Hansgrohe and its affiliates (collectively, the “Company,” “we,” or “us”) wants you to be familiar with how we collect, use and disclose information. This Privacy Policy describes our practices pertaining to information that we collect in connection with:
Collectively, we refer to the Websites, Apps, Social Media Pages, emails, and offline business interactions as the “Services.”
PERSONAL INFORMATION
“Personal Information” is information that identifies you as an individual or relates to an identifiable individual. The Services collect Personal Information, including but not limited to:
Collection of Personal Information
We and our service providers collect Personal Information in a variety of ways, including:
If you do not want information collected through the use of cookies, there is a simple procedure in most browsers that allows you to automatically decline cookies, or be given the choice of declining or accepting the transfer to your computer of a particular cookie (or cookies) from a particular site. You may also wish to refer to http://www.allaboutcookies.org/manage-cookies/index.html. However, if you do not accept these cookies, you may experience some inconvenience in your use of the Services. For example, we may not be able to recognize your computer and you may need to log in every time you visit the applicable Services. You also may not receive advertising or other offers from us that are relevant to your interests and needs.
We may use and disclose other information for any purpose, except where we are required to do otherwise under applicable law. If we are required to treat other information as Personal Information under applicable law, then we may use it for all the purposes for which we use and disclose Personal Information. Con
In some instances, we may combine other information with Personal Information (such as combining your name with your geographic location). If we do combine any other information with personal information, the combined information will be treated by us as Personal Information in accordance with this Policy.
We need to collect Personal Information in order to provide the requested Services to you. If you do not provide the information requested, we may not be able to provide the Services. If you disclose any Personal Information relating to other people to us or to our service providers in connection with the Services, you represent that you have the authority to do so and to permit us to use the information in accordance with this Privacy Policy.
Use of Personal Information
We and our service providers use Personal Information for the following purposes:
We will engage in these activities to manage our contractual relationship with you and/or to comply with a legal obligation.
We use this information to manage our contractual relationship with you.
We engage in these activities to manage our contractual relationship with you, to comply with a legal obligation, and/or based on our legitimate interest.
Disclosure of Personal Information
We disclose Personal Information:
Other Uses and Disclosures
We also use and disclose your Personal Information as necessary or appropriate, in particular when we have a legal obligation or legitimate interest to do so:
OTHER INFORMATION
“Other Information” is any information that does not reveal your specific identity or does not directly relate to an identifiable individual.
Uses and Disclosures of Other Information
We may use and disclose Other Information for any purpose, except where we are required to do otherwise under applicable law. If we are required to treat Other Information as Personal Information under applicable law, we may use and disclose it for the purposes for which we use and disclose Personal Information as detailed in this Policy. In some instances, we may combine Other Information with Personal Information. If we do, we will treat the combined information as Personal Information as long as it is combined.
SECURITY
We seek to use reasonable organizational, technical and administrative measures to protect Personal Information within our organization. Unfortunately, no data transmission or storage system can be guaranteed to be 100% secure. If you have reason to believe that your interaction with us is no longer secure, please immediately notify us in accordance with the “Contacting Us” section below.
CHOICES AND ACCESS
Your choices regarding our use and disclosure of your Personal Information
We give you choices regarding our use and disclosure of your Personal Information for marketing purposes. You may opt out fromreceiving marketing-related emails from us. If you no longer want to receive marketing related emails from us on a going-forward basis, you may opt out by unsubscribing directly in the email.
We will try to comply with your request(s) as soon as reasonably practicable. Please note that if you opt out of receiving marketing related emails from us, we may still send you important administrative messages, from which you cannot opt out.
RETENTION PERIOD
We retain Personal Information for as long as needed or permitted in light of the purpose(s) for which it was obtained and consistent with applicable law.
The criteria used to determine our retention periods include:
THIRD PARTY SERVICES
This Privacy Policy does not address, and we are not responsible for, the privacy, information, or other practices of any third parties, including any third party operating any website or service to which the Services link. The inclusion of a link on the Services does not imply endorsement of the linked site or service by us or by our affiliates.
