デリラ・エルゴ プライバシーポリシー(グローバル)

 

DERILA ERGO PRIVACY POLICY (GLOBAL)

  1. WHY SHOULD YOU READ THIS PRIVACY POLICY?

In Short: This Policy explains how we handle your Personal Data. It helps you understand what we do with your information and what your privacy rights are.

Welcome! This Privacy Policy (“Policy”) explains how UAB Domestica, trading under the Derila Ergo brand and other Household brands ("Company", "we", "us", or "our") handles your Personal Information (“Personal Information” or “Data”) when you: 

  • Visit our sales websites (“Website”);
  • Purchase our products or services (“Goods” or “Service”);
  • Otherwise interact with us (support, social media, contests, affiliate programs, etc.).

This Policy outlines what Data we collect, the purposes for which it is collected, how we use and share it, how long we retain it, your rights, and how we protect your Data. We are committed to processing your Data lawfully, fairly, and transparently in accordance with: 

  • The General Data Protection Regulation (GDPR);
  • The ePrivacy Directive 2002/58/EC;
  • UK General Data Protection Regulation (UK GDPR);
  • Australia’s Privacy Act 1988 and Australian Privacy Principles (APPs);
  • and any other applicable data protection laws.

This Policy applies globally and is founded on the principles of the GDPR. It reflects high-standard data protection values such as lawfulness, fairness, and transparency. Specific national or regional requirements are addressed in the Regional Addenda (for the United Kingdom, Australia, the United States, Canada, and other jurisdictions) located at the end of this Policy.

If you do not agree with our practices, please refrain from using the Website, purchasing our Goods or Services or submitting your Data in any other way. This Policy is effective as of 20th of November 2025. We may update this Policy occasionally, and all updates take effect upon publication, so we encourage you to review it regularly to stay informed.

     2. WHO IS RESPONSIBLE FOR PROTECTING YOUR Personal Data?

We are UAB Domestica, your Personal Data Controller

Our company number is 307174704

Our registered address Gedimino st. 45-7, LT-44239 Kaunas, Lithuania

Our support e-mail address support@derila.com 

We have appointed a Data Protection Officer (DPO) to oversee our data protection obligations. You can contact the DPO directly at dpo@derilaergo.com 

    3. FOR WHAT PURPOSES AND WHAT DATA DO WE COLLECT? 

In Short: We mainly collect only the Data needed to provide our Goods or Services and operate our Website. This section explains why we collect it and how we use it.

We only collect the Data we truly need – and only use it for clear, lawful reasons (e.g., to process your purchase, provide services, respond to your inquiries, ensure Website functionality, etc.). You can find a full list of purposes, the Data we collect, how we use it, and more detailed information in the tables below, see Section 13 of this Policy.

Here are also a few important things for you to know:

  • Lawful basis: We will only process your Data if we have a lawful basis under applicable data protection laws. The lawful bases that we might rely on are normally contract, consent, legal obligation or legitimate interest. 
  • Sensitive Data: we do not intentionally collect or process sensitive sensitive Data (like your health, religious beliefs, or biometric data).
  • Marketing: We only use your Data for marketing if you’ve clearly consented or if we have other legal bases. 
  • Automated tools and AI: We may use AI or other fully or semi-automated technologies to support service delivery (e.g., chatbots, ChatGPT, Gemini etc.), but we do not use automated decision-making that produces legal or similarly significant effects on you within the meaning of Art. 22 of the GDPR.
  • No sale of Data: We never sell your Data to anyone for monetary value.
  • Children’s data: This Website is not intended for minors. We do not knowingly collect Personal Data from minors without appropriate consent. If we become aware that we have inadvertently received Personal Data from a child, we will delete such information promptly. 

    4. FROM WHAT SOURCES DO WE GET YOUR DATA? 

In Short: We get your Data directly from you, through your use of our Website, or from trusted third parties and public sources. This helps us operate our Services and stay in touch with you.

We might collect Data from the following sources:

  • Directly from you: When you place an order, contact us for support or inquiries, fill out forms, surveys, participate in contests or promotional campaigns.
  • Automatically via technology: When you visit or interact with our Website or other online platforms, we automatically collect certain Data, including identifiers and information regarding your activity. We utilize cookies and similar technologies to enhance your experience, analyse usage patterns, and secure our platforms.
  • From third parties, vendors, and service providers: When we receive services from third party providers – such as hosting platforms, software providers, or professional consultants - we normally receive Data about you directly from them.
  • From our affiliate and referral partners: If you follow a referral link or use a partner discount code, we may receive information that might contain your Personal Data. 
  • From other Intra-Group companies (if applicable): Where necessary for internal administrative, service provision, or business development purposes, we may receive your Data from other entities within our corporate group. 
  • From publicly available sources (if applicable): Where appropriate and permitted by law, we may collect Personal Data from public registers (e.g. company registries, professional association websites), official government databases, or social media profiles (e.g. LinkedIn), particularly in the context of business-to-business (B2B) communication, professional outreach or due diligence

     5. DO WE SHARE YOUR DATA WITH OTHERS? 

In Short: Yes, but only when necessary and with strong safeguards—always ensuring your privacy is protected. 

Yes - but only when necessary, and with your privacy in mind.

We may share limited Data with trusted third parties to provide our services, meet legal obligations, or support daily business operations. Whenever we do, we ensure that your Data is protected and handled responsibly. For this reason, parties who process Data on our behalf act as Data Processors and are contractually bound by Data Processing Agreements (DPAs). These agreements ensure that they follow our instructions, apply appropriate safeguards, and do not use your Data for their own purposes. We may share your Data with:

  • Service Providers (Data Processors): We engage with various service providers to support our business functions (e.g. IT support, hosting, payments, analytics, customer service, marketing, auditing, legal services, etc.). Service providers process Data strictly on our behalf and under our documented instructions. 
  • Intra-Group Companies (Data Processors or Joint Controllers): We may share your Data with other entities within our corporate group for internal administrative purposes, centralised services, or to provide integrated services.
  • Public authorities and other Data Controllers: In certain circumstances, your Data may be shared with third parties who act as independent Data Controllers and determine their own purposes and means of processing, such as public authorities, law enforcement agencies, courts, insurers, fraud prevention services agencies, independent service providers etc. 
  • Other corporate entities or auditors: In the context of a potential or actual merger, acquisition, asset sale, or restructuring, we may disclose limited Data to potential investors, buyers, or their auditors, and advisors.
  • Other third parties with your consent: Where legally required, we will only share your Data with third parties if you have explicitly given us your informed, freely given consent. 

    6. HOW LONG DO WE KEEP YOUR DATA?

In Short: We keep your Data only as long as necessary for legal, contractual, or service-related purposes - then we delete or anonymize it securely.

We keep your Data only for as long as necessary to:

  • Fulfil the purposes for which it was collected, 
  • Provide you with our Goods or Services,
  • Comply with legal, regulatory, or contractual obligations, or
  • Resolve disputes or enforce our agreements.

Detailed retention periods for each Data processing purpose are set out in Section 3 of this Policy.

Once the applicable retention period has expired, we will either securely delete your Data or irreversibly anonymize it within a reasonable timeframe, in line with best industry practices and legal requirements.

    7. HOW DO WE ENSURE THE SECURITY OF YOUR DATA?  

In Short: We use strong technical and organizational measures to keep your Data safe and work continuously to prevent unauthorized access and protect your privacy.

We are committed to protecting your Data and take the security of your information seriously. We apply a combination of technical and organisational measures to prevent unauthorised access, accidental loss, misuse, alteration, or disclosure of Personal Data. Our security safeguard practices are based on core data protection principles and include, but are not limited to:

  • Collecting Data only for specified and lawful purposes,
  • Processing Data fairly and transparently,
  • Retaining Data only as long as necessary,
  • Limiting access to Data strictly to authorised employees,
  • Sharing Data with third parties only when legally justified,
  • Providing regular data protection training to our employees,
  • Conducting internal and/or external IT security audits,
  • Using encryption for sensitive data,
  • Performing regular Data backups and activity logging,
  • Continuously improving processes to ensure Data security,
  • Regularly monitor our systems for potential threats or breaches.

While we apply strong security measures, no system is entirely risk-free - especially during internet transmissions. To help protect your Data, please stay vigilant online and always use a strong, unique password, keep it confidential, secure your devices, and be cautious when sharing information, especially via suspicious links. Security incidents resulting from user actions (e.g. credential sharing or phishing) may fall outside our control.

     8. DO WE TRANSFER YOUR DATA INTERNATIONALLY? 

In Short: Yes, sometimes - but only when necessary and always with strong legal safeguards to keep your Data protected.

Yes - but only when necessary, and always with strong protection in place.

We mainly store and process your Data within the European Economic Area (EEA), and there may be times when some of your Data is transferred to trusted partners or service providers located in countries outside the EEA - for example, for cloud hosting, technical support, or specialist services. Where applicable, such recipients are listed in Section 3 of this Policy.

Whenever we send your Data outside the EEA, we make sure that it remains protected, and your privacy rights are respected. We never transfer your Data lightly - we always assess the risks and take appropriate steps to keep your Data safe, wherever it goes. Where Data is transferred outside the EEA:

  • We check whether the country has an “adequacy decision” from the European Commission, which means it provides a level of data protection similar to that of the EU; 
  • Where no adequacy decision exists, we rely on the Standard Contractual Clauses (SCCs) approved by the European Commission. These are legally binding agreements requiring the recipient to uphold EU-level privacy and security standards EU Standard Contractual Clauses
  • Before using SCCs, we conduct a Data Transfer Impact Assessment, as required by the Schrems II decision and EDPB guidance, to evaluate whether additional safeguards are necessary in the recipient country; 
  • Where needed, we may also apply supplementary technical or contractual safeguards, such as encryption, access controls, and audit rights.

If you would like more details about these transfers, you can contact us using the details provided in Section 11 of this Policy.

    9. DO WE USE AUTOMATED DECISION-MAKING OR PROFILING? 

In Short: Yes, but we don’t make important decisions about you based solely on AI. We may use smart tools to support our services, but all important decisions involve real people, not just programs.

Yes. We may use certain Artificial Intelligence (AI) - based tools and fully or semi-automated systems - for example, in customer support or during phone calls - to enhance the speed and accuracy of our services.

However, we do not engage in automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you, within the meaning of Art. 22(1) the GDPR. Specifically:

  • Any recommendations, responses, or information generated by AI tools are provided for informational purposes only and are subject to review and validation by our human staff;
  • We do not use algorithms or automated systems to make decisions about you that produce legal effects (e.g., the denial of a service), without meaningful human involvement;
  • You have the right to request human intervention and express your point of view if you believe any decision or response has been generated through automated means that significantly affects you, and to obtain an explanation and review of such a decision by a human member of our staff.

