PRIVACY POLICY

This Privacy Policy sets out the types of personal data ONENINE, a limited company incorporated in the Netherlands, may collect about you when you interact with us and explains how we process your personal data. References in this Privacy Policy to “ONENINE,” "we," "us," or "our" are to ONENINE.

This Privacy Policy applies if you are a visitor to our websites or social media pages, or if you purchase any products from ONENINE. We may collect, use, store, and transfer different kinds of personal data about you when you visit our websites or social media pages, register for an online account with us, join our loyalty program, contact us, subscribe to our newsletter, purchase any of our products, or register an account.

ONENINE is the “data controller” in respect of your personal data for the purposes of data protection legislation. We are responsible for deciding how we hold and use personal data we collect or receive about you. We respect your privacy and are committed to protecting your personal data. We will ensure that your personal data is stored and used in accordance with this Privacy Policy.

Please read this Privacy Policy carefully. This Privacy Policy may change from time to time. We will regularly review this Privacy Policy, and any updates we make will be posted on our websites. We encourage you to frequently check this page for any changes to stay informed about how we are collecting and processing personal data about you.

This Privacy Policy has been drafted with brevity and clarity in mind. It does not provide exhaustive detail on all aspects of our collection and use of personal data. However, we would be happy to provide any additional information or explanation upon request. If you have any questions or concerns about any of your personal data or information contained within our privacy policy, please contact us using the details below.

Our website is not intended for children (anyone under the age of 18), and we do not knowingly collect data relating to children. No one under age 18 may provide any information to or on the website. We do not knowingly collect personal information from children under 18. If you are under 18, do not use or provide any information on this website or through any of its features, register on the website, make any purchases through the website, use any of the interactive or public comment features of this website, or provide any information about yourself to us, including your name, address, telephone number, email address, or any screen name or username you may use. If we learn we have collected or received personal information from a child under 18, we may delete that information. If you believe we might have any information from or about a child under 18, please contact us at info@one-nine.nl

How to contact us
The person responsible for data protection matters within our organization is the Chief Digital Officer, who can be contacted at info@one-nine.nl

If you have any questions or concerns about this Privacy Policy or our privacy practices, or if you wish to exercise any of your rights over your data as set out in section 12 below, please do not hesitate to contact us by one of the following methods:

  • By post: at our registered office:
    ONENINE B.V.
    Potgieterstraat 27
    5421 PG Gemert
    Netherlands
  • By email: info@one-nine.nl

3. What Data Do We Collect?
Personal data is any information about an individual from which that person can be identified. It does not include data where the identity has been removed (anonymous data).

Whenever we collect, store, use, disclose, or delete your personal data, this is referred to as processing your personal data. As a website user, visitor, customer, we will process different kinds of personal data about you which we have grouped together as follows:

  • Identity Data: Data which identifies you, including your name, title, username, date of birth, and gender.
  • Contact Data: Your contact details such as your billing address, delivery address, email address, and telephone numbers.
  • Purchase Data: Information concerning the products you have purchased from us, including how frequently you purchase from us, whether you have used any discount or gift card codes or other offers, which products you have purchased, how much you have spent with us, and information relating to your membership of our members' reward program, ONENINE Prestige, including how many ONENINE Prestige points you have collected and which rewards tier you are in.
  • Security Data: For your security, we keep an encrypted record of your login password.
  • Customer Service Data: Information relating to your interactions with our customer service team by email, phone, WhatsApp, online chat, or by post, or by submitting an enquiry form on our website or contacting us via our social media pages.
  • Financial Data: Data we collect if you purchase a product from us, such as your bank account and payment card details.
  • Review Data: Information you provide to us when you review our products or services, such as via Trustpilot, or when you provide feedback to our customer service team.
  • Marketing Data: Data we capture when you sign up to receive our newsletter or other marketing communications, including your preferences regarding how we contact you, opt-out data, and any vouchers or other offers we have sent you, as well as data on how you respond to and interact with our marketing communications.
  • Technical Data: Electronic information that is automatically logged/stored by processing equipment, including details of the device(s) you use to access our services, internet protocol (IP) address, your login data, browser type and version, time zone setting and location, country and telephone code where your device is located, browser plug-in types and versions, operating system and platform, and other technology on the devices you use to access our websites or open our emails.
  • Usage Data: Information about how you use our website, including how you navigate and interact with our website, which pages and products you view, the time spent on our website, information about your previous visits, the advertisements you view and click on, the contents of your shopping basket, products on your wish list, and any search terms you enter. We also collect data about how you arrive at our websites (e.g., through a search and the search keywords used).
  • Social Media Data: Data you provide to us directly about your social media accounts or which we have access to when you connect with us, like or follow our social media accounts, including your social media handle, photograph, date of birth, location, occupation, interests, and other information and content you make available via your social media accounts.

