Purpose and Scope
Although we encourage you to read this entire Privacy Statement, this is a summary of some of the more important aspects of the Privacy Statement:
· We may collect Personal Data and other information from you through a variety of sources, including Personal Data we have collected from you, on or offline. We may also combine it with information we receive about you from other sources, such as affiliates, publicly available information sources (including information from your publicly available social media profiles), and other third parties.
· We will not use or share your Personal Data except as described in this Privacy Statement.
· Where applicable, we honour opt-out instructions from you for certain uses of your Personal Data under this Privacy Statement, such as, for example, when you opt out of receiving marketing email communications from us or request us to delete your Personal Data.
· We use appropriate technical and organisational controls to secure and protect your Personal Data and whilst we cannot ensure or warrant that your Personal Data will be completely secure from misappropriation by hackers or from other nefarious or criminal activities we believe that our measures reduce the risk of such activities happening.
General Principles for the Processing of Personal Data
Personal Data will be collected, stored, processed and transmitted in accordance with our established policies and applicable local and international laws, rules and regulations.
The principles of this Policy with respect to the processing of Personal Data are as follows:
1. Personal Data will be processed fairly, lawfully and transparently,
2. Personal Data will be collected for specified, explicit, and legitimate purposes and not further processed for incompatible purposes,
3. Personal Data collected will be adequate, relevant, and not excessive in relation to the purposes for which it is collected,
4. Personal Data collected by Heron Preston Geschaft will be accurate and, where necessary, kept up to date to the best of our ability,
5. Personal Data will be protected against unauthorised access and processing using appropriate technical and organisational security measures and controls; and
6. Personal Data collected by Heron Preston Geschaft will be retained as identifiable data for no longer than necessary to serve the purposes for which the Personal Data was collected.
If Heron Preston Geschaft engages in the processing of Personal Data for purposes other than those specified in this Privacy Statement, Heron Preston Geschaft will provide notice of these changes, the purposes for which the Personal Data will be used, and the recipients of Personal Data.
Collection of Information
Heron Preston Geschaft may collect Personal Data about you from a variety of sources, including, directly from you, from our service providers, from third party information providers, from our Affiliates, and through the operation of the Website.
“Personal Data” collected by Heron Preston Geschaft includes:
· your first and last name;
· billing or shipping address;
· credit card or payment information;
· email address;
· phone number;
· purchase information and history;
· your account number;
· a combination of your username and password used to access the Website.
Sensitive Information (Special Categories of Data)
Unless we specifically request or invite it, we ask that you not send us, and you not disclose, any sensitive personal data (e.g. information related to racial or ethnic origin, political opinions, religion or other beliefs, health, criminal background or trade union membership) on or through this Website or otherwise to us. In those cases where we may request or invite you to provide sensitive personal data, we will do so with your explicit consent, which you may withdraw at any time.
Heron Preston Geschaft collects your Personal Data as follows:
Information You Provide Voluntarily
We may collect Personal Data directly from you when you voluntarily provide it to us. For example, when you communicate with us over the telephone or through the Website by way of email, online chat, web form, or online account registration to obtain access to Offerings, register for an event or training, purchase an Offering, ask questions, attempt to resolve any issues related to the Website or Offerings, or submit feedback and comments.
Information that We Collect Automatically
When you visit our Website, we may collect certain information automatically from your Device. In some countries, including countries in the European Economic Area, this information may be considered Personal Data under applicable data protection laws.
Specifically, the information we collect automatically may include information like your IP address, device type, unique device identification numbers, browser-type, your Media Access Control (MAC) Address, broad geographic location (e.g. country or city-level location) and other technical information. We may also collect information about how your device has interacted with our Website, including the pages accessed and links clicked. We may collect online behavioural data linked to online identifiers through tracking technology and this may be matched to personal data to improve our offerings to you. We will never process your personal data unlawfully and we will also ensure your rights and freedoms are protected.
We use this information for our internal analytics purposes and to improve the quality and relevance of our Website to our visitors. Some of this information may be collected using cookies and similar tracking technology, as explained further under the Section below: “Cookies and Other Website Usage Information.”
From Third Party Information Providers
Heron Preston Geschaft may obtain Personal Data from third parties that have obtained or collected information about you and that have the right to provide that Personal Data to us. Heron Preston Geschaft will only obtain this Personal Data where we have checked that these third parties either have your consent or are otherwise legally permitted or required to disclose your Personal Data to us.
Use of Information
Heron Preston Geschaft uses Personal Data we collect to operate our business and provide you with Offerings, which includes using this data to improve our Offerings and personalise your experiences. We also may use the data to communicate with you, for example, informing you about your account and product information.
