MAMMUT SPORTS GROUP INC. PRIVACY AND DATA PROTECTION POLICY
(Effective as of February 24, 2020)
Mammut Sports Group Inc. (referred to herein as “Mammut”, “you”, “we” or “our” as the context requires) takes data protection issues very seriously.
This policy describes the types of information we may collect from you or that you may provide when you visit the website us.mammut.com (our “Website”) and our practices for collecting, using, maintaining, protecting, and disclosing that information.
This policy applies to information we collect on this Website and in email, text, and other electronic messages between you and this Website.
It does not apply to information collected by:
us offline or through any other means, including on any other website operated by us or any third party (including our affiliates and subsidiaries); or
any third party (including our affiliates and subsidiaries), including through any application or content (including advertising) that may link to or be accessible from or on the Website.
A. RESPONSIBLE ENTITY
The entity responsible for operating our Website and the Mammut online store operated via the Website (the "Online Store"), as well as for collecting, processing and using your personal data in accordance with this Privacy and Data Protection Policy is: Mammut Sports Group Inc., 458 Hurricane Lane, Williston, Vermont 05495, United States of America.
B. COLLECTION AND STORAGE OF PERSONAL DATA
The term "personal data" refers to all information relating to an identified or identifiable physical person. This includes, for example, your name, telephone number, postal address and e-mail address.
Personal data, as defined in the applicable data protection provisions, also include information concerning your use of the Website, which are collected, processed, stored and used by our Web servers to enable the provision and optimization of our Website and ensure system security and for statistical purposes (the "User Data"). These include, inter alia, the connection data of the requesting computer (IP address), the pages that you visit on our Website, the date and length of your visit, the identification data of the type of browser and operating system used, the website from which you visit us, the content of your shopping cart in case of a potential purchase and the length of time until the order is placed.
Apart from the User Data described in para. (2) above, we will only collect personal data if you voluntarily share them with us. The following data, in particular, are collected when you place an order or open a customer account: title, name, postal address, e-mail address. Payment information, such as your bank details or credit card number, is also collected when you place an order.
You have the option to update the data in your customer account anytime und to add further details (e.g. your telephone number or date of birth) on a voluntary basis.
The personal data shared by you (title, name, postal address, e-mail address, telephone number, bank details, credit card number) are stored lawfully and as specified by the applicable data protection provisions. Your data will, of course, be treated confidentially.
C. DATA PROCESSING AND USE
Your personal data will be used, first and foremost, to perform the agreements concluded between you and us, such as delivering products to the address provided by you. Furthermore, your data may be used for purposes of internal marketing research or designing our product line to meet our customers' needs, as well as for sending e-mails containing information about our product line. You may also use our Website anonymously or under a pseudonym where this is technically possible and reasonable. Your data will be transferred to Switzerland, where it will be stored safely in accordance with all applicable laws.
For purposes of delivering goods and processing payments, we transmit the necessary data to logistics companies and payment service providers. These service providers are carefully selected. They are also obligated to treat your data confidentially and to use them exclusively for purposes of making deliveries or processing payments, as applicable.
For purposes of market research and to design our product line in a goal-oriented manner so as to meet our customers' needs on all our sales channels, your data, which have been collected via several different communications channels and systems for mail order, over-the-counter trade and online trade, will be merged into a centralized electronic customer database, analyzed and used for marketing campaigns. You may object to the use of your data for market research purposes at any time.
Furthermore, unless this Privacy and Data Protection Policy specifies otherwise, we will only disclose your personal data to third parties if we are authorized or obligated to do this based on legal provisions or official or court orders or if you have given us your express consent to do this.
In this Section, the term "our product line" refers to both the product line of Mammut Sports Group Inc. and the product line of affiliates of Mammut Sports Group Inc. Likewise, the term "market research" refers to market research conducted both for Mammut Sports Group Inc. and for affiliates of Mammut Sports Group Inc.
D. IDENTITY AND CREDIT CHECK
If we are required to provide our service in advance, for example, in case of a purchase on account, we may carry out a credit check with a credit agency in order to uphold our justified interests on the basis of mathematical and statistical processes, if applicable. To this end, Mammut will provide your name, postal address, shopping cart, the invoice amount, your customer history (i.e., whether, by the time of the purchase, Mammut has had positive or negative payment experiences with you), and, if direct debit is used, your bank details and, if necessary, your date of birth, to carefully selected service providers. These service providers will verify whether any negative indicators exist regarding your credit and then determine your "score value". The "score value" utilises known empirical values and a mathematical statistical procedure, including the use of postal address data, to predict the risk of potential non-payment. If the outcome of the credit check is negative, you will only be offered the option to use payment methods in connection with which we do not provide our service in advance. If the outcome of the credit check is positive, we will provide the service in advance. The legal bases for the disclosure of your personal data to selected service suppliers and for processing the scoring value are our legitimate interests, particularly protecting against non-payment and preventing fraud, as well as the legitimate interests of consumers, such as protecting against excessive debt.
If you choose one of the payment options of our partner Klarna Bank AB (publ), Sveavägen 46, 111 34 Stockholm, Sweden, you will be asked during the ordering process to agree to the transmission to Klarna of the data necessary for the processing of the payment and for an identity and credit check. If you give your consent, your data (name, surname, street, house number, postal code, city, date of birth, telephone number and, in the case of direct debit purchases, the bank account details provided) and data relating to your order will be transmitted to Klarna.