We also collect, use, and share aggregated data such as statistical or demographic data for any purpose. Aggregated data could be derived from your personal data but is not considered personal data in law as this data will not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a specific website feature. However, if we combine or connect aggregated data with your personal data so that it can directly or indirectly identify you, we treat the combined data as personal data which will be used in accordance with this Privacy Policy.

We do not collect any special categories of personal data about you (such as information about your health, race, political opinions, religious beliefs, or sexuality). Nor do we collect any information about criminal convictions and offences.

4. When Do We Collect Your Data?
We collect your data in the following situations:

Direct Interactions: We collect personal data directly from you when you interact with us or correspond with us via our websites, by email, WhatsApp, online chat, by post, or on social media. This includes personal data you provide when you:

  • Visit our website;
  • Create an account on our website;
  • Become a member of ONENINE Prestige, our members' rewards program;
  • Place an order for any of our products;
  • Subscribe to receive our marketing communications;
  • Engage with us on social media, such as by following us, liking our posts, commenting on our posts, or sending direct messages;
  • Contact us by any means, including filling out an enquiry form on our website or by sending us an email;
  • Give us feedback or respond to our request for feedback;
  • Request marketing to be sent to you;
  • Enter a competition, promotion, or survey; or
  • Comment on or review our products.

Automated Technologies or Interactions: When you interact with our website our systems will automatically collect information about your equipment, browsing actions, and patterns. We collect this personal data (namely Technical and Usage Data) by using cookies, tracking pixels, server logs, and other similar technologies. Please see the section on Cookies below and our Cookies Policy. We also collect information using a pixel contained in our marketing emails. We use this information when you interact with our website, and our emails to improve our website content, recommend products of interest to you, and tailor our marketing communications to you.

Other Third Parties: We may also receive personal data about you from various third parties as outlined below:

  • Our third-party ecommerce website provider (currently Shopify), whose services enable us to process electronic orders and payments for products, our third-party app provider (currently Venn Apps), and other providers of technical, payment, and delivery services.
  • Our third-party fraud and abuse detection provider (currently Signifyd Inc.) to help detect and prevent fraudulent transactions on our website. For more information on Signifyd’s processing of your personal data, please see their privacy notice at https://www.signifyd.com/privacy/.
  • Analytics providers such as Google Analytics, Shopify Analytics, and Apple’s App Analytics, who provide us with Technical and Usage Data.
  • Advertising networks such as Google Ads and Facebook, who provide us with Technical and Usage Data.
  • Operators of social media platforms including Facebook, Instagram, Twitter, LinkedIn, YouTube, and TikTok, which may be based outside of the UK and EEA.
  • Review platforms such as Trustpilot, who may provide Review Data.

5. How and Why We Use Your Personal Data
We will only use your personal data when the law allows us to do so. The legal basis will vary depending on the reason for collecting your personal data, and sometimes we may rely on more than one legal basis for processing your data. If you need more information about how we use your personal data and which legal basis we rely on, please contact us.

Below is a summary of the legal basis we rely on to use your personal data, along with practical examples:

  1. Performance of a Contract: We process your data when you purchase products from us to manage and deliver your order, including processing payments. This may involve processing your Identity, Contact, Purchase, Customer Service, and Financial data. We also rely on this basis to manage your membership in ONENINE Prestige, our loyalty program.
  2. Consent: We may send you marketing communications via email or SMS if you have opted in to receive these. Our marketing email provider tracks your interactions with our emails (e.g., delivery, opening, clicking) to tailor content to your interests. You can opt-out of email tracking and marketing communications at any time by using the 'unsubscribe' link or contacting us.
  3. Legal Obligations: We are required to process your personal data to comply with legal and regulatory obligations, such as anti-money laundering laws and consumer contracts legislation. This may involve processing your Identity, Contact, Purchase, Security, Financial, and Technical data.
  4. Legitimate Interests: We may process your personal information (including Identity, Contact, Customer Service, Review, Marketing, Purchase, Technical, Usage, and Social Media data) to understand your preferences and needs, enabling us to send you relevant marketing communications. Our legitimate interests include:
    Managing our relationship with you and notifying you of changes to our terms and conditions or this Privacy Policy.
    Promoting our products and business via our website, email, and social media.
    Personalizing our marketing to enhance your experience.
    Using the 'soft opt-in' to send you direct marketing if you have not opted out.
    Managing the ONENINE Prestige loyalty program, including communication regarding your membership and points.
    Responding to queries, refund requests, and complaints.
    Operating our retail business to further our interests and profitability.
    Improving our products, services, website.
    Processing orders and managing payments.
    Sending you surveys and feedback requests to improve our offerings.
    Administering and protecting our business and website.
    Maintaining accurate business records.
    Protecting our financial interests and managing legal claims.
    Ensuring compliance with relevant terms and conditions.
    Preventing fraud and detecting crime.

