Effective date: February 1, 2023
This applies to the personal data you submit when you visit our website, www.jlindeberg.com, purchase products in any of our physical stores, attending our events, using our apps or in your contact with us in other ways.
This policy applies to J. Lindeberg AB (“J. Lindberg”) and all its’ subsidiaries. Please find the full list of subsidiaries in Appendix 1.
2. OUR STATEMENT ON PRIVACY
General At J. Lindeberg we take your privacy and security very seriously and we are committed to protecting your privacy. We believe that you should easily know what personal data we collect and use, as well as to understand your rights in respect of your personal data.
J. Lindeberg collects and processes personal data in accordance with applicable data protections laws. It is our mission to give you a great fashion experience right from the moment you start browsing the many styles, to the time that you receive your order.
As part of your shopping experience with us, we want to ensure you that we protect and respect your privacy and handle all your personal data with care. We collect personal data we have explicit consent for and/or that are necessary and relevant for fulfilling our agreements and legal obligations.
Why do we collect and store your personal data?
We collect and store personal data for various purposes such as making it possible for you to do your shopping in stores, your online shopping, sign up for our customer club, attend our events and the necessity of fulfilling our legal obligations.
We collect and store data for main purposes such as:
- Purchases Packing and delivering your order
- Customer service
- Customer accounts/Customer club
- Improving your user experience
- Fraud prevention
- Legal obligations and regulatory requirements
We uphold the following principles when handling your personal data:
- We only process personal data when for the purposes we have collected it for.
- We only process personal data if we have a legal basis for the processing.
- We delete your personal data when we no longer need it.
- We do not sell your data.
- We keep your data secure.
We remind you that we do not collect, directly or indirectly, personal data from persons under the age of 16, without prejudice to any local law setting a different minimum age. We therefore ask you not to provide us with personal data of persons who do not meet this requirement.
3. OUR LEGAL BASIS FOR COLLECTING AND PROCESSING PERSONAL DATA
Why we are using and processing your personal data and the legal basis for it
We collect and use your personal data based on one or several of the legal basis in the data protection regulations described below.
We may use personal data if we have obtained your prior consent (for example submit a purchase order, when you make a subscription to our customer club and for to receive newsletter from the customer club).
We may use and process personal data after your consent for:
- Delivery of order
- Clubhouse or Member Only subscriptions and Newsletters
- 'Coming soon' notifications
- My Account
- Marketing through push messages in apps
- Social media
- Cookie-based marketing
- Using our apps or other digital platforms
(GDPR article 6, 1 (a)) Please note that for this specific legal basis, you have the right to withdraw your consent at any time (see below “What rights do you have on your personal data?”).
Performance of a contract
The processing is necessary in connection with any contract between J. Lindeberg AB and you (for example, when you make a purchase). We may use, process, and disclose your personal data for:
Delivery and fulfillment of your purchase order (GDPR article 6, 1 (b))
We have a legitimate interest in carrying out the processing and that legitimate interest is not overridden by your interests, fundamental rights, or freedoms (for example, processing of personal data in the cases described below).
We may use your data with a legitimate interest to:
Perform our customer service to you; provide you with the products or services you requested; provide you after-sale services and manage refunds; improvement of your user experience and monitoring our digital platforms; Improve our product and services and conduct analysis to improve our products and services (including the use of your nationality after anonymisation), user experience and development based on cookies; conduct checks to identify you and verify your identity; manage complaints and litigation; manage the events you registered and/or participated in; to detect, prevent and fight against any fraudulent or illegal activity, including to protect your transactions from payment fraud, to act against counterfeiting and against the resale of our products in violation of our terms and conditions/or outside our distribution network; protect you, employees and other individuals in our stores as well as our property;
(GDPR article 6, 1 (f))
Our legal obligations
We may also use and process personal data to comply with applicable laws and regulations. This means we always need to respect our legal obligations, including providing information to regulatory bodies when legally required, in particular to comply with our legal obligations and prevention and the fight against fraud. We also need to respond to your queries, suggestions and requests, including your data subjects' rights exercises.
(GDPR article 6, 1 (c))
4. COLLECTING & USING YOUR PERSONAL DATA
What information does J.Lindeberg collect?
In order to provide you with our services and to perform our obligations under contract, or to comply with legal obligations, we collect relevant personal data and necessary information. For these purposes, we collect personal data and information such as name, address, phone number, email address, payment details and payment methods.
For you as a partner, supplier, wholesale customer or prospective wholesale customer we collect relevant information such as name, title, company/organisation, phone number, e-mail, address, shipment, delivery and invoice information and dialogue information.
