As at 06/2020
1. Data Controller and its Data Protection Officer
The Controller is:
Zalando Marketing Services GmbH
The data protection officer of the Controller can be reached via the above mail address (Attn.: Data Protection Officer) or by e-mail to firstname.lastname@example.org
2. Scope of this Privacy Notice
This Privacy Notice provides you with an overview of how Zalando Marketing Services GmbH (hereinafter “ZMS”) processes your data. It applies to all websites operated by ZMS in its own name. For the avoidance of doubt, it does not apply to the processing of personal data by Zalando SE; please refer to Zalando SE’s privacy notice.
When using the website for information purposes only, i.e. if you do not provide us with information, we only collect the data that your browser transmits to our server. If you view our Website, we collect the following data:
· IP address
· Date and time of the request
· Content of the request (specific page URL, but not the content of the page as such)
· Access status/HTTP status code
· Web page where the user was referred from (“referer”)
· Information about the operating system and browser software
· Preferred language setting and screen resolution
This data will be processed by us for the following purposes:
· Provision of the website
· evaluation of system security and stability
· compile aggregated, anonymous usage statistics that serve to improve the website
This data may only be personally identifiable via the IP address. Depending on your way of access to the Internet, the IP address may be completely anonymous, or your access provider stores the assignment of a dynamic IP address to you. In the latter case, combining the above-mentioned data with that of your access provider can eventually make a connection between you personally and the above-mentioned data. However, we will only initiate this if this is appropriate in individual cases for the purposes of legal prosecution, and we will otherwise only cooperate in this if this is ordered by competent authorities or courts in individual cases.
The legal basis for the provision of the website is the Performance of Contract.
For the other purposes, the legal basis is the Legitimate Interest in keeping the website and the underlying systems secure, and to improve the usability and performance of the website. For these purposes, the IP address will be anonymized (by truncation of the last octet) at the earliest possible point in time. Under no circumstances do we use this data collected for the purpose of drawing conclusions about you personally.
The data will be stored until the end of the calendar month following use and then be deleted or anonymized (unless required in individual cases for the purpose of legal prosecution) within two working days.
4. Information Stored on your Device (Cookies etc.) and tag manager technologies
4.1.1. Cookies in General
When you use the website, we eventually use technologies to store information on your device. We refer to these technologies as “cookies”, while, for the purpose of this Privacy Notice, this also includes functionally similar technologies (e.g. HTML5 storage objects). Our web server supplying the website can store cookies on your computer or mobile device, respectively. The cookie data are then transmitted back if your computer or mobile device requests information from our servers, so that cookie data can be processed in order to provide the requested information.
If you use the website, you can inspect the cookies in your internet browser. You can also adjust your browser settings to accept cookies or not. Also, we ask you whether or not you want to accept cookies on our Website (your choice is stored in a cookie).
4.1.2. Session Cookie
We use a session cookie that is non-persistent (i.e. will be deleted automatically if you close your browser); this cookie is technically necessary to operate the website, and you cannot opt-out from this cookie. It is a first-party cookie (i.e. a cookie that is only functional towards our servers).
4.1.3. Google Analytics
You can prevent the collection of data generated by the cookie and related to your use of the website (including your IP address) to Google and the processing of this data by Google by downloading and installing the browser plugin available at the following link http://tools.google.com/dlpage/gaoptout ; furthermore, you also have the option of preventing future collection of your data when visiting this website by using the following opt-out cookie: Disable Google Analytics; these possibilities to opt-out from Google Analytics data collection do on no way limit your right to withdraw your consent towards us.
4.1.4. LinkedIn Analytics and LinkedIn Ads
If you give us Consent for doing so, we use conversion tracking technology on our website and the retargeting feature of LinkedIn Ireland Unlimited Company, Wilton Place, Dublin 2, Irland (“LinkedIn”). LinkedIn is an affiliate of LinkedIn Corporation, 2029 Stierlin Court, Mountain View, CA 94043, USA, and data processing in this context is eventually carried out in the USA.
This technology allows visitors to this site to see personalized ads on the LinkedIn social network. It also provides the ability to generate anonymous reports on ad performance and website interaction information. LinkedIn Insight tag is embedded in this website, which connects to the LinkedIn server when you visit this website and are logged into your LinkedIn account.
