PRIVACY POLICY

Effective Date: September 17, 2026

Last Update: September 17, 2026

PART A — GENERAL PRIVACY POLICY

This Part A sets out our global, default privacy standard, written to meet the requirements of the EU General Data Protection Regulation (Regulation (EU) 2016/679, the “GDPR”), and applies to every visitor and customer of the Service, wherever they're located in the world. If you're a resident of the United States, Canada or Australia, the additional terms in Part B, Part C or Part D apply on top of this Part A, and take precedence wherever they say something different.

For PART B — ADDITIONAL TERMS FOR RESIDENTS OF THE UNITED STATES OF AMERICA, click here.

Pour trouver la version française de PART A – GENERAL PRIVACY POLICY, cliquez ici.

Pour trouver la version française de PART C – ADDITIONAL TERMS FOR RESIDENTS OF CANADA, cliquez ici.

Die deutsche Fassung dieser Datenschutzerklärung finden Sie hier.

For PART D - ADDITIONAL TERMS FOR RESIDENTS OF AUSTRALIA, click here.

1. Introduction

This Privacy Policy (“Privacy Policy”) describes how Global Brother S.R.L., a company organized under the laws of Romania, together with any parent, subsidiary, and affiliate companies (collectively, “Global Brother,” “we,” “us,” or “our”), collects, receives, stores, uses, and discloses personal information that we collect about each visitor, user, or customer (each, a “user,” and specifically you, “you” or “your”) of our website at www.skillsofindependence.com, and of our other affiliated websites, subdomains, mobile versions, applications (including mobile applications), and online media under our operation and control, as well as all backup, mirror, replacement, or substitute websites or webpages we make available as part of the services we provide (collectively, the “Service”), the use of which is subject at all times to our Terms and Conditions.

We're committed to respecting the privacy and privacy rights of our users, and we recognize the need for appropriate protection and management of any information that may be used, either alone or in combination with other information, to identify an individual or household (“personal information”). You can choose whether to provide or disclose personal information to us in connection with your use of the Service. If you choose not to provide the personal information we request, you may still be able to visit and use parts of the Service, but you may be unable to access or use certain features, options or services — including placing an order. If you don't agree with any part of this Privacy Policy, please don't use the Service.

The Service may contain links to, or advertisements for, websites or mobile applications operated by third parties, including, without limitation, third-party social media platforms, and therefore not owned or controlled by Global Brother. Links to, and advertisements concerning, such third-party websites or applications are provided for your convenience only. We're not responsible for the content, performance, or privacy practices of these third-party websites or applications, or for your interactions with them, and you visit them at your own risk. Our inclusion of a link or advertisement doesn't imply any endorsement of the material, products, or services provided by that third party, or any association with its owners or operators.

2. Who We Are

The controller responsible for your personal information under this Privacy Policy is:

Global Brother S.R.L.

Registered office & postal address: 201 Barbu Vacarescu str., 21st floor, 2nd District, 020276 Bucharest, Romania

Trade Registry (ONRC) number: J2015008385400

Data protection contact e-mail: [email protected]

Please direct any request relating to the processing of your personal information to the e-mail address above, or to our postal address, marked to the attention of our Legal & Privacy team.

3. Changes to This Policy

We reserve the right, at any time and from time to time, to add to, delete, or modify any part of this Privacy Policy, for any reason and at our discretion. We display the effective date of this Privacy Policy at the top of this document, indicated as “Last Updated.” Unless otherwise indicated, changes to this Privacy Policy apply as soon as they're posted to the Service. If you continue to use the Service after a change becomes effective, that means you accept the revised Privacy Policy, to the extent permitted by applicable law — which is why we encourage you to review this page regularly, so you stay aware of your rights. Where a change is material and applicable law requires us to obtain your fresh consent or give you advance notice (for example, before we can rely on a new legal basis, or before a materially different use of your data begins), we'll do that before the change takes effect.

4. Personal Information We Collect

We may from time to time receive or collect the following categories of personal information about you, depending on how you interact with the Service.

4.1 Information You Provide to Us

If you place an order, leave a product review, contact customer support, or sign up to receive e-mail communications from us, you may provide us with, and we may collect, the following:

  • Identification data: first name, last name.
  • Contact data: e-mail address, telephone number, delivery and billing address.
  • Order data: products ordered, quantities, prices, order date, and order history.
  • Payment data: your chosen payment method. We don't store your full card details — these are processed exclusively by the payment providers described in Section 7 below.
  • Correspondence: messages you send us by e-mail, contact form, or customer support channels, including product reviews, survey responses, and comments or posts you share with us or publicly on our social media channels, which may include photos or videos.
  • Profile data: date of birth and social media handle.
  • Engagement data: your wish list, registry entries, and product ratings.
  • Inferences: preferences and interests we derive from your purchase or browsing history.

4.2 Information We Collect from Third Parties

We may also receive information about you, including personal information, from non-affiliated third parties — in particular, our payment processors.

When you purchase our products through the Service, our third-party payment processors — presently Adyen, ApplePay, GooglePay, Mollie, Airwallex and PayPal (each, a “Payment Processor”) — collect your transaction information, such as the payment method and associated account details and billing address used to complete your purchase, which may be shared with us via encrypted and tokenized methods only. We encourage you to review each Payment Processor's own privacy notice, available on their respective websites, to understand how they handle your information.

4.3 Information We Collect Automatically

When you access or use the Service, we automatically collect certain information through log files, cookies, and similar technologies such as web beacons and pixels, including mobile advertising identifiers and other online identifiers used to recognize your device. We use this information for systems administration, information security and abuse prevention, to understand usage trends, and to analyze and personalize the Service. Alone or combined with other information, this may constitute personal information. Section 6 below explains each of these technologies, and the specific cookies we use, in full.

5. How and Why We Use Your Personal Information

Under the GDPR, we can only use your personal information where we have a valid legal basis for doing so. In plain terms, those legal bases are:

Consent: in some cases you've told us it's okay to use your personal information for a specific purpose — for example, by opting in to marketing e-mails or accepting non-essential cookies.

Contract: we need certain personal information to perform our contract with you — for example, to process and deliver your order.

Legal obligation: sometimes the law requires us to collect or keep certain information — for example, invoicing and accounting records under Romanian tax law.

Legitimate interests: this is a technical term meaning we have a good and fair reason to use your personal information, in ways that don't override your rights and interests. For example, we (i) use identity, device, and location information to prevent abuse of the Service and to keep it secure, and (ii) analyze how users interact with the Service so we can understand what does and doesn't work well, what improvements are worth making, and how to keep the Service safe and enjoyable to use — which lets us improve the experience for all our users.

The table below sets out the specific purposes for which we process your personal information and the legal basis we rely on for each:  

Purpose Legal Basis (GDPR)
Performance of the sales contract (order processing, delivery, invoicing, after-sales service, returns) Contract — Art. 6(1)(b)
Compliance with legal obligations (accounting, tax, responding to authorities) Legal obligation — Art. 6(1)(c)
Operational communications about your order (confirmations, shipping updates, order-related SMS) Contract — Art. 6(1)(b)
Customer support (handling enquiries, complaints, support tickets) Contract — Art. 6(1)(b); Legitimate interest for enquiries from people who are not (yet) customers — Art. 6(1)(f)
Analytics and website improvement (traffic analysis, A/B testing, performance) Legitimate interest, subject to your right to object — Art. 6(1)(f); Consent for non-essential analytics cookies — Art. 6(1)(a)
Advertising and retargeting (e.g., Meta/Facebook Pixel, Microsoft Advertising) Consent — Art. 6(1)(a)
Marketing communications (newsletters, promotional offers) Consent — Art. 6(1)(a), or the “soft opt-in” for existing customers where permitted by local law

5.1 Whether You're Required to Provide Your Data

Providing identification, contact, delivery, and payment data is necessary to place and fulfil an order — without it, we can't process your purchase or deliver your products. Providing information for marketing purposes (for example, newsletter sign-up or accepting marketing cookies) is always optional, and declining has no effect on your ability to place an order.

6. Cookies and Other Tracking Technologies

When you access or use the Service, our servers automatically record certain information your browser sends, through log files. This may include your IP address, browser type, internet service provider, operating system, date/time stamp, referring and exit pages, and pages clicked. We use IP addresses to monitor the general regions from which visitors access the Service, and to help keep the Service secure. Where you're located in the EEA, UK, or another jurisdiction that treats an IP address as personal information, we handle it accordingly.

Like most websites, we use cookies and similar technologies to make the Service work, to remember your preferences, to understand how the Service is used, and, where you've agreed, to help us and our partners show you more relevant advertising. Cookies can be session-based, meaning they exist only for the duration of your visit and disappear once you close your browser, or persistent, meaning they remain on your device after you close your browser until they expire or you delete them. The table below sets out the specific categories of cookies we use, the providers behind them, and the legal basis for each: 

On your first visit, you'll see a cookie banner where you can accept or reject non-essential cookie categories (analytics, functionality, and marketing). You can change your preferences at any time through that banner or your browser settings. Turning off analytics, functionality, or marketing cookies never affects your ability to browse the Service or place an order — it may just mean the Service remembers less about your preferences from visit to visit. You can also block all cookies, including strictly necessary ones, through your browser settings — but if you do, some parts of the Service, including adding items to your cart or completing checkout, may not work properly.

We also use web beacons and pixels — clear electronic images embedded in our pages and e-mails, sometimes on their own and sometimes together with cookies. These help us understand your interactions with our e-mail communications and advertising campaigns; for example, we can tell when you open a marketing e-mail, or when you click a link in one that takes you to the Service.

More specifically: we use Microsoft Clarity to collect digital behavioral data, including heatmaps, session recordings, and usage metrics, using first- and third-party cookies and similar technologies. This helps us understand how visitors use the Service, improve site performance, and prevent fraud. You can opt out through Microsoft's Privacy Statement (privacy.microsoft.com/privacystatement).

We also use Hotjar, a web analytics service provided by Hotjar Ltd. (Malta), to better understand how visitors use the Service. Hotjar collects information about your browsing behavior, including which pages you visit, how long you spend on each page, where you click, and how you scroll, along with technical information such as your browser type, screen resolution, operating system, and general geographic location at the country level. Hotjar doesn't collect sensitive information you enter on the Service, such as payment card numbers — that data never reaches Hotjar's servers. Data collected through Hotjar is used solely to improve your experience on the Service and isn't shared with third parties. You can opt out of Hotjar data collection at any time via the Hotjar Compliance Opt-Out page (hotjar.com/legal/compliance/opt-out).

Other third parties whose technology we use to deliver advertising or measure its performance may also place their own cookies on your device and use web beacons to collect information about your browsing activity over time and across websites, in order to serve you advertising tailored to your interests. This relies on the same consent you give (or decline) through the cookie banner described above — if you haven't consented to Marketing/Targeting cookies, these third parties won't set tracking cookies through the Service. This information doesn't typically include your name or contact details, but may later be associated with personal information we hold about you.

7. How We Share Your Personal Information

7.1 Our Third-Party Service Providers

We share personal information with the categories of recipients below, who act as our processors or, in some cases, as independent controllers for their own purposes. We use commercially reasonable efforts to work only with providers who take appropriate measures to protect your personal information. Where a provider acts as an independent controller for its own purposes (as noted in the table below), that provider is responsible for its own compliance with applicable law and its own privacy policy.

Provider Role / Service Location
CheckoutChamp Order processing Puerto Rico, U.S.A.
Adyen Payment processing Netherlands (EU)
Mollie Payment processing Netherlands (EU)
GooglePay Payment processing California, U.S.A.
ApplePay Payment processing California, U.S.A.
PayPal Payment processing California, U.S.A.
Klarna Buy-now-pay-later (acts as independent controller for its own service) Sweden (EU)
Airwallex Payment processing San Francisco, U.S.A.
Active Campaign Order-related e-mail communications U.S.A.
Google Workspace Confirmation e-mails / receipts U.S.A.
Twilio Operational SMS (where used) U.S.A.
Zendesk Customer support ticketing U.S.A.
Shipping / order management provider Shipping and courier management companies Depends on your location

This list reflects our current service providers. If it changes in a way that affects how we handle your personal information, we'll update this Policy accordingly. The providers above only access your data to the extent necessary to perform their services, and they're contractually bound to protect it. We do not sell or rent your personal information to third parties.

7.2 Business Transfers

Global Brother may assign or transfer its rights and obligations under this Privacy Policy, and transfer any personal information it holds, to a third-party company or entity that acquires or is acquired by Global Brother, or is merged with or into Global Brother, as part of a merger, acquisition, sale, reorganization, or other change of control. Where required by applicable law, we'll notify you of any such transfer and of any choices you may have regarding your personal information.

7.3 Other Disclosures

We may also disclose personal information about you where required by applicable law, or where we believe in good faith that disclosure is reasonably necessary or helpful to:
- comply with legal process, such as a court order, subpoena, or regulatory request;
- enforce our Terms of Use, including investigating potential violations;
- detect, prevent, or otherwise address fraud, security, or technical issues; or
- protect the rights, property, or personal safety of Global Brother, other users of the Service, or the public.

We rely on a legal obligation (GDPR Art. 6(1)(c)) where disclosure is required by law, or on our legitimate interest in protecting our business, users, and the public (GDPR Art. 6(1)(f)) for the other disclosures described above.

8. International Data Transfers

As a Romanian company, Global Brother S.R.L. primarily stores and processes your personal information on servers located in Romania and elsewhere in the European Union.

Some of the providers listed in Section 7.1 are located outside the European Economic Area (EEA), including in the United States. If you're visiting the Service from the EEA, the UK, Switzerland, or another jurisdiction with data protection laws that differ from those where a given provider is located, please be aware that your personal information may be transferred to, stored, and processed in a country whose data protection framework may not offer the same level of protection as your home jurisdiction.

We take this seriously, and we don't transfer your personal information outside the EEA without one or more of the following safeguards in place:
- The EU-US Data Privacy Framework, for providers certified under it;
- Standard Contractual Clauses adopted by the European Commission; or
- Other safeguards recognized under the GDPR.

You can request a copy of the safeguards that apply to a specific transfer, or information about where they've been made available, by contacting us at the address in Section 2. Nothing in this section is intended to, or does, ask you to waive any right you have under the GDPR or other applicable data protection law; where mandatory protections of your home jurisdiction can't lawfully be displaced by contract, they continue to apply to you.