We hope to ensure that the personal data we possess are accurate at all times and therefore we encourage you to update your information in case any changes have occurred. We also may ask you to update your information from time to time. We recommend that you only provide the data requested or necessary for your query.
Fulfillment of your order
To process your order, we need some information and personal data from you. When you place an order with us information regarding your identity (such as name, gender, nationality), you provide us with your contact details such as address, email and phone number, payment method and details (including billing information, payment type or method, charge or credit card number), and of course, which product(s) you wish to purchase and size and other preference. It might also be other information regarding personal data you may provide by filling in forms or by contacting us. We use the information to fulfill your order including sending an order confirmation and packing and delivering your order.
We will inform you on our website or in our stores when information regarding your personal data is required in order to process your request, to respond to your queries or to provide you with our products and services. If you do not provide this information, then it may delay or prevent us from processing your request, responding to your query or providing our products or services to you.
When you contact our customer service via email, chat or phone etc., we will register the personal data that you provide to us. Our customer service has access to all information about your order, so we can help you in the best possible way, whether you have questions about the status of your order, or if you need to return an item, e.g. via an online return portal. Our customer service is also able to see any previous correspondence with you as this allows us to provide you with a better service.
If you use our “Notify Me”-service, we will use your email, in accordance with your request, to notify you when a certain item is back in stock.
Improvement of your user experience
We constantly strive to give you the very best user and shopping experience on our website. We do that in different ways, but an important part of is by tracking your browsing behavior on our website as well as our social media platforms in order for us to improve the user friendliness, layout, functionalities, and overall experience of the site. We do that by using cookies. We also use your browsing data to recommend you products that we think you might like.
In order for us to present you with the best possible fashion advice and most relevant news and marketing, we and our advertising partners use personal data to personalize the recommendations and promotions on our website and to show you relevant advertising on other websites, social media networks and apps.
You can always object to our processing of your personal data for direct marketing purposes, including profiling, by using our request form.
Below you can read more about how we personalize our marketing towards our customer club members, the users of our apps and through our marketing cookies.
Customer Club ('Clubhouse')
For our customer club that you can sign up for in our physical stores or at jlindeberg.com we collect information such as name, e-mail address, gender, payment method and information, and purchase history. This information is used for marketing and internal business purposes, to contact you about events, sales and special offers and new site features, and to provide you with a fulfilling shopping experience.
If you have signed up to our customer club we use information about you to send you newsletters with offers, information about new styles, fashion guides etc., based on your preferences.
Coming Soon notifications
By opting to receive notifications for 'coming soon' products and providing your email address, you give explicit consent to receive marketing communications from J.Lindeberg. You retain the option to unsubscribe at any time by clicking the 'unsubscribe' link located in the email footer or by directly contacting us.
In our apps you can choose to receive push notifications from us regarding campaigns. If you have activated location services on your mobile phone, we may use such information to send push notifications when you are near one of our stores.
At any time, you can deactivate the notifications and location services in the settings on your mobile phone.
Cookie based marketing
Some of our marketing activities are based on cookies. Among other things, the marketing cookies that we use collect information about your style and size preference, device ID, geolocation based on your IP address and your general browsing behavior on our websites. These cookies also track which ads you have already seen, how many times you have seen them, whether you have clicked on any of them and whether or not you have placed an order after clicking. Further, some of the cookies will be able to track you also when you visit other websites or social media networks.
We use that information to personalize the recommendations and promotions on our websites and to show you relevant advertising on other websites such as social media networks and comparison-shopping engines as well as on other applications. For instance, if you have looked at a specific pair of jeans, we may present you with adds for that pair of jeans or similar on your social media news feed.
In addition, we may also combine the information collected by cookies with your order history, past correspondence, and other information you have provided us with for marketing purposes.
You can also opt-out of interest-based advertising by visiting the following websites:
My account / Clubhouse
If you choose to create a personal customer account (My Account), you must provide us with your name and email address. You can also choose to give us your phone number and address. My Account provides you with an overview of your shopping bag, your order history, shipping address, as well as interests and size preferences.
You can update or delete your account at any time by logging in.
We use the personal data submitted by you when you place an order for fraud detection and fraud prevention purposes. For those purposes we may also receive additional information from our payment solution partners.
We use and store your personal data in order to comply with regulatory requirements, e.g. bookkeeping regulations.
5. SHARING PERSONAL DATA
Why we share personal data and to whom
In order to provide our services, we share personal data with our partners. We only share your data when this is allowed by law and all our partners are committed to keeping your data safe. Some of our partners are “data controllers” and others are “data processors”.
