- What is the content of this document? What happens to my personal data when I interact with the VF Group?
- Who controls the processing of my personal data? Who is accountable for it?
- What personal data are processed?
- For what purposes are my personal data processed?
- What are the legal bases for the processing of my personal data as described herein?
- How long will my personal be data processed?
- Are my personal data safe?
- Where do my personal data go? Who are the recipients, where is it transferred and for what purposes?
- Am I obliged to provide my personal data? What are the consequences if I refuse to provide them?
- Do VF Digital Platforms contain elements controlled by third parties? Who is responsible and liable for these elements?
- What are my rights in relation to the processing of my personal data and how can I exercise them?
- Appendix 1 - Data Subject's Rights
What is the content of this document? What happens to my personal data when I interact with the VF Group?
- when you interact with us through digital means, including the website http://www.thenorthface.eu (the “Site”), portals and mobile applications, operated by VF International Sagl, Via Laveggio 5, 6855 – Stabio, Switzerland (collectively “VF Digital Platforms”);
- when you purchase a product or request other services from VF International Sagl or any of its subsidiaries (hereinafter, "we" or "us" or "VF Group"), whether online on our Site or through VF Digital Platforms, or offline in our stores, including when you contact our customer care for post-sale customer services or specific questions or requests;
- when we communicate with you as part of our marketing activities.
We collect and process your personal data in accordance with all applicable data protection laws and regulations, including, without limitation, the laws promulgated on the matter by the European Union, such as the General Data Protection Regulation (EU) 2016/679 of 27 April 2016 ("GDPR") and supplementing national provisions, as well as the orders and guidelines issues by the competent data protection authorities, as applicable (the "Data Protection Laws").
Who controls the processing of my personal data? Who is accountable for it?
The data controller of the personal data (i) that are collected when you use VF Digital Platforms (other than when you purchase goods from us), and (ii) that are collected for our marketing and profiling activities is: VF INTERNATIONAL S.A.G.L. – BRAND DIVISION, Via Laveggio 5, 6855 – Stabio, Switzerland. For further details and how to contact us, please refer to contact us.
VF Europe BV, with registered office at Fountain Business Park, C. Van Kerckhovenstraat 110, 2880 Bornem, Belgium, VAT BE 0405.039.138 RPM Antwerp Division Mechelen, is acting as the representative of VF International Sagl for purposes of personal data protection compliance in the European Union.
The data controller of your personal data when you purchase goods from us is the local entity of the VF Group that sells the goods to you through our Site (for online purchases) or in store (for offline purchases). This local entity is also the data controller of the personal data that you provide when you interact with our customer care. The relevant VF subsidiary is identified on your purchase receipt. A list of the VF subsidiaries acting as data controllers per country is available at Terms of Sale.
Note that the VF entity with which you interact (and to which you provide personal data) is not always the data controller. In the following cases, the VF entity with which you interact acts on behalf of (and will communicate your personal data to) another VF entity, that is the actual data controller of your personal data:
- the VF local subsidiary from which you purchase goods collects your personal data - and, where required by law, asks your consent to use them - for marketing and profiling purposes on behalf of VF International Sagl, which is the data controller in that context as indicated above;
- Alternatively, VF Northern Europe Ltd or our third-party service provider Concentrix Services Bulgaria EOOD, with registered offices at 29 Atanas Dukov Str Rainbow Center, Sofia, Bulgaria, manages our customer care and interacts with you on behalf of the VF local subsidiary from which you purchased the goods, which is the data controller in that context as indicated above.
VF Group's Data Protection Officer may be contacted via our Privacy Office at email@example.com.
What personal data are processed?
Automatic Information Collection on the VF Digital Platforms
The processing of your personal data when you merely visit and consult the Site is limited to the so-called surfing data, namely the data whose transmission to the Site is implicit in the functioning of the systems in charge of the managing of the Site and in the communications protocols peculiar to the Internet. Surfing data are, for example, the IP addresses of the devices you use to connect to the Site and other parameters relating to your device and operating system.
In principle, surfing data, such as those specified above, and for example the number of visits and the time spent on the Site, are collected and processed by us exclusively for statistical purposes and in aggregated form for purposes of measuring and enhancing the functioning of the Site. Due to the nature itself of surfing data, these data may lead to identification of users if they are associated with data held by third parties; however, we do not collect surfing data in order to associate them with identified users, except where said data may be used for purposes of assessing possible responsibilities in case of information crimes realized against the Site or through the Site to the extent permitted by law.