In addition, we are not responsible for the information collection, use, disclosure, or security policies or practices of other organizations, such as Facebook, Apple, Google, Microsoft, RIM, or any other app developer, app provider, social media platform provider, operating system provider, wireless service provider, or device manufacturer, including with respect to any Personal Information you disclose to other organizations through or in connection with the Apps or our Social Media Pages.
USE OF SERVICES BY MINORS
The Services are not directed to individuals under the age of sixteen (16), and we do not knowingly collect Personal Information from individuals under 16.
Your Right To Request Removal of Content
Pursuant to California Business & Professions Code section 22581, if you are a resident of California, under 18, and a registered user of the Services, you may ask us to remove content or information that you have posted to the Services by writing to privacy@hansgrohe-usa.com. Please note that your request does not ensure complete or comprehensive removal of the content or information, as, for example, some of your content may have been reposted by another user.
JURISDICTION AND CROSS-BORDER TRANSFER
Your Personal Information may be stored and processed in any country where we have facilities or in which we engage service providers, and by using the Services you understand that your information will be transferred to countries outside of your country of residence, including the United States, which may have data protection rules that are different from those of your country. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries may be entitled to access your Personal Information.
ADDITIONAL INFORMATION REGARDING THE EEA: Some non-EEA countries are recognized by the European Commission as providing an adequate level of data protection according to EEA standards (the full list of these countries is available here). For transfers from the EEA to countries not considered adequate by the European Commission, we have put in place adequate measures, such as standard contractual clauses adopted by the European Commission and binding corporate rules to protect your Personal Information. You may obtain a copy of these measures by contacting us in accordance with the “Contact Us” section below.
SENSITIVE INFORMATION
Unless we request it, we ask that you not send us, and you not disclose, any sensitive Personal Information (e.g., social security numbers, information related to racial or ethnic origin, political opinions, religion or other beliefs, health, biometrics or genetic characteristics, criminal background, or trade union membership on or through the Services or otherwise to us.
THIRD PARTY PAYMENT SERVICE
The Services may provide functionality allowing you to make payments to the Company using third-party payment services with which you have created your own account. When you use such a service to make a payment to us, your Personal Information will be collected by such third party and not by us, and will be subject to the third party’s privacy policy, rather than this Privacy Policy. We have no control over, and are not responsible for, this third party’s collection, use, and disclosure of your Personal Information.
UPDATES TO THIS PRIVACY POLICY
The “LAST UPDATED” legend at the top of this Privacy Policy indicates when this Privacy Policy was last revised. Any changes will become effective when we post the revised Privacy Policy on the Services.
CONTACTING US
Hansgrohe Inc, located at Bluegrass Lakes Parkway 1490, Alpharetta GA 30004, Georgia, USA, is the company responsible for collection, use, and disclosure of your Personal Information under this Privacy Policy. If you have any questions about this Privacy Policy, please contact us at
or
Hansgrohe Inc
Bluegrass Lakes Parkway 1490
Alpharetta GA 30004
Georgia
You may also contact our Group Data Protection Officer, Ingo Lorenz at privacy@hansgrohe.com. Because email communications are not always secure, please do not include credit card or other sensitive information in your emails to us.
ADDITIONAL INFORMATION REGARDING CALIFORNIA AND OTHER JURISDICTIONS
Collection, Disclosure, Sale and Sharing of Personal Information
The following chart details which categories of Personal Information we collect and process, as well as which categories of Personal Information we disclose to third parties for our operational business purposes, including within the 12 months preceding the date this Privacy Policy was last updated. The chart also details the categories of Personal Information that we “sell” or that we “share” for purposes of cross-context behavioral or targeted advertising, including within the 12 months preceding the date this Privacy Policy was last updated.
