmission through firewalls, spam filters, and similar measures.
16. CHANGES TO OUR PRIVACY STATEMENT
We reserve the right to amend all or part of our Privacy Statements from time to time. The version published on the Site is the version currently in force. Changes to our Privacy Statements are communicated by placing a notice on the Site stating “Revised Privacy Statement(s).” Changes to our Privacy Statements will be effective immediately once published on the Site unless otherwise noted. If we make material changes to our Privacy Statement, we will notify you by prominently posting the changes on our Site as described or by using the contact information you have on file with us. Your use of the Site following any amendments, indicates your consent to the practices described in the revised Privacy Statements. We invite you to periodically review our Privacy Statements to be informed of any relevant changes, especially before providing any data to us.
17. DISPUTES, AGREEMENT TO ARBITRATE, AND CHOICE OF LAW
By using the Site, you and we agree that, if there is any controversy, claim, action, or dispute arising out of or related to your use of the Site, or the breach, enforcement, interpretation, or validity of this Privacy Statement or any part of it (“Dispute”), both parties shall first try in good faith to settle such Dispute by providing written notice to the other party describing the facts and circumstances of the Dispute and allowing the receiving party 30 days in which to respond to or settle the Dispute.
Notice shall be sent:
(1) to us at the address(es) listed above, towards the beginning of this Privacy Statement; and (2) to you at: the contact information on file with us. Both you and we agree that this dispute resolution procedure is a condition precedent that must be satisfied before initiating any litigation or filing any claim against the other party.
If any dispute cannot be resolved by the above dispute resolution procedure, you agree that the sole and exclusive jurisdiction for such dispute will be decided by binding arbitration on an individual basis. arbitration on an individual basis means that you will not have, and you waive, the right for a judge or jury to decide your claims, and that you may not proceed in a class, consolidated, or representative capacity.
Other rights that you and we would have in court will not be available or will be more limited in arbitration, including discovery and appeal rights. All such Disputes shall be exclusively submitted to JAMS (www.jamsadr.com) for binding arbitration under its rules then in effect, before one arbitrator to be mutually agreed upon by both parties. The arbitrator, and not any federal, state, or local court or agency, shall have exclusive authority to resolve any dispute arising under or relating to the interpretation, applicability, enforceability, or formation of this Privacy Statement, including any claim that all or any part of this Privacy Statement is void or voidable. This Privacy Statement has been made in, and shall be construed in accordance with, the laws of the State of New York, without giving effect to any conflict of law principles. The parties acknowledge that this Privacy Statement evidences a transaction involving interstate commerce. Notwithstanding the provision in the preceding paragraph with respect to applicable substantive law, any arbitration conducted pursuant to the terms of this Privacy Statement shall be governed by the Federal Arbitration Act (9 U.S.C. §§ 1-16).