Information you provide voluntarily to us:
We collect and process:
personal data that you provide when you interact with us, through VF Digital Platforms, for example, when you open an account, upload user-generated content on the Site or fill-in forms in store or by using our mobile applications. This personal data may include:
- your name, e-mail address, telephone number
- your username and password
personal data that you provide when you take part/subscribe to our marketing activities (whether through VF Digital Platforms or in our stores), for example, when you subscribe to our newsletter(s) or mailing list(s) or participate to promotions and other initiatives such as loyalty programs, contests and sweepstakes, etc. This personal data may include:
- your name, e-mail address, telephone number
- the history of your purchases
- your gender
- your preferences and interests
personal data that you provide when you purchase goods from us (whether online or in our stores). This personal data may include:
- your name, e-mail address, telephone number
- the history of products you purchase
- details regarding your transaction
personal data that you provide when you interact with our customer care, for example, when you send a question about a product, communicate feedback to us, contact our customer care call center for support, or request specific assistance or service from our customer care. This personal data may include:
- your name, e-mail address, telephone number
- the history of products you purchase
- information regarding the reasons why you contacted customer care
- content of your communications relating to your interaction with customer care
For what purposes are my personal data processed?
We collect and process your personal data for the following purposes:
VF International Sagl, as data controller, processes your personal data for the following purposes:
to operate and manage VF Digital Platforms, including:
- to provide you with the services or functionalities that you request on VF Digital Platforms;
- to create your account and manage your subscription on VF Digital Platforms;
- to improve your browsing experience and ameliorate VF Digital Platforms;
to conduct marketing activities for the VF Group, including:
for direct marketing purposes, including:
- to manage your subscription to our newsletter(s) or mailing list(s) or loyalty program(s);
- to allow participation to promotions and other initiatives, such as contests and sweepstakes;
- to send you (subject to your consent, that is optional), also through e-mail or other electronic communications means, such as SMS, MMS, fax, etc., promotional information and material on our products and services, on special initiatives on price and promotions and on initiatives such as loyalty programs, events, exhibitions and fairs organized by the VF Group or to which the VF Group takes part;
- for survey purposes (subject to your consent, that is optional);
- for profiling purposes (subject to your consent, that is optional);
- to improve our products and services;
- for direct marketing purposes, including:
for other purposes:
- for fraud prevention purposes, through internal procedures aimed at verifying the regularity of transactions, to protect our financial integrity and to protect you against the misuse of data and fraudulent purchases; and
- to comply with our obligations under applicable laws, regulations and to assess and defend a legal right
- to operate and manage VF Digital Platforms, including:
VF local subsidiaries, as data controllers, process your personal data for the following purposes:
to manage your purchases of goods (online and in our stores):
- this includes all activities relating to the purchase of goods, such as for example delivery of goods, billing, returning and exchanging of goods, receiving refunds, purchase and use of gift cards and e-gift cards, as applicable, payment related activities, including use of vouchers;
to provide you with our customer care (see details section 3 below), including:
- to provide you with after-sale services;
- to respond to your request(s) of information, question(s), communication(s) or feedback
- for internal training purposes and improvement of our customer care;
for other purposes:
- for fraud prevention purposes, through internal procedures aimed at verifying the regularity of transactions, to protect our financial integrity and to protect youagainst the misuse of data and fraudulent purchases; and
- to comply with our obligations under applicable laws, regulations and to assess and defend a legal right.
- to manage your purchases of goods (online and in our stores):
Additional information about our customer care
Our customer care is managed alternatively by VF Northern Europe Ltd or our third-party service provider Concentrix Services Bulgaria EOOD, with registered offices at 29 Atanas Dukov Str Rainbow Center, Sofia, Bulgaria, which interacts with you and provides you the service on behalf of the VF local subsidiary from which you purchased the goods. We will process your personal data when you contact our customer support and call center, which may communicate with you through e-mail, chat and telephone. The call center will register your phone number for purpose of call-back and back-office services in order to provide you with the requested support and information. In some cases, for purposes of internal training, quality control and verification, the call may be recorded and the e-mails may be saved to the extent not prohibited under applicable law. You will always be informed in advance of the recording of the communication, and you will have the opportunity to object to such recording, save when this is necessary for verification purposes in relation to your purchase or other reasons, as allowed under applicable laws.
What are the legal bases for the processing of my personal data as described herein?
We will collect and process your personal data for the purposes described in the Section "For what purposes are my personal data processed?" on one of the following legal bases:
- The processing of your personal data is necessary for performance of a contract with you or in order to take steps prior to entering into a contract with you at your request (Article 6, 1., (b) of the GDPR);
- The processing is necessary for the purposes of our legitimate interests or our affiliates' or other third parties' legitimate interests, and such interests are not overridden by your interests or fundamental rights and freedoms (Article 6, 1., (f) of the GDPR); The legitimate interests that we pursue notably include our interest to manage and maintain the contractual relationship with you, to answer to your specific requests, to ask your feedback in order to improve our Site and our products, or to pursue other general marketing activities.