If you have any questions or require more information about how we process your personal data, feel free to reach out.

6. Change of Purpose
We will only use your personal data for the purposes for which we collected it, unless we reasonably believe that we need to use it for another reason that is compatible with the original purpose. If we intend to use your personal data for an unrelated purpose, we will inform you and explain the legal basis that allows us to do so. We may process your personal data without your knowledge or consent when this is required or permitted by law.

7. If You Fail to Provide Personal Data
If we need to collect personal data from you to comply with legal obligations or to fulfill a contract we have with you, and you do not provide that data when requested, we may not be able to perform the relevant contract (for example, delivering your products or processing your payment). In such cases, we may have to cancel the relevant contract.

8. Data Security
We have implemented appropriate security measures to prevent your personal data from being accidentally lost, used, accessed without authorization, altered, or disclosed. Your personal data is accessible only to authorized personnel at ONENINE who require access to fulfill their duties. All staff with access to your personal data will process it only in accordance with our instructions and are subject to a duty of confidentiality.

We also have procedures in place to address any suspected personal data breaches and will notify you and any applicable regulator of a breach when legally required.

However, please note that the transmission of information via the internet is not completely secure. While we do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our website; any transmission is at your own risk. Once we receive your information, we will employ strict procedures and security features to prevent unauthorized access.

9. How Long We Will Keep Your Data
We will retain your personal data only for as long as is reasonably necessary to fulfill the purposes for which we collected it, including satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal data, we consider the nature and sensitivity of the data, the potential risk of harm from unauthorized use or disclosure, the purposes of processing, and applicable legal requirements.

For marketing consents, we may ask for your updated consent if we have not heard from you in a while to confirm your interest in receiving our emails or texts. If you choose to opt-out, we will keep a record of this alongside your contact details to ensure that we do not send you marketing communications in the future.

In some cases, we may anonymize your personal data (so that it can no longer be associated with you) for research or statistical purposes, allowing us to use this information indefinitely without further notice to you.

We will not be liable for any deletion of personal data carried out in accordance with our data retention policy.

10. Who Do We Share Your Data With?
We may share your personal data with the following third parties to perform a contract with you, comply with legal obligations, pursue legitimate business interests, or where you have given consent:

  • Third parties supporting our website, including our ecommerce provider (Shopify) and app provider (Venn Apps).
  • Our third-party warehouse provider (currently Bleckmann Logistics).
  • Delivery couriers and returns carriers (currently ReBound and Happy Returns).
  • Third-party payment providers and ‘buy now pay later’ services such as Stripe, Klarna, Clearpay, Afterpay, PayPal, ApplePay, and Mollie.
  • Accounting software providers (currently Xero and Oracle NetSuite).
  • Marketing and advertising providers like Klaviyo, Ometria, and Yotpo SMS Bump.
  • Data analytics companies such as Google Analytics and Shopify Analytics.
  • Social media platforms and search engines (Facebook, Instagram, Twitter, LinkedIn, YouTube, TikTok, Google) to show you relevant products while browsing.
  • In the event of a merger, divestiture, restructuring, or sale, your data may be transferred as part of our assets.
  • Other companies for fraud protection and risk reduction, including HM Revenue & Customs, police, regulators, and public bodies.
  • Professional advisers such as lawyers, bankers, auditors, and insurers.
  • Courts and government agencies in compliance with legal processes.
  • Our group companies for reporting activities, business operations, and system support.

We require all data processors to respect the security of your personal data and to treat it according to the law. We do not permit them to use your personal data for their own purposes and only allow processing in accordance with our instructions.

In certain cases where we share data with third parties, such as HMRC, those parties may also be controllers of your personal data. We are not responsible for how other data controllers manage or process your information. Please contact those third parties for details on their data practices.