9. Data Retention

We keep your personal information only for as long as necessary to fulfil the purposes described in this Policy, including to satisfy any legal, accounting, or reporting requirements, to resolve disputes, and to enforce our agreements. In general, that means we hold your information while you have an account or an active relationship with us, and afterwards for as long as reasonably necessary for the purposes below or as required by law:

Data category Retention period
Order and invoice data Up to 10 years from invoice date (or shorter statutory period where local tax/accounting law sets one)
Marketing data (e.g., newsletter consent) Until you withdraw consent, with re-permission/deletion after a defined period of subscriber inactivity
Customer support correspondence 3 years from ticket closure as the general default (extend where local civil limitation period is longer, or where the correspondence documents an active warranty/claim)
Browsing / analytics cookie data Cookie lifespan capped at 13 months from placement; underlying analytics data retained max 25 months; consent (where required) refreshed every 6–13 months
Retargeting / marketing cookie data Cookie lifespan capped at 13 months from placement or until consent withdrawn, whichever comes first; consent refreshed every 6–13 months

Once a retention period expires, we delete or anonymize the relevant data.

10. Email Communications and Opt-Out

Unless you've asked us otherwise, or specifically opt out as described here, by using the Service you agree that we may use your information to contact you by e-mail with content relevant to your use of the Service, such as administrative notices, order updates, newsletters you've signed up for, and — where you've consented — marketing and promotional information about Global Brother or the Service.

You can stop receiving marketing e-mails at any time by following the unsubscribe instructions included in each communication, or by contacting us at the e-mail address in Section 16 below. If a third-party vendor sends a newsletter on our behalf, you can unsubscribe following the instructions provided by that vendor. Opting out of marketing communications doesn't affect transactional messages we need to send you about an order you've placed. If you're located in the United Kingdom or the EEA, we won't contact you by e-mail with marketing or promotional information unless you've given prior consent, or another legal basis applies (for example, the “soft opt-in” for existing customers, where permitted).

If you have trouble unsubscribing, please forward the relevant e-mail to us at the address in Section 16, with “Unsubscribe” in the subject line, or contact us directly, and we'll action your request within five (5) business days.

11. Data Security

The security of your personal information matters to us. We've implemented an information security program containing administrative, technical, organizational, and physical controls designed to reasonably safeguard your personal information from unlawful use, unauthorized access, or disclosure. We limit access to your personal information to those employees, contractors, and agents who have a genuine business need to know it.

Depending on the context, the safeguards we use include:
- Encrypted data transmission (SSL/TLS) between your device and our servers;
- Masking, which obscures your information so its structure stays the same but the content is no longer identifiable;
- De-identification and pseudonymization techniques, such as replacing identifiers with customer ID codes;
- Anonymization, which alters your data so it can no longer be used to identify you personally; and
- Access controls on our internal systems and security incident response procedures.

Payments are processed exclusively by PCI DSS-certified providers, and we don't store your full card number. That said, no method of transmission over the internet, and no method of electronic storage, is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we can't guarantee its absolute security.

12. Children's Privacy

The Service is not directed to, and is not intended for use by, anyone under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we've inadvertently collected a child's personal information without appropriate consent, we'll delete it without delay. If you believe we might be in possession of information from or about a child, please contact us at the address in Section 16.

13. Automated Decision-Making and Profiling

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you, within the meaning of GDPR Article 22.

We do use advertising retargeting tools (such as the Meta Pixel and Microsoft Advertising) that build audience profiles from your browsing behavior in order to show you more relevant ads on those platforms. This relies on your consent, given through the cookie banner, which you can withdraw at any time. For the collection and transmission of data through these tools, Meta and Microsoft may act as independent controllers (or jointly with us) for their own advertising purposes, and their own privacy policies apply to that processing.

14. Your Privacy Rights

If you're located in the EEA, the UK, or anywhere else where this Part A applies as your default privacy standard, you have the following rights over your personal information:

- Right of access — to obtain confirmation that we process your data, and a copy of it (GDPR Art. 15).
- Right to rectification — to correct inaccurate or incomplete data (GDPR Art. 16).
- Right to erasure (“right to be forgotten”) — to request deletion of your data in certain circumstances (GDPR Art. 17).
- Right to restriction of processing — to request that we limit processing in certain circumstances (GDPR Art. 18).
- Right to data portability — to receive your data in a structured, commonly used, machine-readable format (GDPR Art. 20).
- Right to object — to object to processing based on our legitimate interest, including profiling (GDPR Art. 21).
- Right to withdraw consent — at any time, without affecting the lawfulness of processing carried out before withdrawal (GDPR Art. 7(3)).
- Right to lodge a complaint — with your local data protection supervisory authority (GDPR Art. 77).

To exercise any of these rights, contact us using the details in Section 16. We'll respond within one month, extendable by a further two months for complex or multiple requests, and we'll let you know if we need more time and why.

14.1 Supervisory Authority


Our lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucharest, Romania, www.dataprotection.ro.


If you reside outside Romania, you may also lodge a complaint with the supervisory authority of your own country. You can find the contact details for your national supervisory authority via the European Data Protection Board's website, at https://www.edpb.europa.eu/about-edpb/our-members_en . If you're located outside the EU/EEA, UK, or Switzerland, you can generally raise concerns with your own country's data protection or privacy authority, where one exists, or contact us directly using the details in Section 16..

15. Do Not Track Signals

Some browsers can send a “Do Not Track” signal to the websites you visit. How browsers communicate this signal isn't yet uniform, and no common industry standard for interpreting it has been developed. For that reason, the Service doesn't currently respond to Do Not Track signals. If you're located in the EEA or UK, you can still control non-essential tracking through our cookie banner, as described in Section 6.

16. Contact Us

Questions or requests about this Privacy Policy or our handling of your personal information can be sent to: E-mail: [email protected]

Postal address: Global Brother S.R.L., 201 Barbu Vacarescu str., 21st floor, 2nd District, 020276 Bucharest, Romania

PART B - ADDITIONAL TERMS FOR RESIDENTS OF THE UNITED STATES OF AMERICA

This Part B supplements the General Privacy Policy in Part A above and applies specifically to residents of the United States. It only covers the points where U.S. law gives you rights or requires disclosures that go beyond Part A — everything in Part A (what we collect, why, who we share it with, security, and so on) still applies to you.

1. Scope of This Part

This Part B is provided to comply with the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the “CCPA”), and other U.S. state privacy laws that may apply depending on your state of residence, including — as applicable and as amended from time to time — the Colorado Privacy Act, the Connecticut Personal Data Privacy and Online Monitoring Act, the Virginia Consumer Data Protection Act, the Utah Consumer Privacy Act, the Texas Data Privacy and Security Act, the Oregon Consumer Privacy Act, the Montana Consumer Data Privacy Act, the Nevada Consumer Health Data Privacy Law, the Washington My Health My Data Act, the Delaware Data Protection Act, the Iowa Data Protection Act, the Nebraska Data Privacy Act, the New Hampshire Privacy Act, the New Jersey Data Privacy Act, the Tennessee Information Protection Act, the Minnesota Consumer Data Privacy Act, the Maryland Online Data Privacy Act, the Indiana Consumer Data Protection Act, the Kentucky Consumer Data Protection Act, and the Rhode Island Data Transparency and Privacy Protection Act (collectively, “US Data Privacy Laws”). Where this Part B conflicts with Part A, this Part B controls for U.S. residents. Terms like “personal information,” “sell,” “share,” and “business” have the meaning given to them under the applicable US Data Privacy Law.

For the purposes of this Part B, “personal information” has the same meaning as under the applicable US Data Privacy Law, and includes information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked, directly or indirectly, with you or your household.

2. Categories of Personal Information We Collect

In the preceding twelve (12) months, or since the launch of the Website on September 17, 2026 if that was less than 12 months ago, we have collected the following categories of personal information about California residents, as defined under the CCPA:

Category Examples Collected?
A. Identifiers Name, postal address, e-mail address, IP address, account name Yes
B. California Customer Records categories Name, address, telephone number, insurance policy number, education and employment history, bank account, credit or debit card number, or other financial information, medical information, or health insurance information Yes
C. Protected classifications
(Cal. or federal law)
Age (40 or older), race, color, ancestry, national origin, citizenship, religion, marital status, medical condition, physical or mental disability, sex (including gender, gender identity, pregnancy or childbirth), sexual orientation, veteran or military status, and genetic information No
D. Commercial information Products or services purchased or considered Yes
E. Biometric information Fingerprints, voiceprints, etc. No
F. Internet or network activity Browsing history, interactions with our Website Yes
G. Geolocation data IP-based location Yes
H. Sensory data Audio, visual, etc. No
I. Professional / employment information Job history No
J. Non-public education information Grades, transcripts, etc. No
K. Inferences Preferences inferred from purchase or browsing history Yes

We collect this information directly from you (for example, when you place an order or contact us) and indirectly through your use of the Website (for example, through cookies as described in Part A, Section 6). We haven't sold or shared any category of personal information listed above, and haven't disclosed any category for a business purpose other than to the service providers listed in Part A, Section 7.1, in the preceding twelve (12) months. Specifically, the categories we've disclosed for that business purpose are Identifiers (Category A), Commercial information (Category D), Internet or network activity (Category F), and Geolocation data (Category G).

This doesn't include publicly available information from government records, deidentified or aggregated information, or information covered by certain sector-specific laws — such as health information covered by HIPAA or California's Confidentiality of Medical Information Act, or information covered by the Fair Credit Reporting Act, the Gramm-Leach-Bliley Act, or the Driver's Privacy Protection Act.

3. How We Use and Disclose Personal Information

We use the categories of personal information above for the business and commercial purposes described in Part A, Section 5, including to fulfil orders, provide customer support, secure and improve the Website, and — where you've consented — send you marketing communications and personalized advertising.

We disclose personal information to service providers for a business purpose, using the categories of providers listed in Part A, Section 7.1. We enter into contracts with these providers that restrict them to using your information only to perform services for us, and that require them to keep it confidential.

We will not collect additional categories of personal information or use the personal information we've collected for materially different, unrelated, or incompatible purposes, without giving you notice.

4. Sale or Sharing of Personal Information; Targeted Advertising

We do not sell your personal information for money. Depending on your state of residence, the use of advertising technologies like the Meta Pixel and similar tools that share information with third-party advertising platforms may be considered a “sale” or “share” of personal information (for example, for cross-context behavioral or targeted advertising) under some US Data Privacy Laws, even though no money changes hands.

You can opt out of this at any time through our cookie preference banner, or by contacting us using the details in Section 11 below. We'll act on your request as soon as reasonably practicable, and in any event within fifteen (15) days of receipt. If you exercise this right, we'll stop sharing your personal information with third parties for cross-context behavioral or targeted advertising purposes going forward. If we ever begin selling personal information for money, or sharing sensitive personal information for these purposes, we'll update this Part B to reflect that and to explain your opt-out and, where required, opt-in rights.

5. Your U.S. State Privacy Rights

Depending on your state of residence, you may have some or all of the following rights:

5.1 Right to Know / Access

To request the categories and/or specific pieces of personal information we've collected about you, the sources, the purposes of collection, and the categories of third parties with whom it's been disclosed, sold, or shared. Requesting specific pieces of information is sometimes called a data portability right; where you make this kind of request, we'll provide the information in a format that's readily usable and lets you transmit it to another entity without hindrance. You can make an access or portability request up to twice in any 12-month period, and we'll deliver our response to your account if you have one with us, or otherwise by mail or electronically, at your choice.

5.2 Right to Delete

To request deletion of personal information we've collected from you, subject to exceptions — for example, to complete a transaction, detect security incidents, debug products to fix errors, comply with the California Electronic Communications Privacy Act or another legal obligation, exercise free speech, conduct public or peer-reviewed research you've consented to, make internal uses reasonably aligned with your expectations, or make other internal, lawful uses compatible with the context in which you provided the information.

5.3 Right to Correct

To request correction of inaccurate personal information we maintain about you. Upon receipt of a verifiable request, we'll use commercially reasonable efforts to correct it.

5.4 Right to Opt Out of Sale/Sharing and Targeted Advertising

Described in Section 4 above.

 

5.5 Right to Limit Use of Sensitive Personal Information

We don't use sensitive personal information for purposes beyond what's necessary to provide the Service. Where required by law, we'll honor requests to further limit such use.

5.6 Right to Non-Discrimination

We won't deny you goods or services, charge you different prices, or provide a different level of service because you exercised any of these rights, or suggest that you might receive any of the above, unless permitted by US Data Privacy Laws. However, we may offer legally permitted financial incentives that reasonably relate to the value of your personal information; participation always requires your prior opt-in consent, which you can revoke at any time.

5.7 Right to Opt Out of Profiling

This right applies to automated processing used to make decisions with a legal or similarly significant effect on you — for example, decisions about credit or access to essential goods or services. Global Brother does not engage in profiling of this kind.

6. Authorized Agents

You may designate an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written authorization, and we may still require you to verify your own identity directly with us. Alternatively, an agent with power of attorney may submit a request on your behalf.

7. How to Submit a Request; Verification and Response Timing

You may submit a request to know, delete, or correct your personal information, or to opt out of sale/sharing, by e-mailing [email protected] or writing to us at the address in Section 11 below. We'll acknowledge your request within ten (10) days and respond within forty-five (45) days, extendable once by another forty-five (45) days for complex requests. We may need to verify your identity before completing your request; any information you provide for verification will be used only for that purpose. Making a request doesn't require you to create an account with us, but requests made through a password-protected account will generally be considered sufficiently verified for information tied to that account. We don't charge a fee to process a request unless it's excessive, repetitive, or manifestly unfounded, and we'll explain our reasoning and give you a cost estimate before proceeding if that's the case.

8. Appeals

If we deny your request, you may appeal by contacting us at the e-mail above within forty-five (45) days of our decision. If you're a resident of Colorado, Connecticut, Delaware, Iowa, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon, Tennessee, Texas, or Virginia, we'll respond to your appeal within sixty (60) days of receipt, or within forty-five (45) days if you're a resident of Colorado, Minnesota, New Jersey, or Oregon. If your appeal is denied, you may be able to contact your state Attorney General. For more information check here: https://www.naag.org/our-work/center-for-consumer-protection/consumer-file-a-complaint/ .

9. California “Shine the Light”

California residents may request, once a year, information about the categories of personal information we've disclosed to third parties for their own direct marketing purposes in the preceding calendar year, and the names of those third parties. As described in this Policy, we don't disclose your personal information to third parties for their own direct marketing without your consent, and we give you a cost-free way to opt out at any time by contacting us — so we're not otherwise required to maintain the third-party list.