    10. WHAT ARE YOUR RIGHTS? 

In Short: You have rights over your Personal Data, including access, correction, deletion, objection, and more. This section outlines how you can exercise them and what to expect.

If we process your Data as set out in this Policy, or you believe we may be doing so, you have the following rights as a Data Subject. These rights apply regardless of whether we process your Data as a client, supplier, contractor, or professional contact: 

  • Right to Be Informed – You have the right to clear, transparent information about how we collect and use your Data. This detailed Policy aims to provide that (Art. 12-13 of the GDPR);
  • Right of Access – You can ask us whether we process your Data and request a copy of the Data we hold about you (Art. 15 of the GDPR);
  • Right to Rectification – If your Data is inaccurate or incomplete, you can ask us to correct or update it (Art. 16 of the GDPR);
  • Right to Erasure (“Right to Be Forgotten”) – You can request that we delete your Data if it is no longer necessary for the purposes for which it was collected, you withdraw your consent (where processing was based on consent), you object and there are no overriding legitimate grounds, or the Data was unlawfully processed. 

Note: This right is subject to limitations. For example, we may retain certain Data if required for legal compliance, dispute resolution, or contractual purposes (Art. 17 of the GDPR);

  • Right to Restrict Processing – You may request that we temporarily limit the processing of your Data in situations such as contesting the accuracy of the Data, or objecting to processing while we assess our legal grounds (Art. 18 of the GDPR);
  • Right to Data Portability – Where processing is based on your consent or a contract and carried out by automated means, you can request a copy of your Data in a structured, commonly used, machine-readable format, and ask us to transfer it to another provider (Art. 20 of the GDPR);
  • Right to Object – You can object to processing based on our legitimate interests or for direct marketing purposes. We will stop such processing unless we demonstrate compelling legitimate grounds (Art. 21 of the GDPR);
  • Right to Withdraw Consent – Where we rely on your consent, you may withdraw it at any time. This will not affect the lawfulness of processing that took place before your withdrawal (Art. 7(3) of the GDPR);
  • Right to Lodge a Complaint – If you’re unhappy with how we handle your Data, please contact us first - we’ll do our best to resolve the issue. However, you may also lodge a complaint with the Lithuanian State Data Protection Inspectorate (https://vdai.lrv.lt/lt/) or the supervisory authority in your country of residence or place of work. 

Please note: Your rights are not absolute. In some cases, the exercise of your rights may be restricted under applicable data protection laws - for example, where fulfilling your request would adversely affect the rights and freedoms of others, or where we are legally required to retain certain Personal Data (e.g. for compliance, legal claims, or regulatory purposes).

    11. HOW TO EXERCISE YOUR RIGHTS OR CONTACT US? 

If you have any general questions about this Policy, how we process Data, a complaint or if you wish to exercise any of your Data Subject rights, you can contact us by email at dpo@derilaergo.com

To help us process your request efficiently, please:

  • Clearly express your question or complaint,
  • Specify which Data Subject right you wish to exercise (if applicable),
  • Provide enough information to identify you (we may ask for proof of identity or proceed identity verification process), and
  • Include any relevant details that will help us respond quickly.

You may also authorise someone to act on your behalf. If so, please ensure your authorized person provides us with written and signed authorisation confirming they are allowed to act for you. We may deny a request if sufficient proof of authorization is not provided.

We aim to respond without undue delay and within one month of receiving your request. 
If your request is particularly complex or involves multiple issues, we may extend this period by an additional month in which case, we will inform you in advance and explain the reason for the delay.

     12. REGIONAL ADDENDA

This Addendum supplements our Global Privacy Policy and applies where your Personal Data is subject to the laws of the country or region in which you reside, or where our processing activities are specifically targeted. These regional terms complement the Global Privacy Policy and override it only where required by applicable local law.

🇬🇧  UNITED KINGDOM (UK)

If you are a UK resident or our processing relates to UK individuals, the processing of your Personal Data is subject to the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018

Your Rights under UK Data Protection Law:

  • Right to be informed (Article 13–14 UK GDPR) – to receive clear information about how we collect and use your Personal Data;
  • Right of access (Article 15 UK GDPR) – to request a copy of the Personal Data we hold about you;
  • Right to rectification (Article 16 UK GDPR) – to have inaccurate or incomplete Personal Data corrected;
  • Right to erasure (Article 17 UK GDPR) – to request deletion of your Personal Data in certain circumstances;
  • Right to restriction of processing (Article 18 UK GDPR) – to limit how we use your Personal Data in specific situations;
  • Right to data portability (Article 20 UK GDPR) – to receive your Personal Data in a structured, commonly used, machine-readable format;
  • Right to object (Article 21 UK GDPR) – to object to processing based on our legitimate interests or for direct marketing;
  • Right not to be subject to solely automated decision-making, including profiling (Article 22 UK GDPR) – where such decisions have legal or similarly significant effects.

International Data transfers from the UK:

If we transfer your Personal Data outside the UK (e.g., to the EEA, the United States, or other countries), we ensure that adequate safeguards are in place, such as:

  • An adequacy regulation issued by the UK Government; or
  • The UK International Data Transfer Agreement (IDTA) or UK Addendum to the EU Standard Contractual Clauses (SCCs), along with appropriate technical and contractual safeguards.

Supervisory Authority:

If you have concerns about how we handle your Personal Data, you may lodge a complaint with the UK’s supervisory authority: Information Commissioner’s Office (ICO), website: https://ico.org.uk. 

🇦🇺 AUSTRALIA

If you are an Australia resident or our processing relates to Australian individuals, the processing of your Personal Data is subject to the the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Your Rights under Australian Privacy Law:

  • Right to access (APP 12) – to request a copy of the personal information we hold about you;
  • Right to correction (APP 13) – to request correction if your personal information is inaccurate, incomplete, or out of date;
  • Right to lodge a complaint – if you believe we have breached your privacy under the APPs, you may submit a formal complaint; 
  • Right to interact anonymously or under a pseudonym (APP 2) you may choose not to identify yourself, where lawful and practicable (for example, for general enquiries). 

Direct Marketing and Unsubscribing:

We apply the same direct-marketing principles described in Section 3 of this Policy, in full compliance with APP 7 and the Spam Act 2003. We only send direct-marketing communications in accordance with these laws. Every electronic message identifies us and includes a functional unsubscribe option. If you unsubscribe, we will cease marketing to you.

International Data transfers from Australia:

We may disclose your personal information to recipients located outside Australia (e.g., in the EU, US, or other countries). Before doing so, we take reasonable steps to ensure that overseas recipients do not breach the APPs. These steps may include:

  • Entering into binding contractual agreements;
  • Conducting privacy and security due diligence;
  • Ensuring technical safeguards such as encryption and access control.

Supervisory Authority:

If a Data breach is likely to result in serious harm, we will promptly notify the Office of the Australian Information Commissioner (OAIC) and affected individuals. Also If you are not satisfied with our response to a privacy concern, you may contact OAIC, website: https://www.oaic.gov.au. 

🇨🇦 CANADA

If you are a Canadian resident or our processing relates to Canadian individuals, your Personal Data is subject to the Personal Information Protection and Electronic Documents Act (PIPEDA) and other applicable privacy laws.

Your Rights under Canadian Privacy Laws:

  • Right to know/access  - Request access to the Personal Information we hold about you and details about how we use and share it.
  • Right to correction  - to request correction of inaccurate Personal Information;
  • Withdraw consent -  Withdraw your consent to our use or disclosure of your Personal Information at any time, except where processing is required by law or necessary to provide requested services.
  • Right to data portability (Law 25) – Receive a copy of your Personal Information in a structured, commonly used format or transfer it to another organization where technically possible.
  • Right to Lodge a Complaint - File a complaint with the Office of the Privacy Commissioner of Canada (OPC) or, if you reside in Quebec, with the Commission d’accès à l’information du Québec (CAI), if you believe your rights have been infringed.

Commercial Electronic Messages (CASL)

We apply the same direct-marketing principles described in Section 3 of this Policy, in full compliance with Canada’s Anti-Spam Legislation (CASL). We obtain express consent (or rely on a permitted implied consent), identify our business in each message, include a working unsubscribe mechanism, and maintain records of consent. You can withdraw consent or unsubscribe at any time. 

International Data transfers from Canada:

Your Personal Data may be transferred outside Canada (e.g., to the EU, U.S., or other countries) for processing. We take contractual, organisational, and technical measures to ensure that any such transfers provide an adequate level of protection consistent with Canadian law or may be subject to foreign access laws. 

Supervisory Authority:

If you are not satisfied with our response to a privacy concern, you may contact: Office of the Privacy Commissioner of Canada (OPC), website: https://www.priv.gc.ca. For Québec residents, you may also contact the Commission d’accès à l’information (CAI) at https://www.cai.gouv.qc.ca .

🇺🇸 UNITED STATES (USA)

If you are a U.S. resident or our processing relates to U.S. individuals, your Personal Data may be subject to state privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and Utah Consumer Privacy Act (UCPA).

Your Rights under U.S. State Privacy Laws (which may vary by state):

  • Right to know/access – to request information about the categories and specific pieces of Personal Data we collect, use, disclose, sell, or share;
  • Right to deletion – to request the deletion of Personal Data we hold about you, subject to certain exceptions;
  • Right to correction – to request correction of inaccurate Personal Data;
  • Right to opt out – to opt out of: 

– the sale or sharing of Personal Data;

– the use of Personal Data for targeted advertising;

– profiling that has legal or similarly significant effects;

  • Right to data portability – to receive a copy of your Personal Data in a portable format;
  • Right to limit use of sensitive Personal Data (CPRA only) – to request restrictions on how we use sensitive information (e.g., precise geolocation, health data, financial data).

International Data transfers from USA:

If we transfer your Personal Data outside the United States (for example, to the EU, UK, or other jurisdictions), we apply contractual, organizational, and technical safeguards designed to ensure that the transferred data receives adequate protection, consistent with applicable U.S. state laws.

Do Not Sell or Share My Personal Information: If you wish to opt out of the sale or sharing of your Personal Data, please click the “Do Not Sell or Share My Personal Information” link available on our website footer.

Universal Opt-Out Mechanisms:

Where required (e.g., under CPRA, CPA, CTDPA), we honor Global Privacy Control (GPC) signals and other recognized universal opt-out mechanisms.

Supervisory Authorities:

If you have concerns about how we handle your Personal Data, you may contact your state Attorney General. For California residents, more information is available at: https://oag.ca.gov/privacy/ccpa.

