Black Diamond Equipment Europe GmbH (“BDEU,” or “we,” “us,” or “our”) respects your privacy and is strongly committed to transparency.
This Privacy Notice (our “Privacy Notice” or “Notice”) describes (i) the types of information we may collect from or about you or that you may otherwise provide when you access or interact with our website, eu.blackdiamondequipment.com/ (the “Website” or “Site”), visit one of our retail stores in Europe or otherwise communicate with us, (ii) our practices for collecting, using, disclosing, protecting, and otherwise processing that information while operating our business, and (iii) your rights and choices with respect to such information.
This Privacy Notice applies solely to individuals located in the European Economic Area (“EEA”) and/or the United Kingdom (“UK”) with whom BDEU interacts including, but not limited to, BDEU’s Website users, customers (current and prospective), and individuals acting in their professional capacity as a representative of a vendor or other third-party company doing business with BDEU.
In addition, this Privacy Notice applies to information we collect:
· on our Website;
- in email, text, and other electronic communications between you and us, such as when you contact us or otherwise submit information to us, whether by telephone or through other means;
· when you interact with our advertising and applications on third-party websites and services, if those applications or advertising include links to this Privacy Notice;
· about you offline, such as in connection with your inquiries into or purchase or use of our products; and
· from third parties.
This Privacy Notice does not apply to information collected by:
- us in any other way offline or through any other means, including on any other websites operated by BDEU or any third party (including our parent, affiliates, and subsidiaries);
· us, our parent or any of our affiliates or subsidiaries related to your or any other individual’s employment or potential employment with us;
· any third party (including our parent, affiliates, and subsidiaries), including through any application or content (such as advertising) that may link to or be accessible from the Website.
We adopt this Privacy Notice to comply with the European Union’s (“EU”) General Data Protection Regulation, and any laws implementing the foregoing by any member states of the EEA and the UK (including the UK Data Protection Act and the UK-GDPR) (collectively, the “GDPR”). Unless otherwise defined in this Privacy Notice, any terms defined by the GDPR have the same meaning when used in this Privacy Notice.
Please read this Privacy Notice carefully to understand our policies and practices regarding your information and how we will treat it before accessing our Website or otherwise engaging with us for our products or services. If you do not agree with our policies and practices, your choice is not to use our Website, products, or services. By accessing or using our Website, products, or services, you agree to this Privacy Notice. This Privacy Notice may change from time to time (see Changes to Our Privacy Notice). Your continued use of our Website, products, or services after we make changes is deemed to be acceptance of those changes, so please check this Privacy Notice periodically for updates.
2. DATA Controller
BDEU is the controller of your Personal Data with offices at Hans-Maier-Strasse 9, 6020 Innsbruck, Austria, and it may be contacted in any manner set forth below in the Contact Information section of this Privacy Notice. At this time, BDEU is not required to appoint a Data Protection Officer or representatives in the EU or UK and has elected not to do so.
3. Information We Collect About You
We collect two basic types of information from you when you provide it to us or when you use or interact with our Website or through our advertising and media across the Internet: Personal Data and non-Personal Data.
Personal Data means any information relating to an identified or identifiable natural person. However, Personal Data does not include any anonymized information. We collect the following types of Personal Data from you depending upon how you interact with us in the online and offline context.
· Identifiers and Contact Data. This includes name, postal address (including billing and shipping address), email address, telephone number (including mobile number), business contact information (such as company name, title, and work email address and/or phone number), online identifiers, and other similar identifiers and contact details.
· Demographic Data. Age; gender (if you are a member of our Pro Program, we may ask you to indicate the gender style of clothes you are purchasing, so we can verify that you are purchasing those items for yourself rather than for someone else).
· Physical Characteristics. Height and weight (if you use the size recommendation solution on our Website).
· Financial Data. Credit, debit or bank account number, or other payment information.
· Order Information. Information about your order details, including the order number, item purchased, date and location of purchase (online or in-store), price of the item, the payment method used; records of products purchased, obtained, or considered, or other purchasing or consuming histories or tendencies; other information as requested to facilitate or complete delivery or to make available and provide ongoing support, maintenance, repair, training, or other services related to the product(s) being purchased.