Categories of Personal Information | Disclosed to Which Categories of Third Parties for Operational Business Purposes | Sold to Which Categories of Third Parties | Shared with Which Categories of Third Parties for Cross-Context Behavioral or Targeted Advertising |
---|---|---|---|
Identifiers, such as name,contact information, online identifiers (ex. IP address) and Social Securitynumbers and other government-issued ID numbers | Affiliated entities service providers; dealers andretailers; ad networks; social networks; business partners; marketingpartners; other businesses; contest sponsors; legal authorities; otherparties in litigation | N/A | Ad networks[JB1] |
Personal information as defined in the California customer records law, such as name, address, telephonenumber, email, profile picture, social media account ID and profile pictures,date of birth, passwords and reminder questions/answers, payment cardinformation, and information related to employment, education and experiences,preferences and interests | Affiliated entities service providers; dealers andretailers; ad networks; social networks; business partners; marketingpartners; other businesses; contest sponsors; legal authorities; otherparties in litigation | N/A | Ad networks |
Protected Class Information, such as sex, marital status, age, race, disability, medical conditions, sexual orientation, gender identity and expression, citizenship,primary language, immigration status and military/veteran status | Affiliated entities; service providers | N/A | None |
Commercial Information, such astransaction information, purchase history, financial details and paymentmethods | Affiliated entities service providers; dealers andretailers; ad networks; social networks; business partners; marketingpartners; other businesses; contest sponsors; legal authorities; otherparties in litigation | N/A | None |
Biometric Information, such asfingerprints and voiceprints | Affiliated entities; service providers | N/A | None |
Internet or network activity information, such as browsing history, online behavior, interest data, andinteractions with our and other websites, applications, systems andadvertisements | Affiliated entities; service providers | N/A | Ad networks |
Geolocation Data, such as devicelocation and IP location | Affiliated entities; service providers[; contestsponsors] | N/A | Ad networks |
Audio/Video Data. Audio,electronic, visual, and similar information, such as images and audio, videoor call recordings created in connection with our business activities | Affiliated entities; service providers | N/A | None |
Education Information subject to thefederal Family Educational Rights and Privacy Act such as student records | Affiliated entities; service providers | N/A | None |
Employment Information. Professional oremployment-related information, such as work history, prior employer,information relating to references, CV, details of qualifications, skills andexperience, human resources data and data necessary for benefits and relatedadministration services | Affiliated entities; service providers | N/A | None |
Inferences drawn from any of the personal information listed above to create a profile or summary about,for example, an individual’s preferences and characteristics | Affiliated entities; service providers | N/A | Ad networks |
Sensitive Personal Information. Personal Information that reveals an individual’s social security, driver’s license, state identification card, or passport number; account log-in, financial account, debit card, or credit card number in combination with any required security or access code, password, or credentials allowing access to an account; geolocation information accurate within a radius of 1850 feet or less; racial or ethnic origin, religious or philosophical beliefs, citizenship, immigration status, or union membership; the contents of mail, email, and text messages unless Company is the intended recipient of the communication; genetic data; Personal Information collected and analyzed concerning an individual’s health; Information on medical history, mental or physical health conditions, or medical treatment or diagnosis by a health care professional; Biometric information used for the purpose of uniquely identifying an individual; Personal Information collected and analyzed concerning an individual’s sex life or sexual orientation; | Affiliated entities; service providers; contestsponsors | N/A | None |
We do not “sell” Personal Information, as defined under applicable law. We have not engaged in such activities in the 12 months preceding the date this Privacy Policy was last updated. Without limiting the foregoing, we do not knowingly sell or share the Personal Information of minors under 16 years of age.
Use of Sensitive Personal Information
Subject to your consent where required by applicable law, we may use Sensitive Personal Information for purposes of providing goods or services as requested by you; ensuring security and integrity; short term transient use such as displaying first party, non-personalized advertising; performing services for our business, including maintaining and servicing accounts, providing customer service, processing or fulfilling orders and transactions, verifying customer information, processing payments, providing financing, providing analytic services, providing storage, or providing similar services on behalf of our business; and activities relating to quality and safety control or product improvement.
