Privacy policy
This Privacy Policy explains how **4FASHION INC**, operating the brand **CHRISTIAN RODIN** (“CHRISTIAN RODIN”, “we”, “our” or “us”), collects, uses, stores and protects your personal information when you visit our website, create an account, place an order, contact us or otherwise use our services.
4FASHION INC acts as the **data controller** for the personal data described in this Privacy Policy.
We are committed to protecting your privacy and processing personal data lawfully, fairly and transparently in accordance with applicable data-protection legislation, including the **General Data Protection Regulation (EU) 2016/679 (“GDPR”)**.
This Privacy Policy may be updated from time to time. We encourage you to review it periodically.
## 1. Information We Collect
Depending on how you interact with CHRISTIAN RODIN, we may collect the following categories of personal information:
### Identity Information
This may include:
* first name;
* last name;
* account username;
* title, where provided; and
* other identification information where necessary for fraud prevention or transaction verification.
### Contact Information
This may include:
* email address;
* telephone number;
* billing address;
* delivery address; and
* other contact information you choose to provide.
### Order & Transaction Information
This may include:
* products purchased;
* order history;
* order value;
* delivery information;
* returns and exchanges;
* refunds;
* promotional codes used;
* payment status; and
* correspondence concerning your purchases.
### Payment Information
Payments are processed through secure payment providers.
Where card details are entered through an independent payment provider, CHRISTIAN RODIN does not store or have access to complete payment-card numbers.
We may receive limited transaction information such as:
* payment confirmation;
* payment method;
* transaction reference;
* authorisation status; and
* the last digits of a payment card where supplied by the payment provider.
### Account Information
Where you create an account, we may process information including:
* account login information;
* saved addresses;
* order history;
* preferences; and
* account activity.
### Customer-Service Information
If you contact us, we may retain:
* emails;
* messages;
* customer-service conversations;
* complaints;
* photographs or documents supplied in connection with a claim;
* return requests; and
* other correspondence.
### Technical & Usage Information
When you use our website, we may collect information such as:
* IP address;
* browser type;
* device type;
* operating system;
* pages viewed;
* time spent on pages;
* referring pages;
* interactions with our website;
* cookie identifiers; and
* advertising or analytics identifiers where permitted.
## 2. How We Collect Your Personal Information
We collect personal information directly from you when you:
* place an order;
* create or update an account;
* subscribe to marketing communications;
* contact Customer Service;
* request a return or exchange;
* participate in a promotion;
* submit a review or other content;
* complete forms on our website; or
* otherwise communicate with us.
We may also receive limited personal information from third parties involved in providing our services, including:
* payment providers;
* fraud-prevention providers;
* delivery and courier companies;
* website and e-commerce providers;
* analytics providers; and
* advertising platforms where legally permitted.
## 3. How We Use Your Personal Information
We process personal information only where we have a lawful basis to do so.
### To Process and Fulfil Your Orders
We use personal information to:
* accept and process orders;
* receive and verify payments;
* prepare products for dispatch;
* arrange delivery;
* communicate order updates;
* process returns, exchanges and refunds; and
* provide post-purchase support.
The legal basis for this processing is generally that it is **necessary for the performance of our contract with you**.
### To Provide Customer Service
We may use your information to:
* respond to enquiries;
* resolve complaints;
* provide product information;
* assist with returns or delivery issues; and
* maintain records of our communications.
Depending on the circumstances, processing may be necessary for the performance of a contract, compliance with legal obligations or our legitimate interests in providing effective customer service.
### To Prevent Fraud & Protect Our Business
We may use personal information to:
* verify transactions;
* detect suspicious activity;
* prevent fraud;
* protect our website;
* protect customers;
* enforce our Terms & Conditions; and
* establish, exercise or defend legal claims.
This processing may be based on our **legitimate interests** in protecting our customers and business, or on compliance with legal obligations.
### To Meet Legal & Regulatory Obligations
We may retain or disclose information where necessary to comply with:
* tax requirements;
* accounting obligations;
* consumer-protection laws;
* law-enforcement requests;
* court orders; and
* other legal or regulatory requirements.
