PRIVACY POLICY

VALID FROM 2019-10-01

INTRODUCTION
JA Shades AB, which conducts business under the trademark JOEY LANG, registered in Sweden under organisation number 559212-4894 (“JA Shades AB”, “Joey Lang”, “we”, “us” or “our”), processes your personal information when you visit and use the services available at “www.joeylang.com” as well as when you shop directly from us and in some cases when you shop from our retailers. We strive for transparency in our handling of visitors and customers personal data and have therefore adopted this privacy policy. Below you will find information about what types of personal data we process, why we do it, what we use it for and how we may share the information. JA Shades AB is responsible for all processing of your personal data.

WHAT PERSONAL DATA ARE WE PROCESSING?
We collect personal information when you (i) buy sunglasses, accessories and other goods, (ii) register for news, invitations and offers, (iii) request support and (iv) use our website. Such personal information includes name, email address, telephone number, delivery address, payment details, IP address, website usage and other information that you voluntarily provide to us.

PURPOSE, LEGAL BASIS AND STORAGE PERIOD
We will use your personal data only for the purposes, and on the legal grounds set out below. We do not use your personal data for any purpose that is inconsistent with the purposes below. Furthermore, we only use your personal data during the period specified under “Storage period”, after this period, your personal data will be permanently deleted.

Please note that the retention periods set forth in this document do not apply to the extent that JA Shades AB is required to retain your personal data (in whole or in part) in accordance with applicable mandatory legislation (eg accounting laws).

PURCHASE
Purpose of processing: When you buy sunglasses, accessories or other goods, we process your personal data in order to fulfill our contractual obligations towards you (see Terms of Use and Purchase). Our website form and direct sales indicate what information you need to submit to us in order to complete your purchase.
Legal basis for processing: The processing is required in order for us to fulfill our agreement with you (see terms and conditions of use).
Storage period: We process your personal data during the term of our agreement (including the one-year warranty period), and then we will delete your personal information. The retention period also applies to purchases that have not been completed due to your card issuer’s consent.

MARKETING
Purpose of processing: When you sign up for news, invitations and offers (marketing directly addressed to you), we process your personal data in order to provide the services you require. Our direct marketing is based on profiling, which means that we customize the information you receive from us based on certain factors. We use the following types of personal data to compile a profile: your gender, your position, your past purchases, your behavior on our website and / or your past behavior when you have received direct marketing directly from us.
Legal basis for processing: The processing is required for our legitimate interest in maintaining good customer relationships.
Storage period: If you refuse or unsubscribe from our marketing (including profiling), we will no longer process your personal information for this purpose. We also delete your personal data if there is no other legal basis for retaining your information (for example, a valid purchase agreement).

SUPPORT
Purpose of processing: When you request support from our customer service via email, we process your personal information in order to help you with the current case.
Legal basis for processing: The processing is required for us to fulfill our agreement with you (see terms and conditions of use).
Storage period: We will delete your information within six months after the relevant case has been finalized.

REMINDERS
Purpose of processing: If you have started a purchase on our website and provide your e-mail address but have not completed the final step in the buying process, we will send you an e-mail with a link to your shopping basket in order to remind you of your unfinished purchases.
Legal basis for processing: The processing is required for our and your legitimate interest in reminding you of your unfinished purchase.
Storage period: We will remove your information within one month from your website visit, unless there is another legal basis for retaining your information (such as a valid purchase agreement). You can notify us that you want to delete your personal data by contacting data@joeylang.com.

WEBSITE USE
Purpose of processing: When you use our website, we process your personal data in order to improve our website and for marketing purposes.
Legal basis for processing: The processing is required for our legitimate interest in improving our website and for re-marketing. For more information, see the section “Cookies”.
Storage period: For more information, see the section “Cookies”.

PREVENT FRAUD
Purpose of processing: We process your personal data in order to perform risk analysis, prevent fraud and manage risks.
Legal basis for processing: The processing is necessary for our legitimate interest in preventing fraud and managing risks.
Storage period: We will delete all personal data used for this purpose at six month intervals, unless there is no other legitimate interest in retaining your information. For purchases that have been canceled in order to prevent fraud, we will delete your personal data two years after the purchase could not be completed.

DATA ANALYSIS
Purpose of processing: We analyze your personal data in order to compile aggregated tracking data (including analyzes of visitors’ use of our website by tracking information about, for example, pageviews, traffic flows, search terms and clicks).
Legal basis for processing: The processing is required for our legitimate interest in producing statistics over time regarding our customers’ use of our services.
Storage period: We anonymize all tracking data if technically possible. Once your personal information has been anonymized, it is no longer considered personal data under applicable data protection legislation. You can notify us that you do not want your data to be used for the above purposes by contacting data@joeylang.com.