10. Children's Privacy (U.S.)

Consistent with the Children's Online Privacy Protection Act (COPPA), the Service is not directed to children under 13, and we don't knowingly collect personal information from children under 13 without verifiable parental consent. More broadly, and consistent with Part A, the Service isn't intended for use by anyone under 18. If you believe we've collected information from a child, please contact us at the e-mail in Section 11 below. You can also visit www.OnGuardOnline.gov for tips from the Federal Trade Commission on protecting children's privacy online.

11. Contact for U.S. Residents

E-mail: [email protected]

Mail: Global Brother S.R.L., 2515 Waukegan Rd PMB 45933, Bannockburn, IL 60015

PART C - ADDITIONAL TERMS FOR RESIDENTS OF CANADA

La version française de ce document se trouve ci-dessous.

This Part C supplements the General Privacy Policy in Part A above and applies to residents of Canada. It only covers the points where Canadian law gives you rights or requires disclosures that go beyond Part A — everything in Part A still applies to you.

1. Scope of This Part

This Part C reflects the requirements of the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Quebec residents, the Act respecting the protection of personal information in the private sector, as amended by Quebec's Law 25. Where this Part C conflicts with Part A, this Part C controls for Canadian residents.

2. Consent

Canadian privacy law is built around consent. By using the Service and providing us with your personal information, you consent to our collecting, using, storing, and disclosing it as described in this Privacy Policy, except where the law requires your express consent — for example, for certain marketing communications. The form of consent we seek — express or implied — will generally depend on the sensitivity of the information involved and your reasonable expectations. You may withdraw your consent at any time, subject to legal or contractual restrictions and reasonable notice, though withdrawing consent may limit our ability to provide certain services to you.

3. How We Collect and Use Personal Information

We collect and use your personal information as described in Part A, Sections 4–5 above, including information you provide directly (for example, when you shop with us or sign up for communications) and information collected automatically through cookies and similar technologies (Part A, Section 6). We may also use your online activity, purchase history, and demographic insights to personalize your experience and deliver relevant marketing, subject to your consent where required. Consistent with PIPEDA's accountability principle, we only collect the personal information reasonably necessary for the purposes described in this Policy.

Depending on how you interact with us, we may also collect your date of birth and social media handle; mobile advertising identifiers and other online identifiers used to recognize your device; your wish list, registry entries, and product ratings; and content you share with us or publicly, including product reviews, survey responses, and comments or posts on our social media channels, which may include photos or videos. We may also draw inferences from this information, such as preferences based on your purchase or browsing history.

We may also use your personal information to communicate with you about contests, sweepstakes, and promotions; to respond to your customer service inquiries; and, with your consent where required, to post your comments or public statements on our platforms or on public posts on our social media channels. Where permitted, we may combine your purchase history with aggregated demographic information — for example, based on postal code — to better understand preferences and deliver tailored marketing and interest-based advertising. “Aggregated information” here means personal information that's been combined and summarized so it represents groups rather than individuals.

4. How We Share Personal Information

In addition to the recipients listed in Part A, Section 7.1, we may share your personal information:

- Within Global Brother S.R.L. and our affiliated companies, to manage operations and fulfil orders;
- With service providers who help us operate the Service (payment processing, fraud prevention, hosting, analytics, and marketing);
- For legal or safety reasons, where required by law or to protect our rights, customers, or partners;
- With your explicit permission;
- With third-party partners, including social media platforms, to show you personalized offers and advertising, with your consent where required by law; we may also share anonymized or aggregated data — which cannot be linked back to you personally — with trusted third parties for research and marketing purposes;
- If you post content on the Service or on our social media channels, that content may be publicly visible to others; and
- In connection with a sale, merger, or transfer of all or part of our business.

5. Cross-Border Storage and Processing

Global Brother S.R.L. is a Romanian company. Your personal information is stored and processed on servers located in Romania and in other places in the EU and may be transferred to other countries as described in Part A, Section 8. Where your information is transferred outside Canada, it may become subject to the laws — including lawful access by government authorities — of the country where it's held. We take contractual and technical steps to require a comparable level of protection for your personal information wherever it's processed.

6. Your Rights Under Canadian Law

Subject to certain exceptions, you have the right to:
- Access the personal information we hold about you, including how it has been used and to whom it has been disclosed; and
- Request correction of inaccurate or incomplete personal information.

To exercise these rights, contact our Privacy Officer using the details in Section 9 below. We'll respond within a reasonable time and, where we can't grant a request, we'll explain why.

7. Managing Your Preferences

You can manage your privacy preferences by:
- Visiting our cookie/privacy preferences page to opt out of non-essential cookies;
- Adjusting your device's notification settings;
- Unsubscribing from marketing e-mails using the link in any e-mail; or
- Contacting us directly using the details in Section 9 below.

Even if you opt out of marketing, we'll still send you transactional messages related to your orders.

8. Notice to Quebec Residents

We do not intend for our websites or online services to be used by anyone under the age of fourteen (14). If you are under the age of fourteen (14), please do not use the Service. If you are over the age of fourteen (14) but under the age of majority in the province in which you reside, you may only use the Service with the involvement and permission of a parent or legal guardian. If you are a parent or guardian and believe we may have collected personal information about a child, please contact us via the channels set out in Section 9 below.

9. Our Privacy Officer

For the purposes of Quebec's Law 25, Global Brother S.R.L. has appointed a Privacy Officer responsible for overseeing our compliance with this Policy in Canada. You can reach our Privacy Officer at:

 E-mail: [email protected]

 Mail: Global Brother S.R.L., 201 Barbu Vacarescu str., 21st floor, 2nd District, 020276 Bucharest, Romania

10. Our Privacy Compliance Framework

In addition to appointing a Privacy Officer, we maintain a framework for protecting the personal information we collect, consistent with PIPEDA's accountability principle. This framework includes policies and procedures covering employee codes of conduct, breach reporting obligations, data retention and destruction practices, staff training, and procedures for addressing complaints and providing individuals with access to their personal information, all in line with this Policy.

PARTIE C - CONDITIONS SUPPLÉMENTAIRES POUR LES RÉSIDENTS DU CANADA

La présente Partie C complète la Politique de confidentialité générale prévue à la Partie A ci-dessus et s’applique aux résidents du Canada. Elle ne couvre que les points pour lesquels le droit canadien vous accorde des droits ou impose des obligations d’information allant au-delà de la Partie A — tout ce qui figure dans la Partie A continue de s’appliquer à vous.

1. Champ d’application de la présente Partie

La présente Partie C reflète les exigences de la Loi fédérale sur la protection des renseignements personnels et les documents électroniques (LPRPDE) et, pour les résidents du Québec, de la Loi sur la protection des renseignements personnels dans le secteur privé, telle que modifiée par la Loi 25 du Québec. En cas de conflit entre la présente Partie C et la Partie A, la présente Partie C prévaut pour les résidents canadiens.

2. Consentement

Le droit canadien de la protection de la vie privée repose sur le consentement. En utilisant le Service et en nous fournissant vos renseignements personnels, vous consentez à ce que nous les collections, les utilisions, les conservions et les divulguions comme décrit dans la présente Politique de confidentialité, sauf lorsque la loi exige votre consentement exprès — par exemple, pour certaines communications marketing. La forme de consentement que nous recherchons — exprès ou implicite — dépendra généralement de la sensibilité des informations en cause et de vos attentes raisonnables. Vous pouvez retirer votre consentement à tout moment, sous réserve de restrictions légales ou contractuelles et d’un préavis raisonnable, bien que le retrait de votre consentement puisse limiter notre capacité à vous fournir certains services.

3. Comment nous collectons et utilisons les renseignements personnels

Nous collectons et utilisons vos renseignements personnels comme décrit à la Partie A, Sections 4 à 5 ci-dessus, y compris les informations que vous nous fournissez directement (par exemple, lorsque vous effectuez des achats chez nous ou vous inscrivez à nos communications) et les informations collectées automatiquement par le biais de cookies et de technologies similaires (Partie A, Section 6). Nous pouvons également utiliser votre activité en ligne, votre historique d’achats et des informations démographiques pour personnaliser votre expérience et vous proposer un marketing pertinent, sous réserve de votre consentement lorsque celui-ci est requis. Conformément au principe de responsabilisation de la LPRPDE, nous ne collectons que les renseignements personnels raisonnablement nécessaires aux finalités décrites dans la présente Politique.

Selon la manière dont vous interagissez avec nous, nous pouvons également collecter votre date de naissance et votre identifiant de réseau social ; les identifiants publicitaires mobiles et autres identifiants en ligne utilisés pour reconnaître votre appareil ; votre liste de souhaits, vos listes de cadeaux et vos évaluations de produits ; ainsi que le contenu que vous partagez avec nous ou publiquement, y compris les avis sur les produits, les réponses aux enquêtes, et les commentaires ou publications sur nos réseaux sociaux, qui peuvent inclure des photos ou des vidéos. Nous pouvons également tirer des déductions de ces informations, telles que des préférences fondées sur votre historique d’achats ou de navigation.

Nous pouvons également utiliser vos renseignements personnels pour communiquer avec vous à propos de concours, de tirages au sort et de promotions ; pour répondre à vos demandes de service client ; et, avec votre consentement lorsque celui-ci est requis, pour publier vos commentaires ou déclarations publiques sur nos plateformes ou sur des publications publiques sur nos réseaux sociaux. Lorsque cela est permis, nous pouvons combiner votre historique d’achats avec des informations démographiques agrégées — par exemple, fondées sur le code postal — afin de mieux comprendre les préférences et de proposer un marketing et une publicité ciblée personnalisés. Les « informations agrégées » désignent ici des renseignements personnels qui ont été combinés et résumés de sorte qu’ils représentent des groupes plutôt que des individus.

4. Comment nous partageons les renseignements personnels

Outre les destinataires énumérés à la Partie A, Section 7.1, nous pouvons partager vos renseignements personnels :

- Au sein de Global Brother S.R.L. et de ses sociétés affiliées, afin de gérer les opérations et d’exécuter les commandes ;
- Avec des prestataires de services qui nous aident à exploiter le Service (traitement des paiements, prévention de la fraude, hébergement, analyse et marketing) ;
- Pour des raisons juridiques ou de sécurité, lorsque la loi l’exige ou pour protéger nos droits, nos clients ou nos partenaires ;
- Avec votre autorisation explicite ;
- Avec des partenaires tiers, y compris des plateformes de médias sociaux, afin de vous présenter des offres et des publicités personnalisées, avec votre consentement lorsque la loi l’exige ; nous pouvons également partager des données anonymisées ou agrégées — qui ne peuvent pas vous être associées personnellement — avec des tiers de confiance à des fins de recherche et de marketing ;
- Si vous publiez du contenu sur le Service ou sur nos réseaux sociaux, ce contenu peut être publiquement visible par d’autres ; et
- Dans le cadre d’une vente, d’une fusion ou d’un transfert de tout ou partie de notre entreprise.

5. Stockage et traitement transfrontaliers

Global Brother S.R.L. est une société roumaine. Vos renseignements personnels sont stockés et traités sur des serveurs situés en Roumanie et dans d’autres pays de l’UE, et peuvent être transférés vers d’autres pays comme décrit à la Partie A, Section 8. Lorsque vos informations sont transférées hors du Canada, elles peuvent être soumises aux lois — y compris à l’accès licite par les autorités gouvernementales — du pays où elles sont conservées. Nous prenons des mesures contractuelles et techniques afin d’exiger un niveau de protection comparable pour vos renseignements personnels, où qu’ils soient traités.

6. Vos droits en vertu du droit canadien

Sous réserve de certaines exceptions, vous avez le droit :
- D’accéder aux renseignements personnels que nous détenons à votre sujet, y compris la manière dont ils ont été utilisés et les personnes à qui ils ont été divulgués ; et
- De demander la correction de renseignements personnels inexacts ou incomplets.

Pour exercer ces droits, contactez notre Responsable de la protection de la vie privée en utilisant les coordonnées indiquées à la Section 9 ci-dessous. Nous répondrons dans un délai raisonnable et, lorsque nous ne pourrons pas donner suite à une demande, nous vous en expliquerons les raisons.

7. Gestion de vos préférences

Vous pouvez gérer vos préférences en matière de confidentialité en :
- Visitant notre page de préférences en matière de cookies/confidentialité pour refuser les cookies non essentiels ;
- Ajustant les paramètres de notification de votre appareil ;
- Vous désinscrivant des e-mails marketing à l’aide du lien figurant dans tout e-mail ; ou
- Nous contactant directement en utilisant les coordonnées indiquées à la Section 9 ci-dessous.

Même si vous vous désinscrivez du marketing, nous continuerons à vous envoyer des messages transactionnels relatifs à vos commandes.

8. Avis aux résidents du Québec

Nous n’avons pas l’intention que nos sites Internet ou services en ligne soient utilisés par toute personne âgée de moins de quatorze (14) ans. Si vous avez moins de quatorze (14) ans, veuillez ne pas utiliser le Service. Si vous avez plus de quatorze (14) ans mais que vous n’avez pas atteint l’âge de la majorité dans la province où vous résidez, vous ne pouvez utiliser le Service qu’avec l’implication et l’autorisation d’un parent ou d’un tuteur légal. Si vous êtes un parent ou un tuteur et que vous pensez que nous avons pu collecter des renseignements personnels concernant un enfant, veuillez nous contacter par les moyens indiqués à la Section 9 ci-dessous.

9. Notre Responsable de la protection de la vie privée

Aux fins de la Loi 25 du Québec, Global Brother S.R.L. a désigné un Responsable de la protection de la vie privée chargé de superviser notre conformité à la présente Politique au Canada. Vous pouvez joindre notre Responsable de la protection de la vie privée à:

 E-mail: [email protected]

Courrier : Global Brother S.R.L., 201 Barbu Vacarescu str., 21e étage, 2e arrondissement, 020276 Bucarest, Roumanie

10. Notre cadre de conformité en matière de protection de la vie privée

En plus de désigner un Responsable de la protection de la vie privée, nous maintenons un cadre de protection des renseignements personnels que nous collectons, conforme au principe de responsabilisation de la LPRPDE. Ce cadre comprend des politiques et des procédures couvrant les codes de conduite des employés, les obligations de signalement des atteintes, les pratiques de conservation et de destruction des données, la formation du personnel, ainsi que les procédures de traitement des réclamations et d’accès des personnes à leurs renseignements personnels, conformément à la présente Politique.

