PRIVACY POLICY

 

In this privacy policy, you can learn more about how GUBI A/S and GUBI Design Inc. ("we", "us", "our") processes your personal data in various situations.

 

We provide you with this information as we are required to do so under the EU General Data Protection Regulation ("GDPR") or the California Consumer Privacy Act ("CCPA").

 

 

Controller

 

Unless otherwise stated below in the individual sections, GUBI acts as a data controller for the processing of your personal data in the following situations:

 

1. when you visit our website or mobile app (cookies, etc.),

2. when you buy products from our web shop/online store and communicate with us in that regard,

3. when you are, or represent, a B2B customer, partner, supplier, or other third party,

4. when you receive our electronic newsletters (direct marketing), and/or

5. when you participate in competitions, events, webinars, etc.

 

Below, you can read more about the various purposes of our processing of your personal data in the different situations. You can also see which data we process, the (legal) basis for our processing of it, for how long we store the personal data, and who we share it with.

 

Further, in the section Your rights etc. you can read about your rights and how to contact us.

 

 

Information we collect

 

We collect non-personal data and personal data. Non-personal data includes information that cannot be used to personally identify you, such as anonymous usage data, general demographic information we may collect, referring/exit pages and URLs, platform types, preferences you submit and preferences that are generated based on the data you submit and number of clicks. Personal data includes any information that can directly or indirectly be used to personally identify you such as your email, address, or contact information, which you submit to us.

 

1 When you visit our website or myGUBI mobile app (cookies etc.)

When you visit our website (GUBI.com) or the myGUBI mobile app, we use cookies or similar technologies to collect data about your visits, including e.g., your navigation on the website or mobile app, the type of browser you use, and your IP address. This information may contain personal data.

 

We collect data in order to ensure a stable, secure, and customer-friendly experience on our web-site and mobile app, as well as to keep statistics about our website and mobile app visitors. In some cases, data is processed in order to target marketing based on the web browser behaviour.

 

The legal basis for our processing is:

 

- for necessary (technical) cookies: article 6(1)(f) of the GDPR, as we are pursuing our legitimate interest in ensuring functionality and security of our website, and

 

- for other cookies: article 6(1)(a) of the GDPR, as you have given your consent.

 

We disclose information about your use of the website to any third-party service providers that you have allowed to place cookies when you use the website.

 

Personal data contained in cookies will be deleted in accordance with the lifetime/period for each specific cookie. Read more about our cookies, including their lifetime and information on whether the use of third-party service providers involve transfer of personal data to third countries, in our Cookie Policy.

 

2 When you buy products from our web shop/online store etc.

The following applies to GUBI A/S customers:

Unless you are a US-based customer (and therefore interacts with GUBI Design Inc.), when you buy a product from the web shop, GUBI A/S acts as a data controller for the processing of your personal data in relation to your purchase at the web shop and/or when you communicate with GUBI A/S in that regard.

 

When you buy products from our web shop

When you buy products from our web shop, we process your personal data, including your name, email, address, phone number (optional) and potential relationship with a specific company (optional), as well as your account- and payment information, including credit card information. The purpose of the processing is to manage your order and deliver the products you have bought.

 

The legal basis for our processing of your name and contact details, including your address, as well as your payment information, is article 6(1)(b) of the GDPR, as the processing is necessary in order for us to fulfil our end of the purchase agreement.

 

Further, we are obligated to store bookkeeping information, including information related to pay-ments/transactions in accordance with the Danish bookkeeping legislation. Based on the GDPR, our legal basis in that regard is article 6(1)(c).

 

Personal data pertaining to your order will, as a starting point, be deleted 6 years after the end of the financial year where your last order has been handled/concluded. In specific situations, we may defer from our general retention periods (in case of e.g., complaints, objections, or other specific situations).

 

We disclose personal data included in our account records to the relevant public authorities, including the tax and customs authorities, in connection with our statutory bookkeeping, etc. Further, we disclose your personal data to service providers for online payments and to the shipping company that delivers your products. Finally, we share the personal data within the group and make your personal data available to our processors who, e.g., host, develop, and support our IT systems.

 

We transfer your personal data to our group companies and our processors and/or other suppliers or vendors located in third countries. Please see below regarding transfer of your personal data to third countries.