· Account Information. If you create an account, we may store and use your name, email address, zip or postal code and other Personal Data you may provide with your account.
· Usage Information. This includes data you provide through your use of our Website, including IP address, browser type and version, browser plug-in types and versions, operating system and platform, device type, advertising ID, browsing history, traffic data, date and time of your visit, general location data (derived from your IP address which may be used to locate the city and state that you are in when you access our Site but cannot be used to precisely locate you), precise geolocation data (if you have opted-in to sharing your location with us through the “locally widget” or a browser prompt from within BDEU's Website), preferences, information collected through cookies and web beacons, and other communication data and the resources that you access, use, or otherwise interact with when using our Site.
· Communications Data. This includes (transcripts of) phone calls and records (or copies) of your electronic communications or correspondence with BDEU or its customer service department.
· Professional or Employment-related Information. If you are applying to participate in (or are otherwise a participant of) our Pro Program, we will collect information related to your professional credentials, licensures, and other qualifications, as well as proof of employment documentation.
· Inferences. Inferences drawn from or created based on any of the information identified in this list to create a profile about, for example, your preferences.
Non-Personal Data includes information that does not personally identify you or information that has been anonymized (collectively, “non-Personal Data”). When we combine non-Personal Data with Personal Data, we treat the combined information as Personal Data.
You can always refuse to provide your Personal Data, but please note that some Personal Data is necessary to make our Website, products, and services available to you. For example, some of the Personal Data we collect from you is required to enter into a contract with BDEU, for BDEU to perform under the contract, and to provide you with our products and services. If you refuse to provide such Personal Data or withdraw your consent to our processing of Personal Data (when appropriate), then in some cases we may not be able to enter into the contract or fulfill our obligations to you under it.
In addition, we do not ask you to provide, and we do not knowingly collect, any Special Categories of Personal Data from or about you.
4. How We Collect Personal Data
We collect your Personal Data from various sources, including:
· directly from you when you provide it to us;
· automatically as you access, navigate through, or otherwise use our Website; and
· information that we create about you as you use our Website; and
· from third parties.
Information You Provide to Us
You may provide us with Personal Data in several ways, including, for example when you:
· Visit or otherwise use or interact with our Website (e.g., making a purchase, posting a product review, etc.);
· Register or create an account with us;
· Purchase our products (in-store), submit a warranty claim, or engage in another transaction with us;
· Correspond with us in any way and enter into a contest or promotion sponsored or offered by or through us;
· Sign up to receive our newsletters, promotional information, or other marketing communications;
· Ask for customer service, support or other assistance; or
· Interact with us in any other way, including, but not limited to, by phone, email, or in-person while at our store.
This information generally includes any of the categories of Personal Data described above in Section 3 (with the exception of Usage Information and Inferences).
Please note that when you make a purchase on our Website, our third-party payment processor (Shopify Payments) generally collects and processes your payment-related information, including your bank account, credit or debit card number or other financial account details. In this context, Shopify’s policies and practices may apply with respect to Personal Data collected by Shopify Payments through your transaction. Shopify is an independent third party, and we are not responsible for how it treats such Personal Data. if you create a “Shop Pay” account, any information, including Personal Data, you submit in connection with that account is collected by Shopify and Shopify’s use of your information is governed by its privacy policy, which can be found here.
In addition, you also may provide information to be published or displayed (hereinafter, “posted”) on public areas of our Website or transmitted to other users of the Site or third parties (collectively, “User Contributions”). Your User Contributions are posted on and transmitted to others at your own risk. We cannot control the actions of other users of our Website with whom you may choose to share your User Contributions. Therefore, we cannot and do not guarantee that your User Contributions will not be viewed by unauthorized persons.