13. DETAILED INFORMATION ABOUT THE PROCESSING OF YOUR PERSONAL DATA

13.1. TO PROCESS AND FULFIL YOUR ORDER 

When do we process your Personal Data?

When you purchase Goods via our Website, we process your Data to manage your order, arrange delivery, handle payments and provide related services (e.g., order confirmation, updates, returns, or refunds).

Note: Goods are sold without creating a customer account.

Data categories

Identification and contact details: full name, delivery address, email address, phone number.

Payment details: price, currency, credit card brand, type, Bank identification number (BIN) number, and issuing country.

Technical information: IP address, language, device type.

Legal basic (s)

GDPR Art. 6(1)(b) – Contract:

  • to complete and deliver your purchase.

Data retention period

Order and payment records are retained for 10 years in line with legal, tax and accounting obligations.

Data recipients

  • Shipping and logistic providers (Worldwide);
  • Payment service providers and banks (EEA and non-EEA);
  • Intra-Group companies (EEA).


13.2. TO PROCESS PAYMENTS AND COMPLY WITH LEGAL OBLIGATIONS 

When do we process your Personal Data?

We process your Personal Data when handling payments related to your orders, subscriptions, discounts, returns, or refunds.

This processing also includes the performance of tax obligations, such as issuing invoices, maintaining accounting records, and fulfilling other legal statutory requirements.

Data categories

Payment Information: payment method (card type, last few card digits), payment token, transaction amount, transaction date and time, refund reasons.

Billing & Legal Data: name, email, phone, billing address, IBAN/account number, payment records, invoices, VAT and other required accounting or legal documentation.

Customs or Import/Export Information (where applicable): personal identification codes or customs data required by law in certain countries (e.g., for shipments subject to customs clearance).

Legal basic (s)

GDPR Art. 6(1)(b) – Contract:

  • to receive and manage payments. 

GDPR Art. 6(1)(c) – Legal obligation:

  • to fulfil statutory accounting requirements.

Data retention period

We retain accounting-related data for 10 years, as required by financial and tax regulations.

Data recipients

  • Payment processors (EU and Non-EEA);
  • Accountings processors (EEA);
  • Intra-Group companies (EEA);
  • Auditors (EEA).

 

13.3. TO PROVIDE CUSTOMER SUPPORT SERVICES

When do we process your Personal Data?

If you contact us by phone and/or in writing (via Live Chat, customer support, email, social media or otherwise), we will keep a record of the fact of your contact and the information you have provided to us, including your Personal Data, to properly process your request and respond to your question, request or complaint.

We use artificial intelligence (AI)-based tools (fully or semi-automated) to assist our customer support team. These tools are used for suggesting draft responses, guiding or answering calls before transfer to a human agent, transcribing and summarising conversations, and providing automated replies to frequently asked or trained questions.Note! All AI-generated outputs are reviewed and validated by human staff where decisions could affect your rights. We do not rely solely on automated decision-making that produces legal or similarly significant effects. We do not use your data for training AI models unless fully anonymized. 

Data categories

When contacted by call: name, surname, mobile phone number, email address, residential address, purchase details and other information required to verify your identity (if needed). Date and time of the call, duration of the call and a recording of the call.

Contact by email / or via Livechat, Customer Support: name, surname, mobile phone number, email address, residential address. Purchase details and other

information required to verify your identity (if needed). Other information related to the written request, attached documents or other visual content, all correspondence history.

Legal basic (s)

GDPR Art. 6(1)(b) – Contract:

  • provide Customer support service.

GDPR Art. 6(1)(f) – Legitimate interest:

  • respond, advise, provide and administer inquiries when any person initiates the first conversation.

Data retention period

Recordings of conversations - 6 months from the moment of creation.

Written communication - 3 years after your inquiry was closed.

We may retain some information longer if we are required to do so to comply with applicable laws or based on justified interests.

Data recipients

  • Customer support platform providers (Non-EEA);
  • AI support tools and chatbots (Non-EEA);
  • Customer support agents (some outside EEA);
  • Intra-Group companies (EEA).

 

13.4. TO PROVIDE TRANSACTIONAL COMMUNICATION

When do we process your Personal Data?

We have the right, in performing our rights and obligations under the Terms (“ToS”), to contact you at any time (e.g., provide transactional communication). We may send you important notifications and information by e-mail, SMS or phone call. 

Note! This important communication is not considered marketing, and you cannot opt out of it.

Data categories

Identification and contact details: name, surname, mobile phone number, e-mail address, residential address.

Call details: date and time, duration, the call recording.

Technical data: copies of electronic messages/SMS, delivery status and date, message opening (reading) status and date, links opened from the message content.

Legal basic (s)

GDPR Art. 6(1)(b) – Contract:

  • administration of the ToS and provision of important notifications.

Data retention period

Recordings of conversations are kept for 6 months from the moment of creation.

Electronic communications history logs are kept for 1 month, unless longer retention is required for legal purposes.

Data recipients

  • Communication service providers - e-mail/SMS/telephony platforms (EEA and Non-EEA);
  • Intra-group companies (EEA).

 

13.5. TO PERFORM DIRECT MARKETING ACTIVITIES

When do we process your Personal Data?

We process your Personal Data to inform you about our Goods and Services, promotions, new features, or to request your feedback. This includes sending general or personalized marketing content e.g., newsletters, promotional messages, surveys via email, SMS, or phone calls.

When you agree to receive marketing communications from the Company, this may include marketing information and offers about this specific brand and other brands operated within the Company. Marketing content may be customised based on the Data we already hold about you (e.g., previous purchases, browsing history, selected preferences), in order to provide you with relevant offers or content.

If you are an existing customer, we may contact you with marketing content about the same or similar products or services, even if you haven’t given explicit consent, provided that you were given the opportunity to object when your contact details were collected, that an opt-out option is included in each message, and that such contact is permitted by applicable law. The opt-out option is clearly provided during your purchase session on the “Thank You” page.

Remember! You have the right to object to or withdraw your consent for direct marketing at any time, free of charge, by:

  • using the unsubscribe link in any email;
  • using the unsubscribe link on the “Thank You” page;
  • replying “STOP” or the specified keyword to an SMS;
  • informing our representative during a call to be added to our Do Not Call list; or
  • emailing us with your request. 

Data categories

Contact details: full name, e-mail address, telephone number, country; 

Logs: consent collection logs (date, method, preferences, unsubscribe information, opt-out requests).

Marketing interaction data: information about how you engage with our marketing materials - such as message delivery and opening status, link clicks, campaign participation, communication preferences, unsubscribe or opt-out actions, and interaction timestamps.
Purchase and engagement history (if applicable): information derived from your previous transactions or marketing interactions, such as products purchased, referral sources, links used, or responses to promotional campaigns.
Technical information (for email or SMS delivery): device type, IP address, country. 

Legal basic (s)

GDPR Art. 6(1)(a) – Consent:

  • to process consent via preferred communication method.

GDPR Art. 6(1)(f) – Legitimate interest:

  • if you are an existing customer and have not objected, we may send limited marketing about similar products or services to maintain our customer relationship (soft opt-in).

Data retention period

3 years from consent given date, unless you unsubscribe earlier. 

Recordings of conversations - 6 months from the moment of creation.

Data recipients

  • Social media service providers (Non-EEA);
  • Marketing service providers (Non-EEA);
  • Intra-Group companies (EEA).

 

13.6. TO INTERACT WITH YOU VIA SOCIAL MEDIA 

When do we process your Personal Data?

We manage our business profiles and accounts on various social networks. If you are interested in our Services and follow our profiles on social networks, participate in our games, promotions, share your photos with us or tag us in your photos, public posts, etc., we collect and use your Data, which we receive directly from you, when you are active in our accounts.


Please note that our accounts are integrated into social networking platforms (e.g. Facebook, Instagram, Linkedin, etc.) and therefore all social platform providers as independent data controllers have full access to collect your Personal Data. You can find detailed information on the data processing, purposes and scope of data use by each social networking platform in the privacy policy of the respective social network. Also if you want to exercise your rights in relation to data processed by social networks, it is more efficient to contact the controller of the social network directly.

Data categories

Identifiers: name, surname, and profile photo;

Public interactions: likes, follows, comments, shares;

Participation: messages you send (content, time, attachments, history), active participation in games/events, any photos you send us or tag us in. 

Legal basic (s)

GDPR Art. 6(1)(a) – Consent:

  • to process Personal Data when you voluntarily take active steps on our social media accounts.

Data retention period

The provider of the social network concerned shall set the time limits for the retention of data. We recommend that you check the privacy policy of the social network concerned.

We normally retain and don’t delete them unless you withdraw consent, request deletion, or the platform enforces earlier deletion.

Data recipients

  • Social media service providers e.g. Facebook, Linkedin, Instagram, Tiktok (Normally these providers are Independent Controllers, however in certain cases, we and the provider may act as joint controllers. You can read more in the privacy notice of each provider) (Non-EEA);
  • Intra-Group companies (EEA);
  • Affiliates (some outside EEA).

 

13.7. TO DEFEND AND PROTECT OUR LEGAL RIGHTS OR INTERESTS 

When do we process your Personal Data?

We may process your Personal Data in case we become a party or concerned party in legal proceedings to which you are subject to, or we are statutorily required to collect and/or provide information about you in order to comply with the applicable law.


Also, in all cases where we suspect fraud, theft, unlawful reselling, misuse of marketing activities with our brand names, or other unlawful activities involving our Website, Company, brands and or services, we report such cases to the appropriate pre-trial investigation authorities (such as the police or prosecutor’s office).

Data categories

All information that we uphold about you and that is a part of the legal process e.g. accounting and legal case files, legal documents, other information you provide us with, other information that we are statutorily required to collect and/or provide. Also, pleadings, claims, court decisions.
If the case arises - information about criminal offenses and convictions, Special category data e.g. health information.

Legal basic (s)

GDPR Art. 6(1)(f) – Legitimate interest:

  • establishment, exercise, or defence of legal claims.
  • to protect our rights and interests.

Data retention period

As long as the legal proceedings are going and 10 years from the date of entry into force of the court or authority's decision, or the date on which the legally binding decision is fully implemented.

Data recipients

  • Legal parties e.g. Attorneys, Notaries, Bailiffs, Auditors, Consultants (EEA and Non-EEA);
  • Courts (EEA);
  • Consumer protection authorities and other institutions (EEA and Non-EEA).

 

13.8. TO MONITOR WEBSITE PERFORMANCE AND MARKETING EFFECTIVENESS 

When do we process your Personal Data?

When you visit and browse our Website, we process certain Personal Data for statistical, analytical, marketing, and performance monitoring purposes. This helps us improve the functionality, stability, security, and overall user experience of our Website.


