- The Policy is designed to provide you with information on how your personal data will be treated by Nanma Luxury Limited (“us”, “we” or “our”).
- Our Policy ensures that we gather, store and handle personal data fairly, transparently, confidentially and with respect towards individual rights. By agreeing to this Policy, you agree to the processing of your personal data in accordance with its provisions.
- Kindly be informed that our Policy is subject to change at any time without notice. Please review it regularly to stay abreast of any changes.
- This Policy applies to all activity on our Site in which the provision and processing of Personal Data is required and to use of our social media platforms. However, information that is classified as public is not subject to this policy.
- CONSENT AND USE OF DATA
- Consent within the meaning of this Policy is your agreement to provide Personal Data when requested or when you freely provide information in accordance with this Policy. Your consent will always be sought for the collection, processing, use or storage of data for any purpose. You will also be made aware of the purpose for which your personal data is collected, and your data will only be applied towards that purpose.
- At any time when your consent is requested, you will also have the option of objecting to the processing of your Personal Data by not providing the requested details or action, as the provision of your Personal Data is absolutely voluntary. Please note however that where you object to the provision of relevant Personal Data, we may be unable to proceed with the provision of our services to you.
- Where you wish to provide the Personal Data of third parties, you are required to ensure that the consent of such third parties is sought and obtained prior to provision to us. By providing the Personal Data of third parties, this consent will be deemed to have been sought and obtained.
- For the avoidance of doubt, we will only collect and/or process your Personal Data where:
- you give us your consent to process your data for one or more purposes;
- it is necessary for the performance of an order instruction;
- it is required for compliance with a legal obligation to which we are subject;
- it is necessary to protect the vital interests of the data subject or of another Person; or
- it is necessary for the performance of a task carried out in the public interest or in the exercise of official public mandate vested in us.
Please note that you have a right to withdraw your consent at any time. More information on the withdrawal of your consent is contained in Clause 9.0 (“Your Rights”) below.
- COLLECTION OF PERSONAL DATA
- Please note that when you visit our Site, we automatically collect certain information about your device, including information about your web browser, IP address, time zone, and some of the cookies that are installed on your device. As you browse the Site, we also collect information about individual web pages or products that you view, the websites or search terms that referred you to our Site, and information about how you interact with the Site. We refer to this automatically collected information as “Device Information”.
- We collect Device Information using the following technologies:
Cookies are small text files containing small packets of data which are stored by a computer when you visit a website. Cookies are automatically created when you visit a website to keep track of your movement within the website. We make use of different types of cookies including.
· Session Cookies: these cookies are temporary and disappear as soon as your browser closes.
· Persistent Cookies: these cookies remain after your browser is closed and may be used for subsequent visits to the Site.
· Pre-Cookies: these are set by the websites you visit.
These may be used for our Site to function properly (“Essential Cookies”), to help us to analyze the traffic on our Site and how it is used by our Users (“Performance Cookies”) and to distinguish you from other Users so that we can understand and provide for the needs of individual Users, and our Users collectively, more efficiently (“Functionality Cookies”).
You have the right to restrict, block or delete cookies sent by our Site or any third-party websites, this can be done in the settings of your browser.
- Log files
These are files that list actions that have occurred on a website. In other words, they track actions occurring on our Site, and collect data including IP address, browser type, referring/exit pages and date/time stamps.
- When you make a purchase or attempt to make a purchase through our Site, we collect certain information from you including your name, email address, billing address, gender, telephone or mobile number, shipping address, payment information including credit card/debit card numbers and any other personal information that may be necessarily required for the purpose of providing our services. We refer to this as our “Order Information”.
- In order to serve you better, we also collect information from you when you fill forms on our Site, when you register for an account, enter a competition, promotion or survey, when you correspond with us by email or otherwise and when you report a problem with our Site. This we refer to as “Site Visit Information”.
- “Personal Data” in this Policy refers to Device Information, Order Information and Site Visit Information.