PART D — ADDITIONAL TERMS FOR RESIDENTS OF AUSTRALIA

This Part D reflects the requirements of the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”) set out in Schedule 1 to that Act, to the extent they apply to Global Brother’s handling of personal information about Australian residents. Where this Part D conflicts with Part A, this Part D controls for Australian residents.

1. Overseas Disclosure of Your Personal Information

Before we disclose your personal information to a recipient outside Australia — including the service providers listed in Part A, Section 7.1, most of whom are located in the EU, UK, or United States — Australian Privacy Principle 8 requires us to take reasonable steps to ensure that recipient doesn't breach the APPs in relation to your information, unless an exception applies (for example, where you've consented after being told the recipient may not be bound by APP-equivalent protections, or the recipient is already subject to a law that has the effect of protecting your information in a way that's substantially similar to the APPs).

We rely on contractual protections with our service providers, in addition to the safeguards described in Part A, Section 8 (International Data Transfers), to meet this requirement. Generally, we remain accountable for how these overseas recipients handle your personal information, in much the same way as if we handled it ourselves.

2. Direct Marketing

Australian Privacy Principle 7 gives you one right about direct marketing that goes beyond the opt-out already described in Part A, Section 10: you can ask us to tell you the source from which we collected your personal information for direct marketing purposes, unless it's impracticable or unreasonable for us to do so.

You can make this request using the contact details in Section 7 below, and we won't charge you a fee to do so.

3. Access and Correction

Australian Privacy Principles 12 and 13 give you the right to request access to the personal information we hold about you, and to request that we correct it if it's inaccurate, out of date, incomplete, irrelevant, or misleading. We'll respond to your request within a reasonable period — namely, within 30 days — and, where we refuse a request, we'll explain why and let you know how to complain about our refusal (see Section 5 below).

We won't charge you a fee to request a correction, and we won't normally charge more than our reasonable costs of retrieving and providing the information for an access request.

4. Data Breach Notification

If we experience a data breach involving your personal information that's likely to result in serious harm to you, we'll notify both you and the Office of the Australian Information Commissioner (OAIC), as required under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.

5. Your Right to Complain

If you think we've mishandled your personal information, please contact us first using the details in Section 7 below, so we can try to resolve your concern directly. If you're not satisfied with our response, or you haven't heard back from us within a reasonable time (namely, in 30 days), you can lodge a complaint with the OAIC:

Office of the Australian Information Commissioner

GPO Box 5288, Sydney NSW 2001, Australia

Phone: 1300 363 992 (within Australia)

Website: www.oaic.gov.au

6. Anonymity and Pseudonymity

Where it's lawful and practicable, you have the option of not identifying yourself, or of using a pseudonym, when dealing with us. In practice this is limited for an online shop — for example, we need your real name and delivery address to fulfil an order — but it applies to browsing the Service and to general enquiries that don't require us to complete a transaction with you.

7. Contact for Australian Residents

E-mail: [email protected]

Mail: Global Brother S.R.L., 201 Barbu Vacarescu str., 21st floor, 2nd District, 020276 Bucharest, Romania

POLITIQUE DE CONFIDENTIALITÉ

Date d'entrée en vigueur : 17 septembre 2026

Dernière mise à jour : 17 septembre 2026

PARTIE A — POLITIQUE DE CONFIDENTIALITÉ GÉNÉRALE

Cette Partie A énonce notre norme de confidentialité globale et par défaut, rédigée pour répondre aux exigences du Règlement général sur la protection des données de l’UE (Règlement (UE) 2016/679, le « RGPD »), et s’applique à tout visiteur et client du Service, où qu’il se trouve dans le monde. Si vous résidez aux États-Unis, au Canada ou en Australie, les conditions supplémentaires prévues à la Partie B, la Partie C ou la Partie D s’appliquent en complément de la présente Partie A, et prévalent partout où elles disposent différemment.

1. Introduction

La présente Politique de confidentialité (« Politique de confidentialité ») décrit la manière dont Global Brother S.R.L., société constituée conformément au droit roumain, ainsi que toute société mère, filiale et société affiliée (collectivement, « Global Brother », « nous », « notre » ou « nos »), collecte, reçoit, conserve, utilise et divulgue les informations personnelles que nous recueillons au sujet de chaque visiteur, utilisateur ou client (chacun, un « utilisateur », et plus particulièrement vous, « vous » ou « votre ») de notre site Internet à l’adresse https://www.lostskillsofindependence.com/ , ainsi que de nos autres sites Internet affiliés, sous-domaines, versions mobiles, applications (y compris les applications mobiles) et médias en ligne sous notre exploitation et notre contrôle, ainsi que de tous les sites Internet ou pages Internet de sauvegarde, de secours, de remplacement ou de substitution que nous mettons à disposition dans le cadre des services que nous fournissons (collectivement, le « Service »), dont l’utilisation est à tout moment soumise à nos Conditions générales.

Nous nous engageons à respecter la vie privée et les droits à la protection de la vie privée de nos utilisateurs, et nous reconnaissons la nécessité d’assurer une protection et une gestion appropriées de toute information pouvant être utilisée, seule ou en combinaison avec d’autres informations, pour identifier une personne physique ou un foyer (« informations personnelles »). Vous pouvez choisir de nous fournir ou de nous divulguer des informations personnelles dans le cadre de votre utilisation du Service. Si vous choisissez de ne pas fournir les informations personnelles que nous demandons, vous pourrez néanmoins visiter et utiliser certaines parties du Service, mais vous risquez de ne pas pouvoir accéder à certaines fonctionnalités, options ou services — y compris la possibilité de passer une commande. Si vous n’acceptez pas une partie quelconque de la présente Politique de confidentialité, veuillez ne pas utiliser le Service.

Le Service peut contenir des liens vers, ou des publicités pour, des sites Internet ou des applications mobiles exploités par des tiers, y compris, sans limitation, des plateformes de médias sociaux tierces, qui ne sont donc ni détenus ni contrôlés par Global Brother. Les liens vers ces sites Internet ou applications tiers, ainsi que les publicités les concernant, sont fournis uniquement pour votre commodité. Nous ne sommes pas responsables du contenu, des performances ou des pratiques de confidentialité de ces sites Internet ou applications tiers, ni de vos interactions avec eux, et vous les visitez à vos propres risques. Le fait que nous incluions un lien ou une publicité n’implique aucune approbation du contenu, des produits ou des services fournis par ce tiers, ni aucune association avec ses propriétaires ou exploitants.

2. Qui sommes-nous

Le responsable du traitement de vos informations personnelles au titre de la présente Politique de confidentialité est :

Global Brother S.R.L.

Siège social et adresse postale : 201 Barbu Vacarescu str., 21e étage, 2e arrondissement, 020276 Bucarest, Roumanie

Numéro au Registre du commerce (ONRC) : J2015008385400

Adresse e-mail de contact pour la protection des données: [email protected]

Veuillez adresser toute demande relative au traitement de vos informations personnelles à l’adresse e-mail ci-dessus, ou à notre adresse postale, à l’attention de notre équipe Juridique & Protection des données.

3. Modifications de la présente Politique

Nous nous réservons le droit, à tout moment et de temps à autre, d’ajouter, de supprimer ou de modifier toute partie de la présente Politique de confidentialité, pour quelque raison que ce soit et à notre discrétion. Nous affichons la date d’entrée en vigueur de la présente Politique de confidentialité en haut du présent document, sous la mention « Dernière mise à jour ». Sauf indication contraire, les modifications apportées à la présente Politique de confidentialité s’appliquent dès leur publication sur le Service. Si vous continuez à utiliser le Service après l’entrée en vigueur d’une modification, cela signifie que vous acceptez la Politique de confidentialité révisée, dans la mesure permise par le droit applicable — c’est pourquoi nous vous encourageons à consulter régulièrement cette page, afin de rester informé de vos droits. Lorsqu’une modification est substantielle et que le droit applicable nous impose d’obtenir votre nouveau consentement ou de vous donner un préavis (par exemple, avant de pouvoir nous fonder sur une nouvelle base légale, ou avant qu’un usage sensiblement différent de vos données ne débute), nous le ferons avant que la modification ne prenne effet.

4. Informations personnelles que nous collectons

Nous pouvons, de temps à autre, recevoir ou collecter les catégories d’informations personnelles suivantes à votre sujet, selon la manière dont vous interagissez avec le Service.

4.1 Informations que vous nous fournissez

Si vous passez une commande, laissez un avis sur un produit, contactez le service client, ou vous inscrivez pour recevoir nos communications par e-mail, vous pouvez nous fournir, et nous pouvons collecter, les éléments suivants :
- Données d’identification : nom, prénom.
- Données de contact : adresse e-mail, numéro de téléphone, adresse de livraison et de facturation.
- Données de commande : produits commandés, quantités, prix, date de commande et historique des commandes.
- Données de paiement : votre mode de paiement choisi. Nous ne conservons pas l’intégralité des données de votre carte — celles-ci sont traitées exclusivement par les prestataires de paiement décrits à la Section 7 ci-dessous.
- Correspondance : messages que vous nous envoyez par e-mail, formulaire de contact ou canaux du service client, y compris les avis sur les produits, les réponses aux enquêtes, ainsi que les commentaires ou publications que vous partagez avec nous ou publiquement sur nos réseaux sociaux, qui peuvent inclure des photos ou des vidéos.
- Données de profil : date de naissance et identifiant de réseau social.
- Données d’engagement : votre liste de souhaits, vos listes de cadeaux et vos évaluations de produits.
- Déductions : préférences et centres d’intérêt que nous déduisons de votre historique d’achats ou de navigation.

4.2 Informations que nous collectons auprès de tiers

Nous pouvons également recevoir des informations à votre sujet, y compris des informations personnelles, auprès de tiers non affiliés — en particulier nos prestataires de paiement.

Lorsque vous achetez nos produits via le Service, nos prestataires de paiement tiers — actuellement Adyen, ApplePay, GooglePay, Mollie, Airwallex et PayPal (chacun, un « Prestataire de paiement ») — collectent vos informations de transaction, telles que le mode de paiement et les coordonnées de compte et l’adresse de facturation associées utilisées pour finaliser votre achat, lesquelles peuvent nous être communiquées uniquement par des méthodes chiffrées et tokenisées. Nous vous encourageons à consulter la politique de confidentialité propre à chaque Prestataire de paiement, disponible sur son site Internet respectif, pour comprendre comment il traite vos informations.

4.3 Informations que nous collectons automatiquement

Lorsque vous accédez au Service ou l’utilisez, nous collectons automatiquement certaines informations par le biais de fichiers journaux, de cookies et de technologies similaires telles que les balises Internet et les pixels, y compris les identifiants publicitaires mobiles et autres identifiants en ligne utilisés pour reconnaître votre appareil. Nous utilisons ces informations pour l’administration des systèmes, la sécurité de l’information et la prévention des abus, pour comprendre les tendances d’utilisation, ainsi que pour analyser et personnaliser le Service. Seules ou combinées à d’autres informations, celles-ci peuvent constituer des informations personnelles. La Section 6 ci-dessous décrit en détail chacune de ces technologies, ainsi que les cookies spécifiques que nous utilisons.

5. Comment et pourquoi nous utilisons vos informations personnelles

En vertu du RGPD, nous ne pouvons utiliser vos informations personnelles que si nous disposons d’une base légale valide pour ce faire. En termes simples, ces bases légales sont les suivantes :

Consentement : dans certains cas, vous nous avez indiqué qu’il était acceptable d’utiliser vos informations personnelles à des fins spécifiques — par exemple, en optant pour la réception d’e-mails marketing ou en acceptant des cookies non essentiels.

Contrat : nous avons besoin de certaines informations personnelles pour exécuter notre contrat avec vous — par exemple, pour traiter et livrer votre commande.

Obligation légale: la loi nous impose parfois de collecter ou de conserver certaines informations — par exemple, les registres de facturation et de comptabilité en vertu du droit fiscal roumain.

Intérêts légitimes : il s’agit d’un terme technique signifiant que nous avons une raison valable et équitable d’utiliser vos informations personnelles, d’une manière qui ne porte pas atteinte à vos droits et intérêts. Par exemple, nous (i) utilisons les informations d’identité, d’appareil et de localisation pour prévenir les abus du Service et le maintenir sécurisé, et (ii) analysons la manière dont les utilisateurs interagissent avec le Service afin de comprendre ce qui fonctionne bien ou non, quelles améliorations valent la peine d’être apportées, et comment maintenir le Service sûr et agréable à utiliser — ce qui nous permet d’améliorer l’expérience de l’ensemble de nos utilisateurs.

Le tableau ci-dessous présente les finalités spécifiques pour lesquelles nous traitons vos informations personnelles, ainsi que la base légale sur laquelle nous nous appuyons pour chacune d’entre elles :  

Finalité Base légale (RGPD)
Exécution du contrat de vente (traitement des commandes, livraison, facturation, service après-vente, retours) Contrat — Art. 6(1)(b)
Respect des obligations légales (comptabilité, fiscalité, réponse aux autorités) Obligation légale — Art. 6(1)(c)
Communications opérationnelles relatives à votre commande (confirmations, mises à jour d’expédition, SMS liés à la commande) Contrat — Art. 6(1)(b)
Service client (traitement des demandes, réclamations, tickets d’assistance) Contrat — Art. 6(1)(b) ; intérêt légitime pour les demandes émanant de personnes qui ne sont pas (encore) clientes — Art. 6(1)(f)
Analyse et amélioration du site Internet (analyse du trafic, tests A/B, performance) Intérêt légitime, sous réserve de votre droit d’opposition — Art. 6(1)(f) ; Consentement pour les cookies d’analyse non essentiels — Art. 6(1)(a)
Publicité et reciblage (par ex., Meta/Facebook Pixel, Microsoft Advertising) Consentement — Art. 6(1)(a)
Communications marketing (newsletters, offres promotionnelles) Consentement — Art. 6(1)(a), ou l’« opt-in souple » pour les clients existants lorsque le droit local le permet

5.1 Caractère obligatoire ou non de la fourniture de vos données

La fourniture des données d’identification, de contact, de livraison et de paiement est nécessaire pour passer et exécuter une commande — sans elles, nous ne pouvons pas traiter votre achat ni livrer vos produits. La fourniture d’informations à des fins de marketing (par exemple, l’inscription à la newsletter ou l’acceptation des cookies marketing) est toujours facultative, et le fait de refuser n’a aucune incidence sur votre capacité à passer une commande.