WHO DO WE SHARE YOUR PERSONAL DATA?
Only those persons who need to process the personal data for the purposes mentioned above have access to your personal data. We may also need to allow our suppliers to access your personal data when they perform services on behalf of us, primarily when providing support and maintenance of IT systems, storage services and marketing. We store your data within the EU / ESS (at present Finland), but in order to maintain a high level of service on our services to you as a customer, in some cases data may need to be transmitted or read by our suppliers’ sister companies and subsidiaries outside the EU. All such transfer of data outside the EU / EEA is in accordance with data protection legislation. Our international transfers of personal data (including transfers to suppliers outside the EU / EEA) are based on the European Commission’s standard contract clauses. The standard contract clauses are available on the European Commission’s website: https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en.
For transfers to any of our US suppliers, the recipient is certified under the EU-US Privacy Shield, which is administered by the US Department of Commerce’s International Trade Administration, International Trade Administration (www.privacyshield.gov).

YOUR RIGHTS
You have the following rights under applicable law:
Right of access: You can request access to your personal data at any time. Upon request, we provide you with a copy of your personal data in a commonly used electronic format.
Right to correction: You have the right to have incorrect personal data corrected as well as to have incomplete personal data supplemented.
Right of removal (“right to be forgotten”): Under certain circumstances (including processing on the basis of your consent), you may request that we delete your user information. Note that this right is not unconditional. Therefore, an attempt to invoke the right may not lead to any action on our part.
Right to object: To certain processing activities carried out by us that relate to your personal data, such as our processing of your personal data based on our legitimate interest. The right to object also applies to the processing of your personal data for direct marketing purposes.
Right to restriction of processing: You may in some circumstances request from us that the processing of your personal data be restricted. Note that this right is not unconditional. Therefore, an attempt to invoke the right may not lead to any action on our part.
Right to data portability: You have the right to obtain your personal data (or to have your personal data transferred directly to another data controller) in a structured, commonly used and machine-readable format.

Finally, you also have the right to file a complaint with the supervisory authority in Sweden, which is currently the Swedish Datainspektionen

You can at any time invoke your rights as above by emailing us at data@joeylang.com and we will help you quickly..

COOKIES
As part of our quest to provide personalized services on our website, we use cookies to store and periodically track information about you. A cookie is the small data file that is sent to your browser from a web server and stored on your hard drive, which makes it easier to access the same page the next time you visit it. For example, a cookie is sent when you register for or information on our website. If you do not want your personal data to be stored in cookies, you can configure your browser to notify you when a cookie is received. In this way, you can decide each time whether or not to accept the use of cookies. However, it may be necessary to use cookies to provide certain features, and if you choose to decline cookies, the features of the website may be restricted. Your browser should contain precise instructions that explain how to control the acceptance of cookies. To be clear, we have summarized which cookies we use on our website below:

COOKIE RESPONSIBLE: JA Shades AB (www.joeylang.com)
Type of cookies: Temporary
Purpose of the file: Cookie message that tracks if you have accepted our privacy policy and terms and conditions or not.
Storage period: 30 days
Stored data: True / false
Third party cookie: No

COOKIE RESPONSIBLE: JA Shades AB (www.joeylang.com)
Type of cookies: First party
Purpose: Session and shopping cart identification
Storage period: Session
Stored data: Session and shopping cart identification data
Third party cookie: No

COOKIE RESPONSIBLE: JA Shades AB (www.joeylang.com)
Type of cookies: Session
Purpose: Session and shopping cart identification
Storage time: Temporary session
Stored data: Session ID
Third party: No

COOKIE RESPONSIBLE: Google Ireland Ltd.
Type of cookies: Third party
Purpose: Performance and statistics
Storage time: Permanently
Stored data: Session ID, anonymous IP address, site statistics
Third party: Yes

COOKIE RESPONSIBLE: Facebook Ireland Ltd.
Type of cookies: Third party
Purpose: Marketing
Storage time: Permanently
Stored data: Session ID, page statistics
Third party: Yes

COOKIE RESPONSIBLE: Stripe Ltd.
Type of cookie: Third party
Purpose: Transaction status tracking
Storage time: Transaction status follow up
Stored data: Session ID
Third party: Yes

DATA SECURITY
We use appropriate technical and organizational security measures to protect your personal data against loss and as protected against access by unauthorized persons. Appropriate security measures that we have taken include the introduction of secure private connections, traceability, disaster recovery and access restrictions. We regularly review our safety principles and routines in order to ensure that our systems are kept protected and secure.

CONTACT INFORMATION
If you have any questions regarding our handling of your personal data or our use of cookies, or if you wish to invoke any of your rights under applicable privacy law, please contact us: data@joeylang.com.

CHANGES IN OUR PRIVACY POLICY
If we change the way we handle your personal information or use cookies, we will immediately update our privacy policy on our website and promptly publish the updated message on the website.