Individual Requests
Subject to applicable law, you may make the following requests
We will not unlawfully discriminate against you exercising your rights applicable privacy law. To make a privacy request, please contact us at privacy@hansgrohe-usa.com. We will verify and respond to your request consistent with applicable law, taking into account the type and sensitivity of the Personal Information subject to the request. In some instances, we may decline to honor your request where the law or right you are invoking does not apply or where an exception applies. We may need to request additional Personal Information from you, such as name, email address, postal address, and purchase history to verify your identity and protect against fraudulent requests. You may make a request on behalf of a child who is under 13 years old if you are the child’s parent or legal guardian. If you make a request to delete, we may ask you to confirm your request before we delete your Personal Information.
Your request to opt-out will apply only to the browser and the device from which you submit the request. You can also broadcast the Global Privacy Control (GPC) to opt-out of targeted advertising for each participating browser you use. To learn more about GPC, visit
Appeal Process
If we refuse to take action on your request, you may appeal this refusal within a reasonable period after you have received notice of the refusal. You may file an appeal by contacting us via email privacy@hansgrohe-usa.com.
Authorized Agents
If an agent would like to make a request on your behalf as permitted under applicable law, the agent may use the submission methods noted in the section entitled “Individual Requests.” Not all kinds of requests can be made by authorized agents in all states. As part of our verification process, we may request that the agent provide, as applicable, proof concerning his or her status as an authorized agent. In addition, we may require that you verify your identity as described in the section entitled “Individual Requests” or confirm that you provided the agent permission to submit the request.
De-Identified Information
Where we maintain or use de-identified or aggregated data, we will continue to maintain and use the de-identified or aggregated data only in a de-identified or aggregated fashion and will not attempt to re-identify the data
ADDITIONAL INFORMATION REGARDING THE EUROPEAN ECONOMIC AREA, UNITED KINGDOM AND SWITZERLAND
International Personal Information Handling
We take assorted measures to meet applicable legal requirements for the transfer of your Personal Information to recipients in countries outside of the EEA, United Kingdom or Switzerland to ensure that the transfer and handling of your Personal Information receives adequate protection in compliance with applicable data protection rules such as the General Data Protection Regulation (“GDPR”), including the use of EU Standard Contractual Clauses and verifying the recipients have adopted Binding Corporate Rules or adhere to the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework. Where your Personal Information is transferred within Hansgrohe, we use an intracompany data transfer agreement.
Personal Information Retention
Your personal information will be retained no longer than reasonably necessary to fulfil the purposes set out in this Privacy Policy, unless a longer retention period is required by applicable law. Generally, this means we will retain your personal information so long as we have your consent to do so unless there is legitimate business or legal purpose to retain your personal information for a longer period (such as tax regulations, commercial laws or, for example, warranty purposes).
Your Rights
You have the right to request under the GDPR and other relevant European international or local data protection rules: (i) access to your personal information (Art. 15 GDPR); (ii) correction of your personal information if it is incomplete or inaccurate (Art. 16 GDPR); (iii) right to deletion (Art. 17 GDPR); (iv) right to restriction of processing (Art. 18 GDPR); (v) right to data portability (Art. 20 GDPR), and (vi) right to object to the processing of your data (Art. 21 GDPR). These rights do not apply if we can show there are compelling and legitimate business or legal reasons for processing that outweigh your interests, or if we need your data for the establishment, exercise or defence of legal claims. If you like would to request a copy of your personal information or exercise any of your other rights, please contact us (Ingo Lorenz / privacy@hansgrohe.com).
For European Customers, that may be the Data Protection regulator in your country or the Data Protection Authority of our entity/subsidiary:
Ingo Lorenz / privacy@hansgrohe.com
For UK Customers, that may be the Information Commissioner’s Office.
https://ico.org.uk/global/contact-us/
+44 (0)303 123 1113