6. Cookies et autres technologies de suivi

Lorsque vous accédez au Service ou l’utilisez, nos serveurs enregistrent automatiquement certaines informations envoyées par votre navigateur, par le biais de fichiers journaux. Cela peut inclure votre adresse IP, le type de navigateur, le fournisseur d’accès à Internet, le système d’exploitation, l’horodatage, les pages de référence et de sortie, ainsi que les pages consultées. Nous utilisons les adresses IP pour surveiller les régions générales à partir desquelles les visiteurs accèdent au Service, et pour contribuer à la sécurité du Service. Lorsque vous vous trouvez dans l’EEE, au Royaume-Uni, ou dans une autre juridiction qui traite une adresse IP comme une information personnelle, nous la traitons en conséquence.

Comme la plupart des sites Internet, nous utilisons des cookies et des technologies similaires pour faire fonctionner le Service, mémoriser vos préférences, comprendre comment le Service est utilisé et, lorsque vous y avez consenti, nous aider, ainsi que nos partenaires, à vous présenter des publicités plus pertinentes. Les cookies peuvent être de session, c’est-à-dire qu’ils n’existent que pendant la durée de votre visite et disparaissent une fois que vous fermez votre navigateur, ou persistants, c’est-à-dire qu’ils restent sur votre appareil après la fermeture de votre navigateur jusqu’à leur expiration ou jusqu’à ce que vous les supprimiez. Le tableau ci-dessous présente les catégories spécifiques de cookies que nous utilisons, les fournisseurs qui les proposent, et la base légale applicable à chacun d’entre eux :  

Lors de votre première visite, un bandeau relatif aux cookies vous permettra d’accepter ou de refuser les catégories de cookies non essentiels (analyse, fonctionnalité et marketing). Vous pouvez modifier vos préférences à tout moment via ce bandeau ou les paramètres de votre navigateur. La désactivation des cookies d’analyse, de fonctionnalité ou de marketing n’affecte jamais votre capacité à naviguer sur le Service ou à passer une commande — cela signifie simplement que le Service mémorisera moins d’informations sur vos préférences d’une visite à l’autre. Vous pouvez également bloquer tous les cookies, y compris les cookies strictement nécessaires, via les paramètres de votre navigateur — mais si vous le faites, certaines parties du Service, y compris l’ajout d’articles à votre panier ou la finalisation du paiement, pourraient ne pas fonctionner correctement.

Nous utilisons également des balises Internet et des pixels — des images électroniques invisibles intégrées dans nos pages et nos e-mails, parfois seules et parfois associées à des cookies. Celles-ci nous aident à comprendre vos interactions avec nos communications par e-mail et nos campagnes publicitaires ; par exemple, nous pouvons savoir quand vous ouvrez un e-mail marketing, ou quand vous cliquez sur un lien qui vous redirige vers le Service.

Plus précisément : nous utilisons Microsoft Clarity pour collecter des données comportementales numériques, y compris des cartes thermiques, des enregistrements de session et des mesures d’utilisation, à l’aide de cookies internes et tiers et de technologies similaires. Cela nous aide à comprendre comment les visiteurs utilisent le Service, à améliorer les performances du site et à prévenir la fraude. Vous pouvez vous désinscrire via la Déclaration de confidentialité de Microsoft (privacy.microsoft.com/privacystatement).

Nous utilisons également Hotjar, un service d’analyse Internet fourni par Hotjar Ltd. (Malte), pour mieux comprendre comment les visiteurs utilisent le Service. Hotjar collecte des informations sur votre comportement de navigation, y compris les pages que vous visitez, le temps que vous passez sur chaque page, les endroits où vous cliquez et la manière dont vous faites défiler les pages, ainsi que des informations techniques telles que le type de votre navigateur, la résolution de votre écran, votre système d’exploitation et votre localisation géographique générale au niveau du pays. Hotjar ne collecte pas les informations sensibles que vous saisissez sur le Service, telles que les numéros de carte de paiement — ces données n’atteignent jamais les serveurs de Hotjar. Les données collectées par Hotjar sont utilisées uniquement pour améliorer votre expérience sur le Service et ne sont pas partagées avec des tiers. Vous pouvez vous désinscrire de la collecte de données Hotjar à tout moment via la page de désinscription de conformité de Hotjar (hotjar.com/legal/compliance/opt-out).

D’autres tiers dont nous utilisons la technologie pour diffuser de la publicité ou en mesurer la performance peuvent également placer leurs propres cookies sur votre appareil et utiliser des balises Internet pour collecter des informations sur votre activité de navigation au fil du temps et sur différents sites Internet, afin de vous proposer des publicités adaptées à vos centres d’intérêt. Cela repose sur le même consentement que vous accordez (ou refusez) via le bandeau relatif aux cookies décrit ci-dessus — si vous n’avez pas consenti aux cookies Marketing/Ciblage, ces tiers ne placeront pas de cookies de suivi via le Service. Ces informations n’incluent généralement pas votre nom ou vos coordonnées, mais peuvent ultérieurement être associées à des informations personnelles que nous détenons à votre sujet.

7. Comment nous partageons vos informations personnelles

7.1 Nos prestataires de services tiers

Nous partageons des informations personnelles avec les catégories de destinataires ci-dessous, qui agissent en qualité de sous-traitants ou, dans certains cas, de responsables du traitement indépendants pour leurs propres finalités. Nous déployons des efforts raisonnables sur le plan commercial pour ne travailler qu’avec des prestataires qui prennent des mesures appropriées pour protéger vos informations personnelles. Lorsqu’un prestataire agit en qualité de responsable du traitement indépendant pour ses propres finalités (comme indiqué dans le tableau ci-dessous), ce prestataire est responsable de sa propre conformité au droit applicable et de sa propre politique de confidentialité.

Prestataire Rôle / Service Localisation
CheckoutChamp Traitement des commandes Porto Rico, États-Unis
Adyen Traitement des paiements Pays-Bas (UE)
Mollie Traitement des paiements Pays-Bas (UE)
GooglePay Traitement des paiements Californie, États-Unis
ApplePay Traitement des paiements Californie, États-Unis
PayPal Traitement des paiements Californie, États-Unis
Klarna Paiement différé (« achetez maintenant, payez plus tard ») (agit en qualité de responsable du traitement indépendant pour son propre service) Suède (UE)
Airwallex Traitement des paiements San Francisco, États-Unis
Active Campaign Communications par e-mail liées aux commandes États-Unis
Google Workspace E-mails de confirmation / reçus États-Unis
Twilio SMS opérationnels (le cas échéant) États-Unis
Zendesk Gestion des tickets du service client États-Unis
Prestataire de gestion des expéditions / commandes Sociétés de transport et de gestion des expéditions Selon votre localisation

Cette liste reflète nos prestataires de services actuels. Si elle évolue d’une manière qui affecte la façon dont nous traitons vos informations personnelles, nous mettrons à jour la présente Politique en conséquence. Les prestataires ci-dessus n’accèdent à vos données que dans la mesure nécessaire à l’exécution de leurs services, et sont contractuellement tenus de les protéger. Nous ne vendons ni ne louons vos informations personnelles à des tiers.

7.2 Transferts d’entreprise

Global Brother peut céder ou transférer ses droits et obligations au titre de la présente Politique de confidentialité, et transférer toute information personnelle qu’elle détient, à une société ou entité tierce qui acquiert Global Brother ou est acquise par elle, ou qui fusionne avec Global Brother, dans le cadre d’une fusion, d’une acquisition, d’une vente, d’une réorganisation ou d’un autre changement de contrôle. Lorsque le droit applicable l’exige, nous vous informerons de tout transfert de ce type et des choix dont vous pourriez disposer concernant vos informations personnelles.

7.3 Autres divulgations

Nous pouvons également divulguer des informations personnelles vous concernant lorsque le droit applicable l’exige, ou lorsque nous estimons de bonne foi que la divulgation est raisonnablement nécessaire ou utile pour :
- nous conformer à une procédure judiciaire, telle qu’une ordonnance judiciaire, une citation à comparaître ou une demande réglementaire ;
- faire respecter nos Conditions d’utilisation, y compris en enquêtant sur des violations potentielles ;
- détecter, prévenir ou remédier à toute fraude, tout problème de sécurité ou toute difficulté technique ; ou
- protéger les droits, les biens ou la sécurité personnelle de Global Brother, des autres utilisateurs du Service, ou du public.

Nous nous fondons sur une obligation légale (Art. 6(1)(c) du RGPD) lorsque la divulgation est requise par la loi, ou sur notre intérêt légitime à protéger notre entreprise, nos utilisateurs et le public (Art. 6(1)(f) du RGPD) pour les autres divulgations décrites ci-dessus.

8. Transferts internationaux de données

En tant que société roumaine, Global Brother S.R.L. stocke et traite principalement vos informations personnelles sur des serveurs situés en Roumanie et ailleurs dans l’Union européenne.

Certains des prestataires mentionnés à la Section 7.1 sont situés hors de l’Espace économique européen (EEE), notamment aux États-Unis. Si vous visitez le Service depuis l’EEE, le Royaume-Uni, la Suisse, ou une autre juridiction dont les lois relatives à la protection des données diffèrent de celles applicables à l’endroit où se trouve un prestataire donné, veuillez noter que vos informations personnelles peuvent être transférées vers, stockées et traitées dans un pays dont le cadre de protection des données peut ne pas offrir le même niveau de protection que votre pays d’origine.

Nous prenons cela très au sérieux, et nous ne transférons pas vos informations personnelles hors de l’EEE sans qu’une ou plusieurs des garanties suivantes ne soient en place :
- Le Cadre de protection des données UE-États-Unis, pour les prestataires certifiés à ce titre ;
- Les clauses contractuelles types adoptées par la Commission européenne ; ou
- D’autres garanties reconnues par le RGPD.

Vous pouvez demander une copie des garanties applicables à un transfert spécifique, ou des informations sur l’endroit où elles ont été mises à disposition, en nous contactant à l’adresse indiquée à la Section 2. Rien dans la présente section n’a pour objet ou pour effet de vous demander de renoncer à un droit dont vous disposez au titre du RGPD ou d’un autre droit applicable en matière de protection des données ; lorsque les protections impératives de votre pays d’origine ne peuvent être légalement écartées par contrat, elles continuent de s’appliquer à vous.

9. Conservation des données

Nous conservons vos informations personnelles uniquement pendant la durée nécessaire pour remplir les finalités décrites dans la présente Politique, y compris pour satisfaire à toute exigence légale, comptable ou de déclaration, pour résoudre des litiges et pour faire respecter nos accords. En général, cela signifie que nous conservons vos informations pendant la durée de votre compte ou de votre relation active avec nous, puis pendant la durée raisonnablement nécessaire aux fins indiquées ci-dessous, ou selon ce que la loi exige :

Data category Retention period
Données de commande et de facturation Jusqu’à 10 ans à compter de la date de la facture (ou une période statutaire plus courte lorsque le droit fiscal/comptable local en prévoit une)
Données marketing (par ex., consentement à la newsletter) Jusqu’au retrait de votre consentement, avec renouvellement du consentement/suppression après une période définie d’inactivité de l’abonné
Correspondance avec le service client 3 ans à compter de la clôture du ticket, à titre de règle générale par défaut (prolongée lorsque le délai de prescription civile local est plus long, ou lorsque la correspondance documente une garantie/réclamation active)
Données de cookies de navigation / d’analyse Durée de vie des cookies limitée à 13 mois à compter de leur dépôt ; données d’analyse sous-jacentes conservées pendant 25 mois maximum ; consentement (lorsque requis) renouvelé tous les 6 à 13 mois
Données de cookies de reciblage / marketing Durée de vie des cookies limitée à 13 mois à compter de leur dépôt ou jusqu’au retrait du consentement, selon la première échéance ; consentement renouvelé tous les 6 à 13 mois

Une fois qu’une période de conservation expire, nous supprimons ou anonymisons les données concernées.

10. Communications par e-mail et désinscription

Sauf si vous nous avez demandé le contraire, ou si vous vous désinscrivez spécifiquement comme décrit ici, en utilisant le Service, vous acceptez que nous puissions utiliser vos informations pour vous contacter par e-mail avec un contenu pertinent au regard de votre utilisation du Service, tel que des avis administratifs, des mises à jour de commande, des newsletters auxquelles vous vous êtes inscrit et, lorsque vous y avez consenti, des informations marketing et promotionnelles concernant Global Brother ou le Service.

Vous pouvez cesser de recevoir des e-mails marketing à tout moment en suivant les instructions de désinscription figurant dans chaque communication, ou en nous contactant à l’adresse e-mail indiquée à la Section 16 ci-dessous. Si un prestataire tiers envoie une newsletter en notre nom, vous pouvez vous désinscrire en suivant les instructions fournies par ce prestataire. Le fait de vous désinscrire des communications marketing n’affecte pas les messages transactionnels que nous devons vous envoyer au sujet d’une commande que vous avez passée. Si vous êtes situé au Royaume-Uni ou dans l’EEE, nous ne vous contacterons pas par e-mail avec des informations marketing ou promotionnelles sans votre consentement préalable, sauf si une autre base légale s’applique (par exemple, l’« opt-in souple » pour les clients existants, lorsque cela est autorisé).

Si vous éprouvez des difficultés à vous désinscrire, veuillez transférer l’e-mail concerné à l’adresse indiquée à la Section 16, avec la mention « Désinscription » dans l’objet, ou nous contacter directement, et nous traiterons votre demande dans un délai de cinq (5) jours ouvrés.

11. Sécurité des données

La sécurité de vos informations personnelles nous tient à cœur. Nous avons mis en place un programme de sécurité de l’information comprenant des mesures administratives, techniques, organisationnelles et physiques conçues pour protéger raisonnablement vos informations personnelles contre toute utilisation illicite, tout accès non autorisé ou toute divulgation. Nous limitons l’accès à vos informations personnelles aux employés, sous-traitants et mandataires qui ont un besoin professionnel réel d’en connaître.

Selon le contexte, les garanties que nous utilisons incluent :
- La transmission chiffrée des données (SSL/TLS) entre votre appareil et nos serveurs ;
- Le masquage, qui dissimule vos informations de sorte que leur structure reste identique mais que leur contenu ne soit plus identifiable ;
- Des techniques de dé-identification et de pseudonymisation, telles que le remplacement des identifiants par des codes d’identification client ;
- L’anonymisation, qui modifie vos données de sorte qu’elles ne puissent plus être utilisées pour vous identifier personnellement ; et
- Des contrôles d’accès sur nos systèmes internes et des procédures de réponse aux incidents de sécurité.

