This Privacy statement has been created by Mr. Sossa B.V. (hereafter ‘Mr Sossa’, ‘We’ or ‘Us’) for the purpose of protecting the privacy and security of personal data.
This Privacy statement explains how Mr Sossa collects and uses personal data.
Mr Sossa applies from 01 December 2018 and may be updated from time to time.
Mr. Sossa B.V.
P.O. Box 18
5750 AA Deurne
This Privacy statement applies to you if you:
- are a customer of Mr Sossa;
- have a subscription to the Mr Sossa newsletter or participate in a promotional activity of Mr Sossa;
- visit the website of Mr Sossa (mrsossa.com) or one of the underlying sub-pages (“Website”);
What personal data does Mr Sossa process and for which purpose?
In the course of its business activities and offering and providing the products and services, Mr Sossa will need to process personal data. “Personal Data” is any information that can directly or indirectly be used to identify a natural person. You provide most of your personal data directly to Mr Sossa.
Below, we will explain per category as indicated in paragraph 1 which personal data is processed by Mr Sossa, for which purpose(s) and on which legal basis. It is possible that you fall in more than one category, for instance if you are a customer of Mr Sossa and also participate in Mr Sossas promotional activity.
Category A. You are a customer of Mr Sossa
Mr Sossa processes personal data of its customers to enable the sale of products, for which Mr Sossa needs to be able to enter into an agreement with you, process your payment and ship the product to you. Furthermore, it is necessary for Mr Sossa to conduct related processing such as provide security, fraud prevention and credit checks and registration.
In this context, Mr Sossa processes the following personal data:
- Contact information, including your name, (invoice and delivery) address, e-mail address and phone number;
- Personal information, including your date of birth and preferences;
- Order information, including product, size, payment method, shipping method, order history;
- Financial information, including your bank account number, credit card number, invoice specifications, order amount, payment status;
- Optional information, such as your gender, company information and account details.
Furthermore, you can make use of the Accountservice of Mr Sossa:
to optimize and simplify your shopping experience, you can create an account on the Webiste. To create an account, Mr Sossa needs the following information:
- Contact information, including your name, address, e-mail address and phone number;
- Account information, including your e-mail address and password.
Category B. Customer Service
If you have questions or complaints regarding the products or services of Mr Sossa, you can contact Mr Sossas customer service. Before Mr Sossa can process your question or complaint, Mr Sossa may need to verify your identity based on your personal data. In the course of the customer service activities, Mr Sossa may receive the following personal data:
- Contact information, including your name, address, e-mail address, age, gender, data of birth, nationality and phone number;
- Content, including the subject of the message, remarks, images and screenshots, the content of the telephone conversation;
- Optional information, such as order number.
Category C. You have a subscription to the Mr Sossa newsletter or participate in a promotional activity of Mr Sossa
Mr Sossa would like to keep you informed of news relating to Mr Sossa and send you special offers. If necessary we will ask your consent before sending you our newsletters and offers. To send you our newsletter, Mr Sossa processes the following information:
- Contact information, including your name, address, e-mail address, age, gender, data of birth, nationality, phone number, Social Media details;
- Order information, including order history, preference history, products in basket;
Category D. You visit the Website
If you visit the Website, Mr Sossa will – after obtaining your consent where legally required – automatically collect information by means of cookies and similar technologies. This information may consist of:
- Technical data like IP-address or cookie-id;
- Information about your connection to the website, including the date, time and type of the connection;
- Social Media details, such as account details.
Mr Sossa uses this personal data for the following purposes:
- To perform our obligations under our agreement with you;
- To remember your language and other preferences;
- To help you obtain information you are looking for;
- To provide a safe and secure service and transactions;
- To measure how many people use our sites, and how they use them, to keep our sites running efficiently and to better understand our audiences;
- To secure, amend and improve our Website;
- To provide your information to third parties in accordance with this Privacy statement.
Who has access to your personal data ?
Mr Sossa may share your personal data with third parties in the following circumstances:
- Mr Sossa may share your personal data with its affiliates, operating groups, subsidiaries and divisions, or with third parties if such is necessary for the purposes as listed above. If appropriate, Mr Sossa will require third parties to conduct activities in a manner consistent with Mr Sossa policies and guidelines in relation to data protection.
