Date of last revision: May 2018, updated to correspond with GDPR requirements
About this policy
At Digital Fabric Ltd (”Zadaa”) we take data protection seriously. We hope that you will take a moment to read this policy.
- What personal data we collect when you create an account, use the Zadaa app or browse on our website (”Services”)
- How we may use and share your personal data
- Your legal rights and how to exercise them
What Personal Data do we Process?
Zadaa collects two types of information from our Users: (i) User Data; and (ii) Technical Data. Although we do not normally use Technical Data to identify you as an individual or combine the technical data with your personal data, you can sometimes be recognized from it. In such situations, Technical Data can also be considered personal data under applicable laws.
Please note that payment information is primarily processed by a third party payment service provider.
Within the Zadaa app we process the following User data:
- Your full name
- Birth year
- Phone number
- E-mail address
- Bank account information
- Height, weight and body type (as reported by you)
- Clothing size information
- Possible communication with us or with other users
- Payment history
- Your purchases on this site (item and value)
- Possible claims or refunds
- Delivery information and delivery status
- Bank account information
- Possible use of campaign or promo codes
- Direct marketing opt-outs and opt-ins
Technical data may include for example the following data:
- IP address
- Device type
- Operating system
- Time of visit
- Browsing patterns within the app or on our website
- Browser type and version
- Language settings
- Crash reports
We may also update and supplement personal data with information provided by third parties in accordance ith applicable data protection laws.
Purposes and legal grounds of processing
We may collect and use Users’ personal data for the following purposes:
- To provide the zadaa.co website and App in accordance with our Terms of Service
- For customer service, feedback and support
- For security improvements and troubleshooting
- To personalize User experience
- To improve and develop our service, including improvements made to algorithms, processes and service experience
- Trend detection and statistics
- Prevention on fraud or other illegal activities or misuse of the service
- To process payments and transactions
- For direct marketing and advertising purposes
- User analytics and statistics
- To comply with laws and regulations
Our legal grounds for processing your personal data are carrying out our user contract, fulfilling our legal obligations and based on our legitimate interests.
How long do we keep your data?
Zadaa does not store personal data longer than is legally permitted and necessary for the purposes specified above. The storage period depends on the nature of the information and the purposes of processing. The maximum period may therefore vary per use.
Once the data is no longer necessary, we delete or anonymize it as soon as reasonably possible.
Cookies and Local Storage Technologies
Our Services may use ””cookies”” and other industry standard local storage technologies and tools like pixel tags, web beacons and local shared objects (flash cookies) to enhance user experience and analyze the use of our services.
Local storage technologies and tools may also be placed on your device by our third-party partners and service providers. The services may also contain advertisements served by third parties that deliver third-party cookies or other tracking technologies to your device so your online activities across third-party sites or online services can be tracked for advertising purposes. We have no access to or control over the third party cookies and technologies. The Network Advertising Initiative provides opt-out mechanisms from some behavioral online advertising: http://www.networkadvertising.org/choices/. Users located in the European Union can learn of their rights relating to online advertising at www.youronlinechoices.eu.
The Services uses Google Analytics and other web analytics services to compile reports on visitor usage and to help us improve the Services. For an overview of Google Analytics, please visit http://www.google.com/analytics/. You can opt-out of Google Analytics with this browser add-on tool: https://tools.google.com/dlpage/gaoptout
Data Disclosures and International Transfers
We may share information regarding Users with our trusted business partners and affiliates strictly for the limited purposes outlined above.
We may use third party service providers to enable us to provide the website or the App or administer related activities on our behalf, such as payment service providers, and services for sending out newsletters or surveys. We may share your information with these third parties only for those limited purposes.
In addition to disclosing personal data, we may disclose pseudonym data, and aggregated or other anonymous data to third parties for advertising and user analytics purposes.
We may disclose personal data to public authorities if we are legally required to do so. We may also transfer or assign your information to our group companies, subsidiaries and affiliates as well as to a subsequent or new owner/operator of the services in case the services, we, our stock and/or assets are acquired or in case of merger, restructuring, bankruptcy, or other corporate reorganization.