Les paiements sont traités exclusivement par des prestataires certifiés PCI DSS, et nous ne conservons pas l’intégralité de votre numéro de carte. Cela dit, aucune méthode de transmission par Internet, et aucune méthode de stockage électronique, n’est sécurisée à 100 %. Bien que nous nous efforcions d’utiliser des moyens commercialement acceptables pour protéger vos informations personnelles, nous ne pouvons pas garantir leur sécurité absolue.

12. Confidentialité des mineurs

Le Service n’est ni destiné ni conçu pour être utilisé par toute personne âgée de moins de 18 ans. Nous ne collectons pas sciemment d’informations personnelles auprès d’enfants de moins de 18 ans. Si nous apprenons que nous avons collecté par inadvertance les informations personnelles d’un enfant sans le consentement approprié, nous les supprimerons sans délai. Si vous pensez que nous pourrions être en possession d’informations provenant d’un enfant ou le concernant, veuillez nous contacter à l’adresse indiquée à la Section 16.

13. Prise de décision automatisée et profilage

Nous ne prenons pas de décisions fondées uniquement sur un traitement automatisé, y compris le profilage, produisant des effets juridiques vous concernant ou vous affectant de manière similaire et significative, au sens de l’article 22 du RGPD.

Nous utilisons des outils de reciblage publicitaire (tels que le Meta Pixel et Microsoft Advertising) qui établissent des profils d’audience à partir de votre comportement de navigation afin de vous présenter des publicités plus pertinentes sur ces plateformes. Cela repose sur votre consentement, donné via le bandeau relatif aux cookies, que vous pouvez retirer à tout moment. Pour la collecte et la transmission de données au moyen de ces outils, Meta et Microsoft peuvent agir en qualité de responsables du traitement indépendants (ou conjointement avec nous) pour leurs propres finalités publicitaires, et leurs propres politiques de confidentialité s’appliquent à ce traitement.

14. Vos droits en matière de protection des données

Si vous êtes situé dans l’EEE, au Royaume-Uni, ou dans tout autre lieu où la présente Partie A s’applique en tant que norme de confidentialité par défaut, vous disposez des droits suivants sur vos informations personnelles :

- Droit d’accès — obtenir la confirmation que nous traitons vos données, et une copie de celles-ci (Art. 15 du RGPD).
- Droit de rectification — corriger des données inexactes ou incomplètes (Art. 16 du RGPD).
- Droit à l’effacement (« droit à l’oubli ») — demander la suppression de vos données dans certaines circonstances (Art. 17 du RGPD).
- Droit à la limitation du traitement — demander que nous limitions le traitement dans certaines circonstances (Art. 18 du RGPD).
- Droit à la portabilité des données — recevoir vos données dans un format structuré, couramment utilisé et lisible par machine (Art. 20 du RGPD).
- Droit d’opposition — vous opposer à un traitement fondé sur notre intérêt légitime, y compris le profilage (Art. 21 du RGPD).
- Droit de retirer votre consentement — à tout moment, sans porter atteinte à la licéité du traitement effectué avant ce retrait (Art. 7(3) du RGPD).
- Droit d’introduire une réclamation — auprès de votre autorité de contrôle locale en matière de protection des données (Art. 77 du RGPD).

Pour exercer l’un quelconque de ces droits, contactez-nous en utilisant les coordonnées indiquées à la Section 16. Nous vous répondrons dans un délai d’un mois, prolongeable de deux mois supplémentaires pour les demandes complexes ou multiples, et nous vous informerons si nous avons besoin de davantage de temps, et pourquoi.

14.1 Autorité de contrôle

Notre autorité de contrôle chef de file est l’Autorité nationale roumaine de surveillance du traitement des données à caractère personnel (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Secteur 1, 010336 Bucarest, Roumanie, www.dataprotection.ro.


Si vous résidez hors de Roumanie, vous pouvez également introduire une réclamation auprès de l’autorité de contrôle de votre propre pays. Vous pouvez trouver les coordonnées de votre autorité de contrôle nationale sur le site Internet du Comité européen de la protection des données, à l’adresse https://www.edpb.europa.eu/about-edpb/our-members_en. Si vous êtes situé hors de l’UE/EEE, du Royaume-Uni ou de la Suisse, vous pouvez généralement soulever vos préoccupations auprès de l’autorité de protection des données ou de la vie privée de votre propre pays, lorsqu’il en existe une, ou nous contacter directement en utilisant les coordonnées indiquées à la Section 16.

15. Signaux « Ne pas suivre »

Certains navigateurs peuvent envoyer un signal « Ne pas suivre » (Do Not Track) aux sites Internet que vous visitez. La manière dont les navigateurs communiquent ce signal n’est pas encore uniforme, et aucune norme sectorielle commune n’a été développée pour son interprétation. Pour cette raison, le Service ne répond pas actuellement aux signaux « Ne pas suivre ». Si vous êtes situé dans l’EEE ou au Royaume-Uni, vous pouvez néanmoins contrôler le suivi non essentiel via notre bandeau relatif aux cookies, comme décrit à la Section 6.

16. Nous contacter


Les questions ou demandes relatives à la présente Politique de confidentialité ou à notre traitement de vos informations personnelles peuvent être adressées à :

E-mail: [email protected]

Adresse postale : Global Brother S.R.L., 201 Barbu Vacarescu str., 21e étage, 2e arrondissement, 020276 Bucarest, Roumanie

DATENSCHUTZERKLÄRUNG

Inkrafttreten: 17. September 2026

Letzte Aktualisierung: 17. September 2026

TEIL A — ALLGEMEINE DATENSCHUTZERKLÄRUNG

Dieser Teil A legt unseren weltweiten Standard-Datenschutzstandard fest, der so gestaltet ist, dass er den Anforderungen der EU-Datenschutz-Grundverordnung (Verordnung (EU) 2016/679, die „DSGVO”) entspricht, und gilt für alle Besucher und Kunden des Dienstes, unabhängig davon, wo sie sich weltweit befinden. Wenn Sie in den Vereinigten Staaten, Kanada oder Australien ansässig sind, gelten zusätzlich die Bestimmungen in Teil B, Teil C oder Teil D zusätzlich zu diesem Teil A und haben Vorrang, soweit sie etwas Abweichendes bestimmen.

1. Einleitung

Diese Datenschutzerklärung (die „Datenschutzerklärung”) beschreibt, wie Global Brother S.R.L., eine nach rumänischem Recht gegründete Gesellschaft, zusammen mit etwaigen Mutter-, Tochter- und verbundenen Unternehmen (zusammen „Global Brother”, „wir”, „uns” oder „unser”), personenbezogene Daten erhebt, empfängt, speichert, nutzt und offenlegt, die wir über jeden Besucher, Nutzer oder Kunden (jeweils ein „Nutzer”, und insbesondere Sie, „Sie” oder „Ihr”) unserer Website unter https://www.lostskillsofindependence.com/ sowie unserer sonstigen verbundenen Websites, Subdomains, mobilen Versionen, Anwendungen (einschließlich mobiler Anwendungen) und Online-Medien, die von uns betrieben und kontrolliert werden, sowie sämtlicher Sicherungs-, Spiegel-, Ersatz- oder Alternativ-Websites oder -Webseiten, die wir im Rahmen der von uns erbrachten Dienstleistungen bereitstellen (zusammen der „Dienst”), erheben, wobei die Nutzung des Dienstes jederzeit unseren Allgemeinen Geschäftsbedingungen unterliegt.

Wir verpflichten uns, die Privatsphäre und die Datenschutzrechte unserer Nutzer zu respektieren, und wir erkennen die Notwendigkeit eines angemessenen Schutzes und einer angemessenen Verwaltung aller Informationen an, die allein oder in Kombination mit anderen Informationen zur Identifizierung einer natürlichen Person oder eines Haushalts verwendet werden können („personenbezogene Daten”). Sie können frei entscheiden, ob Sie uns im Zusammenhang mit Ihrer Nutzung des Dienstes personenbezogene Daten zur Verfügung stellen oder offenlegen. Wenn Sie sich entscheiden, die von uns angeforderten personenbezogenen Daten nicht bereitzustellen, können Sie den Dienst möglicherweise weiterhin besuchen und teilweise nutzen, jedoch möglicherweise nicht auf bestimmte Funktionen, Optionen oder Dienstleistungen zugreifen oder diese nutzen — einschließlich der Aufgabe einer Bestellung. Wenn Sie mit einem Teil dieser Datenschutzerklärung nicht einverstanden sind, nutzen Sie den Dienst bitte nicht.

Der Dienst kann Links zu oder Werbung für Websites oder mobile Anwendungen enthalten, die von Dritten betrieben werden, einschließlich, aber nicht beschränkt auf soziale Medienplattformen Dritter, und die daher nicht im Eigentum oder unter der Kontrolle von Global Brother stehen. Links zu und Werbung für solche Websites oder Anwendungen Dritter werden ausschließlich zu Ihrer Bequemlichkeit bereitgestellt. Wir sind nicht verantwortlich für den Inhalt, die Leistung oder die Datenschutzpraktiken dieser Websites oder Anwendungen Dritter oder für Ihre Interaktionen mit ihnen, und Sie besuchen sie auf eigenes Risiko. Die Aufnahme eines Links oder einer Werbung bedeutet keine Billigung des Materials, der Produkte oder Dienstleistungen des jeweiligen Dritten oder eine Verbindung zu dessen Eigentümern oder Betreibern.

2. Wer wir sind

Der für Ihre personenbezogenen Daten im Sinne dieser Datenschutzerklärung Verantwortliche ist:

Global Brother S.R.L.

Sitz und Postanschrift: 201 Barbu Vacarescu str., 21. Stock, 2. Bezirk, 020276 Bukarest, Rumänien

Handelsregisternummer (ONRC): J2015008385400

E-Mail-Adresse für Datenschutzanfragen: [email protected]

Bitte richten Sie Anfragen zur Verarbeitung Ihrer personenbezogenen Daten an die oben genannte E-Mail-Adresse oder an unsere Postanschrift, zur Aufmerksamkeit unseres Teams für Recht & Datenschutz.

3. Änderungen dieser Erklärung

Wir behalten uns das Recht vor, jederzeit und von Zeit zu Zeit Teile dieser Datenschutzerklärung zu ergänzen, zu löschen oder zu ändern, aus beliebigem Grund und nach unserem Ermessen. Wir geben das Datum des Inkrafttretens dieser Datenschutzerklärung oben in diesem Dokument an, gekennzeichnet als „Zuletzt aktualisiert”. Sofern nicht anders angegeben, gelten Änderungen dieser Datenschutzerklärung ab dem Zeitpunkt ihrer Veröffentlichung im Dienst. Wenn Sie den Dienst nach Inkrafttreten einer Änderung weiterhin nutzen, bedeutet dies, dass Sie die überarbeitete Datenschutzerklärung akzeptieren, soweit dies nach geltendem Recht zulässig ist — daher empfehlen wir Ihnen, diese Seite regelmäßig zu überprüfen, um über Ihre Rechte informiert zu bleiben. Wenn eine Änderung wesentlich ist und geltendes Recht von uns verlangt, Ihre erneute Einwilligung einzuholen oder Sie vorab zu informieren (zum Beispiel, bevor wir uns auf eine neue Rechtsgrundlage stützen können, oder bevor eine wesentlich andere Nutzung Ihrer Daten beginnt), werden wir dies tun, bevor die Änderung wirksam wird.

4. Personenbezogene Daten, die wir erheben

Wir können von Zeit zu Zeit die folgenden Kategorien personenbezogener Daten über Sie erhalten oder erheben, abhängig davon, wie Sie mit dem Dienst interagieren.

4.1 Informationen, die Sie uns zur Verfügung stellen

Wenn Sie eine Bestellung aufgeben, eine Produktbewertung abgeben, den Kundendienst kontaktieren oder sich für den Erhalt von E-Mail-Mitteilungen von uns anmelden, können Sie uns Folgendes zur Verfügung stellen, und wir können Folgendes erheben:

- Identifikationsdaten: Vorname, Nachname.
- Kontaktdaten: E-Mail-Adresse, Telefonnummer, Liefer- und Rechnungsadresse.
- Bestelldaten: bestellte Produkte, Mengen, Preise, Bestelldatum und Bestellhistorie.
- Zahlungsdaten: Ihre gewählte Zahlungsmethode. Wir speichern Ihre vollständigen Kartendaten nicht — diese werden ausschließlich von den in Abschnitt 7 unten beschriebenen Zahlungsdienstleistern verarbeitet.
- Korrespondenz: Nachrichten, die Sie uns per E-Mail, Kontaktformular oder Kundendienstkanäle senden, einschließlich Produktbewertungen, Umfrageantworten sowie Kommentare oder Beiträge, die Sie mit uns oder öffentlich in unseren sozialen Medien teilen, die Fotos oder Videos enthalten können.
- Profildaten: Geburtsdatum und Social-Media-Kennung.
- Interaktionsdaten: Ihre Wunschliste, Registrierungseinträge und Produktbewertungen.
- Ableitungen: Präferenzen und Interessen, die wir aus Ihrer Kauf- oder Browsing-Historie ableiten.

4.2 Informationen, die wir von Dritten erhalten

Wir können auch Informationen über Sie, einschließlich personenbezogener Daten, von nicht verbundenen Dritten erhalten — insbesondere von unseren Zahlungsdienstleistern.

Wenn Sie unsere Produkte über den Dienst kaufen, erheben unsere externen Zahlungsdienstleister — derzeit Adyen, ApplePay, GooglePay, Mollie, Airwallex und PayPal (jeweils ein „Zahlungsdienstleister”) — Ihre Transaktionsdaten, wie die Zahlungsmethode und die zugehörigen Kontodaten sowie die zum Abschluss Ihres Kaufs verwendete Rechnungsadresse, die uns ausschließlich über verschlüsselte und tokenisierte Verfahren mitgeteilt werden können. Wir empfehlen Ihnen, die eigene Datenschutzerklärung jedes Zahlungsdienstleisters, die auf dessen jeweiliger Website verfügbar ist, zu lesen, um zu verstehen, wie dieser mit Ihren Informationen umgeht.

