The protection of personal data is important to Ollin BV. Ollin BV makes every effort to protect the data and to act in accordance with the rights of the data subject and the privacy laws. Please read this statement carefully. It provides important information on how Ollin BV uses personal data and explains the privacy rights of the data subject.
Personal data is processed in accordance with the European General Data Protection Regulation 2016/679 of 27 April 2016 (“GDPR”), the Belgian law of 8 December 1992 (“Privacy Law”), the law of 13 June 2005 (“Electronic Communications Law”) and the associated implementing decrees.
2. Identification and contact details of the processor
Name of company: Ollin BV
Commercial name(s): YUNO
Address: A. Stocletlaan 214 – 2570 Duffel- Belgium
E-mail: [email protected]
Telephone: +32 (0)59/41.25.61
Hereinafter referred to as “Ollin BV”.
This Privacy Statement applies to all existing and future agreements, customers and users of all website(s), applications and services of Ollin BV, hereinafter referred to as “the data subject”.
4. Data collected, purposes and legal bases
4.1 Order details
This data is used to make it possible to process orders and to carry out the agreements between Ollin BV and the person concerned. Furthermore, this data is used for compliance with legal obligations and to provide product support. Following consent, this data can also be used for sending marketing and personalised advertising (legitimate interest). These data include:
4.2 Sleep profile data
This data is used to form a sleep profile of the person concerned via the/digital measurement on the website or in the applications, and thus to provide a product recommendation. This product advice can be sent by e-mail to the person concerned. These data include:
- Date of birth
- Width of shoulders, waist and hips
- Sleeping position
- Current mattress base
4.3 Contact details
This data is collected when using one of the contact forms or registration forms on the websites, or when the data subject contacts one of the contact methods such as e-mail, chat, or similar methods. This data is used to provide the person concerned with support or to reply to his/her message. These data include:
4.4 Historical data
This data is used to provide targeted product advice based on previous orders & sleep profiles and to produce anonymous statistics. Furthermore, this data is used for compliance with legal obligations and to provide support to the person concerned. These data include:
- Order history with details of each order (date, products, shipping details, payment details, …)
- Customer ratings
- Product ratings
- Sleep profiles
5. Transfer to third parties
Ollin BV does not sell or share data with third parties, unless this is necessary for the fulfilment of the intended purposes or agreements. In this case, the data of the person concerned will be shared with a partner of Ollin BV. This may be the case, for example, with a carrier who needs the data of the person concerned in order to deliver the order. Where possible, the data is anonymised and only the most necessary data is transmitted.
Ollin BV guarantees that any recipient of data will take the necessary technical and organisational measures to protect the personal data. Ollin BV concludes a processing agreement with each partner.
Every partner with whom Ollin BV cooperates is based in the European Union, and complies with the European General Data Protection Regulation 2016/679 of 27 April 2016 (“GDPR”) OR is based in America and is on the US Privacy Shield list (https://www.privacyshield.gov/list) and thus maintains an equally high standard of privacy protection as in Europe.
6. Storage period
Personal data will be kept for the time necessary to fulfil legal requirements (e.g. in the field of accounting).
Other data that are no longer used will be anonymised or deleted where possible within a period of 4 years.
7. Right of access, rectification, deletion, restriction, objection and portability of personal data
The person concerned may always exercise the rights set out below. The data subject exercises these rights subject to certain exceptions for the protection of public interest (e.g. prevention or detection of crime) and the interests of Ollin BV (e.g. preservation of legal privilege). The data subject may exercise these rights by contacting Ollin BV using the details set out in Article 2 of this Privacy Statement. If the data subject exercises these rights, Ollin BV will verify within one month whether the data subject is entitled to them and take the necessary actions. Ollin BV may ask the data subject for additional information to confirm his identity.
7.1 Right of inspection (Art. 15 GDPR)
The data subject may at any time request information on the data held by Ollin BV on the data subject. This information includes the categories of data processed by Ollin BV, the purposes & legal grounds for which they are processed, the source of the data if not obtained directly from the data subject, and, where applicable, the recipients to whom Ollin BV has transferred the data. The data subject may obtain from Ollin BV a free copy of his data which is part of the contract.
7.2 Right to rectification (Art. 16 GDPR)
The data subject may request that Ollin BV correct their data. Ollin BV will take appropriate measures, based on the latest information available to Ollin BV, to ensure the accuracy, completeness and relevance of the data held by Ollin BV.
7.3 Right to data erasure (Art. 17 GDPR)
The data subject may request Ollin BV to delete his data if required by law. In accordance with Art. 17 of the GDPR, this could be the case when:
- The personal data are no longer needed for the purposes for which they were collected or otherwise processed.
- The data subject withdraws the consent on which the processing is based and there is no other legal basis for the processing.
- The data subject objects to the processing, and there are no overriding mandatory legitimate grounds for the processing, or if the data subject objects to the processing for direct marketing.
- The personal data have been unlawfully processed.
Insofar as processing is not necessary:
- To fulfil a legal processing obligation.