Klarna may also use third party tools to detect and prevent fraud. Data obtained with these tools may be stored by third parties in encrypted form so that they can only be read by Klarna. Only if you select a payment method of our cooperation partner Klarna, this data will be used, otherwise the data will expire automatically after 30 minutes. The legal basis for processing and transmission is the consent.
By registering for the Mammut Newsletter, you expressly authorize us to use your e-mail address (including metadata) for internal advertising purposes. You can object to delivery of the newsletter and the use of your e-mail address for advertising purposes with prospective effect at any time by clicking on the link included in the newsletter or in the promotional e-mails or via e-mail to firstname.lastname@example.org. We will also notify you of this right of objection separately in the e-mail that accompanies our newsletter and in all other promotional e-mails.
F. DATA COLLECTION TECHNOLOGIES
Pages of our Website and/or e-mail communications may contain small electronic files known as web beacons that allow us, for example, to count users who have visited those pages or opened an e-mail and for other related website statistics.
G. THIRD PARTY TRACKING TECHNOLOGIES
This Website uses Google Analytics, a web analysis service of Google Inc. ("Google", www.google.com) and Econda Shop Monitor from Econda GmbH ("Econda", www.econda.de). We do not control these third parties’ tracking technologies or how they may be used.
Google Analytics uses "cookies", text files that are stored on your computer and make it possible to analyse your use of the Website. The information generated by the cookie regarding your use of this Website is normally transferred to one of Google's servers in the USA and stored there. Note that the local authorities may access these data. However, if IP anonymization is activated on this Website, your IP address will be abbreviated beforehand. We thus collect and store data anonymously, from which we create pseudonymous user profiles. Only in exceptional cases will the full IP address be transferred to one of Google's servers in the USA and abbreviated there. Google will utilise this information on behalf of the operator of this Website to analyse the use of this Website, compile reports on Website activity and to provide its operator with additional services related to the use of the Website and of the Internet. The IP address transmitted by your browser in connection with Google Analytics will not be combined with other Google data. You can find additional information about data protection at Google here: https://www.google.com/intl/en/policies/privacy/partners. You can prevent the storage of cookies by configuring your browser software appropriately; however, please note that, if you do this, you may not be able to use all of this Website's features to the fullest extent.
You can also prevent the data generated by the cookie regarding your use of the Website (including your IP address) from being recorded and transferred to Google and from being processed by Google by downloading and installing the browser plugin via the following link: tools.google.com/dlpage/gaoptout.
To ensure the tailored design and optimum performance of this website, solutions and technologies by econda GmbH (www.econda.de) not only collect and store anonymized data, but also utilize this data to compile usage profiles by means of pseudonyms. Cookies can be used for this purpose which make it possible for an Internet browser to be recognized. Without the express consent of a visitor, however, usage profiles will not be stored together with data pertaining to the pseudonymous visitor. IP addresses, in particular, are rendered indecipherable immediately after receipt, which makes it impossible to match a usage profile with an IP address. Visitors to this website can opt out at the following link: http://www.econda.com/econda/company/data-protection/.
If you have any other questions about the use of your personal information by Google or Econda, please contact them directly.
H. USE OF SOCIAL PLUGINS
On the Website, we use "social plugins", e.g. from Facebook, Twitter, Google etc., which bear the logo of the respective provider.
If you call up a page on our Website that contains one of these social plugins, a direct connection to the provider's computer will be set up via your computer's browser. The plugin's content is transferred by the provider directly to your computer and integrated into the web page by your browser. The provider thereby receives notification that you have called up the relevant Mammut Website. If you are simultaneously logged on to the respective provider, this provider may also add your visit to your profile. If you interact with the plugins by, e.g., pressing on a Like button or posting a comment, the corresponding information is sent by your browser directly to the provider and stored there. If that process is prevented, you have to log off the provider of the social plugin before visiting our Website. However, this does not rule out the possibility that the providers of a social plugin will collect data anonymously and set a cookie on your computer as soon as you log in via that plugin. The data collected in this manner may subsequently be added to your profile as soon as you log on to the provider. If you want to prevent this, you can activate the option "Block cookies from third-party providers" in your browser settings. In case of integrated content, your browser will then not send any cookies to the server. However, if you select this setting, other features of our Website may no longer function.
I. DATA SECURITY
Your payment data are protected in the course of transmission to our servers by using SSL security procedures (Secure Socket Layer) in connection with 256-bit encryption. You can check the security of the connection using the information in your browser's URL display. If the start of the address line changes from "http" to "https", the connection is secure.
Furthermore, all service providers used for purposes of processing payments are PCI-DSS certified (Payment Card Industry Data Security Standard). By complying with the PCI Data Security Standards, they fulfil the most stringent requirements of e-Commerce industry standards. More information about this is available, for instance, at www.pcisecuritystandards.org.
J. RIGHT TO INFORMATION, CORRECTION, BLOCKING OR DELETION, ETC.
To the extent required by law, you have the right to obtain information free of charge regarding your stored data, and, if applicable, the right to the correction or deletion of this data.
Should you have any additional questions concerning data protection and the processing of your personal data, please e-mail us at email@example.com. Of course, you may also use the contact details provided in the “Contact Us” section of the Website.
Mammut Sports Group Inc. reserves the right to amend this Privacy and Data Protection Policy from time to time.