 

When you communicate with us

When you communicate with us (e.g., via email), your communication may often contain personal data, e.g., your contact details and other personal data you may provide us with. We process this personal data for the purpose of managing and answering your inquiries and orders and to com-municate with you.

 

The legal basis for the processing is article 6(1)(f) of the GDPR, as we are pursuing our legitimate interests in managing general inquiries and providing customer support services.

 

Personal data pertaining to your communication will, as a starting point, be deleted 6 years after the end of the financial year where your inquiry has been handled/concluded. In specific situations, we may defer from our general retention periods (in case of e.g., complaints, objections, or other specific situations).

 

We share your personal data within the group and make your personal data available to our processors who e.g., host, develop, and support our IT systems.

 

We transfer your personal data to our group companies and our processors and/or other suppliers or vendors located in third countries. Please see below regarding Transfer of your personal data to third countries.

 

The following applies to GUBI Design Inc. customers:

Processing of personal data

If you as a United States-based customer buy a product from the web shop operated by GUBI Design Inc. and/or communicate with GUBI Design Inc. in that regard, GUBI Design Inc. will process your personal data in accordance with the CCPA or applicable State law equivalent.

 

This section provides additional details about the personal data we collect and use for purposes of CCPA or applicable State law equivalent.

 

The sections above describe the personal data we may have collected about you within the last 12 months, including the categories of sources of that information (see above under "The following applies to GUBI A/S customers "). We collect this information for the purposes of, as well as disclose it, as described in the above sections.

 

Your CCPA rights and choices.

As a United States consumer and subject to certain limitations under the CCPA or applicable State law equivalent, you have choices regarding our use and disclosure of your personal data:

 

• Exercising the right to know: You may request the following information about the personal data we have collected about you (see also below under Your Rights etc.):

o The categories and specific pieces of personal data we have collected about you,

o The categories of sources from which we collected the personal data,

o The business or commercial purpose for which we collected the personal data,

o The categories of third parties with whom we shared the personal data, and

o The categories of personal data about you that we disclosed for a business pur-pose, and the categories of third parties to whom we disclosed that information for a business purpose.

• Exercising the right to delete: You may request that we delete the personal data we have collected from you, subject to certain limitations under applicable law.

• Exercising the right to opt-out from a sale: You may request to opt out of any “sale” of your personal data that may take place. We do not use, share, rent, or sell the personal data of our customers for interest-based advertising. We do not sell or rent the personal data of our customers or our site visitors.

• Non-discrimination: The CCPA or applicable State law equivalent provides that you may not be discriminated against for exercising these rights.

 

If you have a question about our privacy policies, please contact us (see contact information below).

 

3 When you are or represent a B2B customer, partner, supplier or other third party

When we communicate with you

When we communicate (e.g., via email), including if you communicate with us as or on behalf of a B2B customer, partner, supplier, or another third party, your communication may often contain personal data, e.g., your contact details (including name and email address), association with a certain company, or other personal data you may provide us with. We may also receive such per-sonal data from a third party, such as your employer. If you communicate via our website form, we process personal data related to country and customer type. If you are a member of the press or otherwise connected to the media, we process your name and contact details as part of the com-munication related to press releases or similar. Such personal data is also stored in our CRM-system (see below under "Customer Administration (CRM)").

 

We process this personal data for the purpose of managing and answering your inquiries and orders and to communicate with you/the company you represent.

 

The legal basis for the processing is article 6(1)(f) of the GDPR, as we are pursuing our legitimate interests in managing general inquiries, providing customer support, and fulfilling any agreement we may have concluded with the company you represent.

 

If you are not or do not represent a customer, personal data pertaining to our general communica-tion with you (such as email inquiries) will be deleted 6 years after the end of the financial year where your last inquiry has been handled/concluded. If you are or represent a customer, please see the retention period below under "Customer Administration (CRM)".

 

Any personal data included in particular inquiries, agreements, or other matters, as well as any personal data used for standard sales and customer service activities (such as your contact de-tails) are shared with our group companies. This is done for the purpose of providing efficient and stable customer service, irrespective of what group company you have concluded an agreement with. That also means that we may have received personal data about you from one of our group companies, e.g., for the purpose of processing such inquiries.

 

We disclose personal data included in our account records to the relevant public authorities, including tax and customs authorities, in connection with our statutory bookkeeping, etc. We may also disclose your personal data to our relevant business partners, including external advisors. We share your personal data within the group and make your personal data available to our proces-sors who, for example, host, develop, and support our IT systems.

