Privacy Policy
Thank you for visiting our website.
It is important to us that we protect and respect your privacy when you choose to use our services.
In addition to being the preferred supplier of jewelry, our ultimate goal is to process your personal data responsibly and appropriately, so that you can feel safe using our services.
We have high ethical standards and have established strict internal procedures that ensure that we process your personal data in the best possible way.
In our privacy policy you can read the terms for the processing of your personal data and the rights you have in connection with using our website.
If you have any questions or comments about our privacy policy - or if you would like to get in touch with us in any other way, please feel free to contact us.
What services do we provide?
Our company manufactures and delivers classic jewelry in gold, silver, pearls and gemstones of exquisite quality.
For this purpose, we collect a variety of data about you.
In the other menus, we have explained what we collect, why we do it, what we do to protect your data, where we collect the personal data from and what rights you have in this regard.
What is personal data?
Personal data can be many things.
It can be a name, address and phone number. It can also be a picture or an IP address.
Personal data is any information that can be used to identify a person. Therefore, it is not just the individual piece of information that determines whether something can be called personal data.
If several pieces of personal data cannot identify a person individually, but together they can, they have the character of personal data.
We collect personal data in several ways
We collect personal data about you in the following ways:
-When you purchase our products physically in our store
-When you are in contact with our customer service]
-When you sign up for our newsletter
-When you provide us with the personal data yourself
-When you provide information to third parties with whom we have a collaboration
You can find out in the menu below why we do it and on what basis we do it.
We use your personal data in several ways
Here you can read the following:
- That we collect and use your personal data for specific purposes
- That we delete your personal data when it is no longer necessary
- That we continuously check and update your personal data
- That we disclose your personal data in certain cases
We collect and use your personal data for specific purposes
The purpose of collecting and using your personal data can be divided into the following categories:
- In the first category There is certain personal data we need to know about you in order to provide our service to you. For example, your name, telephone number and email address, i.e. necessary identification and contact information.
This therefore constitutes our lawful 'processing basis'. If we cannot process this personal data, we cannot provide our service to you.
We may also have another basis for processing, for example, that we are required by law to register and store certain personal data. For example, this is personal data for our compliance with tax legislation and the Danish Accounting Act.
If we want to use your personal data in a way other than the way we collected it because it was necessary, we will inform you if the 'framework' of the original purpose is exceeded. We will do this before we start and at the same time inform you of the reasons for this.
- In the second category There is certain personal data that we would like to know about you so that we can adapt our communication and marketing to you and otherwise optimize your relationship with us so that we can offer you exactly the services and products you need.
It also involves the collection of personal data about your use of our website, including IP addresses and the placement of cookies on your computer. This may be necessary for our website to function properly.
None of the personal data in category 2 is strictly necessary for us to provide our service to you. Therefore, you must provide explicit consent for us to collect and use this personal data.
Our basis for processing in this regard is therefore your consent.
Your consent is voluntary and if you have given it to us, you can withdraw it at any time by contacting us using the contact information at the bottom of our privacy policy.
If we wish to use your personal data in a way other than the one for which we collected it based on your consent, we will always ask for your renewed consent if the 'framework' of the original purpose is exceeded. We will do this before we proceed and will inform you of the reasons for this at the same time.
- In the third category There is certain personal data that we store so that we can safeguard our interests in the future, if necessary. Our basis for processing is 'legitimate interests', as understood in applicable personal data legislation.
This means, among other things, that we store your personal data for a period based on a specific assessment. The time period and the scope of the personal data in this processing are determined based on the criteria that you can see in the section 'we delete your information when it is no longer necessary'.
We delete your personal data when it is no longer necessary.
We make a judgement call to see when we no longer need your personal data. When we no longer need the personal data in accordance with the purpose for which we collected it, we delete it.
We will delete your personal data after 6 months, as we assess that we no longer need it at this time.
We must store some personal data for a minimum of 5 years due to legislation, including the Danish Accounting Act. For example, this is personal data used for issuing invoices so that we can settle tax and VAT correctly and document it to the authorities.
As our service includes a product for which we have a responsibility to you or others, we generally store some personal data for a minimum of 10 years. This includes email correspondence with you.
We do this to safeguard our financial interests and legal position if someone believes that we have acted in a way that requires responsibility. In that case, we must be able to document what personal data we have received, what agreement was entered into with the customer and what we have done in relation to the customer, so that we can safeguard our interests. We 'cleanse' the documents of the personal data that is not necessary for this.