4.3 Informationen, die wir automatisch erheben

Wenn Sie auf den Dienst zugreifen oder ihn nutzen, erheben wir automatisch bestimmte Informationen über Protokolldateien, Cookies und ähnliche Technologien wie Web-Beacons und Pixel, einschließlich mobiler Werbekennungen und anderer Online-Kennungen, die zur Wiedererkennung Ihres Geräts verwendet werden. Wir verwenden diese Informationen zur Systemverwaltung, zur Informationssicherheit und Missbrauchsprävention, um Nutzungstrends zu verstehen und um den Dienst zu analysieren und zu personalisieren. Allein oder in Kombination mit anderen Informationen können diese personenbezogene Daten darstellen. Abschnitt 6 unten erläutert jede dieser Technologien sowie die von uns eingesetzten spezifischen Cookies im Einzelnen.

5. Wie und warum wir Ihre personenbezogenen Daten verwenden

Nach der DSGVO dürfen wir Ihre personenbezogenen Daten nur verwenden, wenn wir dafür über eine gültige Rechtsgrundlage verfügen. Vereinfacht ausgedrückt sind dies die folgenden Rechtsgrundlagen:

Einwilligung: In einigen Fällen haben Sie uns mitgeteilt, dass die Verwendung Ihrer personenbezogenen Daten für einen bestimmten Zweck zulässig ist — zum Beispiel durch die Anmeldung für Marketing-E-Mails oder die Annahme nicht essenzieller Cookies.

Vertrag: Wir benötigen bestimmte personenbezogene Daten, um unseren Vertrag mit Ihnen zu erfüllen — zum Beispiel, um Ihre Bestellung zu bearbeiten und zu liefern.

Rechtliche Verpflichtung: Manchmal verlangt das Gesetz von uns, bestimmte Informationen zu erheben oder aufzubewahren — zum Beispiel Rechnungs- und Buchführungsunterlagen nach rumänischem Steuerrecht.

Berechtigte Interessen: Dies ist ein technischer Begriff, der bedeutet, dass wir einen guten und fairen Grund haben, Ihre personenbezogenen Daten in einer Weise zu verwenden, die Ihre Rechte und Interessen nicht überwiegt. Zum Beispiel (i) verwenden wir Identitäts-, Geräte- und Standortinformationen, um Missbrauch des Dienstes zu verhindern und ihn sicher zu halten, und (ii) analysieren wir, wie Nutzer mit dem Dienst interagieren, damit wir verstehen können, was gut funktioniert und was nicht, welche Verbesserungen sich lohnen und wie wir den Dienst sicher und angenehm nutzbar halten können — was es uns ermöglicht, die Erfahrung für alle unsere Nutzer zu verbessern.

Die folgende Tabelle enthält die spezifischen Zwecke, für die wir Ihre personenbezogenen Daten verarbeiten, sowie die Rechtsgrundlage, auf die wir uns jeweils stützen:  

Zweck Rechtsgrundlage (DSGVO)
Erfüllung des Kaufvertrags (Bestellabwicklung, Lieferung, Rechnungsstellung, Kundendienst nach dem Kauf, Rückgaben) Vertrag — Art. 6 Abs. 1 lit. b
Erfüllung rechtlicher Verpflichtungen (Buchhaltung, Steuern, Beantwortung behördlicher Anfragen) Rechtliche Verpflichtung — Art. 6 Abs. 1 lit. c
Betriebliche Mitteilungen zu Ihrer Bestellung (Bestätigungen, Versandaktualisierungen, bestellbezogene SMS) Vertrag — Art. 6 Abs. 1 lit. b
Kundendienst (Bearbeitung von Anfragen, Beschwerden, Support-Tickets) Vertrag — Art. 6 Abs. 1 lit. b; berechtigtes Interesse für Anfragen von Personen, die (noch) keine Kunden sind — Art. 6 Abs. 1 lit. f
Analyse und Verbesserung der Website (Traffic-Analyse, A/B-Tests, Leistung) Berechtigtes Interesse, vorbehaltlich Ihres Widerspruchsrechts — Art. 6 Abs. 1 lit. f; Einwilligung für nicht essenzielle Analyse-Cookies — Art. 6 Abs. 1 lit. a
Werbung und Retargeting (z. B. Meta/Facebook Pixel, Microsoft Advertising) Einwilligung — Art. 6 Abs. 1 lit. a
Marketingmitteilungen (Newsletter, Werbeangebote) Einwilligung — Art. 6 Abs. 1 lit. a, oder das „weiche Opt-in” für Bestandskunden, soweit nach lokalem Recht zulässig

5.1 Ob Sie zur Bereitstellung Ihrer Daten verpflichtet sind

Die Bereitstellung von Identifikations-, Kontakt-, Liefer- und Zahlungsdaten ist erforderlich, um eine Bestellung aufzugeben und auszuführen — ohne sie können wir Ihren Kauf nicht bearbeiten oder Ihre Produkte nicht liefern. Die Bereitstellung von Informationen zu Marketingzwecken (zum Beispiel Newsletter-Anmeldung oder Zustimmung zu Marketing-Cookies) ist stets freiwillig, und eine Ablehnung hat keine Auswirkung auf Ihre Fähigkeit, eine Bestellung aufzugeben.

6. Cookies und andere Tracking-Technologien

Wenn Sie auf den Dienst zugreifen oder ihn nutzen, zeichnen unsere Server automatisch bestimmte von Ihrem Browser gesendete Informationen über Protokolldateien auf. Dies kann Ihre IP-Adresse, den Browsertyp, den Internetdienstanbieter, das Betriebssystem, Datums-/Zeitstempel, verweisende und ausgehende Seiten sowie angeklickte Seiten umfassen. Wir verwenden IP-Adressen, um die allgemeinen Regionen zu überwachen, aus denen Besucher auf den Dienst zugreifen, und um zur Sicherheit des Dienstes beizutragen. Befinden Sie sich im EWR, im Vereinigten Königreich oder in einer anderen Rechtsordnung, die eine IP-Adresse als personenbezogene Daten behandelt, behandeln wir sie entsprechend.

Wie die meisten Websites verwenden wir Cookies und ähnliche Technologien, um den Dienst funktionsfähig zu machen, Ihre Präferenzen zu speichern, zu verstehen, wie der Dienst genutzt wird, und, soweit Sie zugestimmt haben, um uns und unseren Partnern zu helfen, Ihnen relevantere Werbung zu zeigen. Cookies können sitzungsbasiert sein, d. h. sie bestehen nur für die Dauer Ihres Besuchs und verschwinden, sobald Sie Ihren Browser schließen, oder dauerhaft, d. h. sie verbleiben auf Ihrem Gerät, nachdem Sie Ihren Browser geschlossen haben, bis sie ablaufen oder Sie sie löschen. Die folgende Tabelle enthält die spezifischen Kategorien von Cookies, die wir verwenden, die dahinterstehenden Anbieter und die Rechtsgrundlage für jede Kategorie:  

Bei Ihrem ersten Besuch sehen Sie ein Cookie-Banner, über das Sie nicht essenzielle Cookie-Kategorien (Analyse, Funktionalität und Marketing) akzeptieren oder ablehnen können. Sie können Ihre Präferenzen jederzeit über dieses Banner oder Ihre Browsereinstellungen ändern. Das Deaktivieren von Analyse-, Funktions- oder Marketing-Cookies beeinträchtigt niemals Ihre Fähigkeit, den Dienst zu nutzen oder eine Bestellung aufzugeben — es bedeutet lediglich, dass sich der Dienst von Besuch zu Besuch weniger an Ihre Präferenzen erinnert. Sie können auch alle Cookies, einschließlich unbedingt erforderlicher Cookies, über Ihre Browsereinstellungen blockieren — tun Sie dies jedoch, funktionieren möglicherweise einige Teile des Dienstes, einschließlich des Hinzufügens von Artikeln zu Ihrem Warenkorb oder des Abschlusses des Bezahlvorgangs, nicht ordnungsgemäß.

Wir verwenden außerdem Web-Beacons und Pixel — unsichtbare elektronische Bilder, die in unsere Seiten und E-Mails eingebettet sind, manchmal allein und manchmal zusammen mit Cookies. Diese helfen uns, Ihre Interaktionen mit unseren E-Mail-Mitteilungen und Werbekampagnen zu verstehen; zum Beispiel können wir erkennen, wann Sie eine Marketing-E-Mail öffnen oder wann Sie auf einen Link darin klicken, der Sie zum Dienst führt.

Konkret: Wir verwenden Microsoft Clarity, um digitale Verhaltensdaten zu erheben, einschließlich Heatmaps, Sitzungsaufzeichnungen und Nutzungsmetriken, unter Verwendung von First- und Third-Party-Cookies und ähnlichen Technologien. Dies hilft uns, zu verstehen, wie Besucher den Dienst nutzen, die Website-Leistung zu verbessern und Betrug zu verhindern. Sie können sich über die Datenschutzerklärung von Microsoft (privacy.microsoft.com/privacystatement) abmelden.

Wir verwenden außerdem Hotjar, einen von Hotjar Ltd. (Malta) bereitgestellten Webanalysedienst, um besser zu verstehen, wie Besucher den Dienst nutzen. Hotjar erhebt Informationen über Ihr Browsing-Verhalten, einschließlich der von Ihnen besuchten Seiten, der auf jeder Seite verbrachten Zeit, der Stellen, auf die Sie klicken, und der Art, wie Sie scrollen, sowie technische Informationen wie Ihren Browsertyp, Ihre Bildschirmauflösung, Ihr Betriebssystem und Ihren allgemeinen geografischen Standort auf Länderebene. Hotjar erhebt keine sensiblen Informationen, die Sie im Dienst eingeben, wie zum Beispiel Zahlungskartennummern — diese Daten erreichen die Server von Hotjar niemals. Die über Hotjar erhobenen Daten werden ausschließlich zur Verbesserung Ihrer Erfahrung im Dienst verwendet und nicht an Dritte weitergegeben. Sie können sich jederzeit über die Hotjar-Opt-out-Seite (hotjar.com/legal/compliance/opt-out) von der Datenerhebung durch Hotjar abmelden.

Andere Dritte, deren Technologie wir zur Bereitstellung von Werbung oder zur Messung ihrer Leistung nutzen, können ebenfalls eigene Cookies auf Ihrem Gerät platzieren und Web-Beacons verwenden, um Informationen über Ihre Browsing-Aktivität über die Zeit und über verschiedene Websites hinweg zu erheben, um Ihnen auf Ihre Interessen zugeschnittene Werbung anzuzeigen. Dies beruht auf derselben Einwilligung, die Sie über das oben beschriebene Cookie-Banner erteilen (oder ablehnen) — wenn Sie den Marketing-/Targeting-Cookies nicht zugestimmt haben, setzen diese Dritten keine Tracking-Cookies über den Dienst. Diese Informationen umfassen in der Regel nicht Ihren Namen oder Ihre Kontaktdaten, können jedoch später mit personenbezogenen Daten verknüpft werden, die wir über Sie besitzen.

7. Wie wir Ihre personenbezogenen Daten weitergeben

7.1 Unsere externen Dienstleister

Wir geben personenbezogene Daten an die nachstehend genannten Kategorien von Empfängern weiter, die als unsere Auftragsverarbeiter oder in einigen Fällen als eigenständige Verantwortliche für ihre eigenen Zwecke handeln. Wir bemühen uns in wirtschaftlich angemessenem Umfang, nur mit Anbietern zusammenzuarbeiten, die geeignete Maßnahmen zum Schutz Ihrer personenbezogenen Daten treffen. Handelt ein Anbieter als eigenständiger Verantwortlicher für seine eigenen Zwecke (wie in der nachstehenden Tabelle vermerkt), ist dieser Anbieter für seine eigene Einhaltung des geltenden Rechts und seine eigene Datenschutzerklärung verantwortlich.

Anbieter Rolle / Dienstleistung Standort
CheckoutChamp Bestellabwicklung Puerto Rico, USA
Adyen Zahlungsabwicklung Niederlande (EU)
Mollie Zahlungsabwicklung Niederlande (EU)
GooglePay Zahlungsabwicklung Kalifornien, USA
ApplePay Zahlungsabwicklung Kalifornien, USA
PayPal Zahlungsabwicklung Kalifornien, USA
Klarna Ratenzahlung / „Jetzt kaufen, später bezahlen“ (handelt als eigenständiger Verantwortlicher für den eigenen Dienst) Schweden (EU)
Airwallex Zahlungsabwicklung San Francisco, USA
Active Campaign Bestellbezogene E-Mail-Kommunikation USA
Google Workspace Bestätigungs-E-Mails / Belege USA
Twilio Betriebliche SMS (soweit verwendet) USA
Zendesk Kundendienst-Ticketing USA
Versand- / Bestellabwicklungsdienstleister Versand- und Kurierunternehmen Abhängig von Ihrem Standort

Diese Liste spiegelt unsere derzeitigen Dienstleister wider. Wenn sie sich in einer Weise ändert, die sich auf die Art und Weise auswirkt, wie wir Ihre personenbezogenen Daten verarbeiten, werden wir diese Erklärung entsprechend aktualisieren. Die oben genannten Anbieter greifen nur in dem für die Erbringung ihrer Dienstleistungen erforderlichen Umfang auf Ihre Daten zu und sind vertraglich zu deren Schutz verpflichtet. Wir verkaufen oder vermieten Ihre personenbezogenen Daten nicht an Dritte.

7.2 Unternehmensübertragungen

Global Brother kann seine Rechte und Pflichten im Rahmen dieser Datenschutzerklärung sowie sämtliche von ihm gehaltenen personenbezogenen Daten an ein Drittunternehmen oder eine Drittstelle übertragen, das/die Global Brother erwirbt oder von Global Brother erworben wird, oder mit Global Brother verschmilzt, im Rahmen einer Fusion, Übernahme, eines Verkaufs, einer Umstrukturierung oder eines anderen Kontrollwechsels. Soweit geltendes Recht dies vorschreibt, werden wir Sie über eine solche Übertragung und über etwaige Wahlmöglichkeiten hinsichtlich Ihrer personenbezogenen Daten informieren.

7.3 Sonstige Offenlegungen

Wir können personenbezogene Daten über Sie auch offenlegen, wenn geltendes Recht dies vorschreibt, oder wenn wir in gutem Glauben davon ausgehen, dass die Offenlegung angemessen erforderlich oder hilfreich ist, um:
- einem rechtlichen Verfahren nachzukommen, wie einer gerichtlichen Anordnung, einer Vorladung oder einer behördlichen Anfrage;
- unsere Nutzungsbedingungen durchzusetzen, einschließlich der Untersuchung möglicher Verstöße;
- Betrug, Sicherheits- oder technische Probleme zu erkennen, zu verhindern oder anderweitig zu beheben; oder
- die Rechte, das Eigentum oder die persönliche Sicherheit von Global Brother, anderen Nutzern des Dienstes oder der Öffentlichkeit zu schützen. .