Depending on your cookie preferences and consent choices, we may collect various information through cookies and similar tracking technologies, using trusted tools such as Google Analytics 4 or other authorized analytics and marketing platforms. Detailed information is provided in our Cookie Policy

Data categories

Identifiers: IP address or other device identifiers;

Technical information: device type, browser type, language settings, hardware/software settings and configurations, referring URLs (websites visited before/after);

Usage information: pages visited on our Website, interactions, clicks, or session behavior, visit timestamps, session duration, selected interface or account preferences (if applicable). 

Legal basic (s)

GDPR Art. 6(1)(a) – Consent:

  • We process this data only if you have actively consented to the use of performance and analytics cookies (via our Cookie Banner).

Data retention period

For more information on the retention periods of cookies, please refer to our Cookie Policy.

Data recipients

 

13.9. TO ORGANISE CONTESTS AND GIVEAWAYS

When do we process your Personal Data?

We process your Personal Data when you participate in our contests, competitions, games, or events. This is done to manage your participation, communicate with you, and (where applicable) publish or promote the outcomes of the activity.

Data categories

Identifiers: full name, email address, phone number;

Participation: social media engagement (comments, shares, “likes”, “follows”, reactions) contest entries, responses, evaluation/ratings, event attendance;

Media content: submitted or captured photos/videos, image/voice in recording.

Legal basic (s)

GDPR Art. 6(1)(a) – Consent:

  • for contest participation, contacting winners.

Data retention period

Contest participant data – retained for 1 year after the announcement of winners or as described in specific contest terms, unless a shorter or longer period is specified. 

Data recipients

  • Social media platform providers (Non-EEA);
  • Contest partners and co-organizers (EEA and Non-EEA).

13.10. TO CREATE AND USE PROMOTIONAL CONTENT

When do we process your Personal Data?

We process your Personal Data when you submit, create, or allow us to use content that features you for promotional purposes. This includes:

  • User-generated content (UGC), such as testimonials, reviews, photos, or videos that you share with us directly or tag us in on social media.
  • Participation in photo or video shoots organized by us, where your image, voice, or personal identifiers may be used for marketing or advertising campaigns.

Where applicable, a separate image-use or content-use agreement will be signed before publication or distribution, or consent will be collected via a dedicated form.

Data categories

Identifiers: full name, username or profile name;

Media content: photo, video, or audio recordings;

Participation: testimonials, reviews, or other content you provide or permit us to use, social media identifiers (tags, mentions, handles), image-use or promotional content agreement (if applicable), consent logs. 

Legal basic (s)

GDPR Art. 6(1)(a) – Consent:

  • when you voluntarily provide content or participate in promotional activities.

GDPR Art. 6(1)(b) – Contract: 

  • where the content is used under an affiliate, influencer, or advertising agreement.

Data retention period

UGC and campaign content: retained for up to 2 years from the date of collection or consent, unless a shorter or longer period is specified or consent is withdrawn.

Advertising campaign content: archived for up to 10 years for legal, contractual, or compliance purposes.

Data recipients

  • Social media platforms (EEA and Non-EEA); 
  • Marketing and advertising agencies; 
  • Affiliate partners and campaign organisers;
  • Intra-group companies (EEA).

13.11. TO ADMINISTER AFFILIATE SERVICES 

When do we process your Personal Data?

When you participate in our Affiliate Program (e.g., promoting our Goods or Services via links, campaigns, or other agreed methods), we process your Personal Data to manage your participation, track referrals, calculate commissions, and make payments. We may also use your Data to communicate with you about affiliate program updates, compliance checks, complaints or performance reporting.

Data categories

Identifiers: name, surname, and contact details (e-mail address, phone number),
Affiliate account/login details;

Payment and billing details: bank account, or other payment identifiers, invoices;

Performance and tracking data: referral codes, campaign statistics, generated leads/sales, IP address, cookies where applicable; 

Cookies: tracking data where applicable (subject to Cookie Policy and local regulations).

Legal basic (s)

GDPR Art. 6(1)(b) – Contract: 

  • necessary for managing participation in the Affiliate Program, tracking referrals, and making payments.

GDPR Art. 6(1)(f) – Legitimate interest: 

  • fraud prevention, program integrity, and communication with affiliates.

Data retention period

Affiliate program data – retained for the duration of your participation in the program and up to 5 years after termination (for accounting, legal, and fraud-prevention purposes); 
Payment records – retained for 10 years to comply with financial/accounting laws;

Affiliate photos and videos - as agreed in specific affiliate program, or mutual agreement. 

Data recipients

  • Affiliate platform providers and tracking technology providers (some may be outside the EEA); 
  • Intra-group companies (EEA);
  • Tax authorities, auditors, or regulators (where required by law).


13.12. TO REVIEW AND MANAGE FEEDBACKS

When do we process your Personal Data?

We process your Personal Data when you submit a review or feedback through our website, post-purchase surveys, user account, or other communication channels. This processing includes verifying the origin and authenticity of the feedback, moderating its content to prevent misuse (e.g., offensive, false, or misleading statements), and publishing verified reviews to ensure transparency, improve our services, and maintain customer trust.

Data categories

Identifiers: name, surname, and contact details (e-mail address, phone number); 

Feedback content: review text, rating, comments, photos, or other media voluntarily submitted by you.

Legal basic (s)

GDPR Art. 6(1)(a) – Consent: 

  • To review and publish feedback.

Data retention period

Feedback and reviews retained and published for up to 3 years or until withdrawn.

Data recipients

  • Third party review management platforms (EEA and some may be outside the EEA)
  • Intra-group companies (EEA);


13.13. TO MAINTAIN WEBSITE SERVICE AND SECURITY

When do we process your Personal Data?

We process your Personal Data automatically and through technical logs whenever you access, browse, or interact with our website or online services. This includes processing necessary to maintain service functionality, detect and prevent unauthorized activities, ensure information system security, and comply with applicable cybersecurity or legal obligations.


Data categories

Technical and usage data: IP address, device type, operating system, browser type and version, session identifiers, access time, and pages visited, cookie data.

Log and diagnostic data: server and application logs, error reports, authentication events, and security alerts.

Legal basic (s)

GDPR Art. 6(1)(f) – Legitimate interest: 

  • to ensure the security, integrity, and continuous operation of our website and IT systems.

Data retention period

Technical and log data are typically retained for up to 12 months from collection unless a longer period is required for security investigations, legal obligations, or incident resolution.

Data recipients

  • Intra-group companies (EEA);
  • IT infrastructure and hosting service providers (EEA and some may be outside the EEA);
  • Security and monitoring service providers (EEA and some may be outside the EEA).


THE END OF POLICY

 

の取り扱いについて説明しています。これにより、私たちがあなたの情報をどのように扱うのか、またあなたのプライバシー権がどのようなものかをご理解いただくのに役立ちます。

ようこそ! このプライバシーポリシー(「ポリシー」)は、UAB ConvenityDerila Ergoブランドおよびその他の家庭用ブランド (「Company」、「we」、「us」、 または「当社の」)がお客様が下記を行う際に扱うお客様の個人情報(「個人情報」または「データ」)の扱いについて説明しています。

  • 販売ウェブサイト(「ウェブサイト」)を閲覧
  • 当社の製品やサービス(「Goods」または「サービス」)を購入
  • それ以外は、サポート、SNS、コンテスト、アフィリエイトプログラムなど、当社とのやり取り

このポリシーは、当社が収集するデータ、その目的、どのように利用・共有、どのくらいの期間保持するか、お客様の権利、そしてどのようにデータを保護するかを明記しています。私たちは、以下の条件に従い、合法的かつ透明性を持ってお客様のデータを処理することを約束します。 

  • 一般データ保護規則(GDPR)
  • eプライバシー指令 2002/58/EC
  • 英国一般データ保護規則(UK GDPR)
  • オーストラリアのプライバシー法1988年およびオーストラリアプライバシー原則(APPs)
  • その他適用されるデータ保護法

このポリシーは世界的に適用され、GDPRの原則に基づいています。 これは法に準拠した、公正かつ透明性のある高水準のデータ保護に対する価値観を反映しています。特定の国または地域の要件は、本ポリシーの末尾にある英国、オーストラリア、アメリカ合衆国、カナダおよびその他の管轄区域向けの 地域付録 で扱っています。

当社の慣行に同意されない場合は、ウェブサイトの利用、商品やサービスの購入、その他の方法でのデータ提出を控えてください。本ポリシーは2025年11月20日 より有効です。 このポリシーは時折更新される場合がありますが、すべての更新は公開時に有効となりますので、情報を得るために定期的にご確認いただくことをお勧めします。

     2. 個人データの保護責任は誰にあるのか?

当社はUAB Convenity、お客様の個人データ管理者です

当社の会社番号は306178201 

登録住所は、Gedimino street 45-7, LT-44239 Kaunas

サポートメールアドレス support@derila.com 

当社はデータ保護責任者(DPO)を任命し、データ保護の義務を監督しています。DPOに直接ご連絡頂けます。 dpo@derilaergo.com 

    3. どのような目的で、どんなデータを収集しているのか? 

概要:主に商品やサービスの提供やウェブサイトの運営に必要なデータのみを収集しています。このセクションでは、なぜそれを収集し、どのように使うのかを説明します。

当社は本当に必要なデータのみを収集しており、購入処理、サービス提供、問い合わせへの対応、ウェブサイトの機能確保など、明確で法的な理由でのみ使用しています。 目的の完全なリスト、収集するデータ、利用方法、そしてより詳細な情報は、以下の表でご覧いただけます。このポリシーの第13節をご覧ください。

ここに、知っておくべき重要なポイントもいくつかあります:

  • 合法的根拠: 適用されるデータ保護法に基づく合法的な根拠がある場合のみ、お客様のデータを処理します。当社が依拠する法的根拠は通常、契約、同意、法的義務、または正当な利益です。 
  • 機密データ: 健康、宗教、生体認証データなどの機密データを意図的に収集または処理する はありません。
  • マーケティング: お客様からの明確な同意がある場合や他の法的根拠がある場合に限り、マーケティングにデータを使用します 。 
  • 自動化ツールおよびAI: 当社はAIやその他の完全または半自動化技術(例:チャットボット、ChatGPT、Geminiなど)をサービス提供を支援するために使うことがありますが、GDPR第22条の意味で法的または同等に重大な影響をもたらす自動意思決定のために使用しません。
  • データの販売禁止: 当社は決してお客様のデータを金銭的価値のために誰かに販売しません。
  • 子どものデータ: このウェブサイトは未成年者向けではありません。当社は、適切な同意なしに未成年者の個人データを故意に収集することはありません。もし誤って子どもから個人データを受け取ったことに気づいた場合、その情報は速やかに削除いたします。 

    4. データはどのような情報源から得ているのですか? 