The legal basis for this processing is **compliance with a legal obligation**.
### Marketing
Where permitted by law, we may use your email address or other contact details to send you information about:
* new collections;
* product launches;
* special offers;
* events;
* promotions; and
* other CHRISTIAN RODIN news.
Where consent is required, marketing communications will only be sent after you have provided valid consent.
You may withdraw your consent or unsubscribe at any time by using the unsubscribe link contained in our marketing emails or by contacting us.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal.
## 4. Personalisation & Analytics
We may analyse how customers interact with our website in order to:
* improve the website;
* understand product interest;
* optimise navigation;
* analyse website performance;
* measure the effectiveness of marketing;
* identify technical problems; and
* improve the shopping experience.
Where required, analytics or advertising technologies will only operate after the user has provided the relevant cookie consent.
## 5. Cookies & Similar Technologies
CHRISTIAN RODIN uses cookies and similar technologies.
Cookies are small files placed on your device that allow websites to operate, remember certain information or understand how visitors use the website.
We may use:
**Strictly necessary cookies** — required for the website to function, including checkout, security and account functionality.
**Preference cookies** — used to remember selections and preferences.
**Analytics cookies** — used to understand how visitors interact with the website and improve its performance.
**Advertising and marketing cookies** — used, where permitted, to measure advertising and provide more relevant marketing.
Strictly necessary cookies may be used without consent where legally permitted.
Non-essential cookies requiring consent will only be activated after appropriate consent has been obtained. The EDPB confirms that consent is generally required for storing or accessing non-essential cookies, while strictly necessary cookies are exempt. ([European Data Protection Board][1])
You may manage your cookie preferences using the cookie settings available on our website.
## 6. Sharing Your Personal Information
We do not sell personal information.
We may share personal information with carefully selected third parties where necessary to operate our business.
These may include:
* payment processors;
* banks;
* fraud-prevention providers;
* courier and logistics companies;
* warehouse or fulfilment providers;
* e-commerce and website providers;
* cloud-hosting providers;
* IT and security providers;
* email and marketing platforms;
* analytics providers;
* advertising platforms, where permitted;
* accountants;
* auditors;
* insurers;
* legal advisers; and
* government, regulatory or law-enforcement authorities where legally required.
Third-party processors are authorised to process personal information only as necessary to provide their services to us and are required to protect that information in accordance with applicable data-protection law.
The GDPR distinguishes between the controller, which determines why and how data is processed, and processors acting on its behalf. ([European Commission][2])
## 7. International Data Transfers
Some of our service providers may process information outside Greece or outside the European Economic Area.
Where personal information is transferred outside the EEA, we will take appropriate measures required by applicable law to protect the information.
These may include:
* transferring data to countries recognised as providing an adequate level of protection;
* using European Commission Standard Contractual Clauses; or
* relying on another legally recognised transfer mechanism.
## 8. Data Retention
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including compliance with legal, accounting, tax, fraud-prevention and dispute-resolution requirements.
Retention periods may therefore vary depending on the type of information.
For example:
* order and transaction records may be retained for the period required under applicable tax, accounting and commercial legislation;
* customer-service correspondence may be retained for as long as reasonably necessary to manage the relevant matter;
* marketing information may be retained until consent is withdrawn or the information is no longer required;
* account information may be retained while the account remains active and for an appropriate period thereafter; and
* information relevant to legal disputes may be retained until applicable limitation periods have expired.
GDPR requires personal data to be kept no longer than necessary for the purpose for which it was collected, subject to legal retention requirements. ([European Commission][3])
## 9. Security
CHRISTIAN RODIN and 4FASHION INC use reasonable administrative, organisational and technical measures designed to protect personal information against:
* unauthorised access;
* accidental loss;
* disclosure;
* alteration;
* misuse; and
* destruction.
These measures may include encrypted communications, access controls, secure payment systems and other appropriate safeguards.