Wir stützen uns auf eine rechtliche Verpflichtung (Art. 6 Abs. 1 lit. c DSGVO), wenn die Offenlegung gesetzlich vorgeschrieben ist, oder auf unser berechtigtes Interesse am Schutz unseres Unternehmens, unserer Nutzer und der Öffentlichkeit (Art. 6 Abs. 1 lit. f DSGVO) für die übrigen oben beschriebenen Offenlegungen.

8. Internationale Datenübermittlungen

Als rumänisches Unternehmen speichert und verarbeitet Global Brother S.R.L. Ihre personenbezogenen Daten hauptsächlich auf Servern, die sich in Rumänien und anderweitig in der Europäischen Union befinden.

Einige der in Abschnitt 7.1 aufgeführten Anbieter befinden sich außerhalb des Europäischen Wirtschaftsraums (EWR), unter anderem in den Vereinigten Staaten. Wenn Sie den Dienst aus dem EWR, dem Vereinigten Königreich, der Schweiz oder einer anderen Rechtsordnung mit von der Rechtsordnung des jeweiligen Anbieterstandorts abweichenden Datenschutzgesetzen besuchen, beachten Sie bitte, dass Ihre personenbezogenen Daten in ein Land übermittelt, dort gespeichert und verarbeitet werden können, dessen Datenschutzrahmen möglicherweise nicht das gleiche Schutzniveau bietet wie Ihr Herkunftsland.

Wir nehmen dies ernst und übermitteln Ihre personenbezogenen Daten nicht außerhalb des EWR, ohne dass eine oder mehrere der folgenden Garantien bestehen:
- der EU-US-Datenschutzrahmen, für die danach zertifizierten Anbieter;
- die von der Europäischen Kommission verabschiedeten Standardvertragsklauseln;
- oder andere nach der DSGVO anerkannte Garantien.

Sie können eine Kopie der für eine bestimmte Übermittlung geltenden Garantien anfordern, oder Informationen darüber, wo diese verfügbar gemacht wurden, indem Sie uns unter der in Abschnitt 2 angegebenen Adresse kontaktieren. Nichts in diesem Abschnitt bezweckt oder bewirkt, dass Sie auf ein Recht verzichten, das Ihnen nach der DSGVO oder anderem geltenden Datenschutzrecht zusteht; soweit zwingende Schutzbestimmungen Ihres Herkunftslandes nicht rechtmäßig durch Vertrag abbedungen werden können, gelten diese weiterhin für Sie.

9. Datenspeicherung

Wir bewahren Ihre personenbezogenen Daten nur so lange auf, wie dies zur Erfüllung der in dieser Erklärung beschriebenen Zwecke erforderlich ist, einschließlich zur Erfüllung rechtlicher, buchhalterischer oder meldebezogener Anforderungen, zur Beilegung von Streitigkeiten und zur Durchsetzung unserer Vereinbarungen. Im Allgemeinen bedeutet dies, dass wir Ihre Daten aufbewahren, solange Sie ein Konto oder eine aktive Beziehung mit uns haben, und danach so lange, wie es für die nachstehenden Zwecke angemessen erforderlich ist oder gesetzlich vorgeschrieben ist:

Datenkategorie Aufbewahrungsfrist
Bestell- und Rechnungsdaten Bis zu 10 Jahre ab Rechnungsdatum (oder eine kürzere gesetzliche Frist, soweit das lokale Steuer-/Buchführungsrecht eine solche vorsieht)
Marketingdaten (z. B. Newsletter-Einwilligung) Bis zum Widerruf der Einwilligung, mit erneuter Einholung der Erlaubnis/Löschung nach einem festgelegten Zeitraum der Inaktivität des Abonnenten
Korrespondenz mit dem Kundendienst 3 Jahre ab Schließung des Tickets als allgemeine Standardregel (verlängert, soweit die örtliche zivilrechtliche Verjährungsfrist länger ist oder die Korrespondenz eine aktive Gewährleistung/einen aktiven Anspruch dokumentiert)
Browsing-/Analyse-Cookie-Daten Cookie-Lebensdauer begrenzt auf 13 Monate ab Platzierung; zugrunde liegende Analysedaten maximal 25 Monate aufbewahrt; Einwilligung (soweit erforderlich) alle 6–13 Monate erneuert
Retargeting-/Marketing-Cookie-Daten Cookie-Lebensdauer begrenzt auf 13 Monate ab Platzierung oder bis zum Widerruf der Einwilligung, je nachdem, was früher eintritt; Einwilligung alle 6–13 Monate erneuert

Nach Ablauf einer Aufbewahrungsfrist löschen oder anonymisieren wir die betreffenden Daten.

10. E-Mail-Kommunikation und Abmeldung

Sofern Sie uns nichts anderes mitgeteilt haben oder sich nicht ausdrücklich wie hier beschrieben abmelden, erklären Sie sich mit der Nutzung des Dienstes damit einverstanden, dass wir Ihre Informationen verwenden dürfen, um Sie per E-Mail mit Inhalten zu kontaktieren, die für Ihre Nutzung des Dienstes relevant sind, wie z. B. Verwaltungsmitteilungen, Bestellaktualisierungen, Newsletter, für die Sie sich angemeldet haben, und — soweit Sie zugestimmt haben — Marketing- und Werbeinformationen über Global Brother oder den Dienst.

Sie können den Erhalt von Marketing-E-Mails jederzeit beenden, indem Sie den in jeder Mitteilung enthaltenen Abmeldeanweisungen folgen oder uns unter der in Abschnitt 16 unten angegebenen E-Mail-Adresse kontaktieren. Wenn ein externer Anbieter im Auftrag von uns einen Newsletter versendet, können Sie sich gemäß den von diesem Anbieter bereitgestellten Anweisungen abmelden. Die Abmeldung von Marketingmitteilungen hat keine Auswirkung auf Transaktionsmitteilungen, die wir Ihnen im Zusammenhang mit einer von Ihnen aufgegebenen Bestellung senden müssen. Befinden Sie sich im Vereinigten Königreich oder im EWR, werden wir Sie nicht ohne Ihre vorherige Einwilligung per E-Mail mit Marketing- oder Werbeinformationen kontaktieren, sofern nicht eine andere Rechtsgrundlage gilt (zum Beispiel das „weiche Opt-in” für Bestandskunden, soweit zulässig).

Sollten Sie Schwierigkeiten bei der Abmeldung haben, leiten Sie die betreffende E-Mail bitte an die in Abschnitt 16 angegebene Adresse weiter, mit „Abmeldung” in der Betreffzeile, oder kontaktieren Sie uns direkt, und wir werden Ihre Anfrage innerhalb von fünf (5) Werktagen bearbeiten.

11. Datensicherheit

Die Sicherheit Ihrer personenbezogenen Daten ist uns wichtig. Wir haben ein Informationssicherheitsprogramm mit administrativen, technischen, organisatorischen und physischen Kontrollen implementiert, das darauf ausgelegt ist, Ihre personenbezogenen Daten angemessen vor rechtswidriger Nutzung, unbefugtem Zugriff oder Offenlegung zu schützen. Wir beschränken den Zugang zu Ihren personenbezogenen Daten auf jene Mitarbeiter, Auftragnehmer und Vertreter, die einen echten geschäftlichen Bedarf an dieser Kenntnis haben.

Je nach Kontext umfassen die von uns eingesetzten Schutzmaßnahmen:
- verschlüsselte Datenübertragung (SSL/TLS) zwischen Ihrem Gerät und unseren Servern;
- Maskierung, wodurch Ihre Informationen so verschleiert werden, dass ihre Struktur gleich bleibt, ihr Inhalt jedoch nicht mehr identifizierbar ist;
- De-Identifizierungs- und Pseudonymisierungstechniken, wie das Ersetzen von Identifikatoren durch Kunden-ID-Codes;
- Anonymisierung, wodurch Ihre Daten so verändert werden, dass sie nicht mehr zur persönlichen Identifizierung verwendet werden können; und
- Zugriffskontrollen für unsere internen Systeme und Verfahren zur Reaktion auf Sicherheitsvorfälle.

Zahlungen werden ausschließlich von PCI-DSS-zertifizierten Anbietern verarbeitet, und wir speichern nicht Ihre vollständige Kartennummer. Dennoch ist keine Methode der Übertragung über das Internet und keine Methode der elektronischen Speicherung zu 100 % sicher. Obwohl wir uns bemühen, wirtschaftlich vertretbare Mittel zum Schutz Ihrer personenbezogenen Daten einzusetzen, können wir deren absolute Sicherheit nicht garantieren.

12. Datenschutz von Kindern

Der Dienst richtet sich nicht an Personen unter 18 Jahren und ist nicht für deren Nutzung bestimmt. Wir erheben wissentlich keine personenbezogenen Daten von Kindern unter 18 Jahren. Sollten wir feststellen, dass wir versehentlich personenbezogene Daten eines Kindes ohne die erforderliche Einwilligung erhoben haben, werden wir diese unverzüglich löschen. Wenn Sie glauben, dass wir möglicherweise Informationen von oder über ein Kind besitzen, kontaktieren Sie uns bitte unter der in Abschnitt 16 angegebenen Adresse.

13. Automatisierte Entscheidungsfindung und Profiling

Wir treffen keine Entscheidungen, die ausschließlich auf einer automatisierten Verarbeitung, einschließlich Profiling, beruhen und die Sie betreffende rechtliche Wirkung entfalten oder Sie in ähnlicher Weise erheblich beeinträchtigen, im Sinne von Artikel 22 der DSGVO.

Wir verwenden Werbe-Retargeting-Tools (wie den Meta Pixel und Microsoft Advertising), die auf Grundlage Ihres Browsing-Verhaltens Zielgruppenprofile erstellen, um Ihnen auf diesen Plattformen relevantere Werbung zu zeigen. Dies beruht auf Ihrer über das Cookie-Banner erteilten Einwilligung, die Sie jederzeit widerrufen können. Für die Erhebung und Übermittlung von Daten über diese Tools können Meta und Microsoft als eigenständige Verantwortliche (oder gemeinsam mit uns) für ihre eigenen Werbezwecke handeln, und ihre eigenen Datenschutzerklärungen gelten für diese Verarbeitung.

14. Ihre Datenschutzrechte

Wenn Sie sich im EWR, im Vereinigten Königreich oder an einem anderen Ort befinden, an dem dieser Teil A als Ihr Standard-Datenschutzstandard gilt, haben Sie die folgenden Rechte hinsichtlich Ihrer personenbezogenen Daten:

- Recht auf Auskunft — Bestätigung zu erhalten, dass wir Ihre Daten verarbeiten, sowie eine Kopie davon (Art. 15 DSGVO).
- Recht auf Berichtigung — unrichtige oder unvollständige Daten zu korrigieren (Art. 16 DSGVO).
- Recht auf Löschung („Recht auf Vergessenwerden”) — unter bestimmten Umständen die Löschung Ihrer Daten zu verlangen (Art. 17 DSGVO).
- Recht auf Einschränkung der Verarbeitung — unter bestimmten Umständen die Einschränkung der Verarbeitung zu verlangen (Art. 18 DSGVO).
- Recht auf Datenübertragbarkeit — Ihre Daten in einem strukturierten, gängigen und maschinenlesbaren Format zu erhalten (Art. 20 DSGVO).
- Widerspruchsrecht — der auf unserem berechtigten Interesse beruhenden Verarbeitung, einschließlich Profiling, zu widersprechen (Art. 21 DSGVO).
- Recht auf Widerruf der Einwilligung — jederzeit, ohne dass die Rechtmäßigkeit der bis zum Widerruf erfolgten Verarbeitung berührt wird (Art. 7 Abs. 3 DSGVO).
- Recht auf Beschwerde — bei Ihrer örtlichen Datenschutz-Aufsichtsbehörde (Art. 77 DSGVO).

Um eines dieser Rechte auszuüben, kontaktieren Sie uns unter den in Abschnitt 16 angegebenen Kontaktdaten. Wir werden innerhalb eines Monats antworten, verlängerbar um weitere zwei Monate bei komplexen oder mehreren Anfragen, und wir werden Sie informieren, falls wir mehr Zeit benötigen und warum.

14.1 Aufsichtsbehörde

Unsere federführende Aufsichtsbehörde ist die Rumänische Nationale Aufsichtsbehörde für die Verarbeitung personenbezogener Daten (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sektor 1, 010336 Bukarest, Rumänien, www.dataprotection.ro.


Wenn Sie außerhalb Rumäniens ansässig sind, können Sie auch bei der Aufsichtsbehörde Ihres eigenen Landes eine Beschwerde einreichen. Die Kontaktdaten Ihrer nationalen Aufsichtsbehörde finden Sie auf der Website des Europäischen Datenschutzausschusses unter https://www.edpb.europa.eu/about-edpb/our-members_en. Befinden Sie sich außerhalb der EU/des EWR, des Vereinigten Königreichs oder der Schweiz, können Sie sich in der Regel mit Bedenken an die Datenschutz- oder Datenschutzbehörde Ihres eigenen Landes wenden, soweit eine solche besteht, oder uns direkt unter den in Abschnitt 16 angegebenen Kontaktdaten kontaktieren.

15. „Do Not Track”-Signale

Einige Browser können ein „Do Not Track”-Signal an die von Ihnen besuchten Websites senden. Die Art und Weise, wie Browser dieses Signal übermitteln, ist noch nicht einheitlich, und es wurde bislang kein gemeinsamer Branchenstandard für seine Auslegung entwickelt. Aus diesem Grund reagiert der Dienst derzeit nicht auf „Do Not Track”-Signale. Befinden Sie sich im EWR oder im Vereinigten Königreich, können Sie nicht essenzielles Tracking weiterhin über unser Cookie-Banner steuern, wie in Abschnitt 6 beschrieben.

16. Kontakt

Fragen oder Anfragen zu dieser Datenschutzerklärung oder zu unserem Umgang mit Ihren personenbezogenen Daten können gerichtet werden an:

E-mail: [email protected]

Postanschrift: Global Brother S.R.L., 201 Barbu Vacarescu str., 21. Stock, 2. Bezirk, 020276 Bukarest, Rumänien