We continuously check and update your personal data.
We continuously check that the personal data we process about you is not incorrect or misleading.
We do this by sending you a confirmation upon conclusion of the agreement regarding the personal data we have registered about you.
You can use the contact information at the bottom to notify us of your changes.
We disclose your personal data in these cases
We do not sell, publish or otherwise disclose your personal data to others unless:
- it is necessary for us to perform our service to you, or
- it is necessary for us to comply with the law, or
- you have given us consent to it, or
- it is necessary to protect a business partner or a third party (there are strict rules in the law for having to disclose personal data on this basis)
- this is as part of our use of data processors, both inside and outside the EU
If necessary . We work with selected and trusted partners to deliver our service to you, including data processors.
We provide them with the necessary personal data so that we can overall provide our service to you.
This could be, for example, production of goods and collection of goods. It could also be the Central Register of Personal Data, so that we can update any name or address changes in databases about our customers.
If you have given consent. We disclose personal data to companies, organizations or individuals outside our company and group if we have your consent.
Your consent and thus the disclosure to our partners means, among other things, that our partners may contact you for sales and marketing purposes.
You can object to this type of disclosure at any time, and you can also opt out of marketing inquiries in the CPR register.
If required by law, or to protect ourselves, a business partner, or a third party. In some cases, the law allows us to disclose personal data without your consent. Sometimes we have to. Other times we can .
To the extent permitted by law, we may disclose personal data in order to either protect or enforce our rights. The same applies to the rights of our partners and third parties.
Examples where it may be relevant are, for example, in connection with the prevention of fraud or other criminal offences.
Our use of data processors, both inside and outside the EU. We obtain your consent before we transfer your personal data to partners in third countries, unless they act as our data processors. A third country can, for example, be certain countries in Africa. The USA is not a third country due to the so-called Privacy Shield agreement between the USA and the EU, if the company in the USA has joined the Privacy Shield agreement.
If we transfer your personal data to third countries, we have ensured that their level of protection of personal data matches the requirements we have set for ourselves in this policy and the requirements we are subject to in relation to legislation.
You have many rights.
In this section you can read that you have a number of rights in connection with our processing of your personal data, including that you have:
- Right to have incorrect personal data corrected
- Right to access your personal data and receive a copy
- Right to have your personal data deleted
- Right to demand restriction
- Right to object to processing
- Right to withdraw consent
- Right to request information about transfers to countries and organizations outside the EU
- Right to avoid profiling
- Right to complain about our processing of your personal data
If you would like to know more, or exercise your rights, please contact us using the contact details below.
Right to have incorrect personal data corrected
We check that the personal data we process about you is not incorrect or misleading. We do this by comparing your personal data with public registers.
You have the right to have your personal data that we hold rectified (corrected).
Right to access your personal data and receive a copy
You have the right at any time to gain insight into the personal data we have registered about you and to be provided with a copy of the personal data.
You can also be informed about the purposes of the processing, how long we store your personal data, whether we make automated decisions (including profiling), who we disclose the personal data to and where we have the personal data from. However, this does not apply if you are already familiar with the personal data.
We would like to point out that the right to access may be limited in order to protect the personal data of other people and our trade secrets.
Right to have your personal data deleted
You may at any time request the deletion of your personal data that we hold. If we no longer have a purpose for holding the personal data, we will delete it as soon as possible after your request.
Right to demand restriction of processing
You have the right to request us to restrict the processing of your personal data at any time.
Right to object to processing
You have the right to object to our processing of your personal data at any time. This includes the right to object to our use of the personal data for marketing purposes. We will consider your objection as soon as possible if you make such an objection.
Right to withdraw consent
You can revoke the consent(s) you have given us at any time.
Right to request information about transfers to countries and organizations outside the EU
You have the right to be informed whether we transfer personal data to a country outside the EU.
We can inform you that we transfer personal data to IT companies that act as our data processors in the USA [and other countries, if so, which ones].
All of our data processors in the USA have joined the Privacy Shield agreement (read more here: https://www.datatilsynet.dk/erhverv/tredjelande/eu-us-privacy-shield/ ) and have committed to complying with applicable personal data legislation.
We can therefore pass on personal data to the companies.
Right to avoid profiling and automated decision-making
You have the right at any time to prevent us from creating profiles of you and your personal data or making automated decisions.
We can inform you that we do not carry out profiling in our company or make automated decisions.
