Privacybeleid

Introduction


HFL takes your privacy very seriously and shall handle your personal data with the
utmost security and care. In this Privacy Statement you will learn how we handle
your data as well as learn about your rights concerning our processing of your data.
We advise that you read this Privacy Statement thoroughly. Should you have any
questions or remarks, please contact us at [email protected].

Who is HFL?


HFL is the besloten vennootschap HFL Laboratories BV, with registered office at
(5175 AX) Loon op Zand listed at the Traderegister of the Dutch Chamber of
Commerce under 52725820.
HFL is as the controller ultimately responsible with regard to the processing of your
personal data.


How does HFL use your personal data?


Underneath you will find an overview of the purposes for the processing of your
personal data. You will also find a specification of which data HFL uses for that
specific purpose, the legal justification, and the amount of time HFL keeps this data.
For clarity’s sake, we have categorised the purposes.
Services, customer management and financial administration
Purpose: Order Management
Information: Delivery address, Billing address, Email, Phone, Account number,
Order Number, Complaint content, COC number, VAT number,
Customer number
Legal basis: Necessary for the performance of a contract
Storage
period:
As long as necessary for this purpose
Purpose: Handling complaints
Information: Delivery address, Billing address, Email, Phone, Account number,
Order Number, Complaint content, COC number, VAT number,
Customer number
Legal basis: Necessary for the performance of a contract
Storage
period:
As long as necessary for this purpose
Purpose: Invoicing
Information: Delivery address, Billing address, Email, Phone, Account number,
Order Number, Complaint content, COC number, VAT number,
Customer number
Legal basis: Necessary for the performance of a contract
Storage
period:
As long as necessary for this purpose
Purpose: Services
Information: Data necessary to provide the service
Legal basis: Necessary for the performance of a contract
Storage
period:
As long as necessary for this purpose
Purpose: Handling complaints
Information: Data necessary to provide the service
Legal basis: Necessary for the performance of a contract
Storage
period:
As long as necessary for this purpose
Purpose: Invoicing
Information: Data necessary to provide the service
Legal basis: Necessary for the performance of a contract
Storage
period:
As long as necessary for this purpose
Purpose: CRM
Information: Name, Username, Email, Location, Social media account, Browser,
Phone
Legal basis: Legitimate interests
importance: Commercial interests
Storage
period:
As long as necessary for this purpose
Purpose: Job application
Information: Name, Username, Email, Location, Social media account, Browser,
Phone
Legal basis: Legitimate interests
importance: Commercial interests
Storage
period:
As long as necessary for this purpose
Marketing
Purpose: Direct marketing
Information: Name, Email, Click behaviour Legitimate interests
Legal basis: Legitimate interests
Interest concerned: Commercial interests
Storage period: As long as necessary for this purpose
Purpose: Newsletter
Information: Name, Email, Click behaviour Legitimate interests
Legal basis: Legitimate interests
Interest concerned: Commercial interests
Storage period: As long as necessary for this purpose
Purpose: Social media marketing
Information: Name, Email, Click behaviour Legitimate interests
Legal basis: Legitimate interests
Interest concerned: Commercial interests
Storage period: As long as necessary for this purpose
Website
Purpose: Account
Information: Name, Address, Email, Username
Legal basis: Necessary for the performance of a contract
Storage period: As long as necessary for this purpose
Purpose: Submitting reviews or messages
Information: Name, Address, Email, Username
Legal basis: Necessary for the performance of a contract
Storage period: As long as necessary for this purpose
Security and fraud prevention
Purpose: data security
Information: Phone, Professional activities, Name, Address
Legal basis: Legitimate interests
Interest concerned: Commercial interests
Storage period: As long as necessary for this purpose
Research and Development
Purpose: Market research
Information: Email, Phone, Behavioural data
Legal basis: Legitimate interests
Interest concerned: Commercial interests
Storage period: As long as necessary for this purpose
Purpose: Scientific research
Information: Email, Phone, Behavioural data
Legal basis: Legitimate interests
Interest concerned: Commercial interests
Storage period: As long as necessary for this purpose

How did we obtain your personal data?

HFL has obtained your data because you have provided this data to us. .

What are your rights?

Under the European General Data Protection Regulation you have a number of
rights with regard to your data and the processing thereof:

Access
You may access your personal information and make any necessary changes in your
account. If you would like to see which personal data HFL has obtained about you,
you may exercise your right of access by submitting a request to HFL.

Making changes
If you wish to make changes to the personal information that you have seen as a
result of a request for access and you are unable to make the changes yourself in
your account, you may request that HFL makes these changes for you. You may
request that HFL modifies, corrects, supplements, erases or shields your
information.

Restriction of processing of personal data
You also have the right, under certain conditions, to ask HFL to restrict the
processing of your personal data.

Right to object
If processing of your data takes place on the grounds of ’legitimate interest’ by HFL
or a third party, you have the right to object to that processing.

Portability of data
You have the right to obtain your personal data from HFL. HFL will provide this in a
structured and commonly used format, which can easily be opened using commonly
used digital systems.

Withdrawing consent
When the legal basis for a particular processing is your explicit consent, you have
the right to withdraw that consent. This does not affect past processing, but does
mean that we will no longer be allowed to process this data in the future. It may also
result in HFL no longer being able to provide you with certain services.

Response from HFL
A request can be sent to [email protected]. HFL will comply with your
request as soon as possible and in any case no later than one (1) month after HFL
has received such a request. If HFL rejects your request, we will indicate in our reply

why the request was rejected.
Recipients of your personal data
Your data may be transmitted to:

• Data processors
It is possible that HFL is required to submit your data to a third party, for example
to fulfil a legal obligation.

Can changes be made to this Privacy Statement?

This Privacy Statement is subject to changes. We therefore advise you to regularly
read the Privacy Statement for any such changes.
Questions, remarks, and complaints

If you have any questions regarding this Privacy Statement or the way in which HFL
uses your data, you can send an e-mail to [email protected]. If you have a
complaint about the way your data is processed, please send an e-mail to
[email protected]. Furthermore, you always have the right to contact the
competent national data protection authority. In The Netherlands, this is the
Autoriteit Persoonsgegevens.