概要: 当社はお客様のデータを直接、ウェブサイトの利用、または信頼できる第三者や公開情報源から取得しています。これにより、サービスを運営し、お客様と連絡を取り合うことができます。

以下の情報源からデータを収集することがあります。

  • お客様から直接: ご注文いただいた際は、サポートや問い合わせ、フォームやアンケートへのご記入、コンテストやプロモーションキャンペーンへのご参加など。
  • 技術によって自動的に: 当社ウェブサイトやその他のオンラインプラットフォームを訪問または利用すると、識別子や活動に関する情報を含む特定のデータを自動で収集します。当社はクッキーなどの技術を活用し、お客様の体験を向上させ、使用パターンを分析し、プラットフォームのセキュリティを強化しています。
  • 第三者、ベンダー、サービス提供者から: ホスティングプラットフォーム、ソフトウェアプロバイダー、専門コンサルタントなどの第三者プロバイダーからサービスを受ける際、通常は直接お客様に関するデータを入手します。
  • アフィリエイトおよび紹介パートナーからの情報: 紹介リンクをたどったりパートナー割引コードを使用した場合、個人情報を含む可能性のある情報を受け取る場合があります。 
  • その他のグループ内企業(該当する場合)から: 社内の管理、サービス提供、または事業開発の目的で必要に応じて、当社は当社グループ内の他の事業体からお客様のデータを受領することがあります。 
  • 公開情報(該当する場合)から: 法律で許可されている場合、当社は企業登録簿、専門職協会ウェブサイト、公式政府データベース、ソーシャルメディアプロフィール(例:LinkedIn)から個人データを収集することがあります。特に企業間(B2B)コミュニケーション、専門的アウトリーチ、デューデリジェンスの場合に行います。 

     5. データは他者と共有されますか? 

概要: はい、ただし必要な時だけ、そして強力な保護策をもって行います。常にプライバシーが保護されていることを確認しています。 

はい、ただし必要な時だけ、お客様のプライバシーを念頭に置きながら。

サービス提供、法的義務の履行、または日常業務の支援のために、信頼できる第三者と限られたデータを共有する場合があります。その際は、お客様のデータが保護され、責任を持って取り扱われることを保証します。このため、私たちの代理としてデータを処理する当事者はデータ処理者として行動し、データ処理契約(DPA)に契約的に拘束されます。これらの契約は、彼らが当社の指示に従い、適切な安全対策を適用し、お客様のデータを自分の目的で利用しないことを保証しています。当社はお客様のデータを以下と共有することがあります:

  • サービスプロバイダー(データ処理業者): ITサポート、ホスティング、決済、分析、カスタマーサービス、マーケティング、監査、法務サービスなど、さまざまなサービスプロバイダーと連携して事業機能を支えています。 サービス提供者は、私たちの代理および文書化された指示のもとにデータを厳密に処理します。 
  • グループ内企業(データ処理会社または共同コントローラー): 当社は、社内の管理目的、中央集権的サービス、または統合サービスの提供のために、当社のグループ内の他の組織とデータを共有することがあります。
  • 公的機関およびその他のデータ管理者: 特定の状況下では、あなたのデータは独立したデータ管理者として行動し、公的機関、法執行機関、裁判所、保険会社、詐欺防止サービス機関、独立サービス提供者など、独立したデータ管理者として行動する第三者と共有されることがあります。 
  • その他の法人や監査人: 合併、買収、資産売却、または再編の文脈では、潜在的な投資家、買い手、その監査人、アドバイザーに対して限定的なデータを開示することがあります。
  • ご同意のもとで他の第三者: 法的に義務付けられている場合、明確に情報に基づいた自由な同意を得た場合のみ、データを第三者と共有します。 

    6. データはどのくらいの期間保存されますか?

概要: 法的、契約上、またはサービス関連の目的で必要な期間のみデータを保持し、その後は安全に削除または匿名化します。

当社は、以下のために必要な期間のみデータを保持します。

  • 収集した目的の履行
  • 当社の商品またはサービスの提供
  • 法的、規制的、または契約上の義務の遵守
  • 紛争の解決、契約の強制

各データ処理目的の詳細な保持期間は本ポリシーの第3節に定められています。

該当する保存期間が終了すると、業界のベストプラクティスおよび法的要件に従い、合理的な期間内に安全にデータを削除するか、不可逆的な匿名化を行います。

    7. データのセキュリティをどのように確保するか?  

概要: 私たちは強力な技術的・組織的措置を用いてデータを安全に守り、不正アクセスを防ぎプライバシーを守るために継続的に取り組んでいます。

当社はお客様のデータを保護し、情報のセキュリティを真剣に考えることにコミットしています。技術的および組織的な対策を組み合わせて、個人データの不正アクセス、偶発的な紛失、誤用、改変、開示を防止しています。当社のセキュリティ保護の実践は、基本的なデータ保護原則に基づいており、以下を含みますが、これに限定されません。

  • 特定かつ合法的な目的のみでデータを収集する
  • 公正かつ透明性を持ってデータを処理する
  • 必要な期間だけデータを保持する
  • データへのアクセスは認可された従業員のみに限定する
  • 法的に正当化された場合にのみ第三者とデータを共有する
  • 従業員に対して定期的なデータ保護研修を提供する
  • 内部および/または外部のITセキュリティ監査の実施する
  • 機密データに暗号化を用いる
  • 定期的なデータバックアップと活動ログを取る
  • データのセキュリティを確保するためにプロセスを継続的に改善する
  • 潜在的な脅威や侵害がないかシステムを定期的に監視する

強力なセキュリティ対策を講じていますが、特にインターネット送信中は完全にリスクのないシステムは存在しません。データを守るために、オンラインでは常に警戒し、強力でユニークなパスワードを使用し、機密保持、デバイスのセキュリティ、特に疑わしいリンクによる情報共有には注意してください。ユーザーの操作(例:認証情報共有やフィッシング)によるセキュリティインシデントは、当社の制御外となる場合があります。

     8. データを国外に転送しますか? 

概要: はい、時にはそうですが、必要な時のみ、そして常に強力な法的保護策を講じデータを保護します。

はい、しかし必要な時だけ、そして常に強力な保護を施します。

当社は主に欧州経済領域(EEA)内でデータを保存・処理しており、クラウドホスティング、技術サポート、専門サービスなど、EEA外の国々にデータの一部が移管される場合があります。該当する場合、そのような受取人は本ポリシー第3節記載されています。

EEA外にデータを送る際は、必ず保護され、プライバシー権が尊重されるよう確認しています。当社は決して軽率にデータを移転せず、リスクを評価し、データがどこに行っても安全な管理に適切な措置を講じています。データがEEA外で転送される場合、次のことを行います:

  • 当社は、その国が欧州委員会から「十分性認定」を受けているかどうかを確認します。これはEUと同等のデータ保護レベルを提供することを意味します。 
  • 十分性の決定が存在しない場合は、欧州委員会が承認した標準契約条項(SCC)に依拠しています。これらは法的拘束力のある合意であり、受領者がEU標準のプライバシーおよびセキュリティ基準(EU標準契約条項)を守ることを義務付けています。
  • SCCを使用する前に、Schrems II判決およびEDPB指針に基づき、受領国に追加の安全措置が必要かどうかを評価するためにデータ転送影響評価を実施します。 
  • 必要に応じて、暗号化、アクセス制御、監査権などの補助的な技術的または契約上の安全措置を適用することもあります。

これらの移管についてさらに詳しくご希望の場合は、本ポリシーの第11条に記載された情報を使ってお問い合わせください

    9. 自動意思決定またはプロファイリングを使っているか? 

概要: はい、しかし当社では、AIだけで重要な決定を下すわけではありません。私たちはスマートツールを使ってサービスを支えていますが、すべての重要な決定はプログラムだけでなく、実際の人々に関わっています。

はい。当社は、顧客サポートや電話対応などで、人工知能(AI)ベースのツールや完全または半自動化システムを用いて、サービスのスピードと正確性を高めることがあります。

しかし、当社は、GDPR第22条第1項の意味で、お客様に法的影響を及ぼす、または同様に重大な影響を与える自動意思決定(プロファイリングを含む)には関与していません 。具体的には:

  • AIツールによって生成された推奨、回答、情報は情報提供のみを目的としており、当社のスタッフによるレビューと検証の対象となります。
  • 当社は、人と人に意味のある関与なしに、法的影響(例えばサービスの拒否)をもたらす意思決定を行うためにアルゴリズムや自動化システムを使いません。
  • 自動的な手段で決定や回答がお客様に重大な影響を与えたと考える場合は、人間の介入を要請し、ご自身の見解を表明し、当スタッフの人間による説明とレビューを得る権利がお客様にあります。

    10. どんな権利がありますか? 

概要: お客様にはアクセス、訂正、削除、異議申し立てなど、お客様の個人データに対して権利を有しています。このセクションでは、どのように行使できるか、そして何を期待すべきかを説明します。

本ポリシーに定められた通りにお客様のデータを処理する場合、またはそうしている可能性があると考える場合、データ主体として以下の権利を有します。これらの権利は、クライアント、サプライヤー、請負業者、または専門的な担当者としてお客様のデータが処理される際にも適用されます。 

  • 情報を得る権利 – データ収集や利用方法について明確かつ透明な情報を得る権利があります。この詳細な政策は 、GDPR第12条第13条に基づき、以下を提供します。
  • アクセス権 – 当社がお客様のデータを処理しているかどうか、または当社が保有しているあなたに関するデータのコピーを請求することができます(GDPR第15条 )。
  • 是正権 – データが不正確または不完全であれば、GDPR第16条訂正または更新を依頼できます。
  • 消去権(「忘れられる権利」) – 収集目的でデータが不要になった場合、同意を撤回した場合(同意に基づく処理の場合)、異議を唱えてそれが正当な理由によって覆されない場合、またはデータが不法に処理された場合は削除を要請できます。 

注意:この権利には制限があります。例えば、法的遵守、紛争解決、契約目的のためであれば、特定のデータを当社が保持することがあります (GDPR第17条)。

  • 処理制限の権利 – データの正確性に異議を唱えたり、法 的根拠を評価する間に処理に異議を申し立てるなどの状況で、データの処理を一時的に制限するよう要請することができます(GDPR第18条)。
  • データポータビリティ – お客様の同意または契約に基づいて自動処理が行われる場合、構造化された一般的かつ機械可読な形式でデータのコピーを請求し、他の提供者への転送を依頼できます(GDPR第20条 )。
  • 異議申し立て – 正当な利益やダイレクトマーケティング目的での処理に異議を唱えることができます。当社は、GDPR第21条に基づく正当な正当な根拠を示せない限り、そのような処理を停止します 。
  • 同意撤回権 – あなたの同意に依存する場合、いつでも撤回できます。これは、退 前に行われた処理の合法性(GDPR第7条第3項)には影響しません。
  • 苦情申し立ての権利 – データの取り扱いにご満足いただける場合は、まずご連絡ください。できる限り問題解決に努めます。ただし、リトアニア国家データ保護監察局(https://vdai.lrv.lt/lt/)や居住国や勤務先の監督機関にも苦情を申し立てることができます。 

ご注意ください: お客様の権利は絶対的なものではありません。場合によっては、あなたの権利の行使が適用されるデータ保護法の下で制限されることがあります。例えば、お客様の要求を履行することが他者の権利や自由に悪影響を及ぼす場合や、法令遵守、法的請求、規制上の目的など、特定の個人データを法的に保持する義務が当社にある場合などです。

    11. 権利の行使や連絡方法について? 