 

We transfer your personal data to our group companies and processors and/or other suppliers or vendors located in third countries. Please see below regarding Transfer of your personal data to third countries.

 

Customer Administration (CRM), use of GUBI Partner Portal, and/or establishing a myGUBI app account and use of the myGUBI mobile app

 

We will register your personal data in our IT system (“CRM System”), including your name, contact details, and, if you do not represent a company, your bank account information. If you are representing a company, we process information about your association with such company. We process this personal data as part of our day-to-day customer administration, e.g., for the purpose of keeping in touch and maintaining the customer relationship, for billing purposes, or in order to deliver our services.

 

If you sign-up for the GUBI Partner Portal, we process your email address (if this is a personal address) and the password you generate (if this is linked to a person). If you establish a myGUBI app account, we process the contact details you provide to us, including e.g., your name and contact details and the password you generate. When using the myGUBI mobile app, we process personal data related to any comments you might give in relation to our products and we may track your behaviour in the myGUBI mobile app, if you have given permission to track.

 

The legal basis for our processing is article 6(1)(f) of the GDPR. With regard to the CRM processing, we pursue our legitimate interest in solving day-to-day customer administrative tasks and communicating with our retailers and other persons, as well as managing accounting and finance tasks. With the GUBI Partner Portal and myGUBI app account, we pursue our legitimate interest in ensuring you are able to log on to the portal/account and, in relation to the portal, follow the pur-chase history related to the business that you represent. In relation to the myGUBI app, we pur-sue our legitimate interest in processing your comments in relation to the development, produc-tion, and sale of our products. With regard to any tracking on the myGUBI mobile app, please see above under Section 1 and our Cookie Policy.

 

Personal data related to CRM matters will generally be deleted 6 years after the end of the finan-cial year in which the customer relationship has ended. With the GUBI Partner Portal and myGUBI app account, personal data will be deleted when the log on/account has been inactive for 2 years.

 

We may disclose your personal data to our relevant business partners, including external advisors. We share your personal data within the group and make your personal data available to our pro-cessors who for example, host, develop, and support our IT systems.

 

We transfer your personal data to our group companies, processors, and/or other suppliers or vendors located in third countries. Please see below regarding Transfer of your personal data to third countries.

 

4 When you receive our newsletter (direct marketing)

When you subscribe to our newsletter, we register your name, email address, and the preferences you have given in connection with your subscription. We process this personal data for the pur-pose of being able to send you newsletters. If you have interacted with us prior to subscribing to our newsletter (e.g., by browsing our website or purchasing products) we use such information to recommend relevant products to you through our newsletters (profiling).

 

The legal basis for our processing is your consent in accordance with section 10 of the Danish Marketing Practices Act (markedsføringsloven) and article 6(1)(a) of the GDPR.

 

Personal data pertaining to our distribution of electronic newsletters will be deleted 2 years after our last newsletter has been distributed, unless you have withdrawn your consent (i.e., unsub-scribed) before such time.

 

Right to object to profiling and direct marketing

 

Profiling based on legitimate interests

For reasons relating to your particular situation, you have the right to object to the processing of your personal data where the processing is based on our legitimate interests and/or includes profiling as stated above. Hereafter, GUBI A/S may no longer process the personal data unless GUBI A/S demonstrates compelling legitimate grounds for the processing which override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defence of legal claims.

 

Direct marketing

If personal data is processed for direct marketing, you have the right at any time to object to the processing of your personal data for such marketing, including the right to object to profiling in so far as it relates to direct marketing. If you object to processing for the purpose of direct marketing, the personal data may no longer be processed for this purpose.

 

See our contact information below.

 

We share your personal data within the group and make your personal data available to our pro-cessors who for example, host, develop, and support our IT systems.

 

We transfer your personal data to our group companies, processors, and/or other suppliers or vendors located in third countries. Please see below regarding Transfer of your personal data to third countries.

 

5 When you participate in competitions, events, webinars etc.

If you sign-up for competitions, events, webinars, etc., you provide us with your name and email address and association with a certain company. We process this personal data for administration purposes and in order to be able to communicate with you/the company you represent.