Your data will also be shared with Signifyd Inc., which provides us with fraud and abuse detection services. For details on what personal data Signifyd collects and how it uses that data, please refer to their privacy notice at Signifyd Privacy Notice.

11. International Transfers
If we need to transfer your data outside the UK or the EEA, we ensure your data receives essentially equivalent protection as if it were processed within the UK or EEA by implementing at least one of the following safeguards:

  • We will transfer your personal data to countries that have been recognized as providing an adequate level of protection for personal data by UK adequacy regulations (for data transfers from the UK) or EEA adequacy regulations (for data transfers from the EEA).
  • In some cases, we will take steps to ensure that the recipient provides an adequate level of protection for the rights and freedoms of data subjects regarding the processing of personal information and that appropriate safeguards are in place to comply with data protection legislation. If you want further information on these arrangements, please contact us.

12. Your Rights Over Your Data
You have certain rights concerning the personal data that we process about you (where we are the data controller, meaning we determine the purpose and means of processing):

  • The right to request access to your personal data that we hold and receive certain information relating to that data.
  • The right to ask us to rectify inaccurate data or complete incomplete data.
  • The right to receive or request that your personal data be transferred to a third party in a structured, commonly used, and machine-readable format (this right only applies to automated information that you initially provided consent for us to use or where we used the information to fulfill a contract with you).
  • The right to request the erasure of personal data if it is no longer necessary for the purposes for which it was collected or processed, or if you have successfully objected to processing (please note that we may not always be able to comply with your erasure request for specific legal reasons, which will be communicated to you if applicable).
  • The right to object to our processing of your personal data in certain circumstances, including the right to request that we not process your personal data for marketing purposes.
  • The right to restrict the processing of your personal data, for example, if you wish us to verify the accuracy of the data or if you have objected to our use of your data while we verify whether we have overriding legitimate grounds for processing it.
  • Where we process personal data relating to you based on your consent, you may withdraw your consent at any time (this will not affect the legality of any processing carried out prior to the withdrawal). If you withdraw your consent, we may not be able to provide certain products or services to you.

If you wish to exercise any of the above rights, please contact us.

We may ask you to verify your identity if you make a request to exercise any of your rights. This is a security measure to ensure that personal data is not disclosed to anyone who is not entitled to receive it. We may also contact you for further information to expedite our response. You will not be charged a fee to access your personal data (or to exercise any other rights). However, we may charge a reasonable fee if your request is clearly unfounded or excessive. Alternatively, we may refuse to comply with your request in such cases.

We will strive to respond to all legitimate requests within one month. Occasionally, it may take us longer than a month if your request is particularly complex or if you have made several requests. In this case, we will notify you and keep you updated.

13. Marketing Preferences
You have several options for stopping direct marketing communications from us:

  • Click the ‘unsubscribe’ link in any email, or text ‘STOP’ in response to any SMS message we send you.
  • Contact us via email at info@one-nine.nl.

Please note that you may continue to receive communications for a short period after changing your preferences while our systems are updated.

14. Cookies
Our website uses cookies to distinguish you from other users. This helps us provide a good experience while browsing our website and allows us to improve our website, products, and services. For more information on how cookies work, please visit www.cookiecentral.com and www.allaboutcookies.org. We are not responsible for the content of third-party websites.

To learn more about the cookies we use and why, please see our Cookie Policy.

You can set your browser to refuse all or some cookies or to alert you when websites set or access cookies. The above websites provide guidance on how to do this. If you disable or refuse cookies, please note that some parts of our website may become inaccessible or not function correctly.

To opt out of being tracked by Google Analytics across all websites, please visit https://tools.google.com/dlpage/gaoptout.

You can also use your social media platforms and their privacy settings to adjust your preferences regarding cookies and tracking. For Facebook/Meta, please see: https://www.facebook.com/help/568137493302217.

Targeted Advertising: You can opt out of receiving targeted advertising from members of the following schemes:

  • Network Advertising Initiative
  • Your Online Choices

Cookies that allow us to identify you are considered personal data. We will only use cookies that capture personal data where we have a legal basis for doing so. The information obtained from cookies, to the extent it is considered personal data, will be used by us in accordance with our Privacy Policy.

15. Third-Party Links
Our website may contain links to third-party websites, plug-ins, and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website we encourage you to read the privacy policies of every website you visit.