Information We Collect Through Automatic Data Collection Technologies
We and our service providers or partners engage in automatic data collection to provide content, advertising, functionality, and other services that measure and analyze ad performance or user behavior on the Website, and may use cookies and/or web beacons to understand usage of the Website and improve our content and offerings and to deliver advertisements in which you might be interested. These technologies collect statistical and other information, including Personal Data (such as Usage Information), about you and your use of the Website. Some of the tracking technologies we and our service providers or partners may use include:
· Cookies (or browser cookies). These are small text files that may be placed on your computer or device by us or our service providers and partners when you visit our Website. Some of these cookies are managed by us (first-party cookies), while others are managed by third parties that we do not control (third-party cookies). A cookie assigns a unique identifier to your web browser or device and may enable us, our vendors, or third parties to recognize you as the same user who has used the Website and relate your use of the Website to other information about you, such as your usage information and other Personal Data. We may use cookies in a variety of ways. For example, we may use cookies to:
o Provide us with information about which portions of our Website are the most popular by enabling us to see what web pages a user visits and how much time a user spends on each page.
o Personalize your experience on our Website (e.g., to recognize you by name when you return to our site, to save your password in password-protected areas, to enable shopping carts, or to tailor content, or product and service offerings).
o Help us advertise to you and understand which ads you have seen.
These small data files serve various functions:
o Necessary: These are cookies that are strictly necessary for the functioning of our Site or for performing services that an individual user has requested. For instance, these cookies are necessary to allow us to operate our Site so you may access it as you have requested. These cookies let us recognize that you have created an account and have logged into that account to access the Site. They also include cookies that enable us to remember your previous actions within the same browsing session.
o Preferences: Enhances the performance and functionality of our Website but are non-essential to their use. However, without these cookies, certain functionality may become unavailable.
o Statistics: Allows us to understand the effectiveness of our services and marketing campaigns, as well as to customize our services based on this information.
o Advertising: Personalizes the ads delivered to you on our Site and on other sites. These cookies collect data about your online activity and allow ads to be displayed that may be of relevant interest to you. These cookies also record which ads you have seen and whether you engaged with the ad. These cookies help make sure that the ads you see are valuable to you and not repetitive.
Except for those cookies that are necessary for the operation of our Website, we will only use cookies if we have your explicit consent to use them in the UK and the EEA.
· Web Beacons. A web beacon is an electronic image called a single-pixel, pixel tags, or “clear gifs” that is a small piece of code that is used to collect anonymous and aggregate advertising metrics, such as the counting of page views, promotion views, or advertising responses. Web beacons can recognize certain types of information, such as a user’s cookie number, time and date of a page view, and description of the page where the web beacon is placed. These web beacons may be used to deliver cookies. Pages of our Website and our e-mails may contain web beacons.
Third-Party Use of Cookies and Other Tracking Technologies
Some content or applications, including advertisements, on the Website are served by third parties, including advertisers, content providers, and analytics providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Website. The information they collect may be associated with your Personal Data or they may collect information, including Personal Data, about your online activities over time and across different websites and other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control these third parties’ tracking technologies or how they may be used. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For information about how you can opt out of receiving targeted advertising from many providers, you can learn more about interest-based advertisements and your opt-out rights and options from members of the European Interactive Digital Advertising Alliance on its website (https://edaa.eu/ and http://www.youronlinechoices.eu).
Information We Create About You
We may also create certain information about you. When we associate this information with other Personal Data about you, we consider this information to be Personal Data. This information includes information associated with your account with us (if one exists) [Account Information]; records of products or goods purchased, obtained, or considered, or other purchasing or consuming histories or tendencies [Order Information]; and a profile reflecting your preferences [Inferences]; and transcripts of phone calls of your electronic communications with us and/or customer service [Communications Data].
Information We Collect from Third Parties
In certain instances, we may also collect limited Personal Data from third parties, such as your employer if you have applied to become a member of our Pro Program. This information may include certain Identifiers and Contact Data, including your name and email address.
5. How We Process Your Personal Data
We process your Personal Data for specific purposes. Those purposes for our processing and the individual lawful basis associated with each such processing activity are set out below.