We may engage third parties to perform services in connection with operation of our business. Examples of these services include order processing, payment services and authentication and fraud detection. We provide personal data to these third parties, but we authorize them to use the information only in connection with the services they perform.
The below described partners are data controllers meaning that they are directly responsible for the processing of your data. We only share personal data to the extent it is required for performance of their services, e.g. payment or shipping.
When you complete an order, your payment is handled by our payment solution partners. Some of our payment solution partners are data controllers such as (Shopify Payments, Klarna and Paypal). In order to be able to offer you these payment options, we will pass certain aspects of your personal information, such as contact and order details, in order for the payment providers to assess whether you qualify for their payment options and to tailor the payment options for you. You can find more information about these providers, including their terms and conditions and privacy policies on their websites.
Afterwards, your order is sent to our warehouse partner. When your order is packed and ready to ship, we share your name, address, email, and phone number with our carrier partners to fulfill your delivery.
For marketing purposes, we may share non-reversible and encrypted (hashed) information about you and your use of our websites and services with our advertising partners who may combine it with other information that you have provided to them directly or that they have collected themselves. We also share information such as your IP address and order information with our affiliate partners to settle commission for their reference to our web shop.
We may also disclose personal data to third-party providers acting on behalf of J.Lindeberg and approved by the company.
The partners described below are data processors who are only allowed to process personal data on behalf of us and according to our instructions.
Our payment solution partners Shopify Payments, Klarna and Paypal handle your payments as a data processor. Your payment details are sent directly to Shopify Payments, Klarna and Paypal where it is handled and stored in a highly secure environment in compliance with regulatory standards.
All such processing is based on our prior instructions set out in a binding contract that is compliant with the requirements of applicable law.
These providers are committed to confidentiality and are not permitted to use your personal data for any other purposes. We also require them to use appropriate security measures to protect your personal data.
Our technical service providers process your personal data when they have access to our databases or store personal data in their applications. These service providers include, for example, hosting providers, providers of our website platform and providers of message distribution tools. In addition, we have partners who provide tools related to customer service and customer experiences, e.g. a chat tool on our website or a customer experience feedback tool.
Part of those service providers are located outside of your country, notably outside the EU. We have taken steps to ensure all personal data is provided with adequate protection and that all transfers of personal data, including outside the EU are done lawfully. Where we transfer personal data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the EU requirements for the transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses, or under other appropriate safeguards as described in section 6 below.
Other situations where we share data
For customer club members, we share information about your orders and other activities on our online shops such as your online shopping bag and your wish list with the customer club.
We may also share personal data to relevant authorities or third parties if we are obliged by law, a court decision, or a decision of another authority, or for the purposes of responding to legal proceedings or other lawful requests. We also report fraud incidents to the relevant law enforcement authorities.
We may also disclose or otherwise process your personal data, in accordance with applicable law, to defend our legitimate interests (for example, in civil or criminal legal proceedings). For example, we may disclose such personal data as necessary to identify, contact or bring legal action against a person or entity who may be violating our Terms and Conditions or Policies, or who may be causing injury to, or interfering with, other users of our digital platforms.
In the event that J. Lindeberg or group companies, or all or part of its or their assets, are acquired by a third party, your personal data may be included in the transferred assets.
6. TRANSFERRING DATA OUTSIDE THE EU
Personal data may be transferred to the country where you are located or where some of our partners of our partners handling your personal data is located. This includes transfers to countries outside the European Union (“EU”) and to countries that do not have laws that provide adequate protection for personal data according to the European Commission.
Where we transfer personal data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the EU requirements for the transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses, or under other appropriate safeguards.
To obtain a copy of the relevant adequate safeguards, you can send us your request using the details in section “How to contact us” below.
Some of our partners handle your personal data outside the EU. Unless otherwise stated, the transferred data is safeguarded by the EU Commission’s Standard Contractual Clauses.
In addition, some of our partners may use external subcontractors (sub-processors) located outside the EU. In such case, our partner is obligated to keep your personal data safeguarded. If you want specific information about these external sub-processors, please contact our data protection officer Martin Börjesson.
7. HOW LONG DO WE STORE YOUR DATA?
We only store your personal data for as long as it is necessary to fulfill the purpose for which it was collected, to establish, defend or exercise legal claims or to comply with regulatory requirements, e.g. bookkeeping regulations in the countries where we operate.
When this is no longer the case, the information will be deleted.