Lawsuit
We do everything we can to ensure that your personal data is processed securely and that your rights are optimally protected, and we regularly review our procedures and the handling of personal data.
If, contrary to expectations, you believe that we are not handling your inquiry and your rights in accordance with the law, please contact us, preferably by email with the text "complaint" in the subject line.
You can write to us at smykker@birgittemunch.dk.
We will then forward your inquiry to a senior employee in our company so that any misunderstandings and misconceptions can be resolved.
If you still believe that we are not handling your inquiry and your rights in accordance with the law, you can complain to the Danish Data Protection Authority via:
Inspectorate
Borgergade 28
1300 Copenhagen K
Telephone: 33 19 32 00
Children
Our company is aimed at adults. We do not knowingly collect personal data from or about children.
We are realistic that, for example, children's use of electronic devices can never mean with 100% certainty that we do not receive personal data about children.
We have tried to set up our systems as best as possible so that we cannot receive personal data from children and we will immediately delete the personal data if we become aware that we have inadvertently received personal data about children.
If you are a parent or guardian and believe that your child has provided personal data to us knowingly or unknowingly, please contact us as soon as possible via our contact details at the bottom.
How do we store your personal data?
We are obliged to protect your personal data. Both because it follows from the law, but also because our own internal ethical rules require that we take good care of your personal data.
We use appropriate and appropriate technical and organizational security measures to ensure that unauthorized access is not created to the personal data we store. The purpose of this is to ensure that the personal data is not used, destroyed, altered, disclosed or otherwise misused.
In this section you can read that
- We have internal rules on information security in relation to personal data.
- We have implemented IT technical measures
- User behavior is important to ensure a sufficiently high level of security
- We inform affected individuals if there is a risk of or an actual data breach.
We have internal rules on information security, which contain guidelines and procedures.
This includes, among other things, that personal data is only accessible to the employee(s) who need it.
Employees who need to handle personal data have signed a confidentiality agreement.
Included in our information security rules is that we continuously train our employees in the correct handling of personal data and check that the rules are complied with by the employees.
In terms of IT technology, we have implemented the following measures:
- Installed antivirus on all IT systems that process personal data
- Installed password on computers with regular renewal requirement
- Continuous backup of all IT systems that process personal data
- Installed systems for processing personal data that are in accordance with industry requirements and guidelines
- Restricting access to personal data so that only those employees who need it have access. And only to the extent necessary
- Entered into data processing agreements with suppliers who process personal data on our behalf, so that we ensure that the processing is in accordance with the law and our own rules and ethical standards
The risk and disclaimer
The greatest danger of misuse of personal data arises from people's own actions.
It is up to each individual to take good care of their own personal data (including never providing passwords to others), and it is up to our company to take human interference into account.
Although we have taken the above measures to limit risks when processing personal data, this cannot constitute a 100% guarantee that no accidental incidents will occur.
We therefore disclaim any loss resulting from unintended events related to our use and processing of your personal data to the extent we can do so pursuant to applicable law.
We cannot therefore be held liable for losses of any kind arising in connection with the use of our company, our products and services, our website, systems, apps and other software to the extent that we can do so pursuant to applicable law.
We recommend that you also take measures to secure your personal data.
You can do this by, among other things, closing your browser after use, logging out of all accounts after use, and installing antivirus, antimalware and other software that can improve the security of your computer.
We recommend that you regularly update software, the apps you use, your computer and mobile devices and never disclose your password to others.
Information
As mentioned, we have taken a number of measures to secure the processing of your personal data.
Should our IT systems and other security measures nevertheless be compromised, we will notify you without undue delay if the compromise poses a high risk to your rights and freedoms.
Links to other service providers
Our website may contain links to other websites that do not belong to our company.
We are not responsible for the content of these websites and our privacy policy does not apply to these companies' websites.
Contact information
Our company GULDSMEDEVÆRKSTED V/BIRGITTE B MUNCH is the data controller and ensures that your personal data is processed in accordance with the law:
GOLDSMITH WORKSHOP WITH BIRGITTE B MUNCH
Address: Danmarksgade 46
CVR: 17145487
Phone number: 98 43 80 66
Mail: smyklar@birgittemunch.dk
Website: www.birgittemunch.dk
Updating this Privacy Policy
We update our privacy policy when we assess the need for it. This may be, for example, when we offer new services and products.
When we make changes to the privacy policy, we will mention it below.