Purposes of Processing |
Categories of Personal Data |
Legal Basis for Processing |
· To track, process, and fulfill orders, shipments, purchases, returns, warranties, and similar transactions, as well as to prevent transactional fraud |
· Identifiers and Contact Data · Demographic Data · Financial Data · Order Information · Account Information |
· Contractual necessity · Legitimate interest (e.g., fraud prevention, fulfilling customer orders, etc.) |
· To provide you with customer service (e.g., responding to your inquiries or requests; communicating with you regarding your transaction; investigating and addressing your concerns; monitoring and improving our responses; etc.) |
· Identifiers and Contact Data · Financial Data · Order Information · Physical Characteristics · Account Information · Communications Data |
· Legitimate interest to ensure that we can handle your request in a way that meets your expectations |
· To provide our Website and its content to you, as well as allow you to participate in interactive features on our Website |
· Usage Data |
· Legitimate interest to make our Website and related products and services available to you to access, use, or otherwise purchase · Consent (if you have opted in to our use of non-essential cookies/web beacons) |
· To create, maintain, customize, and secure your account with us (if you have one) |
· Identifiers and Contact Data · Demographic Data · Financial Data |
· Consent (if you have registered an account with us) |
· To verify professional credentials and proof of employment for acceptance into our Pro Program |
· Identifiers and Contact Data · Professional or Employment-related Information |
· Consent (if you voluntarily apply to become a Pro Program member) · Contractual necessity |
· To administer surveys, sweepstakes, promotions, and other contests offered by or through BDEU that you participate in or otherwise enter |
· Identifiers and Contact Data
|
· Consent (if you voluntarily participate in these surveys, sweepstakes, promotions, or other contests) |
· To facilitate our rewards/ loyalty program(s) |
· Identifiers and Contact Data · Usage Data · Account Information · Order Information |
· Consent (if you have opted in to participate in our rewards/loyalty program(s)) |
· To operate and optimize our business, improve our Website, products and services, personalize your experience with us, and deliver content and product and service offerings relevant to your interests, including targeted offers and ads through our Website, third-party sites, and via email or text message. This also includes advertising or marketing our products and services to you (such as through newsletters, marketing offers, promotions, and other similar communications that we send to you). |
· Identifiers and Contact Data · Demographic Data · Order Information · Physical Characteristics · Usage Data · Account Information · Order Information · Communications Data · Inferences |
· Legitimate interests to (i) conduct our daily business and communicate with (prospective) corporate customers or suppliers, (ii) provide visitors to our Website with the best possible user experience (and thus analyze trends and website traffic to administer and optimize our services), and (iii) perform direct marketing · Consent - if you have opted in to our use of non-essential cookies/web beacons and to receive marketing-related communications from us |
· To measure and report on the delivery of ads (including counting ad impressions to unique visitors, verifying positioning and quality of ad impressions), and auditing compliance with this specification and other standards |
· Identifiers and Contact Data · Usage Data |
· Consent (if you have opted in to our use of non-essential cookies/web beacons) |
· To monitor the performance of our Website, including metrics such as total number of visitors, and traffic |
· Identifiers and Contact Data · Usage Data |
· Consent (if you have opted in to our use of non-essential cookies/web beacons) |
· To notify you about changes to our Website or any products we offer or provide though them |
· Identifiers and Contact Data
|
· Compliance with a legal obligation · Legitimate interest to ensure you are presented with the most current updates to our Website and products |
· To help maintain the safety, security, and integrity of our Website, products and services, databases and other technology assets, and business, including to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, and prosecute those responsible for that activity |
· Identifiers and Contact Data · Usage Data |
· Legitimate interests to (i) comply with our legal and regulatory obligations, (ii) ensure the security of our systems and data to a standard that goes beyond our legal obligations, (iii) protect our data and systems, and (iv) prevent and detect criminal or unauthorized activity that could be damaging for you and/or us |
· To verify or maintain the quality or safety of a product that is owned, manufactured for, or controlled by us |
· Order Information · Communications Data |
· Compliance with a legal obligation · Legitimate interest to ensure the quality and safety of our products meets your expectations and industry standards |
· To evaluate or conduct a significant corporate transaction or restructuring, including a merger, acquisition, dissolution or other sale or transfer of some or all of BDEU’s assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, in which Personal Data held by BDEU is among the assets transferred |
· Identifiers and Contact Data |
· Compliance with a legal obligation · Legitimate interest of BDEU (or of a third party) to protect, realize, and grow the value in our business and assets |