- Where your specific consent is required to the processing of your personal data as described herein, your personal data will be processed based on such consent (Article 6, 1., (a) of the GDPR);
How long will my personal be data processed?
Personal data are not kept for longer than the time necessary to achieve the specific data processing purposes described herein. This may be up to 10 years after the end of the contractual relationship with you (statute of limitation for legal claims in most EEA countries), unless a shorter or longer retention period applies under applicable laws.
Are my personal data safe?
We are committed to protect the security and confidentiality of your personal data. We take – and require that any service provider and/or third party processor processing personal data on our behalf and on our instructions takes – appropriate technical and organizational measures to prevent loss and destruction, even accidental, of data, unauthorized access to data, unlawful or unfair use of data. Moreover, information systems and software programs are configured so that personal and identification data are used only when necessary to achieve the specific processing purpose from time to time sought.
We deploy a variety of advanced security technologies and procedures to help protecting personal data against the risks outlined above. For example, personal data provided by users are stored on secured servers placed in controlled locations. Moreover, for the transmission of some data through the Internet are deployed encryption techniques such as the Secure Socket Layer (SSL) protocol.
However, please note that no electronic transmission or storage of information is 100% secure. Therefore, despite the security measures that we have put in place to protect your personal data, we cannot guarantee that loss, misuse, or alteration of data will never occur.
Where do my personal data go? Who are the recipients, where is it transferred and for what purposes?
Personal data collected through our Site or other VF Digital Platforms, as part of the sale of goods in our stores and as part of our customer care, are stored on the servers provided and managed by our third-party storage and hosting provider Rackspace Limited, with registered offices at 5 Millington Road, Hyde Park Hayes, Middlesex, UB3 4AZ, servers located in London, United Kingdom. Certain personal data collected as part of the sale of goods in our stores might also be stored locally in the store. All these personal data may be shared with recipients as detailed below.
- Your personal data will be accessible within our organization by the internal and external personnel that need to access it because of their duties in relation to the processing purposes herein specified. We ensure that these persons are held by appropriate security and confidentiality duties.
Your personal data may also be accessible by third party service provider that we appoint to process personal data on our behalf and on our instructions (as data processors). These data processors include:
- third party service providers to which we may revert to for performance of professional, technical and organizational services functional to the managing of VF Digital Platforms and the activities performed therein, such as for example the sales of goods and related activities, the managing of functionalities offered by VF Digital Platforms and of the initiatives and services that you may subscribe to and require through VF Digital Platforms, and for services strictly functional to achievement of the other processing purposes herein specified;
- third party service providers to which we revert for closing purchase transactions and payment processing through our e-commerce platform;
third party service providers that are managing and supporting the VF Digital Platforms, the relevant e-com platform and all the pre- and post-sale activities, such as, order processing, performance marketing, financial services, warehouse management, and customer relationship management;
A list of these data processors, with indication of where they are located, is available upon request to our Privacy Office. These data processors are bound by appropriate contractual obligations to implement adequate security measures to protect security and confidentiality of personal data.
- Your personal data may also be communicated to other companies of the VF Group within the European Economic Area, processing personal data on behalf of the data controller(s) identified above. A list of these VF Group's companies, with indication of where they are located, is available upon request to our Privacy Office. For example, VF Europe BV provides accounting and back-office services and VF Northern Europe Ltd post-sale customer care, as data processors, to the data controllers identified above under "Who Controls the Processing of my Personal Data"
- Your personal data may also be shared with institutions, authorities, public entities, banks and financial institutions, professionals, independent consultants, also in associate form, business partners or other legitimate recipients as permitted by applicable laws and regulations, for example in case of judicial processes, request by competent courts and authorities or other legal obligation, to protect and defend our rights and property and VF Digital Platforms.
- Lastly, we may also communicate your personal data to third parties in case of mergers, acquisitions, transfers of any of our assets, products, websites or operations.
Except for the foregoing, personal data will not be shared with third parties, natural persons or legal entities, that are unrelated to, or that do not perform a business, professional or technical function for us.
Personal data will not be communicated to third parties for their own marketing purposes.
Such transfers take place on the processing bases identified in Section 3 above.
These abovementioned recipients may be located in countries other than the country in which personal data was originally collected, it being noted that your personal data will in principle only be transferred within the European Economic Area or other countries recognized by the EU Commission as adducing an adequate level of protection of personal data.
In case any of the above recipient is established in a country outside the EEA that is not covered by an adequacy decision of the European Commission and therefore does not provide the same level of protection for your personal as in the EEA, we shall implement appropriate safeguards, including, but not limited to relevant data transfer agreements based on the EU Commission Standard Contractual Clauses for the transfer of data to third countries (Article 46, 2., (c) of the GDPR,) or binding corporate rules (Article 47 of the GDPR). A copy of these appropriate safeguards may be obtained by contacting our Privacy Office at firstname.lastname@example.org
Am I obliged to provide my personal data? What are the consequences if I refuse to provide them?