本ポリシー、データの処理方法、苦情、またはデータ主体権利の行使を希望される場合は、メールでお問い合わせください。 dpo@derilaergo.com 。 

ご要望を効率的に処理するために、以下にご協力ください:

  • 質問や不満を明確に表明してください。
  • どのデータ主体権利を行使したいか(該当する場合は)を明確にしてください。
  • 本人を識別できる十分な情報を提供してください(本人確認の提出や本人確認の手続きを進める場合があります)
  • 迅速な対応に役立つ関連情報も含めてください。

また、第三者に代理として行使させることもできます。その場合、代理人があなたの代理として行動できることを証明する書面および署名済みの許可書を必ず提供してください。十分な承認証明が提供されない場合、申請を却下することがあります。

ご依頼いただいてから1か月 以内に、不必要な遅延なく返信することを目指しています。 
ご要望が特に複雑で複数の問題が絡む場合は、この期間をさらに1か月延長することがあります 、その場合は事前にお知らせし、遅延の理由を説明いたします。

     12. 地域補足

この付録はグローバルプライバシーポリシーを補完するものであり、お客様の個人データが居住国や地域の法律の対象となる場合、または当社の処理活動が特定の対象となっている場合に適用されます。これらの地域別用語はグローバルプライバシーポリシーを補完し、適用される現地法で求められる場合にのみそれを上書きします。

🇬🇧  イギリス(UK)

もしお客様が英国居住者であったり、当社の処理が英国個人に関するものであれば、個人データの処理は 英国一般データ保護規則(UK GDPR)および2018年データ保護法の対象となります。 

英国データ保護法の下でのお客様の権利:

  • 知る権利 (英国GDPR第13条第14条) — 個人データの収集および使用方法について明確な情報を受け取ること
  • アクセス権 (英国GDPR第15条) — 当社が保有する個人情報のコピーを請求すること
  • 修正権(英国GDPR第16条) – 不正確または不完全な個人データの訂正すること
  • 消去権 (英国GDPR第17条) — 特定の状況下で個人データの削除を要求すること
  • 処理制限の権利 (英国GDPR第18条) — 特定の状況であなたの個人データの使用を制限すること
  • データポータビリティ 権利(英国GDPR第20条) — 構造化された、一般的に使われる機械読可能な形式で個人データを受信すること
  • 異議申し立て権 (英国GDPR第21条) – 正当な利益に基づく処理やダイレクトマーケティングに対する異議申し立て
  • プロファイリング (英国GDPR第22条) を含む、完全に自動化された意思決定の対象外となる権利。これらの決定が法的または同様に重要な影響を及ぼす場合に限られます。

英国からの国際データ転送:

個人データを英国外(例:EEA、アメリカ合衆国、その他の国々)へ移転する場合、以下のような十分な安全対策を講じることを確実にしています。

  • 英国政府が発行した適格性規則;または
  • 英国国際データ転送協定(IDTA)またはEU標準契約条項(SCC)への英国付録、および適切な技術的および契約上の保護措置。

監督権限:

個人データの取り扱いについて懸念がある場合は、英国の監督機関である情報コミッショナー事務所(ICO)に苦情を申し立てることができます。ウェブサイト: https://ico.org.uk 

🇦🇺 オーストラリア

もしあなたがオーストラリア居住者であったり、当処理がオーストラリア人個人に関するものであれば、あなたの個人データの処理は1988年 プライバシー法(連邦)および オーストラリアプライバシー原則(APPs)の対象となります。

オーストラリアプライバシー法の下でのあなたの権利:

  • アクセス権(APP 12) — 当社が保有する個人情報のコピーを請求する権利;
  • 訂正 権(APP 13) — 個人情報が不正確、不完全、または古くなっている場合に訂正を請求すること;
  • 苦情を申し立てる権利 – APPに基づくプライバシーを侵害したと思われる場合は、正式な苦情を提出できます。 
  • 匿名または偽名での交流権 (APP 2) 合法かつ実行可能な場合(例えば一般的な問い合わせの場合)であれば、自己名乗らずに選択できます。 

ダイレクトマーケティングと購読解除:

本ポリシー第3条に記載 直接マーケティング原則を適用し、APP 7および2003年スパム法を完全に遵守しています。私たちはこれらの法律に従って直接マーケティングのみを送信しています。すべての電子メッセージには私たちの名が特定され、機能的な購読解除オプションが含まれています。購読を解除すると、あなたへのマーケティングを終了します。

オーストラリアからの国際データ転送:

オーストラリア国外(例:EU、米国、その他の国)にいる受取人に個人情報を開示する場合があります。その前に、海外受領者がAPPに違反しないように合理的な措置を講じます。これらのステップには以下が含まれます:

  • 拘束力のある契約の締結;
  • プライバシーおよびセキュリティのデューデリジェンスの実施;
  • 暗号化やアクセス制御などの技術的保護策の確保。

監督権限:

データ漏洩が深刻な被害をもたらす可能性が高い場合は、オーストラリア情報コミッショナー室(OAIC)および関係者に速やかに通知いたします。また、プライバシーに関するご回答に満足できない場合は、OAICのウェブサイト( https://www.oaic.gov.au)にご連絡ください。 

🇨🇦 カナダ

もしあなたがカナダ居住者であったり、当処理がカナダ人に関するものであれば、あなたの個人データは の個人情報保護電子文書法(PIPEDA) およびその他の適用されるプライバシー法の対象となります。

カナダのプライバシー法に基づくあなたの権利:

  • 知る権利/アクセス  - 当社が保有する個人情報や、その利用・共有の詳細へのアクセスを申請してください。
  • 訂正権  - 不正確な個人情報の訂正を求める権利;
  • 同意撤回 - 法律で処理が義務付けられている場合や、要求されたサービスを提供するために必要な場合を除き、個人情報の使用または開示への同意をいつでも撤回できます。
  • データポータビリティの権利 (法25) – 構造化された一般的に使われる形式で個人情報のコピーを受け取るか、技術的に可能な場合は他の組織に移管してください。
  • 苦情申し立て権 - 権利が侵害されたと考える場合は、カナダプライバシーコミッショナー事務所(OPC)またはケベック州に居住する場合は、ケベック情報委員会(CAI)に苦情を申し立ててください。

商用電子メッセージ(CASL)

本ポリシー第3条に記載されている直接マーケティングの原則 、カナダの反スパム法(CASL)を完全に遵守しています。私たちは明示的な同意(または許可された黙示的同意に依拠)、各メッセージで事業の明示を行い、機能する購読解除メカニズムを組み込み、同意の記録を保持しています。いつでも同意を撤回したり、購読解除したりできます。 

カナダからの国際データ転送:

あなたの個人データはカナダ国外(例:EU、米国、その他の国へ)へ転送されることがあります(処理のためにS。私たちは、そのような移転がカナダ法に適合する十分な保護を提供するか、または外国アクセス法の対象となる可能性があることを保証するために、契約上、組織的、技術的措置を講じています。 

監督権限:

プライバシーに関するご回答にご満足いただけない場合は、以下にご連絡ください:カナダプライバシーコミッショナー事務局(OPC)、ウェブサイト: https://www.priv.gc.ca。ケベック州の方は、情報委員会(CAI)にも連絡 https://www.cai.gouv.qc.ca

🇺🇸 アメリカ合衆国(USA)

もしあなたがアメリカ合衆国Sなら。居住者または当社の処理は米国Sに関連しています。個人の皆様、あなたの個人データは、 カリフォルニア消費者プライバシー法(CCPA/CPRA)、バージニア消費者データ保護法(VCDPA)、コロラドプライバシー法(CPA)、コネチカットデータプライバシー法(CTDPA)  、ユタ州消費者プライバシー法(UCPA)など、州のプライバシー法の対象となる場合があります。

米国Sにおけるあなたの権利。州のプライバシー法(州によって異なる場合があります):

  • 知る権利/アクセス – 私たちが収集、使用、開示、販売、共有する個人データのカテゴリーや特定の情報について情報を求めること;
  • 削除 権 – 特定の例外を除き、保有する個人データの削除を要請する権利;
  • 訂正 権 – 不正確な個人データの訂正を求める権利;
  • オプトアウトの権利 – オプトアウトする権利: 

– 個人データの販売または共有;

– ターゲット広告のための個人データの使用;

– 法的または同等に重要な効果を持つプロファイリング;

  • データポータビリティ 権利 — あなたの個人データをポータブル形式で受け取る権利;
  • 機密個人データの使用制限 権(CPRAのみ)— 機密情報の利用方法(例:正確な位置情報、健康データ、金融データ)の制限を求める権利。

アメリカからの国際データ転送:

米国外(例えばEU、英国、その他の法域)に個人データを移転する場合、移行されたデータが適用される米国の適切な保護を受けられるよう契約上、組織的、技術的上の安全措置を適用します。S州法です。

個人情報の販売や共有禁止: 個人データの販売や共有を拒否したい場合は、当ウェブサイトのフッターにある「個人情報の販売や共有禁止」リンクをクリックしてください。

ユニバーサル・オプトアウトの仕組み:

必要に応じて(例:CPRA、CPA、CTDPA)、グローバルプライバシーコントロール(GPC)信号およびその他の認められた普遍的なオプトアウトメカニズムを尊重しています。

監督機関:

個人データの取り扱いについてご懸念がある場合は、州の司法長官にご連絡ください。カリフォルニア州在住の方には、詳細は以下のサイトでご覧いただけます: https://oag.ca.gov/privacy/ccpa

13. 個人情報の処理に関する詳細な情報

13.1. 注文の処理と履行 

個人データはいつ処理されますか?