· To (i) carry out our legal and contractual obligations, (ii) enforce our rights arising from any contracts entered into between you and us, (iii) exercise or defend legal claims, (iv) respond to legally binding requests from law enforcement, regulatory authorities, or other third parties or as otherwise may be required by applicable law, court order, or governmental regulations, and (v) and for litigation case management and evidentiary purposes |
· Identifiers and Contact Data · Demographic Data · Financial Data · Account Information · Order Information · Usage Information · Communications Data · Inferences · Professional- or Employment-related Information |
· Compliance with a legal obligation · Legitimate interest to manage legal proceedings and to defend BDEU against any possible civil claims or regulatory enforcement action [*Note: BDEU may process some or all of the Personal Data listed in the preceding column if necessary to comply with a valid request from a regulator or other official body of authority, or where it is relevant to any ongoing or prospective legal proceedings.] |
6. Lawful Basis for Processing Your Personal Data
The processing of your Personal Data is lawful only if it is permitted under the GDPR. As noted above, we have a lawful basis for each of our processing activities (except when an exception applies as described below):
· Consent. By using our Website, you consent to our collection, use, and sharing of your Personal Data as described in our Privacy Notice. If you do not consent to the terms of this Privacy Notice, please do not use the Website. We will also ask for or otherwise obtain your consent to process your Personal Data in certain circumstances, such as to: (i) communicate with you about our products and services; (ii) provide you with marketing, promotional, and similar information or materials; and (iii) place cookies (that are not necessary for the operation of our Website) and/or related technologies onto your device when you visit our Website.
· To Fulfill Our Obligations to You Under our Contract. We process your Personal Data as necessary to perform our responsibilities under our contract with you – for example, to process your order and deliver the product(s) you purchased.
· Compliance with Legal Obligations. To meet our regulatory and legal obligations, we may need to process some of your Personal Data.
· Legitimate Interests. We will process your Personal Data as necessary for our legitimate interests. Our legitimate interests are balanced against your interests and rights and freedoms and we do not process your Personal Data if your interests or rights and freedoms outweigh our legitimate interests. We process your Personal Data only as far as it is necessary to achieve the purpose outlined in our Privacy Notice. Our processing activities will not unreasonably intrude on your privacy and ultimately benefits you in optimizing its provision of the Website and its features to you. Specifically, we rely upon on several legitimate interests for processing your Personal Data, as set forth in the table above in Section 5.
7. Disclosure of Your Information
We may disclose your information as needed to fulfill the purposes described in this Notice and as permitted by applicable law.
· When We Work Together. We may share information between and among BDEU and its parent company, Black Diamond Equipment, Ltd. for purposes of system administration, configuration assistance, troubleshoot support, processing warranty claims, and other business purposes.
· When We Work with Service Providers & Business Partners. We may share each of the categories of Personal Data described above, for a variety of business purposes, with our service providers and business partners who provide an array of services such as payment processing, website and data hosting, product and service delivery, customer service, advertising and marketing (including counting ad impressions and audience creation), facilitating sweepstakes and BDEU loyalty/rewards program benefits and communication, ensuring compliance with industry standards, personalization, analytics services, maintaining and servicing accounts, processing or fulfilling orders and transactions, verifying customer information, research, auditing, and data processing. We strive to contractually prohibit these service providers and business partners from retaining, using, or disclosing your Personal Data for any purpose other than performing agreed upon services for us.
· When We Work on Business Transactions. If we become involved with a merger, corporate transaction or another situation involving the transfer of some or all of our business assets, we may share your information with business entities or people involved in the negotiation or transfer.
· When Sharing Helps Us Protect Safety and Lawful Interests. We may disclose your information if we believe that the disclosure is required by law, if we believe that the disclosure is necessary to enforce our agreements or policies, or if we believe that the disclosure will help us protect the rights, property, safety of BDEU or our customers or partners.
· When You Give Consent. We may share information about you with other companies if you give us permission or direct us to share the information.
· When You Post on Our Website. If you post information on our Website, such as in the form of a product review, the information that you post may be seen by other visitors to our Website. We are not responsible for the information you choose to submit in these public areas.