We may process or transfer your personal data in and to any country where we operate or where we have employees or service providers or partners, including countries outside the European Union or the European Economic Area. Such processing, transfer and assignments will be carried out in compliance with applicable law. In cases where the level of data protection may not be deemed adequate by the European Commission, we always, by applying contractual and other measures, ensure that adequate protection for your personal data is provided as required by applicable laws, for personal data transfers to third countries. If you wish to know more about international transfers of your personal data, you may contact us via the contact details given below.
As with any other business, Zadaa could merge with or be acquired by another company, sell all or substantially all of its assets or a line of business, or undergo a similar event. Zadaa has the right to assign or share the information it maintains, including personal data, to one or more affiliates or to one or more successors, assigns, acquirers, or affiliates in connection with a restructuring, reorganization, merger, acquisition or other change of control of Zadaa, as well as in the unlikely event of Zadaa’s insolvency, bankruptcy or receivership.
We will only send you direct marketing content if you have opted in to receiving it.
In any case you have the right to prohibit us from using your personal data for direct marketing purposes by contacting us or by using the unsubscribe possibility offered in connection with our newsletter.
Safeguarding your Data
We do our best to keep your data safe and secure. We use administrative, organizational, technical, and physical safeguards to protect the personal data we collect and process. Measures may include, for example, where appropriate, encryption, pseudonymization and access right systems. We regularly test our systems, and other assets for security vulnerabilities.
Should despite of the security measures, a security breach occur that is likely to have negative effects to your privacy, we will inform you and relevant authorities as required by applicable data protection laws.
Right to Access
You have the right to know what personal data we have stored about you by sending us a written request to the address indicated below.
Right to Correct
You also have the right to have incorrect/unprecise, incomplete, outdated, or unnecessary personal data we have stored about you corrected or completed by contacting us on the address indicated below. In case you consider your personal data collected by us to be inaccurate, or you wish your personal data to be erased in a case where the processing of your personal data has been deemed unlawful, or the personal data is no longer necessary, or you have objected to the processing and the existence of legitimate grounds for processing are being verified, you may request restriction of processing of your personal data.
Right to erasure
You may also ask us to erase your personal data from our systems. We will comply with such request unless we have a legitimate ground to not delete the data.
Right to withdraw your consent
You have the right to opt out of receiving electronic direct marketing communications from us by clicking on the opt-out link provided in all marketing communications we send you, and choosing not to receive marketing communications from us in the future. You also have the right to prohibit us from using your personal data for direct marketing purposes, market research and profiling by contacting us on the addresses indicated below. In case your personal data is processed based on your consent, you have the right to withdraw your consent for such processing.
Please note that in case you prohibit us from processing your personal data, we may not be able to continue to provide the Services to you.
Users may object to the processing of personal data if such data are processed for other purposes than those necessary for the provision of the Service to the User or for compliance with a legal obligation. In case we do not have legitimate grounds to continue processing such personal data, we shall no longer process the personal data after your objection.
Users may request us to restrict processing of personal data for example when your data erasure, rectification or objection requests are pending and/or when we do not have legitimate grounds to process your data. This may however lead to fewer possibilities to use our site.
In certain cases users may have the right to receive their personal data from us in a structured and commonly used format and to independently transmit those data to a third party.
How to use these rights
These rights may be used by sending a letter or secure e-mail to us on the addresses set out above, including the following information: name, address, phone number and a copy of a valid ID.
We may request the provision of additional information necessary to confirm the identity of the data subject. We may charge a reasonable administrative processing fee in case less than 12 months have passed since your last data request.
We may reject requests that are unreasonably epetitive, excessive or manifestly unfounded.
In case you consider our processing activities of your personal data to be inconsistent with the applicable data protection laws, you may lodge a complaint with the local supervisory authority for data protection.
The Services are not intended for users under the legal age of 16. We do not knowingly collect any personal data from children under this age.
Digital Fabric Oy
Business ID 2688054-4
Address Bulevardi 14 A 5th floor, 00120 Helsinki Finland