Heron Preston Geschaft may use your Personal Data for a variety of purposes (the “Purposes”), including to:
· Provide you with the products and services you purchase. We provide these in line with our contractual obligations to you, either directly through us or through our partners;
· Provide, maintain and improve the Website and our Offerings, including to operate certain features and functionality of the Website;
· Understand user preferences to enhance users’ experience with Heron Preston Geschaft and its Affiliates, contractors, and business partners;
· Research and analyse the effectiveness of the Website and the marketing, advertising and sales efforts of Heron Preston Geschaft, its Affiliates, contractors, and business partners;
· Process orders and payments made through the Website;
· Develop additional Offerings;
· Comply with a legal obligation or respond to lawful requests by public authorities (including national security or law enforcement requirements);
· Manage our everyday business needs;
· Prosecute and/or defend a court, arbitration or similar legal proceedings;
· Communicate directly with you by sending you newsletters, promotions and special offers or information about new products and services on an ongoing basis in accordance with your marketing preferences. You can unsubscribe from our marketing communications by clicking “Unsubscribe” at the bottom of any communication we issue, or by contacting us;
· Communicate directly with you by email to respond to customer service inquiries or comments through the Website, social media or otherwise, to discuss issues relating to your account or the Website, and to provide customer support;
· Deliver advertising to you, including to help advertisers and publishers serve and manage ads on the Website or on third party sites, and to tailor ads based on your interests and browsing histories;
· Compile aggregated statistics about the operation and use of our Website and to better understand the preferences of the visitors of our Website; and
We may combine and enhance the Personal Data we collect about you with other information we receive from third parties to provide you with the best service possible.
We may also use the Personal Data we collect about you through the Website to generate anonymised, aggregated data. When we do so, we ensure that the anonymised, aggregated data is no longer personally identifiable and may not later be used to identify you.
We share your Personal Data as necessary to complete any transaction or provide any Offering you have requested or authorised or with your consent where appropriate. We also share Personal Data with vendors, resellers and distributors, service providers, Affiliates and business units when required by law.
We may share personal data internally with teams such as Sales, Customer Service, Finance, Marketing and Operations to ensure your products and services are delivered in line with your purchasing agreement with us. We will only ever process this data for as intended. We may do this to respond to legal process, to protect our customers, to maintain the security of our business, and to protect the rights or property of Heron Preston Geschaft. You can contact us anytime around how we share your data internally.
We may disclose your Personal Data as follows:
Affiliates and Business Units
Heron Preston Geschaft may share your Personal Data with our Partners regardless of whether these entities share the Heron Preston Geschaft brand. We may also share your Personal Data with other business units that also offer products or services under the Heron Preston Geschaft brand. Our Affiliates and business units will use your Personal Data we share with them in a manner consistent with this Privacy Statement.
Heron Preston Geschaft may share your Personal Data with other users when you elect to interact with those users (or request that we communicate with them on your behalf) through the Website. This may include facilitating communications with other users or enabling posting of Personal Data to areas of the Website accessible by other users. You should be aware that any Personal Data (or other information) you provide in these areas may be read, collected, and used by others who access them.
Law Enforcement and Safety
Heron Preston Geschaft may share your Personal Data with any competent law enforcement, regulatory, government agency, court, other governmental officials, or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) in connection with actual or proposed litigation, (iii) to exercise, establish or defend our legal rights or interests or protect our property, security and people, or (iv) to protect your vital interests or those of any other person.
Sale or Acquisition of Assets
If Olive & Orange Limited transfers ownership or control of any portion of www.heroned.shop to an actual or potential buyer, whether in the context of an acquisition, merger, reorganisation, or other disposition of all or any portion of our business, assets, or stock (including in connection with any bankruptcy or similar proceedings), we may transfer your Personal Data to that actual or potential buyer, provided that the use of your Personal Data by that third party remains subject to applicable law.
If you have asked us to share data with third party sites (such as social media sites), their servers may not be secure. Note also that, despite the measures taken by us and the third parties we engage, the internet is not secure. As a result, others may nevertheless unlawfully intercept or access private transmissions or data.
Other Important Privacy Information
Below you will find additional privacy information you may find important.
Your Data Protection Rights
You can exercise your rights at any time by contacting us using the information in the “Questions and Contact Information” section.
You have the following data protection rights:
1. The right to be informed
2. The right of access
3. The right to rectification
4. The right to erasure
5. The right to restrict processing
6. The right to data portability
7. The right to object
Similarly, if we have collected and process your Personal Data with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Data conducted in reliance on lawful processing grounds other than consent.
Security of Personal Data
Heron Preston Geschaft takes what it considers to be appropriate technical and organisational controls and measures to secure and protect your Personal Data from unauthorised or unlawful processing and against accidental loss or destruction of, or damage to it, or its misuse, and disclosure. These include strong user access controls, segmented network architecture and comprehensive employee policies and training. It is a priority of Heron Preston Geschaft to ensure all Personal Data is protected and secured to the highest level.