8. Automated Decision-Making
We do not use your Personal Data with any automated decision-making process, including profiling, which may produce a legal effect concerning you or similarly significantly affects you.
9. Your Rights
The GDPR provides you with certain rights with regards to our processing of your Personal Data. These rights replace the similar rights provided in our Privacy Notice or are supplemental to such rights.
· Access and Update. You can review and change your Personal Data we have about you by notifying us through the Contact Information below of any required changes or errors in to ensure that it is complete, accurate, and as current as possible. You could also modify some of the Personal Data associated with your account (if you have one with us) via your account settings. We may not be able to accommodate your request if we believe it would violate any law or legal requirement or cause the information to be incorrect.
· Restrictions. You have the right to restrict our processing of your Personal Data under certain circumstances. In particular, you can request we restrict our use of it if you contest its accuracy, if the processing of your Personal Data is determined to be unlawful, or if we no longer need your Personal Data for processing but we have retained it as permitted by law.
· Portability. To the extent the Personal Data you provide to BDEU is processed based on your consent or contractual necessity and we process it through automated means, you have the right to request that we provide you a copy of, or access to, all or part of such Personal Data in structured, commonly used and machine-readable format. You also have the right to request that we transmit this Personal Data to another controller, when technically feasible.
· Withdrawal of Consent. To the extent that our processing of your Personal Data is based on your consent, you may withdraw your consent at any time by closing your account or notifying us through the Contact Information below. In addition, where you have consented to (i) our use of non-essential cookies, you may withdraw your consent at any time by accessing the cookie consent manager on our Website or adjusting your browser’s settings to refuse those cookies, or (ii) receive marketing-related communications from us, you may withdraw your consent at any time by clicking the “unsubscribe” link at the bottom of any email you receive from us or replying with the word “STOP” to any text message you receive from us. Withdrawing your consent will not, however, affect the lawfulness of the processing based on your consent before its withdrawal, and will not affect the lawfulness of our continued processing that is based on any other lawful basis for processing your Personal Data.
· Right to be Forgotten. You have the right to request that we delete all of your Personal Data. We will only delete your Personal Data when we no longer have a lawful basis for processing your Personal Data or after a final determination that your Personal Data was unlawfully processed. We may not accommodate a request to delete information if we believe the deletion would violate any law or legal requirement or cause the information to be incorrect. In all other cases, we will retain your Personal Data as set forth in this Notice.
· Complaints. You have the right to lodge a complaint with the applicable supervisory authority in the country you live in, the country you work in, or the country where you believe your rights under applicable data protection laws have been violated. If you are located in the UK, you may lodge such a complaint with the Information Commissioner’s Office in the UK. However, before doing so, we ask that you contact us directly using the Contact Information below to give us an opportunity to work with you to resolve any concerns about your privacy.
· How You May Exercise Your Rights. You may exercise any of the above rights by contacting us through any of the methods listed under Contact Information below. If you contact us to exercise any of the foregoing rights, we may ask you for additional information to verify your identity. We reserve the right to limit or deny your request if you have failed to provide sufficient information to verify your identity or to satisfy our legal and business requirements. Please note that if you make unfounded, repetitive, or excessive requests (as determined in our reasonable discretion) to access your Personal Data, you may be charged a fee subject to a maximum set by applicable law.
10. Consent to Transfers outside the EEA and UK
In order to provide our Website, products, and services to you, your Personal Data may be transferred to, stored, and/or otherwise processed in a country other than the one in which it was collected, including the United States. For instance, your Personal Data may be processed by staff operating outside the EEA and UK who work for our parent company, Black Diamond Equipment Ltd., or is otherwise stored outside the EEA and UK for any of the purposes described in this Notice. Accordingly, your Personal Data may be stored and processed outside the country where you reside or are located, including to countries that may not or do not provide an equivalent level of protection for your Personal Data. In limited circumstances, federal, state, and local governments, courts, or law enforcement or regulatory agencies in the United States may be able to obtain disclosure of your information through the laws of the United States. By using our Website, you represent that you have read and understood the above and hereby consent to the storage and processing of Personal Data outside the country where you reside or are located, including in the United States.