 

The legal basis for the processing is article 6(1)(f) of the GDPR, as we are pursuing the legitimate interests referred to above. If you are not or do not represent a customer, personal data processed for such purposes will generally be deleted 6 years after the end of the financial year in which the personal data was collected. If you are or represent a customer, please see the reten-tion period above under "Customer administration (CRM)" in section 3.

 

We share your personal data within the group and make your personal data available to our processors who, for example, host, develop, and support our IT systems.

 

We transfer your personal data to our group companies, processors, and/or other suppliers or vendors located in third countries. Please see below regarding Transfer of your personal data to third countries.

 

 

Children’s Privacy

 

The GUBI website and services provided therein are not directed to anyone under the age of 13. The GUBI website does not knowingly collect or solicit information from anyone under the age of 13, or allow anyone under the age of 13 to sign up for any services offered therein. In the event that we learn that we have gathered personal data from anyone under the age of 13 without the consent of a parent or guardian, we will delete that data as soon as possible. If you believe we have collected such data, please contact us (see Contact details below).

 

 

Transfer of your personal data to third countries

 

If stated under one of the above sections that we transfer your personal data to third countries, the following applies:

 

In case that we transfer your personal data personal to our group companies, we transfer such personal data to the United States, Australia, and China.

 

In case that we transfer your personal data to our processors and/or other suppliers or vendors, your personal data is transferred to Switzerland and the United States.

 

The basis for the transfer to the United States, Australia, and China is the Commission Decision of 4 June 2021 on standard contractual clauses for the transfer of personal data to third countries pursuant to Regulation (EU) 2016/679 of the European Parliament and of the Council.

 

With regard to Switzerland, the basis for the transfer is the Commission Decision of 26 July 2000 pursuant to Directive 95/46/EC of the European Parliament and of the Council on the adequate protection of personal data provided in Switzerland.

 

If you want additional information about our transfer of personal data to third countries, including a copy of the above-mentioned standard contractual clauses, you may make a request for such additional information by contacting us (see Contact details below).

 

 

Your rights etc.

 

You have special rights to help you control your personal data, and we wish to make it easy for you to exercise those rights:

 

Right to withdraw consent

Where you have given your consent for our processing of your personal data, you have the right to withdraw your consent at any time. You can withdraw your consent by contacting us (see Contact details below).

 

If you withdraw your consent, the withdrawal will not affect the lawfulness of processing that has already been carried out based on your consent.

 

Right of access

You have the right to have confirmed whether collection or processing your personal data has taken place, and, if so, you have the right to request a copy of your personal data in a digital format.

 

Right of rectification

You have the right to require that we correct any inaccurate personal data, and that we complete incomplete personal data.

 

Right of erasure

In certain circumstances, you have the right to request that we erase personal data concerning you; for example, if it is no longer necessary for the purposes in which it was originally collected.

 

Right to restrict processing

In certain circumstances, you have the right to request that we restrict the processing of your personal data, for example, if you believe that the personal data is not accurate or lawfully processed.

 

Right to object to the processing

In certain circumstances, you have the right to request that we stop processing your personal data. Please see above in relation to your right to object to profiling and direct marketing.

 

Right to data portability

In certain circumstances, you have the right to receive the personal data you have provided us with in a structured, commonly used, machine readable format, and the right to have us transmit the data to another entity, where technically feasible.

 

Complaint to a supervisory authority

If you want to lodge a complaint with a supervisory authority about GUBI A/S’ processing of your personal data (see sections 1-5 above), you can do so by contacting the Danish Data Protection Agency via their website, www.datatilsynet.dk. With regard to GUBI Design Inc. (see section 2 above), you may contact the applicable United States federal or state governing body.

 

You can read more about your rights in the Danish Data Protection Agency's guidelines on data subjects' rights, which is available at datatilsynet.dk (in Danish) and at datatilsynet.dk (in English).

 

To read more about your rights under the California Consumer Privacy Act, information is available at CCPA.

 

Please contact us if you wish to exercise any of your rights. The relevant contact details are stated below.

 

 

Changes to our Privacy Policy

 

We reserve the right to change this privacy policy at any time. You should thus periodically check the privacy page for updates.

 

 

Contact details

 

If you have any questions about how we process personal data, please contact us.

GUBI A/S
CVR no. 17 94 03 84
Orientkaj 18-20
DK-2150 Nordhavn
Denmark

 

GUBI Design Inc.

Please reach out to GUBI A/S


Phone: + 45 33 32 63 68
Email: gubi@gubi.com