You can also request us to delete personal data. We will comply with such request unless we are obligated to store the information for regulatory reasons or unless the information is relevant due to a pending legal case/dispute.
8. HOW DO WE PROTECT PERSONAL DATA?
Lindeberg AB has implemented a number of security measures to ensure that our internal procedures comply with the security standards required in accordance with applicable data protection laws. J. Lindeberg AB always strives to protect your personal data in the best possible way and is working continuously to make sure we live up to the set standards. Access to personal information is always restricted to only the personnel that need access for processing.
9. YOUR RIGHTS
What rights do you have on your personal data?
As a consumer in the EU, your personal data rights are covered by the General Data Protection Regulation (EU) 2016/679, General Data Protection Regulation (GDPR). This means that your rights as a data subject are the same in all EU Countries.
When we collect and use your personal data you have a number of privacy rights. If you wish to exercise any of your rights, please submit our online request form.
In accordance with GDPR, you can, at any time, request access, rectification, erasure and portability of your personal data or restrict and object to the processing of your personal data. Below you can read more about these rights.
Right of access
One of the most important rights that you have is the right to request access to the data that we have registered on you. If you request access, we will provide you with a copy of your personal data.
Right to erase (right to be forgotten)
Another important right in terms of your relationship with us is that you have the right to be forgotten, meaning you can file a request asking that we delete the data that we have registered on you. We may not be able to delete all your personal data as we are required to continue to store certain data in order to comply with legal requirements or to establish, defend or exercise legal claims.
Right to object
You are entitled to object to the processing of your personal data on certain grounds. For example, you can object to the processing of your personal data for direct marketing purposes, including profiling.
Right to rectification
If you believe that the data we have registered on you is inaccurate or incomplete, please let us know and we will make sure to update your information.
Right to restriction
In combination with some of your other rights you can also request that we restrict the use of your personal data, e.g. instead of full erasure or during our assessment of your objection.
Right to withdraw your consent
You may at any time decide to withdraw your consent to the processing of your personal data. If your consent is withdrawn, it does not prevent us from processing your personal data based on other legal bases if any, such as fulfilling your orders and storing your order data as required by applicable law.
If you no longer wish to receive our marketing/promotional information, we remind you that you may withdraw your consent to direct marketing at any time directly from the unsubscribe link included in each electronic marketing message we send to you. If you do so, we will promptly update our databases, and will take all reasonable steps to meet your request at the earliest possible opportunity, but we may continue to contact you to the extent necessary for the purposes of any products or services you have requested.
Right to data portability
You can file a request asking us to supply you with the personal data that you have provided to us in a structured, commonly used and machine-readable format and to transmit the data directly to a specific recipient.
If you wish to lodge a complaint about how we handle your personal data, you can always contact our customer service team. You can also file a complaint with your local data supervisory authority.
EXPORT, DELETION OR UPDATE OF INFORMATION
Please see below guidelines on how we can assist you with exporting, deleting and changing information.
If you want us to Export and send you all personal data we have collected on you, please follow below steps:
- Download the Export Personal Data PDF
- Fill in the PDF and send to email@example.com
- When we receive your mail/email, we will process your request as soon as possible. You will be notified about the status of your request through the e-mail address you have entered in the application.
- In order to make sure that your information does not end up in the wrong hands, we will send the findings to your registered address.
If you want us to Delete all personal data we have collected on you, please follow the below steps.
- Download the Delete Personal Data PDF.
- Fill in the PDF and send it with regular mail to the below address:
- Mark the letter ”Privacy”
- Lindeberg AB
- Stadsgårdshamnen 24
- 116 45 Stockholm
- When we receive your mail we will process your request as soon as possible. You will be notified about the status of your request through the e-mail address you have entered in the application.
If you want us to Change any of your personal data that we have collected, please follow below steps.
- All requests regarding changing data in our Customer club att www.jlindeberg.com should be sent to firstname.lastname@example.org
- All requests regarding changing the data the J. Lindeberg AB keep should be sent to email@example.com
We encourage you to review the site periodically and we will alert you that changes have been made by updating the Effective Date of the Policy.
List of subsidiaries to J. Lindeberg AB
- Lindeberg Danmark APS
- Lindeberg Deutschland GmbH
- Lindeberg Norge A/S
- Lindeberg Schweiz AG
- Lindeberg Ltd
- Lindeberg Österreich Gmbh
- Lindeberg OY
- Lindeberg USA Corp
- J. Lindeberg USA LLC
- J. Lindeberg USA Retail LLC
- J. Lindeberg USA ECOM, LLC