Your Personal Data is transferred by BDEU to another country only if it is required or permitted under applicable data protection law and provided that there are appropriate safeguards in place to protect your Personal Data. To ensure your Personal Data is treated in accordance with the Privacy Notice, BDEU uses Data Protection Agreements between itself and all other recipients of your data that include, where applicable, the standard contractual clauses adopted by the European Commission and/or the Information Commissioner’s Office (“ICO”) in the UK (collectively, the “Standard Contractual Clauses” or “SCCs”).
The European Commission and the ICO in the UK have determined that the transfer of Personal Data pursuant to the SCCs provide for an adequate level of protection of your Personal Data, however, the SCCs may need to be supplemented in some cases with additional measures on a case-by-case basis after an analysis that such supplemental measures can provide you with an essentially equivalent level of protection as afforded in the EEA and/or the UK. When, as a result of this analysis, we believe this to be appropriate and necessary, the SCCs have been supplemented in this way. Under these SCCs, you have the same rights as if your Personal Data was not transferred to such third country. You may request a copy of the Data Protection Agreement by contacting us through the Contact Information below.
11. Data security
We have implemented measures designed to secure your Personal Data from accidental loss and from unauthorized access, use, alteration, and disclosure. The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Website, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the Internet is not completely secure. Although we do our best to protect your Personal Data, we cannot guarantee the security of your Personal Data transmitted to our Website. Any transmission of Personal Data is at your own risk. We are not responsible for circumvention of any privacy settings or security measures contained on the Website or in your operating system.
12. Data Retention
We will only retain your Personal Data for as long as necessary to fulfill the purposes for which we collected it and in accordance with our legal obligations, our records retention practices, or as otherwise permitted or required by law.
For example, if you have set up an account with us on our Website, we will retain your Personal Data associated with that account for the entire time that you keep it open or until you request us to delete your Personal Data (subject to the below). In addition, we may have a legal obligation to retain Personal Data relating to a purchase you made with us. We will delete your data once the legal obligation expires or after the period of time specified in our records retention guidelines. Similarly, we may need to retain Personal Data in order to exercise our legal rights or defend legal claims involving you (or the company at which you work if it is one of our customers). We will delete this information once it is no longer needed for such purposes. We may also retain some or all of your Personal Data when your information is subject to one of the following exceptions:
· When stored in our backup and disaster recovery systems. Your Personal Data will be deleted when the backup media your Personal Data is stored on expires or when our disaster recovery systems are updated.
· When necessary to help ensure the security and integrity of our Website and IT systems. Your Personal Data will be deleted when we no longer require it for such purposes.
In general, where we are processing Personal Data based on:
· our legitimate interests, we generally will retain the data for a reasonable period of time based on the particular interest, taking into account the fundamental interests and the rights and freedoms of data subjects;
· contractual necessity, we generally will retain the information for the duration of the contract plus some additional limited period of time that is necessary to comply with law or that represents the statute of limitations for legal claims that could arise from the contractual relationship; or
· your consent, we generally will retain the information for the period of time necessary to carry out the processing activities to which you consented, subject to your right, under certain circumstances, to have certain of your Personal Data erased (see Your Rights).
We reserve the right to amend this Privacy Notice at its discretion and at any time. If we make material changes to how we treat our users’ Personal Data, we will notify you by email to the email address we have on file for you, through the posting of a notice on the home page of our Website, or by using a similar method. The date this Privacy Notice was last updated is identified at the top of the first page. You are responsible for ensuring we have an up-to-date active and deliverable email address for you, and for periodically visiting our Website and this Privacy Notice to check for any changes. Your continued use of our Website following the posting of changes constitutes your acceptance of such changes.
If you have any questions, concerns, complaints, or suggestions regarding our Privacy Notice, have any requests related to your Personal Data described in the Privacy Notice, or otherwise need to contact us, you can do so using the contact information below:
Black Diamond Equipment Europe GmbH
Hans-Maier-Strasse 9
6020 Innsbruck, Austria
Phone: +43 1253 74 599 333
Email: info@blackdiamond.eu