INTRODUCTION
Hasta Siempre respects your privacy and is committed to protecting your personal information. This Privacy Policy will tell you how we take care of your personal data when you visit our website (collectively, the “website” or “site”) and will inform you of your privacy rights and how the law protects you.
1. IMPORTANT INFORMATION AND WHO WE ARE
THE PURPOSE OF THIS PRIVACY POLICY
The purpose of this Privacy Policy is to provide you with information about how Hasta Siempre collects and processes your personal information when you use this Site, including any data you may provide through the Site when you sign up to receive our marketing materials, purchase a product or service, sell through our Site, or enter a contest.
This Site is not intended for children, and we do not knowingly collect data relating to children.
It is important that you read this Privacy Policy along with any other privacy notice posted on our Site from time to time so that you are fully aware of how and why we use your data.
CONTROLLER
Hasta Siempre is the controller and is responsible for your personal data.
We have designated a Data Protection Officer (DPO) who is responsible for overseeing matters related to this Privacy Policy. If you have any questions, including requests to exercise your legal rights, please get in touch with us through our customer contact page and indicate that your request is addressed to DPO.
CONTACT US
If you would like to ask us a question or otherwise exercise your legal rights regarding your personal data, the easiest way is to contact us through our customer contact page. This page is controlled by our excellent customer service team, who will forward your request to the appropriate departments.
CHANGES TO OUR PRIVACY POLICY AND YOUR RESPONSIBILITY TO INFORM US OF CHANGES
We may need to update this Policy at any time and without notice, and if we do, we will notify you, for example, by sending an email to all of our customers.
It is important that the personal information we keep about you is accurate and up-to-date. Please inform us if your personal information changes during the course of your relationship with us, and periodically review the information in your account settings on our website.
LINKS TO THIRD PARTIES
This Web site may contain links to third-party Web sites, plug-ins, and applications. Clicking on these links or enabling these connections may allow third parties to collect or transmit data about you. We have no control over these third-party sites and are not responsible for their privacy statements. When you leave our Site, we encourage you to read the privacy policies of the sites you visit.
2. THE INFORMATION WE COLLECT ABOUT YOU
Personal data, or personal information, is any information about an individual from which that individual can be identified. It does not include data in which the identity is deleted (anonymous data).
We may collect, use, store and share different types of personal information about you, which we have grouped together as follows:
Identification information, which includes your first and last name. They may also include your gender.
Contact information is the information we use to contact you, including your billing address, shipping address, email address, phone number, and cell phone number.
Financial Data is the payment method and card association used to process payments on your orders. We do not store or process your card information ourselves; it is processed and automatically stored through one of our third-party service providers. We encrypt your payment card data in your browser and securely transfer this Data to our respective third-party service provider for payment processing.
Transaction Data is information about the transactions you have made on our Site, including any photos or other data you have provided regarding an order, payments to and from you, and other information about the products and services you have purchased from us.
Technical Data is information about the device(s) you use to access our Site, including your Internet Protocol (IP) address, browser type, and version, location, types and versions of browser plug-ins, operating system and platform, and other technology on the devices you use to access this Site.
Profile Data includes your username (email address), login details, purchases or orders you have made, your interests, preferences, reviews, and survey responses.
Usage Data includes information about how you use our Site, products, and services. This includes your browsing patterns and information such as how long you stay on one of our web pages and what you view on our Site and for what purpose, the page that brought you to our Site and the clickstream during your visit to our Site, page response times and page interaction information (the clicks you make on the page).
Marketing and communication data includes your preferences for receiving marketing services from us and your communication preferences.
We also collect, use and share aggregated and/or anonymized data (“Aggregated Data”), such as statistical or demographic data, for analytical purposes. Aggregated Data may be derived from your Personal Data but is not considered Personal Data by law because the Data does not directly or indirectly reveal your identity. For example, we may aggregate your usage data to calculate the percentage of users accessing a particular site feature. However, if we combine or link aggregated data with your personal data in a way that may directly or indirectly identify you, we treat the combined data as personal data that will be used in accordance with this Privacy Policy.
IF YOU HAVE NOT PROVIDED PERSONAL INFORMATION
If we are required by law or by the terms of a contract we have with you to collect personal data, and you do not provide this Data when requested, we may not be able to fulfill the contract we have entered into or are attempting to enter into with you (for example, if you do not provide suitable delivery instructions to provide you with goods or services). In this case, we may have to cancel the product or service you received through us, but we will notify you in due course.
