PRIVACY POLICY
1) INFORMATION ON THE COLLECTION OF PERSONAL DATA AND CONTACT DETAILS OF THE CONTROLLER 1.1 Thank you for visiting our website and for your interest in our store. Below, we inform you about the handling of your personal data when using our website. Personal data is any information with which you could be personally identified. 1.2 The data controller in charge of data processing on this website, within the meaning of the Personal Information Protection and Electronic Documents Act (PIPEDA) and the General Data Protection Regulation (GDPR), is Sophie Montreal. The data controller is the natural or legal person who alone or jointly with others determines the purposes and means of the processing of personal data. 1.3 For security reasons and to protect the transmission of personal data and other confidential content (e.g., orders or inquiries), this website uses SSL or TLS encryption. You can recognize an encrypted connection by the "https://" prefix and the lock symbol in your browser's address bar.
2) DATA COLLECTION WHEN VISITING OUR WEBSITE When using our website for information purposes only (i.e., if you do not register or otherwise provide us with information), we only collect data that your browser transmits to our server (so-called "server log files"). When you access our website, we collect the following data that is technically necessary for us to display the website to you:
-
Our visited website
-
Date and time at the moment of access
-
Amount of data sent in bytes
-
Source/reference from which you came to the page
-
Browser used
-
Operating system used
-
IP address used (if applicable, in anonymized form)
Processing is carried out based on our legitimate interest in improving the stability and functionality of our website. The data will not be passed on or used in any other way. However, we reserve the right to check the server log files retrospectively should concrete evidence point to illegal use.
3) COOKIES To make visiting our website attractive and to enable the use of certain functions, we use so-called cookies on various pages. These are small text files that are stored on your end device. Some of the cookies we use are deleted after the browser session ends, i.e., after you close your browser (session cookies). Other cookies remain on your device and enable us or our partner companies (third-party cookies) to recognize your browser on your next visit (persistent cookies). Some cookies serve to simplify the ordering process by saving settings (e.g., remembering the contents of a virtual shopping cart for a later visit). If personal data is also processed by individual cookies implemented by us, the processing is carried out for the execution of the contract or to safeguard our legitimate interests in the best possible functionality of the website. You can set your browser to inform you about the setting of cookies and individually decide on their acceptance or exclude the acceptance of cookies for certain cases or in general. Please note that if cookies are not accepted, the functionality of our website may be limited.
4) CONTACTING US Personal data is collected when you contact us (e.g., via contact form or email at support@sophie-montreal.com). The data collected via a contact form can be seen from the respective form. This data is stored and used exclusively for the purpose of responding to your request or for establishing contact and the associated technical administration. Your data will be deleted after final processing of your inquiry, provided that there are no statutory retention requirements to the contrary.
5) DATA PROCESSING WHEN OPENING A CUSTOMER ACCOUNT AND FOR CONTRACT EXECUTION Personal data will continue to be collected and processed if you provide it to us for the execution of a contract or when opening a customer account. The data collected can be seen from the respective input forms. Deletion of your customer account is possible at any time and can be requested by sending a message to the controller's address. We store and use the data provided by you for contract processing. After the complete processing of the contract or deletion of your customer account, your data will be blocked with respect to tax and commercial retention periods and deleted after the expiration of these periods.
6) USE OF YOUR DATA FOR DIRECT MARKETING 6.1 Subscription to our Email Newsletter If you subscribe to our email newsletter, we will regularly send you information about our offers. The only mandatory information for sending the newsletter is your email address. We use the double opt-in procedure. This means that we will only send you an email newsletter after you have explicitly confirmed that you consent to receiving it. You can unsubscribe from the newsletter at any time via the link provided in the newsletter or by contacting us. 6.2 Sending the Newsletter to Existing Customers If you have provided us with your email address when purchasing goods or services, we reserve the right to regularly send you offers for similar goods or services from our range. You have the right to object to this use of your email address at any time.
7) DATA PROCESSING FOR ORDER FULFILLMENT To fulfill your order, we work with shipping service providers. We pass on your payment data to the commissioned credit institution or payment service provider:
-
PayPal: In the case of payment via PayPal, credit card via PayPal, or direct debit via PayPal, we pass your payment data on to PayPal (Europe) S.a.r.l. et Cie, S.C.A., Luxembourg.
-
Klarna (SOFORT): If applicable, payment processing is carried out via Sofort GmbH (part of the Klarna Group).
8) CUSTOMER REVIEW REMINDER We use your email address as a one-time reminder to submit a review of your order, provided we have your explicit consent to do so. You may revoke your consent at any time.
9) SOCIAL MEDIA AND PLUGINS Our website uses social plugins from social networks (e.g., Facebook, Instagram, Google). To protect your data, we use solutions that only establish a connection to the social network's servers when you actively click on the respective button.
10) ONLINE MARKETING AND WEB ANALYTICS We use Google tools (such as Google Analytics, Google AdWords, and DoubleClick) to optimize our ads and analyze visitor flow anonymously. We also use retargeting tools (such as the Facebook Pixel) to display relevant advertising to you after you visit our website, but only with your prior consent.
11) YOUR RIGHTS Under applicable data protection laws, you have extensive rights regarding the processing of your personal data:
-
Right of Access: Request information about the data we process.
-
Right to Rectification: Correct inaccurate or incomplete data.
-
Right to Erasure: Request the deletion of your data.
-
Right to Restriction of Processing.
-
Right to Data Portability.
-
Right to Revoke Consent.
-
Right to Complain: Lodge a complaint with a supervisory authority (in Canada, the Office of the Privacy Commissioner of Canada - OPC).
12) RIGHT TO OBJECT IF WE PROCESS YOUR PERSONAL DATA ON THE BASIS OF OUR LEGITIMATE INTEREST, YOU HAVE THE RIGHT TO OBJECT TO THIS PROCESSING AT ANY TIME ON GROUNDS RELATING TO YOUR PARTICULAR SITUATION. THE SAME APPLIES TO DIRECT MARKETING.
13) DATA RETENTION PERIOD The duration of the storage of personal data is determined by legal retention periods (e.g., commercial and tax retention periods, which in Canada are typically 6 years as required by the Canada Revenue Agency). After the expiration of this period, the corresponding data will be routinely deleted, provided it is no longer necessary for the fulfillment or initiation of a contract.