Privacy Policy Spa-Plus B.V.

About our privacy policy

Spa-Plus B.V. cares a lot to your privacy. We therefore only process data that we need for (improving) our services and we carefully handle the information we have collected about you and your use of our services. We never make your data available to third parties for commercial purposes.
This privacy policy applies to the use of the website and the services provided by Spa-Plus. The starting date for the validity of these conditions is 25/05/2018, with the publication of a new version the validity of all previous versions expires. This Privacy Policy describes what information about you is collected by us, what this data is used for and with whom and under what conditions this data can possibly be shared with third parties. We also explain to you how we store your data and how we protect your data against misuse and what rights you have with regard to the personal data you provide to us.
If you have any questions about our privacy policy, please contact our privacy contact person, you will find the contact details at the end of our privacy policy.

About data processing

Below you can read how we process your data, where we store it (or have it stored), what security techniques we use and who can view the data.

Web shop software

OpenCart

Our website/product catalog has been developed with OpenCart software.
No personal data is shared with OpenCart.

One.com

Our website/product catalog has been developed with Opencart software, we have opted for One.com for our web hosting. Personal data that you make available to us for the benefit of our services will be shared with this party. One.com has access to your data to provide us (technical) support, they will never use your data for any other purpose. One.com is obliged to take appropriate security measures based on the agreement we have with them. These security measures consist of the application of SSL encryption and a strong password policy. Backups are made on a regular basis to prevent the loss of data.

Order processing

Zoho

For order processing, we use software from Zoho. Personal data that you make available to us for the benefit of our services will be shared with this party. Zoho has access to your data to provide us (technical) support, they will never use your data for any other purpose. Zoho is obliged to take appropriate security measures based on the agreement we have with them. These security measures consist of the application of SSL encryption, a strong password policy and secure data storage. Backups are made on a regular basisl to prevent the loss of data.

Web hosting

One.com

We use web hosting and e-mail services from One.com. One.com processes personal data on our behalf and does not use your data for its own purposes. However, this party can collect metadata about the use of the services. This is not personal data. One.com has taken appropriate technical and organizational measures to prevent loss and unauthorized use of your personal data.

E-mail and mailing lists

Zoho

We use Zoho, a third party that handles the e-mail traffic from our website and the mailing of any newsletters. All confirmation emails you receive from us are sent via the Zoho servers. Zoho will never use your name and email address for your own purposes. At the bottom of every e-mail newsletter sent via Zoho you will see the 'unsubscribe' link. If you click here you will not receive an e-mail newsletter from us. Your personal data is stored securely by Zoho. Zoho uses cookies and other internet technologies which provide insight into whether e-mails are opened and read.

One.com

We use the services of One.com for our regular business e-mail traffic. This party has taken appropriate technical and organizational measures to prevent abuse, loss and corruption of your and our data as much as possible. One.com has no access to our mailbox and we treat all our email traffic confidentially.

Shipping and logistics

UPS, DPD, MainFreight, Rotra, Rabelink and van der Heijden

If you place an order with us, it is our job to have your order delivered to you. We use the services of UPS and DPD (parcel services) and MainFreight, Rotra, Rabelink and van der Heijden (carriers) to carry out the deliveries. It is therefore necessary that we share your name and address details with these parcel services and carriers. These parcel services and carriers use this data only for the purposes of executing the delivery. In the event that these parcel services and carriers engage subcontractors, these parcel services and carriers also make your data available to these parties.

Invoicing and accounting

Zoho

For our administration and accounting we use the services of Zoho. We share your name and address and details regarding your order. This data is used for managing sales invoices. Your personal data is transmitted and stored in a protected manner. Zoho is obliged to maintain secrecy and will treat your information confidentially. Zoho does not use your personal data for purposes other than those described above.

Purpose of data processing

General purpose of processing

We process your data for the following purposes:
- For the benefit of our services
- To inform you about changes to our products and services

Automatically collected data

Data that is automatically collected by our website is processed with the aim of further improving our services. This information (eg your IP address, web browser and operating system) is not personal data.

Participation in tax and criminal investigation

In some cases, Spa-Plus can be required on the basis of a legal obligation to share your data in connection with government tax or criminal investigations. In such a case, we are forced to share your information, but we will oppose it within the possibilities that the law offers us.

Retention periods

We retain your information for as long as you are our client. This means that we keep your customer profile until you indicate that you no longer wish to use our services. If you indicate this to us, we will also consider this as a request to be forgotten. On the basis of applicable administrative obligations, we must keep invoices with your (personal) data, so we will keep this data for as long as the applicable term requires us to so. However, employees no longer have access to your client profile and documents that we have produced as a result of your orders.

Your rights

Based on the applicable Dutch and European legislation, you as a data subject have certain rights with regard to the personal data processed by or on behalf of us. We explain below which rights these are and how you can invoke these rights.

In principle, in order to prevent abuse, we will send transcripts and copies of your data only to the e-mail address that we have on file for you. In the event that you wish to receive the data at another e-mail address or for example by post, we will ask you to identify yourself. We keep records of completed requests, in the case of a request to be forgotten we will keep anonymous data. You will receive all transcripts and copies of data in the machine-readable data format that we use within our systems.

You have the right to file a complaint with the Dutch Data Protection Authority at any time if you suspect that we are using your personal data in the wrong manner.

Right of inspection

You always have the right to access the data that we process (or have processed) and that relate to your person or that can be traced back to you. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you a copy of all data with an overview of the processors who have this data, to the e-mail address we have on file for you, stating the category under which we have stored this data.

Right to rectification

You always have the right to have the data modified that we process (or have processed) and that relate to your person or that can be traced back to you. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you a confirmation that the details have been changed to the e-mail address we have on file for you.

Right to restriction of processing

You always have the right to limit the data that we process (or have processed) and that relate to your person or that can be traced back to you. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you a confirmation to the e-mail address we have on file for you that the data will no longer be processed until you cancel the restriction.

Right of transferability

You always have the right to have the data that we process (or have processed) and that are related to your person or that can be traced back to you, be carried out by another party. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you transcripts or copies to the e-mail address we have on file for you, of all information about you that we have processed or that have been processed for us by other processors or third parties. In all likelihood, we will no longer be able to continue our services in such a case, because the secure linking of data files can no longer be guaranteed.

Right of objection and other rights

In certain cases you have the right to object to the processing of your personal data by or on behalf of Spa-Plus. If you object, we will immediately stop the data processing pending the handling of your objection. If your objection is well-founded, we will make transcripts and/or copies of data that we process (or have processed) available to you and then permanently discontinue the processing. You also have the right not to be subject to automated individual decision making or profiling. We do not process your data in such a way that this right applies. If you are of the opinion that this is the case, please contact us via the e-mail address below.

Cookies

Google Analytics

Through our website, cookies of the American company Google are pleaced as part of the "Analytics" service. We use this service to track and get reports on how visitors use the website. This processor may be obliged to provide access to these data on the basis of applicable laws and regulations. We have not allowed Google to use the obtained analytics information for other Google services.

Cookies from third parties

In the case that software solutions from third parties use cookies, this is stated in this privacy statement.

Changes to the privacy policy

We reserve the right to change our privacy policy at any time. On this page you will always find the most recent version. If the new privacy policy affects the way in which we process already collected data relating to you, we will notify you by e-mail.

Contact details

Spa-Plus

Industrieweg 8b
5571 LJ Bergeijk
The Netherlands

T  +31-(0)497-555562

E  info@spa-plus.eu