3. HOW IS YOUR PERSONAL INFORMATION COLLECTED?
We use various methods to collect data from and about you, including through:
Direct interaction. You may provide us with your personal, contact, transaction, profile, financial, marketing and communication data by using our website, filling out forms, or contacting us by mail, phone, email, or otherwise. This includes personal data that you provide when you:
you purchase a product or service (including gift cards) through our Site;
You create an account on our Site;
You request a marketing newsletter;
Participate in a contest; or
leave us feedback.
Automated technology or interactions. When you interact with us, we may automatically collect usage and technical data about your equipment, activities, and browsing patterns. We collect this personal data through the use of cookies, server logs, and other similar technologies.
4. THIRD-PARTY DATA SOURCES/DATA EXCHANGES:
We also collect and exchange data with the following vendors:
Vendors: we share your personal data (name, address, gender, billing address, email address, phone, and cell phone number, and any personalization data you provided as part of your order) with the Vendor from whom you placed your order so that they can fulfill your order and manage it as part of the sales process that we provide in accordance with our Terms and Conditions for Customers. Any order placed will be treated as your order to transfer your personal data in this manner. The Vendor will act as an independent data controller on an independent basis and will process your personal data in accordance with its own policies and security measures. We are not responsible for protecting your information when it is under their control, but you may exercise against such Vendor all rights that you might otherwise have against us as set forth in this Privacy Policy.
When we share your personal information with a Seller, you should be aware of the following:
The Seller (name and contact information) will be listed on our website. You will be able to contact the Seller directly through our Site with any questions or concerns;
The Seller will process your personal information (including name, address, gender, billing address, email address and phone number, as well as any personalization data, if provided by you) for the purposes stated above, namely to manage your order;
In all other respects, Seller is responsible for processing your personal data in accordance with the Data Protection Laws, including in the same manner as we do, as outlined in Sections 9 and 10 below.
Essential Service Providers: sometimes, other companies provide us with data about you that we may need in our legitimate interest in doing business with you, and sometimes it is necessary to fulfill our contract with you. This is usually financial or transactional data. This happens when we connect to third-party payment service providers. They let us know that you have paid for their products, and, if appropriate and/or necessary, they provide us with your Contact and Transaction Data. We may also use third-party contractors to provide us with technical or delivery services related to your account.
Professional Advisors and Investors: We may also share your data with professional advisors, such as our lawyers and insurers, for risk and claims management and/or as part of our relationship and obligations to our investor organizations. This is in our legitimate interests.
Group: There is a possibility that we may sell our business to a third party, reorganize our business or become insolvent. In such a scenario, our customer database is one of the largest parts of our business, so we would need to share it with a third-party buyer and its advisors. This is done in the legitimate interest of selling our business. We may also expand our group of companies, in which case we may share your data within our group to improve our products and services, and because some of our internal support services may be shared across the group. This is done in our legitimate interests related to cost efficiency and the development of our business. When this happens, we place a link to all group companies and their locations in this Privacy Policy, and they will use your data in the ways outlined in this Policy.
Enforcement/Compliance: We will cooperate with all third parties to enforce their intellectual property or other rights. We will also cooperate with law enforcement authorities within or outside your country of residence. This may include disclosing your personal information to government or law enforcement agencies or individuals when we believe in good faith that disclosure is required by law or when we, in our sole discretion, believe that disclosure is necessary to protect our legal rights or the rights of third parties and/or to comply with a lawsuit, court order, fraud disclosure or lawsuit filed against us. In such cases, we may raise or waive any legal objection or right available to us. Such use of your Data is in our legitimate interests to protect the security of our business. We may also use your data and share it with the recipients listed in this Privacy Policy to comply with our legal obligations.
5. HOW DO WE USE YOUR PERSONAL DATA?
5.1 We use your personal data to provide our services, for example, to send service messages, process payments and/or fulfill orders.
5.2 We use your personal data to help us communicate effectively with you if you attempt to contact us through the Site.
5.3 If you have given permission on the Site, we may use your personal information to send you emails (or other communications such as mail, telephone, or SMS) with information about our products or third-party services that may be of interest to you, including information about special offers or promotions.