Except in relation to the surfing data (please refer to the above section 3 - "What personal data are processed? ), providing your personal data may be a requirement necessary to enter into or to perform a contract, including for the performance of certain services and functionalities offered by VF Digital Platforms, such as subscription to the Site, subscription to our newsletter(s), the purchase of goods through the Site or in our stores, the management of participation to loyalty programs, promotions and other initiatives communicated through VF Digital Platforms or in our stores, replying to and managing of request of information, questions, communication or feedback. In the above referenced circumstances, refusal to provide your personal data would make it impossible for us to perform the contract or to provide the requested services, products or information as above specified.
Providing your personal data for survey, marketing and other profiling purposes, as above specified, is optional; refusal to provide your personal data for these purposes will not have any impact on the entering into or performance of the contract. When requested under Data Protection Laws, we will collect your prior consent before proceeding to processing your personal data for these purposes.
Do VF Digital Platforms contain elements controlled by third parties? Who is responsible and liable for these elements?
VF Digital Platforms may contain links to other sites, as well as objects or elements controlled by third parties.
An example is plug-ins that may connect VF Digital Platforms to social networks ("social plug-in") and that are usually identified by the relevant social network's logo. If you interact with a social plug-in on any VF Digital Platform, your browser may send such social network certain data relating to you, such as your user ID, information on the relevant VF Digital Platform, date and time, and other browser-related information. Such information will be processed by the social networks, owned and operated by third parties, according to their privacy policies.
What are my rights in relation to the processing of my personal data and how can I exercise them?
You are entitled at any moment to enforce the rights available to you under applicable Data Protection Laws, including, but not limited, to the right of access, rectification, restriction, erasure, opposition (including objecting, at any time and for free, to the processing of your personal data for direct marketing purposes), right to portability as well as the right to withdraw your consent. You also have the right to lodge a complaint with the competent supervisory authority.
For any query or request relating to the personal data processing by VF and to enforce the rights under Data Protection Laws, you may contact our Privacy Office at email@example.com.
Appendix 1 - Data Subject's Rights
Right of access
Subject to applicable law, you have the right to obtain confirmation from us as to whether or not personal data that concerns you is processed, and, if so, to request access to such personal data including, without limitation, the categories of personal data concerned, the purposes of the processing and the recipients or categories of recipients. However, we do have to take into account the rights and freedoms of others, so this is not an absolute right. If you request more than one copy of the personal data undergoing processing, we may charge a reasonable fee based on administrative costs.
Right to rectification
You have the right to request from us the rectification of inaccurate personal data concerning you. Depending on the purposes of the processing, you also have the right to request that incomplete personal data be completed, including by means of providing a supplementary statement.
Right to erasure ('right to be forgotten')
You have the right to request from us the erasure of personal data concerning you in certain circumstances as defined under applicable law. When your request falls within one of those circumstances, we will erase your personal data without undue delay. If, for technical and organisational reasons, we were not able to erase your personal data, we will ensure that it is fully and irreversibly anonymized so that we will not longer be holding such personal data about you.
Right to restriction of processing
In certain circumstances as defined under applicable law, you have the right to request the restriction of processing of your personal data. In such case, your personal data shall, with the exception of storage, only be processed with your consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another natural or legal person or for reasons of important public interest.
Right to data portability
In certain circumstances as defined under applicable law, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you may have the right to transmit that data to another data controller or to have such personal data transmitted directly from us to another data controller, where technically feasible.
Right to object
In certain circumstances as defined under applicable law, you have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data by us and we can be required to no longer process your personal data unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims. This notably applies in case of processing of your personal data based on our legitimate interests or for statistical purposes.
Right to object to direct marketing
Where your personal data are processed for direct marketing purposes, you have the right to object at any time to processing for such direct marketing (including profiling related to such direct marketing).
Right not to be subject to a decision based solely on automated processing
Subject to certain restrictions, you have the right not to be subject to a decision based solely on automated processed, including profiling, which produces legal effects on you similarly significantly affects you.
Right to withdraw consent
If you wish to access such personal data or exercise any of the rights listed above, you should apply in writing, providing evidence of your identity, to our Privacy Office at firstname.lastname@example.org.
Any communication from us in relation to your rights as detailed above will be provided free of charge. However, in case of requests that are manifestly unfounded or excessive, in particular because of their repetitive character, we may charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or refuse to act on the request.
In case you have a complaint about the processing of your personal data, you have the right to lodge a complaint with a competent supervisory authority.