当社ウェブサイトで商品を購入された場合、お客様のデータを処理し、注文管理、配送手配、支払い処理、関連サービス(例:注文確認、更新、返品、返金など)を提供します。

注: 商品は顧客アカウントを作成せずに販売されます。

データカテゴリ

身分証明書および連絡先情報: 氏名、配達先住所、メールアドレス、電話番号。

支払い情報: 価格、通貨、クレジットカードブランド、種類、銀行識別番号(BIN)番号、発行国。

技術情報: IPアドレス、言語、デバイスタイプ。

法的基礎

GDPR 第6条第1項(b)– 契約:

  • ご購入を完了し、届けること。

データ保持期間

注文および支払い記録は、法的、税務、会計上の義務に従い、 10年間 保持されます。

データ受信者

  • 輸送および物流プロバイダー(世界)、
  • 決済サービス提供者および銀行(EEAおよび非EEA);
  • グループ内企業(EEA)。


13.2. 支払い処理および法的義務の遵守 

個人データはいつ処理されますか?

注文、サブスクリプション、割引、返品、返金に関する支払い処理時に、あなたの個人データを処理します。

この処理には、請求書の発行、会計記録の管理、その他の法定要件の履行などの税務義務の履行も含まれます。

データカテゴリ

支払い情報: 支払い方法(カードの種類、最後の数桁)、支払いトークン、取引金額、取引日時、返金理由。

請求・法的データ: 氏名、メールアドレス、電話番号、請求先住所、IBAN/口座番号、支払い記録、請求書、付加価値税(VAT)およびその他の必要な会計・法的書類。

税関または輸出入情報(該当する場合): 、特定の国で法律で義務付けられている個人識別コードや税関データ(例:通関対象の貨物の場合)。

法的基礎

GDPR 第6条第1項(b)– 契約:

  • 支払いの受領と管理。 

GDPR第6条第1項(c)– 法的義務:

  • 法定会計要件を満たすためです。

データ保持期間

財務および税務規制の要件に従い、 10年間 、会計関連データを保持しています。

データ受信者

  • 決済処理業者(EUおよび非EEA);
  • 会計処理業者(EEA);
  • グループ内企業(EEA);
  • 監査人(EEA)。

 

13.3. カスタマーサポートサービスの提供

個人データはいつ処理されますか?

電話や書面(ライブチャット、カスタマーサポート、メール、ソーシャルメディアなど)でご連絡いただく場合は、ご連絡の事実やご提供いただいた情報(個人情報を含む)を記録し、リクエストを適切に処理し、ご質問や依頼、苦情に対応いたします。

私たちは 人工知能(AI)ベースのツール (完全または半自動化)を用いてカスタマーサポートチームを支援しています。これらのツールは、ドラフト回答の提案、通話の誘導や応答の提示、会話の文字起こしと要約、よくある質問や訓練された質問への自動応答提供に使われます。注! すべてのAI生成出力は、権利に影響を与える可能性のある場合、人間のスタッフによって審査・検証されます。私たちは、法的または同等に重要な影響を生み出す自動意思決定のみに頼ることはありません。 完全に匿名化されていない限り、AIモデルのトレーニングにはお客様のデータを使用しません。 

データカテゴリ

電話で連絡された場合:氏名、姓、携帯電話番号、メールアドレス、居住地住所、購入情報、その他本人確認に必要な情報を してください。通話の日時、通話時間、通話の録音。

メールまたはライブチャットでのお問い合わせは、カスタマーサポート 氏、姓、携帯電話番号、メールアドレス、居住地住所まで。購入情報およびその他の情報

本人確認に必要な情報(必要に応じて)です。書面による依頼に関連するその他の情報、添付書類やその他の視覚的コンテンツ、すべての通信履歴。

法的基礎

GDPR 第6条第1項(b)– 契約:

  • カスタマーサポートサービスを提供しています。

GDPR第6条第1項(f)– 正当な利益:

  • 誰かが最初の会話を始めた場合、回答、助言、提供、問い合わせの実施を行います。

データ保持期間

会話の録音 - 作成から6ヶ月

書面によるコミュニケーション - 問い合わせが終了してから3年

適用される法律の遵守や正当な利益に基づく場合、一部の情報を長く保持することがあります。

データ受信者

  • カスタマーサポートプラットフォームプロバイダー(非EEA);
  • AIサポートツールおよびチャットボット(非EEA);
  • カスタマーサポート担当者(一部はEEA外)、
  • グループ内企業(EEA)。

 

13.4. 取引的コミュニケーションを提供すること

個人データはいつ処理されますか?

私たちは利用規約(「ToS」に基づく権利と義務を果たす際に、いつでもあなたに連絡する権利(例:取引的なコミュニケーション)を有します。重要な通知や情報をメール、SMS、または電話でお送りすることがあります。 

注意! この重要なコミュニケーションはマーケティングとはみなされず、オプトアウトすることはできません。

データカテゴリ

身分証明書および連絡先情報: 氏、姓、携帯電話番号、メールアドレス、居住地住所。

通話詳細: 日時、通話時間、通話録音。

技術データ:電子メッセージ/SMSのコピー 、配達状況と日付、メッセージの開封状況(読み取り)状況と日付、メッセージ内容から開いたリンク。

法的基礎

GDPR 第6条第1項(b)– 契約:

  • 利用規約の管理および重要な通知の提供。

データ保持期間

会話の録音は、作成の瞬間から 6ヶ月 保存されます。

電子通信履歴ログは、法的理由でより長期の保存が必要な場合を除き、 1か月保存されます。

データ受信者

  • 通信サービスプロバイダー - 電子メール/SMS/電話プラットフォーム(EEAおよび非EEA);
  • グループ内企業(EEA)。

 

13.5. ダイレクトマーケティング活動を行うこと

個人データはいつ処理されますか?

私たちは、商品やサービス、プロモーション、新機能についてお知らせしたり、フィードバックを求めたりするために、あなたの個人データを処理しています。これには、ニュースレター、プロモーションメッセージ、アンケート(メール、SMS、電話など)などの一般的またはパーソナライズされたマーケティングコンテンツの送信が含まれます。

当社からのマーケティング コミュニケーションの受信に同意した場合、これにはこの特定のブランドや当社内で運営されている他のブランドに関するマーケティング情報やオファーが含まれる可能性があります。マーケティングコンテンツは、既に保有しているデータ(例:過去の購入履歴、閲覧履歴、選択した好み)に基づいてカスタマイズされ、関連するオファーやコンテンツを提供することが可能です。

既存の顧客であれば、明確な同意がなくても、連絡先情報が収集された際に異議申し立ての機会があり、各メッセージにオプトアウトオプションが含まれ、かつ該当法で許可されている場合に限り、同一または類似の製品やサービスに関するマーケティングコンテンツについて連絡することがあります。購入時の「Thank You」ページで、オプトアウトオプションが明確に提供されています。

覚えておいて! あなたはいつでも無料でダイレクトマーケティングに異議を唱える権利があります。

  • どのメールでも購読解除リンクを使うこと;
  • 「Thank You」ページの購読解除リンクを使ったこと;
  • SMSに対して「STOP」または指定されたキーワードで返信すること;
  • 電話中に担当者に連絡し、当団体の「電話禁止リスト」に追加すること;または
  • ご要望のメールを送りました。 

データカテゴリ

連絡先情報: 氏名、メールアドレス、電話番号、国; 

ログ: 同意収集ログ(日付、方法、設定、購読解除情報、オプトアウトリクエスト)。

マーケティングインタラクションデータ:メッセージの配信や開封状況、リンククリック数、キャンペーン参加状況、コミュニケーションの好み、購読解除やオプトアウトアクション、インタラクションタイムスタンプなど、マーケティング資料へのエンゲージメントに関する情報
購入およびエンゲージメント履歴(該当する場合):過去の取引やマーケティングのやり取りから得られた 情報(購入した商品、紹介先、使用されたリンク、プロモーションキャンペーンへの反応など)。
技術情報 (メールまたはSMS配信用): デバイスタイプ、IPアドレス、国。 

法的基礎

GDPR第6条第1項(a)– 同意:

  • 同意を優先的なコミュニケーション方式で処理すること。

GDPR第6条第1項(f)– 正当な利益:

  • 既存の顧客で異議を唱えていない場合は、顧客関係を維持するために類似製品やサービスについて限定的なマーケティングを行う場合があります(ソフトオプトイン)。

データ保持期間

同意日から3年 、ただし早く購読解除した場合は別です。 

会話の録音 - 作成から6ヶ月

データ受信者

  • ソーシャルメディアサービスプロバイダー(非EEA);
  • マーケティングサービス提供者(非EEA);
  • グループ内企業(EEA)。

 

13.6. ソーシャルメディアを通じてあなたと交流するために 

個人データはいつ処理されますか?

私たちはビジネスプロフィールやアカウントを様々なソーシャルネットワークで管理しています。当社のサービスに興味があり、ソーシャルネットワークでプロフィールをフォローし、ゲームやプロモーションに参加、写真の共有やタグ付け、公開投稿などでご連絡いただく場合は、アカウントでアクティブな際に直接受け取ったデータを収集・利用します。


当社のアカウントはFacebook、Instagram、LinkedInなどのソーシャルネットワーキングプラットフォームに統合されているため、独立したデータ管理者としてすべてのソーシャルプラットフォーム提供者があなたの個人データを収集する完全なアクセス権を持っています。各ソーシャルネットワーキングプラットフォームが使用するデータ処理、目的、範囲については、それぞれのソーシャルネットワークのプライバシーポリシーで詳細情報を見つけることができます。また、ソーシャルネットワークが処理したデータに関して権利を行使したい場合は、ソーシャルネットワークの管理者に直接連絡する方が効率的です。

データカテゴリ

識別子: 氏、姓、プロフィール写真;

公開のやり取り: いいね、フォロー、コメント、シェア;

参加:あなたが送る メッセージ(内容、時間、添付ファイル、履歴)、ゲームやイベントへの積極的な参加、送ってくれた写真やタグ付けなど。 

法的基礎

GDPR第6条第1項(a)– 同意:

  • ソーシャルメディアアカウントで自主的に行動を起こした際に個人データを処理すること。

データ保持期間

関係するソーシャルネットワークの提供者は、データの保持期間を定めます。該当するソーシャルネットワークのプライバシーポリシーをご確認いただくことをお勧めします。

通常は、同意を撤回したり削除を要請したり、プラットフォームが早期削除を強制しない限り、保持し削除しません。

データ受信者

  • Facebook、LinkedIn、Instagram、TikTokなどのソーシャルメディアサービスプロバイダー(通常、これらのプロバイダーは独立したコントローラーですが、場合によっては私たちとプロバイダーが共同コントローラーとして行動することもあります。各プロバイダーのプライバシー通知(非EEA)で詳細を読むことができます。
  • グループ内企業(EEA);
  • 加盟会社(EEA外の一部)。

 

13.7. 我々の法的権利または利益を守り保護すること 

個人データはいつ処理されますか?