5.4 We may use personal information to recognize you when you visit or return to the Site, to track anonymous traffic and usage patterns, to prevent or detect fraud or abuse, or to help us improve the Site. We may use cookies to do this. For more information about how we use cookies, see above.
5.5 We retain personal information about closed accounts to comply with legal obligations, enforce our terms and conditions, prevent fraud, collect payment due, resolve disputes, troubleshoot problems, assist with investigations and other actions permitted by law.
5.5 We may access, delete, change, retain or otherwise use any personal information if we have reason to believe that it violates our terms and conditions, or that such steps are necessary to protect us or others, or that a criminal act has been committed, or if we are required to do so by law or appropriate authority.
We do not conduct automated decision-making. We may profile you, if you are a potential client for the purpose of targeting marketing to you, and when we do, it is in our legitimate interest to make sure that our marketing is relevant to its audience. For example, we may determine the appropriate audience for a promotion by what products on our Site you have previously reviewed or expressed interest in.
MARKETING
We may use your personal, contact, technical, user, and profile information to form opinions about what we think you might want or need, or be interested in. This is how we decide what products, services, and offers may be relevant to you. For these purposes, we only use data that you provide to us directly, as well as aggregated data provided to us by our analytics partners. We do not track which other sites you may visit after visiting our Site, although, like most sites, we may record a site that referred you to our Site (for example, a search engine or third party site that has a link to our Site).
We strive to give you choices about the use of some personal information, especially with respect to marketing and advertising.
Generally, we only send electronic marketing mailings – for example, by email – to people who have previously purchased similar products from us, and it is in our legitimate interests to do so. We always offer a way to opt-out of receiving such marketing mailings the first time you purchase our products and in every marketing message that follows. Sometimes we may send marketing mailings to increase sales, which is in our legitimate interest, in which case we will rely on you to let us know that you do not want to receive such mailings by opting out (see the “Unsubscribe” section below).
Where you have not previously bought from us but have registered your details with us (for example, by entering a competition or signing up for a newsletter), we will only send you marketing communications if you opted in to receiving marketing at the time and so given us your express consent (which you may withdraw at any time – see Opting Out below).
We may also share specific data with other advertising platforms to show you targeted ads, including social media, search engines, or streaming video platforms. We do this through:
Using cookies that record your visits to our website and we may also provide these platforms with your email address to create “audiences” of users matching a particular demographic/category to target our marketing. Please see the terms of use of social media, search engines, or video streaming platforms for more information about these services. It is in our legitimate interest to send you direct marketing mailings. For details on how you can change your marketing preferences, see the Unsubscribe section below. Our Cookie Policy also explains how you can change your cookie preferences.
OPT-OUT
You may ask us to stop sending you marketing messages at any time by logging into your account and changing your marketing preferences by following the unsubscribe links in any marketing message sent to you or by contacting us at any time.
If you opt-out of receiving marketing emails from us, we will no longer share your email address with other advertising platforms (see “Third Party List”). However, you may continue to see our ads through them due to their overall demographic targeting. Please see the terms and conditions of social media, search engines, or video streaming platforms for more information on opting ut of seeing these ads.
If you opt-out of receiving marketing messages, this does not apply to personal data provided to us as a result of product/service purchases or related correspondence, and we will continue to process such data in accordance with this Privacy Policy and only where permitted by law.
COOKIES
You can set your browser to refuse all or some browser cookies or to alert you when websites set or access cookies. If you disable or reject cookies, please note that some parts of this Site may become unavailable or may not function properly.
CHANGE OF PURPOSE.
We will only use your personal information for the purpose for which we collected it unless we reasonably believe that we need to use it for another reason and that reason is compatible with the original purpose.
If we need to use your personal data for an unrelated purpose, we will notify you and explain the legal basis that allows us to do so.
Please note that we may process your personal data without your knowledge or consent, in accordance with the above rules, if required or permitted by law.
THIRD PARTIES.
When you place an order on our Site, this information will also be received by the appropriate Seller on our marketplace so they can process and deliver your order. We may also pass on any information about your order or inquiry to the Seller if necessary.
We also use other third parties to process your personal information, and they change from time to time. Please check the Third Party Vendor List regularly to stay informed.
6. DISCLOSURE OF YOUR PERSONAL INFORMATION
We require all third parties to keep your personal data secure and to treat it in accordance with the law, and they may only use your data for the purposes set out in our agreement with them. We will always cooperate with them to protect your privacy.