Under the following link you can object to data-based advertising via Linkedin:
If you are logged in to LinkedIn, you can deactivate the collection of data at any time by following this link:
These possibilities to opt-out from LinkedIn personalized advertising do on no way limit your right to withdraw your consent towards us.
4.2. Google Tag Manager
This website uses the Google Tag Manager. This service allows website tags to be managed through an interface. Google Tag Manager only implements tags, but does not set cookies and does not collect any personal information. Google Tag Manager triggers other tags that may collect personal information. However, Google Tag Manager does not access this information. Any cookies or tracking disabled at domain or cookie level will remain disabled even when implemented with Google Tag Manager.
5. Contact Form and E-Mail
When you contact us by e-mail or via a contact form, we will store and process your e-mail address and, if you provide it, your name and telephone number in order to respond to your message.
We will restrict the processing of the data arising in this context after processing is no longer necessary. Your message and our response will further be stored in order to fulfill legal obligations (German trade and tax laws, §§ 257 HGB, 147 AO) for the duration of six full years, and afterward be deleted.
6. Data Transfers (including third-country transfers)
6.1 Data Transfers to Google and LinkedIn
As described in Section 6 above, we transfer data to LinkedIn and Google, respectively, if you have given us consent to do so. The data may eventually be processed in the United States of America. Both LinkedIn and Google have self-certified and subscribed to the EU-US Privacy Shield Program for providing an adequate level of protection of personal data.
6.2. Service Providers
We use various service providers for the technical hosting of this website and the processing of e-mail messages and other information. We have concluded Data Processing Agreements with all of such service providers. Some of them may be in third countries, in which case we ensure an adequate level of protection by one of the measures provided in Chapter 5 of the GDPR.
7. Legal Bases
We refer to different legal bases in this Privacy Notice. Such terms refer to certain provisions of the General Data Protection Regulation (GDPR):
· “Consent” refers to Art 6 para 1 sentence 1 lit a GDPR.
· “Performance of Contract” refers to Art 6 para 1 sentence 1 lit b GDPR.
· “Legal Obligation” refers to Art 6 para 1 sentence 1 lit c GDPR (in conjunction with the legal obligation named for each individual case).
· “Legitimate Interest” refers to Art 6 para 1 sentence 1 lit f GDPR.
8. Withdrawal of Consent and Objection to Data Processing
8.1. If you have given your consent to the processing of your data and/or the receipt of marketing e-mails, you can withdraw your consent at any time with effect for the future. To do this, notify (e.g. by e-mail) the Controller mentioned under 1. above or its data protection officer.
8.2. To the extent we base the processing of your personal data on a Legitimate Interest, you may object to the processing. To do this, notify (e.g. by e-mail) the Controller mentioned under 1. above or its data protection officer. If you wish to file such an objection, we kindly ask you to explain the reasons why your interest outweighs ours. In the event of your objection, we will check the situation and either stop or adjust our processing of your data, or point out to you our overriding interest, on the basis of which we will continue our processing.
9. Your rights
You are entitled to request from us:
· Access to your personal data (right to information) pursuant to Article 15 GDPR,
· Rectification of any inaccurate personal data pursuant to Article 16 GDPR.
· Erasure of your personal data (“right to be forgotten”) in particular cases in accordance with Article 17 GDPR.
· Restriction of processing your personal data for the period during which a rectification or erasure request is examined, in accordance with Article 18 GDPR.
· To receive your personal data in a structured, commonly used, and machine-readable format for transmission to another controller (right to data portability) in accordance with Article 20 GDPR.
If you wish to exercise one or several of these rights, please notify (e.g. by e-mail) the Controller mentioned under 1. above or its data protection officer.
If you wish to complain about data processing, please notify (e.g. by e-mail) the Controller mentioned under 1. above or its data protection officer.
You also have the right to file a complaint with a data protection authority. The responsible authority for the Controller is the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information).
At least within the European Economic Area (EEA), you may also choose to file your complaint with any other data protection authority, in particular in the member state of your habitual residence, your place of work, or the place of the alleged infringement.
11. Amendments to this Privacy Notice
This Privacy Notice is currently valid as of June 20, 2020. We reserve the right to amend this Privacy Notice. You can refer to the current version of the Privacy Notice at any time at zms.zalando.com/privacy-policy
for more information