- OUR PURPOSES FOR COLLECTION OF PERSONAL DATA
- We will use your Personal Data to:
- execute your orders placed on the Site including processing your payment information, arranging for shipping and providing you with invoices and/or order confirmations (this includes the provision of your Personal Data to our merchant Users for the execution of your orders where applicable);
- identify and investigate illegal activity such as fraud;
- screen orders for potential risk or fraud;
- provide you with information relating to our products or services;
- improve and optimize our Site;
- share with third parties/affiliates, both as necessary to fulfill your orders and for marketing purposes, insofar as this does not conflict with the requirements for the protection of your Personal Data;
- update or confirm existing records;
- respond to your enquiries;
- better understand our Users’ access and use our Site and for other research and analytical purposes;
- process your job application if you apply for a job with us;
- comply with legal authority or other lawful requests by regulators; and
- to fulfil our general business operation needs including accounting, recordkeeping and other administrative functions.
Any further processing of your Personal Data will only be for archiving or statistical purposes. In these or any other instances where we intend to further process your Personal Data for a purpose other than those specified above, we will provide you, prior to such further processing, with information on that other purpose and request your consent by updating this Policy and obtaining your consent again.
You can always update or amend the Personal Data provided to us through our self-service portal if subscribed thereto. Other means of updating your Personal Data include written requests through e-mail or letters or verbal requests over the phone.
- DATA RETENTION
- We will only retain your Personal Data for a period for which is reasonably necessary for the provision of our services to you and to fulfil the reasons for which it was collected. Further, we will delete Personal Data where:
- it is no longer necessary in relation to the purposes for which it was collected or processed;
- you withdraw your consent to the processing of your Personal Data;
- you object to the processing of your Personal Data and there are no overriding legitimate grounds for the processing;
- your personal data is found to have been processed at variance with the provisions of the law; or
- compliance with a legal obligation requiring the erasure of Personal Data.
- SOCIAL MEDIA, THIRD PARTIES AND THIRDPARTY ACCOUNTS
- In view of the nature of our business and in order to fulfil our commercial, regulatory and contractual objectives, we may share your Personal Data with third parties including exhibitors, agents, affiliates, courier service providers. Their use of your Personal Data will always be controlled, to the extent that they are only allowed to use the data strictly for the purpose we have stated, and you will never be contacted by them unless your consent has been secured in advance.
- Where necessary, applicable Personal Data may be shared with foreign exhibitors, courier service providers, in accordance with the parameters set forth in the Regulation, subject to the existence of one of the following (“Data Transfer”):
- you have explicitly consented to the Data Transfer;
- the Data Transfer is necessary for the completion of an order instruction
- the Data Transfer is necessary for important reasons of public interest, the establishment, exercise or defense of legal claims or to protect your vital interests or those of other persons or where you are physically or legally incapable of giving consent.
- By granting us access to any Third Party Accounts, you understand that we may access, use, make available and store (if applicable) any content that you have provided to and stored in your Third Party Account (“Social Network Content”) so that it is available on and through the Site via your account (including without limitation any friend lists) and we may submit to and receive from your Third Party Account additional information provided by you.
Depending on the Third-Party Accounts you choose and subject to the privacy settings that you have applied in such Third-Party Accounts, Personal Data that you post to your Third-Party Accounts and other Social Network Content may be available on and through your account on the Site. Please note that if a Third-Party Account or associated service becomes unavailable or our access to such Third-Party Account is terminated by the third-party service provider, then Social Network Content may no longer be available on and through the Site.
You will have the ability to disable the connection between your account on the Site and your Third-Party Accounts at any time. PLEASE NOTE THAT YOUR RELATIONSHIP WITH THE THIRD-PARTY SERVICE PROVIDERS ASSOCIATED WITH YOUR THIRD-PARTY ACCOUNTS IS GOVERNED SOLELY BY YOUR AGREEMENT(S) WITH SUCH THIRD-PARTY SERVICE PROVIDERS. We are not responsible for any of your Social Network Content for any reason. You acknowledge and agree that we may access your email address book associated with a Third-Party Account and your contacts list stored on your devices, solely however, for the purposes of identifying and informing you of those contacts who have also registered to use the Site.