7. DATA SECURITY
We have taken appropriate security measures to prevent accidental loss, use or unauthorized access, modification or disclosure of your personal data. In addition, we restrict access to your personal data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your personal information according to our instructions and are required to maintain confidentiality.
We have developed procedures to respond to any suspected personal data breach and will notify you and any applicable regulatory authority of the breach if we are required by law to do so.
You acknowledge that the Internet is not a completely secure means of communication, and accordingly, we cannot guarantee the security of any information you send us (or we send you) over the Internet. We will not be liable for any damages that you or others may suffer as a result of the loss of confidentiality of such information.
8. DATA RETENTION
HOW LONG WILL YOU USE MY PERSONAL INFORMATION?
We will only retain your personal data for as long as necessary to fulfill the purposes for which we collected it, including to satisfy any legal, accounting or reporting requirements.
To determine the appropriate retention period for your personal data, we consider the scope, nature and sensitivity of the personal data, the potential risk of harm from unauthorized use or disclosure of your personal data, the purposes for which we process your personal data and whether we can achieve those purposes by other means, and applicable legal requirements. For example, your order information will be retained for as long as we need to retain this Data to comply with our legal and regulatory requirements. Generally, this is 6 years, unless a longer period is required by law.
In some circumstances, you may ask us to delete your Data: see “Your Legal Rights” below for more information.
In some circumstances, we may anonymize your personal data (so that it is no longer associated with you) for research or statistical purposes, in which case we may use this information indefinitely without further notice to you.
9. YOUR LEGAL RIGHTS.
Under certain circumstances, you have rights under data protection laws with respect to your personal data.
You have the right to:
Request access to your personal data (commonly known as a “data subject access request”). This will allow you to obtain a copy of the personal Data we keep about you and to check whether we are processing it lawfully.
Request a correction of the personal Data we keep about you. This will allow you to correct any incomplete or inaccurate data about you, although we may need to verify the accuracy of new Data you provide to us.
Request deletion of your personal information. This allows you to ask us to delete or remove personal data if we have no compelling reason to continue processing it. For example, if you believe we no longer need them for the purposes for which we originally collected them as explained to you in this Privacy Policy, if you have withdrawn your consent to their use and we have relied on that consent under this Policy, if you believe we cannot demonstrate a “legitimate interest” in continuing to process them and we have relied on that legitimate interest to process them as explained to you in this Policy. You also have the right to ask us to remove or delete your personal information if you have successfully exercised your right to object to processing (see below), if we may have processed your information unlawfully, or if we are required to delete your personal information by local law. Please note, however, that we may not always be able to comply with your request to delete your Data for specific legal reasons, which will be communicated to you, if applicable, at the time of your request.
Object to processing your personal data if we rely on legitimate interests (or those of a third party) and there is something in your particular situation that causes you to object to processing on this basis because you believe it affects your fundamental rights and freedoms. You also have the right to object if we process your personal data for direct marketing purposes. In some cases, we can demonstrate that we have a compelling legitimate reason for processing your information that overrides your rights and freedoms.
Ask us to restrict the processing of your personal information. This allows you to ask us to suspend the processing of your personal information in the following cases: (a) if you want us to establish the accuracy of the Data; (b) if our use of the Data is illegal but you do not want us to erase it; (c) if you need us to keep the Data even if we no longer need it because you need it to establish, exercise or defend legal claims; or (d) you objected to our use of your data, but we need to check whether we have a valid legal basis for using it.
Request a transfer of your personal data to you or a third party. We will provide you or a third party of your choice with your personal data in a structured, generally accepted, machine-readable format. Please note that this right only applies to automated information that you originally gave us consent to use, or if we used that information to fulfill a contract with you.
Withdraw consent at any time if we rely on consent to process your personal information. However, this will not affect the legality of any processing done before you withdraw your consent.
If you wish to exercise any of these rights, please contact us by marking your request for DPL attention.
NO FEE IS USUALLY REQUIRED.
You will not have to pay a fee to access your personal information (or to exercise any of your other rights). However, we may charge a reasonable fee if your request is clearly unreasonable, repetitive or excessive. In addition, we may deny your request under such circumstances.
WHAT WE MAY NEED FROM YOU
We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to an unauthorized person. We may also contact you to ask for additional information in connection with your request to expedite our response.
Last Modified: 9th June 2021