- Especially with regard to the retention periods required by law.
- To establish, exercise or substantiate a legal claim.
7.4 Right to restriction of processing (Art. 18 GDPR)
The data subject may request Ollin BV to restrict the processing of their data if:
- The data subject disputes the accuracy of the personal data for a period that allows the controller to verify the accuracy of the personal data.
- The processing is unlawful and the data subject opposes the erasure of the personal data and requests the restriction of their use instead.
- Ollin BV no longer needs his data for the establishment, exercise or proving of a legal claim.
- The data subject has objected to the processing pending the answer to the question whether the legitimate interests of Ollin BV outweigh the interests of the data subject.
7.5 Right to data portability (Art. 20 GDPR)
If technically feasible, the data of the person concerned will be passed on to another responsible party at his request. This right is available to the data subject insofar as the data processing is based on his/her consent or is necessary for the performance of a contract; and only for the personal data that the data subject has provided to Ollin BV. Instead of receiving a copy of their data, the data subject may also request that Ollin BV transfers the data directly to another processor designated by the data subject.
7.6 Right to object (Art. 21 GDPR)
The data subject may, at any time and for reasons relating to their particular situation, object to the processing of their personal data if this data processing concerns their consent or our legitimate interests or those of third parties. In that case, Ollin BV will stop processing the data. The latter does not apply if Ollin BV has compelling legitimate grounds for processing which override the interests of the data subject, or if Ollin BV needs the data for the establishment, exercise or support of legal claims.
8. Direct marketing and mailing
Ollin BV may use the collected data for direct marketing such as newsletters and commercial mailings tailored to the individual (by post or by e-mail), following the explicit consent of the individual. The data subject may at any time ask Ollin BV to stop using their data for direct marketing purposes by clicking on the unsubscribe link at the bottom of the e-mail or by contacting Ollin BV using the details specified in Article 2 of this privacy statement.
Ollin BV may also use the collected data for so-called “service e-mails”, which are e-mails or messages that are necessary to inform the person concerned of important information regarding the execution of the agreement. These include:
- Information about his current order or delivery
- Invoices and receipts
- Appointment requests and confirmations
- Communication in connection with warranty and repairs
- Notifications related to his account on the website or in applications
The data subject may not request that their data be no longer used for this purpose, as this would jeopardise the performance of the contract by Ollin BV.
Cookies are small information files that are stored on the device used by the person visiting the website, such as a computer, tablet, smartphone or smartwatch, when visiting the website. In the following, “cookies” are also understood to mean similar techniques.
When using the websites or applications, the data subject agrees that Ollin BV may place these cookies on their device. Most browsers automatically accept cookies, but can be configured not to do so or to warn the user when a cookie is being sent. If the data subject wishes to disable cookies, the data subject can consult the instructions of the browser to find out how to do so. If the person concerned deactivates cookies, it is possible that they will no longer be able to access certain functions on the website. The person concerned may also at any time remove the cookies already installed from their device.
Ollin BV uses the following types of cookies:
9.1 Necessary cookies
These cookies are essential in order to enable the data subject to navigate around the website and use its functions. Without these cookies, certain parts of the website or applications will not work, or not work optimally. These cookies do not collect data that can be used for marketing purposes or to remember his browsing history.
9.2 Functional cookies
These cookies remember certain choices and changes the person makes on the site (such as their language setting) so that the person gets an improved, more personalised browsing experience. The information these cookies collect is stored anonymously.
9.3 Analytical cookies
Via the websites or applications, a cookie of the US company Google is installed as part of the Google Analytics service. Google Analytics is registered on the US Privacy Shield list and thus has as high a standard of privacy protection as in Europe.
Ollin BV uses this service to track and get reports about how visitors use the website. This enables Ollin BV to improve its services and products.
10. Data protection
Ollin BV uses a range of security measures, including encryption and authentication tools, to help protect and maintain the security, integrity and availability of the data.
Ollin BV, together with its service providers, subcontractors and business partners, makes every effort to maintain physical, electronic and procedural safeguards to protect the data in accordance with the applicable data protection requirements. Ollin BV uses, among others, the following security measures:
- There are internal agreements & regulations regarding data access. Only the data that is strictly necessary is accessed.
- Transfer and storage of collected digital data is always encrypted.
- Every access to digital data is logged.
- All websites & applications are provided with SSL certificates.
- All IT systems are equipped with virus/malware protection and the latest updates & patches.
- All networks are equipped with firewalls & other active protections to prevent unauthorised access
- Physical precautions are taken to prevent unauthorised access to data.
11. Establishing and reporting unauthorised access
If Ollin BV determines that unauthorised persons have had access to personal data, the competent authorities and the person concerned will be notified within 72 hours after the determination and analysis by an expert.
If the person concerned considers that their data are not being processed in accordance with this privacy statement, they can contact Ollin BV using the details specified in Article 2 of this privacy statement.
The data subject also has the right to lodge a complaint with the Commission for the Protection of Privacy ([email protected]).