However, no internet transmission or electronic-storage system can be guaranteed to be completely secure.
Customers are responsible for protecting their own account passwords and should not share login credentials with others.
## 10. Your Rights Under GDPR
Subject to applicable law, you may have the right to:
* **access** personal information we hold about you;
* **correct** inaccurate or incomplete personal information;
* request **erasure** of personal information in certain circumstances;
* request **restriction** of processing;
* **object** to certain processing;
* receive certain information in a structured, commonly used and machine-readable format under the right to **data portability**;
* withdraw consent at any time where processing is based on consent; and
* object at any time to the use of your personal information for direct marketing.
You may also have rights relating to automated decision-making where applicable.
These rights are established under the GDPR and are explained by the European Commission. ([European Commission][4])
To exercise any of these rights, please contact CHRISTIAN RODIN using the contact details provided below.
We may request reasonable information to verify your identity before processing a request.
We will normally respond to valid requests within the time limits required by applicable law.
## 11. Direct Marketing
You have the right to object to direct marketing at any time.
You may unsubscribe by:
* selecting the **unsubscribe** link in a marketing email; or
* contacting CHRISTIAN RODIN Customer Service.
After unsubscribing, you may still receive communications necessary to administer your account or fulfil your orders.
## 12. Children
The CHRISTIAN RODIN website and online store are not intended for children to independently enter into purchases.
Customers placing orders must be at least 18 years old or otherwise legally capable of entering into the relevant contract.
Individuals under the age of 18 should use the website with the involvement of a parent or legal guardian where appropriate.
We do not knowingly seek to collect unnecessary personal information from children.
## 13. Third-Party Websites
Our website may contain links to websites operated by third parties.
CHRISTIAN RODIN and 4FASHION INC are not responsible for the privacy practices, content or security of third-party websites.
We encourage users to review the privacy policies of any external websites they visit.
## 14. Social Media & Advertising Platforms
Where you interact with CHRISTIAN RODIN through social-media platforms or advertisements, those platforms may process your personal information independently under their own privacy policies.
Where permitted by law and your cookie preferences, we may use technologies supplied by advertising platforms to:
* measure advertising performance;
* understand website conversions;
* create advertising audiences; and
* show relevant advertisements.
Where consent is legally required for such technologies, they will not be activated before consent is obtained.
## 15. Automated Decision-Making
We do not ordinarily make decisions producing legal or similarly significant effects solely through automated processing.
Certain automated systems may nevertheless be used for purposes such as fraud detection, transaction security or website personalisation.
Where GDPR grants specific rights in relation to automated decision-making, those rights will be respected.
## 16. Changes to Your Information
You are responsible for ensuring that personal information provided to CHRISTIAN RODIN is accurate and up to date.
Where an account facility is available, certain information may be updated directly through your account.
Alternatively, you may contact Customer Service to request correction of your information.
## 17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect:
* changes to our services;
* changes in technology;
* changes to our business practices; or
* changes in legal or regulatory requirements.
Any updated Privacy Policy will be published on our website.
Where a change materially affects how we use personal information, we will take appropriate steps to notify users where required by law.
## 18. Your Right to Lodge a Complaint
If you have concerns about how your personal information is processed, we encourage you to contact us first so that we can address the matter.
You also have the right to lodge a complaint with the competent data-protection supervisory authority.
For matters falling within its jurisdiction in Greece, this is the:
**Hellenic Data Protection Authority (HDPA)**
The HDPA accepts complaints concerning alleged violations of GDPR and other applicable data-protection legislation. ([dpa.gr][5])
## 19. Contact & Data Controller
The data controller is:
**4FASHION INC**
Operating the brand **CHRISTIAN RODIN**
**Registered Address:** [INSERT REGISTERED BUSINESS ADDRESS]
**Privacy / Customer Service Email:** [INSERT CHRISTIAN RODIN EMAIL]
For questions concerning this Privacy Policy, your personal information or the exercise of your data-protection rights, please contact us using the details above.