16. How to Complain
If you are unhappy with how we have used your personal data, please let us know by emailing us at info@one-nine.nl.

You have the right to make a complaint at any time to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens), the supervisory authority for data protection issues in the Netherlands (www.autoriteitpersoonsgegevens.nl). However, we would appreciate the opportunity to address your concerns before you approach the Dutch Data Protection Authority, so please do contact us first, and we will do our best to resolve your complaint.

17. Changes to your data
It is important that the personal data we hold about you is accurate and current. Please let us know if your contact details change during your relationship with us. You have the right to correct any information we hold about you that you think is wrong or incomplete. Please contact us if you want to do this.

COOKIES POLICY
This Cookie Policy explains what cookies ONENINE may set when you use our websites or apps.

Our use of cookies
Our websites and apps use cookies to distinguish you from other users. This helps us to provide you with a good experience when you browse our websites or use our apps and to improve our sites, products, and services. To find out more about how we use cookies, please take a few moments to read this Cookie Policy.

What are cookies?
A cookie is a small data file that is stored on your browser or the hard drive of your computer (or another electronic device). More information about cookies can be found at www.allaboutcookies.org and www.cookiecentral.com. Please note we cannot be responsible for the content on external websites.

We use cookies for the reasons set out below. Some of the functions that cookies perform can also be achieved using similar technologies (for example, tracking pixels, tags, and server logs). References to ‘cookies’ in this Policy include references to these other technologies.

The types of cookies we use
We use the following cookies:

  • Strictly necessary cookies: These cookies are essential for the operation of our websites or apps. They include, for example, cookies that enable you to log into your account, use a shopping cart, or make use of e-billing services.
  • Analytical or performance cookies: These allow us to recognize and count the number of visitors and to see how visitors move around our websites or apps when they are using them. This helps us to improve the way our websites and apps work, for example, by ensuring that users are finding what they are looking for easily.
  • Functionality cookies: These are used to recognize you when you return to our websites or apps. This enables us to remember your preferences (for example, your choice of language or region).
  • Targeting cookies: These cookies record your visit to our websites or apps, the pages you have visited, and the links you have followed. We will use this information to make our websites/apps and our advertising and marketing communications more relevant to your interests. We may also share this information with third parties for this purpose.

We do not require your consent to use strictly necessary cookies. We request your consent before using analytical or performance cookies, functionality cookies, or targeting cookies.

Third-party cookies
We use cookies from third parties on our websites and apps over which we have no control. These third-party cookies are strictly necessary, analytical, or targeting cookies. You can find more information about these third-party cookies in the table at the end of this Cookies Policy. You can also find out more information on cookies provided by the following third parties at the links set out below:

  • Shopify
  • Google
  • AddThis
  • Facebook/Meta
  • AdRoll

We use a pixel contained in our emails to track whether they are opened and which features people click on. This means that we can send you email content that’s more relevant and tailored to you. You can easily opt out of our marketing emails at any time. Please see our privacy notice at Privacy Policy.

Changing your cookie preferences
You can change your cookie preferences at any time by visiting Cookie Preferences to manage the use of cookies.

You can block cookies by activating the settings on your browser that allow you to refuse the setting of all or some cookies. To find out how to do this, visit www.allaboutcookies.org. However, if you use your browser settings to block all cookies (including strictly necessary cookies), you may not be able to access all or parts of our website, and your experience of our website may be impaired.

Google Analytics: To opt out of being tracked by Google Analytics across all websites, please visit https://tools.google.com/dlpage/gaoptout.

You can also use your social media platforms and their privacy settings to adjust your preferences on cookies and tracking. For Facebook/Meta, please see: https://www.facebook.com/help/568137493302217.

Targeted Advertising: The following are opt-out schemes that allow you to opt out from receiving targeted advertising from members of those schemes:

  • Network Advertising Initiative
  • Your Online Choices

More about your privacy: Cookies that allow us to identify you will be considered to be personal data. We will only use these cookies, which capture your personal data, where we have a legal basis to do so. The information we obtain from the use of cookies will, to the extent that it is considered to be personal data, be used by us in accordance with our Privacy Policy.

Third-party websites
When we include links on our website to other websites, please bear in mind that these third-party websites will have their own privacy and cookie policies that will govern the use of any information you submit on those websites. These third-party websites may set their own cookies that capture your personal data. We recommend you read their policies as we are not responsible or liable for the actions of any third parties.

Contact
If you have any concerns or require any further information, please do not hesitate to contact us at info@one-nine.nl