While no system is completely secure, we believe the measures implemented by Heron Preston Geschaft reduce our vulnerability to security problems to a level appropriate to the type of data involved. We have security measures in place to protect our user database and access to this database is restricted internally. However, it remains your responsibility:
· Where you have a client account for the website:
o To log off or exit from the website when not using it;
o To ensure no-one else uses the website while your device is logged on to the website (including by logging on to your device through a mobile, Wi-Fi or shared access connection you are using);
o To keep your password or other access information secret. Your password and log in details are personal to you and should not be given to anyone else or used to provide shared access for example over a network. You should use a password which is unique to your use of the website – do not use the same password as you use for another site or email account; and,
· To maintain good internet security. For example, if your email account is compromised this could allow access to your account with us if you have given those details and/or permitted access through those accounts. You should keep all your account details secure. If you think that any of your accounts have been compromised you should change your account credentials with us, and make sure any compromised account does not allow access to your account with us. You should also tell us as soon as you can so that we can try to help you keep your account secure and if necessary warn anyone else who could be affected.
Heron Preston Geschaft cannot ensure or warrant that Personal Data will be completely secure from misappropriation by hackers or from other nefarious or criminal activities, or in the event of a failure of computer hardware, software, or a telecommunications network. Heron Preston Geschaft will notify you in the event we become aware of a security breach involving your Personal Data (as defined by the applicable foreign, federal, state, and local laws) in line with our Breach Management process.
Legal Basis for Processing Personal Data
Our legal basis for collecting and using the Personal Data information described above will depend on the Personal Data concerned and the specific context in which we collect it. However, we will normally collect Personal Data from you only:
· Where we need the Personal Data to perform a contract with you (such as to fulfil your purchase of an Offering);
· Where the processing is in our legitimate interests and not overridden by your rights; or
· Where we have your consent to do so, which can be withdrawn at any time as mentioned above.
In some cases, we may also have a legal obligation to collect Personal Data from you or may otherwise need the Personal Data to protect your vital interests or those of another person.
A legitimate interest is when we have a business or commercial reason to use your information, so long as this is not overridden by your own rights and interests. If we collect and use your Personal Data in reliance on our legitimate interests (or those of any third party), this interest will normally be to operate our platform and communicating with you as necessary to provide our products and services to you, and for our legitimate commercial interest, for instance, when responding to your queries, improving our platform, or for the purposes of detecting or preventing illegal activities.
When we process your personal data for such marketing purposes (and other activities) we consider and balance any potential impact on you and your data protection rights. We will not use your personal data for marketing and other activities where the impact on you overrides our interests (unless we are otherwise lawfully permitted to do so). We may have other legitimate interests, and if appropriate, we will make clear to you at the relevant time what those legitimate interests are.
You have the right to object to processing based on legitimate interests. (This will not always mean we need to stop using your personal data, although for direct marketing-related processing we must stop if you ask us to). See Your ‘Data Protection Rights’ above.
It is your responsibility to provide Heron Preston Geschaft with accurate Personal Data. Except as otherwise set forth in this Privacy Statement, Heron Preston Geschaft shall only use Personal Data in ways that are compatible with the purposes for which it was collected or subsequently authorised by you. To the extent necessary for these purposes, Heron Preston Geschaft shall take reasonable steps to ensure that Personal Data is accurate, complete, current and relevant to its intended use.
International Data Transfers
Your Personal Data may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have data protection laws that are different to the laws of your country.
Specifically, our primary Website servers are in the The Netherlands and our partners operate around the world. This means that when we collect your Personal Data we may process it in any of these countries. However, we have taken appropriate safeguards to require that your Personal Data will remain protected in accordance with this Privacy Statement.
These include implementing the European Commission’s Standard Contractual Clauses for transfers of Personal Data between our Affiliates, which require us to protect Personal Data they process from the EEA in accordance with European Union data protection law. We have implemented similar appropriate safeguards with our partners.
We retain Personal Data we collect from you in line with our business retention periods. For example, where we have an ongoing legitimate business need to do so (such as to provide you with a product or service, or to comply with applicable legal, tax or accounting requirements), we may retain the data for up to 7 years.
Third Party Websites
Heron Preston Geschaft will use a self-assessment approach to verify compliance with this Privacy Statement and periodically verify that the Privacy Statement is accurate, comprehensive for the information intended to be covered, prominently displayed, implemented and accessible.
Heron Preston Geschaft may from time to time revise this Privacy Statement in its sole and absolute discretion to reflect changes in our business practices. If we revise this Privacy Statement, we will notify you by posting the updated Privacy Statement on this Website. We will always seek your consent for any changes in the way we process your personal data, as required by applicable data protection laws.
Purpose and Scope