You can deactivate the connection between the Site and your Third-Party Account through our self-service portal if subscribed thereto, by written requests through e-mail or letters or verbal requests over the phone. We will make every effort to delete any information stored on our servers that was obtained through such Third-Party Account.
- DATA SECURITY AND PROTECTION
- We take and will endeavour to continue to take all reasonable steps in order to protect our information and all Personal Data. To prevent unauthorized access and maintain security against foreseeable hazards, we have in place physical, electronic and managerial procedures to protect, secure and safeguard our Users’ Personal Data and ensure accuracy of our records.
- We use secure socket layer (SSL) protocol technology for the collection and any permitted transfers of your data. However, we cannot guarantee the security of any Personal Data disclosed to us or collected by us to the extent that we have no control over the public or third-party network through which Personal Data may be sent to our Site.
- We have in place a Data Protection Officer who deals with security of information and Personal Data as well as with compliance with the Regulation. Our Data Protection Officer is who can be contacted by e-mail at firstname.lastname@example.org and the knowledge and skills of our Data Protection Officer are continuously updated.
- Our staff are trained on the importance of data security and practical aspects of the Regulation, confidentiality and our security system. We have procedures in place in relation to our obligations under the Regulation. Accordingly, staff are aware of the information security issues and can go to the Data Protection Officer with any issues relating to or arising from the Regulation, Privacy or Personal Data.
- We monitor and log access to assist in the detection and investigation of security breaches and any attempted breaches where they occur and have in place relevant controls which alert us to breaches in our security. We endeavor to investigate every breach of security and take relevant measures as required by law.
- We maintain a business continuity plan which identifies our business functions and assets (including Personal Data), as a contingency to protect against the event of any disaster. The plan sets out the procedures for protecting and restoring Personal Data if necessary.
- YOUR RIGHTS
- Right to Withdraw Consent
You have a right, at any time, to withdraw your consent to the processing of your Personal Data. Withdrawing consent is as straightforward as giving consent and you can do so via our Site, where you are subscribed or have an account, or by written requests through email or letters or by verbal requests over the phone. Please note that where applicable, this may mean that we will be unable to proceed with order instructions.
The withdrawal of your consent cannot be back-dated and thus will have no effect on processing already performed during the period of consent.
- Right to Access, Change, Deletion, Restriction, Objection, Copies
You have the right to:
- access your Personal Data;
- receive copies of Personal Data (subject to a possible fee in the case of excessive requests);
- object to processing of your Personal Data;
- restrict the processing of your Personal Data;
- rectify or update inaccurate Personal Data;
- request the porting of your Personal Data; and
- request the deletion of your Personal Data.
Should you ever wish to exercise any of these rights, please contact us.
- The Right to Complain to the Regulator and Seek Redress
In the event you feel that your Personal Data has been misapplied or misused in any way, please contact us within 90 days of the issue and we will endeavor to resolve the issue within 30 days of acknowledging receipt of the complaint.
- PROMOTIONAL MESSAGES
- We may sometimes contact you with products, services or events that we think may be of interest to you. If you do not wish to receive such messages from us, you can opt out at any time through our self-service portal if subscribed thereto, by written requests through e-mail or letters or verbal requests over the phone.
- For any enquiries in respect of this Policy please contact us or our Data Protection Officer using the contact details provided on our Site and in this Policy.
This Policy only covers our operations on the Site, on our social media platforms and any other marketing or sales channels. Any third-parties to which we may provide links may have in place their own privacy and data protection policies, which may differ from ours. We accept no responsibility or liability in respect of Personal Data provided to any third-party platforms.