- Mr Sossa may share your personal data with data processors, i.e. parties processing personal data on our behalf. In such cases, these third parties may only use your personal data for the purposes described above and only in accordance with our instructions. Mr Sossa will only use processors which provide sufficient guarantees to implement appropriate technical and organizational measures and ensure the protection of the rights of data subjects.
- Mr Sossa employees may have access to your personal data if necessary for the performance of their tasks. In such a case, access will be granted only if necessary for the purposes described above and only if the employee is bound by confidentiality.
- Mr Sossa may share your personal data if required to do so by law, court order, or other legal process, for example, with law enforcement agencies or other governmental agencies, to establish or exercise our legal rights or in connection with a corporate transaction, such as a divesture, merger, consolidation, or asset sale, or in the unlikely event of bankruptcy.
How long will Mr Sossa keep your personal data?
Mr Sossa retains your personal data for a limited amount of time and will delete your personal data after it is no longer necessary for the purposes of the processing. The exact period of time is based on the type of the personal data and the legal obligations or business purposes for retaining it. After the retention period, the personal data will be either destroyed or anonymized.
What measures does Mr Sossa take to protect your personal data?
Mr Sossa has taken appropriate technical and organizational measures to protect your personal data against accidental or unlawful processing, including by ensuring that:
- your personal data is protected against unauthorized access;
- the confidentiality of your personal data is assured;
- the integrity and availability of your personal data will be maintained;
- personnel is trained in information security requirements; and
- actual or suspected data breaches are reported in accordance with applicable law.
Where does Mr Sossa store and transfer your personal data?
Due to the nature of our business and the services we provide to our clients, Mr Sossa may need to transfer your personal data to locations outside the country where you reside. In any case where we transfer personal data, Mr Sossa shall ensure that such a transfer is subject to appropriate safeguards.
For the European Union, such transfers to third parties may for instance be governed by a contract based on the model contractual clauses for data transfers approved by the European Commission as set out in article 46(2) of the General Data Protection Regulation. You can obtain an extract or copy of these documents by making a request using the contact details above.
What rights can you exercise in relation to your personal data?
Based on the law applicable to the use of your personal data, you may be able to exercise a number of rights in relation to your personal data. Note that in many cases, your rights are not absolute and we may not be required to comply with your request. A number of such rights, as may be applicable in the European Union, are explained below.
Right of access
You are entitled to a copy of the personal data we hold about you and to learn details about how we use it. Your personal data will usually be provided to you digitally.
Right to rectification
We take reasonable steps to ensure that the information we hold about you is accurate and complete. However, if you believe this is not the case, you can ask us to update or amend it.
Right to erasure
In certain circumstances, you have the right to ask us to erase your personal data, for example where the personal data we collected is no longer necessary for the original purpose, where personal data has become obsolete or where you withdraw your consent. However, this will need to be balanced against other factors. For example, we may not be able comply with your request due to certain legal or regulatory obligations.
Right to restriction of processing
In certain circumstances, you are entitled to ask us to (temporarily) stop using your personal data, for example where you think that the personal data we hold about you may be inaccurate or where you think that we no longer need to use your personal data.
Right to data portability
In certain limited circumstances, you may have the right to ask that we transfer personal data that you have provided to us to a third party of your choice.
Right to object
You have the right to object to processing which is based on our legitimate interests. Unless we have a compelling legitimate ground for the processing, we will no longer process the personal data on that basis when you file an objection. Note however, that we may not be able to provide certain services or benefits if we are unable to process the necessary personal data for that purpose.
Rights relating to automated decision-making
You have the right not to be subjected to automated decision-making, including profiling, which produces legal effect for you or has a similar significant effect. If you have been subject to an automated decision and do not agree with the outcome, you can contact us using the details below and ask us to review the decision.
Right to withdraw consent
We may ask for your consent to process your personal data in specific cases. When we do this, you have the right to withdraw your consent at any time. Mr Sossa will stop the further processing as soon as possible after the withdrawal of your consent. However, this does not affect the lawfulness of the processing before consent was withdrawn.
Please use the contact details above if you would like to exercise any of your rights.
What if you have other questions or complaints?
Questions or complaints regarding the processing of your personal data can be directed at Mr Sossa by using the contact information as provided at the top of this Privacy statement.