私たちは、あなたが対象となる法的手続きの当事者または関係者となる場合、または適用法に準拠するためにあなたに関する情報の収集・提供を法的に義務付けられた場合に、あなたの個人データを処理することがあります。


また、詐欺、窃盗、違法な再販、ブランド名でのマーケティング活動の不正利用、または当社のウェブサイト、会社、ブランドおよびサービスに関わるその他の違法行為が疑われる場合は、警察や検察庁など適切な予備調査機関に報告します。

データカテゴリ

当社があなたについて守るすべての情報、そして法的手続きの一部である会計・法的事件ファイル、法的書類、あなたが提供するその他の情報、法的に収集・提供が義務付けられているその他の情報。また、訴状、請求、裁判所の判決も含まれます。
事件が発生した場合 - 犯罪や有罪判決に関する情報、特別カテゴリーのデータ(例:健康情報)。

法的基礎

GDPR第6条第1項(f)– 正当な利益:

  • 法的請求の確立、行使、または防衛。
  • 私たちの権利と利益を守るために。

データ保持期間

法的手続きが進行中 であり、裁判所や当局の決定が発令された日から10年 、または法的拘束力のある決定が完全に実施された日から10年経過している限りです。

データ受信者

  • 法的当事者(例:弁護士、公証人、執行官、監査人、コンサルタント(EEAおよび非EEA);
  • 裁判所(EEA);
  • 消費者保護当局およびその他の機関(EEAおよび非EEA)が含まれます。

 

13.8. ウェブサイトのパフォーマンスとマーケティング効果の監視 

個人データはいつ処理されますか?

当ウェブサイトをご覧いただくと、統計、分析、マーケティング、パフォーマンスモニタリングの目的で特定の個人データを処理します。これにより、当社のウェブサイトの機能性、安定性、セキュリティ、そして全体的なユーザー体験の向上につながります。


クッキーの好みや同意の選択に応じて、Google Analytics 4やその他の認可された分析・マーケティングプラットフォームなどの信頼できるツールを用いて、クッキーや類似の追跡技術を通じて様々な情報を収集することがあります。詳細は当社の クッキーポリシーに記載されています。 

データカテゴリ

識別子:IPアドレスまたはその他のデバイス識別子;

技術情報:デバイスタイプ、ブラウザタイプ、言語設定、ハードウェア/ソフトウェアの設定および設定、参照URL(訪問前後のウェブサイト);

利用情報:当社ウェブサイトで訪れた ページ、インタラクション、クリック、セッション振る舞い、訪問タイムスタンプ、セッション時間、選択したインターフェース、または該当する場合のアカウント設定。 

法的基礎

GDPR第6条第1項(a)– 同意:

  • パフォーマンスおよび分析クッキーの使用に積極的に同意された場合にのみ、このデータを処理します(クッキーバナー経由)。

データ保持期間

クッキーの保持期間の詳細については、当社の クッキーポリシーをご参照ください。

データ受信者

 

13.9. コンテストやプレゼント企画の開催

個人データはいつ処理されますか?

コンテスト、競技会、ゲーム、イベントに参加する際には、あなたの個人データを処理します。これは、参加状況を管理し、コミュニケーションを取るため、そして(該当する場合は)活動成果を公開または促進するために行われます。

データカテゴリ

識別子: 氏名、メールアドレス、電話番号;

参加: ソーシャルメディアでの参加(コメント、シェア、「いいね」「フォロー」、リアクション)、コンテストの応募数、回答数、評価・評価、イベント参加数;

メディア内容: 写真や動画、録音中の画像や音声を投稿または撮影したもの。

法的基礎

GDPR第6条第1項(a)– 同意:

  • コンテスト参加、当選者への連絡。

データ保持期間

コンテスト参加者データ – 受賞者発表後または特定のコンテスト用語で説明された1年間 1年間保持されます。期間が短期間または長期間で指定されていない限り。 

データ受信者

  • ソーシャルメディアプラットフォームプロバイダー(非EEA);
  • コンテストのパートナーおよび共催者(EEAおよび非EEA)。

13.10. プロモーションコンテンツの作成および使用のために

個人データはいつ処理されますか?

あなたが投稿、作成、またはプロモーション目的であなたをフィーチャーしたコンテンツの使用を許可する際に、私たちはあなたの個人データを処理します。これには以下が含まれます:

  • ユーザー生成コンテンツ(UGC)は、直接私たちに共有されたり、ソーシャルメディアでタグ付けされたユーザー生成コンテンツ(UGC)です。
  • 当社が主催する写真やビデオ撮影への参加。ここでは、あなたの画像、声、または個人識別子がマーケティングや広告キャンペーンに使用されることがあります。

該当する場合、公開または配布前に別途画像使用またはコンテンツ使用契約に署名するか、専用のフォームを通じて同意を収集します。

データカテゴリ

識別子: 氏、ユーザー名またはプロフィール名;

メディア内容: 写真、ビデオ、または音声記録;

参加: の推薦文、レビュー、または提供または使用を許可したその他のコンテンツ、ソーシャルメディア識別子(タグ、言及、ハンドル)、画像使用やプロモーションコンテンツの契約(該当する場合)、同意ログ。 

法的基礎

GDPR第6条第1項(a)– 同意:

  • 自発的にコンテンツを提供したり、プロモーション活動に参加したりする場合。

GDPR 第6条第1項(b)– 契約: 

  • コンテンツがアフィリエイト、インフルエンサー、または広告契約のもとで使用される場合。

データ保持期間

UGCおよびキャンペーン内容:収集または同意日から最大2年間保持されます。ただし、より短期間または長期間が指定されたり同意が取り消された場合は除き、  期間が制限されます。

広告キャンペーン内容:法的、契約的、またはコンプライアンスの目的で最大10年間アーカイブ  。

データ受信者

  • ソーシャルメディアプラットフォーム(EEAおよび非EEA); 
  • マーケティング・広告代理店; 
  • アフィリエイトパートナーおよびキャンペーン主催者;
  • グループ内企業(EEA)。

13.11. 関連サービスの管理 

個人データはいつ処理されますか?

アフィリエイトプログラムに参加する際(例:リンク、キャンペーン、その他の合意された方法で商品やサービスのプロモーションを行う場合)、私たちはあなたの個人データを処理し、参加管理、紹介の追跡、コミッションの計算、支払いを行います。また、アフィリエイトプログラムの最新情報、コンプライアンスチェック、苦情、パフォーマンス報告などについても、あなたのデータを活用して連絡を取ることがあります。

データカテゴリ

識別子: 氏、姓、連絡先(メールアドレス、電話番号)、
アフィリエイトアカウント/ログイン情報;

支払いおよび請求の詳細:銀行口座 またはその他の支払い識別子、請求書;

パフォーマンスおよび追跡データ: 紹介コード、キャンペーン統計、生成されたリード/売上、IPアドレス、該当するクッキー; 

クッキー:該当する場合は追跡データを(クッキーポリシーおよび現地の規制に従え)

法的基礎

GDPR 第6条第1項(b)– 契約: 

  • アフィリエイトプログラムへの参加管理、紹介の追跡、支払いに必要です。

GDPR第6条第1項(f)– 正当な利益: 

  • 不正防止、プログラムの整合性、そして提携会社とのコミュニケーション。

データ保持期間

アフィリエイトプログラムデータ – プログラム参加期間中および終了後最大5年  保持されます(会計、法務、詐欺防止の目的); 
支払い記録 – 財務・会計法に準拠するため 10年間 保管;

アフィリエイトの写真や動画 - 特定のアフィリエイトプログラムで合意されたもの、または相互の合意によるものです。 

データ受信者

  • アフィリエイトプラットフォームプロバイダーおよび追跡技術プロバイダー(EEA外のものもある場合もあります); 
  • グループ内企業(EEA);
  • 税務当局、監査人、または規制当局(法律で義務付けられている場合)。


13.12. フィードバックのレビューと管理

個人データはいつ処理されますか?

ウェブサイト、購入後のアンケート、ユーザーアカウント、その他のコミュニケーションチャネルを通じてレビューやフィードバックを投稿すると、個人情報を処理します。この処理には、フィードバックの出所と真正性の検証、悪用(例:攻撃的、虚偽、誤解を招く発言)を防ぐための内容のモデレーション、そして透明性を確保し、サービスを向上させ、顧客の信頼を維持するための検証済みレビューの公開が含まれます。

データカテゴリ

識別子: 氏、姓、連絡先(メールアドレス、電話番号); 

フィードバック内容: 、テキスト、評価、コメント、写真、その他のメディアを自発的に投稿したものをレビューします。

法的基礎

GDPR第6条第1項(a)– 同意: 

  • フィードバックのレビューと公開。

データ保持期間

フィードバックやレビューは最大3年間、または撤回されるまで保持・公開されます。

データ受信者

  • 第三者の審査管理プラットフォーム(EEAおよび一部はEEA外の場合もあります)
  • グループ内企業(EEA);


13.13. ウェブサイトのサービスとセキュリティを維持するため

個人データはいつ処理されますか?

当社が当社のウェブサイトやオンラインサービスにアクセスし、閲覧、またはやり取りする際には、個人データを自動および技術ログを通じて処理します。これには、サービス機能の維持、不正行為の検出と防止、情報システムのセキュリティ確保、適用されるサイバーセキュリティまたは法的義務の遵守に必要な処理が含まれます。


データカテゴリ

技術的および使用データ: IPアドレス、デバイスタイプ、オペレーティングシステム、ブラウザの種類とバージョン、セッション識別子、アクセス時間、訪問ページ、クッキーデータ。

ログおよび診断データ: サーバーおよびアプリケーションのログ、エラーレポート、認証イベント、セキュリティアラート。

法的基礎

GDPR第6条第1項(f)– 正当な利益: 

  • ウェブサイトおよびITシステムのセキュリティ、完全性、継続的な運用を確保すること。

データ保持期間

技術的およびログデータは、セキュリティ調査、法的義務、またはインシデント解決のためにより長い期間が必要な場合を除き、収集後 最大12か月 保持されます。

データ受信者

  • グループ内企業(EEA);
  • ITインフラおよびホスティングサービス提供者(EEAおよび一部EEA外のプロバイダー)、
  • セキュリティおよび監視サービス提供者(EEAおよび一部はEEA外の場合もあります)。


政策の終焉