Privacy Policy

Data we collect and how we collect it

We collect data directly from individuals and we never purchase or acquire data outside of the public domain. We collect, process and store data of employees, prospective employees, partners, customers of this site and 3rd party suppliers.

We never collect sensitive or special category data other than to satisfy additional laws outside of data protection such as employment law or when you give it to us directly. 

Here is a useful table:

Data

Customers

Partners

3rd Party Suppliers

Name

Address

Email

Phone number

Purchase history

IP Address*

*when visiting our website

Data we collect for employment purposes can be found within our employee contracts and full data protection policy. This notice relates directly to customers of this site.

Customers = customers who visit this website, receive marketing via email or SMS and place orders with us

3rd Parties = suppliers of goods or services to us

Employee = someone who works for us

Prospective employee = someone who has applied for or has been approached directly by us for a vacant job role 

 

Your Privacy Choices and Rights

Your choices

You can choose not to provide us with personal data. If you choose to do this, you can continue to use this website(s) and browse its pages, but we will not be able to process transactions or continue a relationship without personal data.

You can block cookies by activating a setting on our cookie banner allowing you to refuse cookies. You can also delete cookies through your browser settings. If you turn off cookies, you can continue to use the website(s) and browse its pages. See the cookie section below for further detail.

You can opt out from marketing by clicking the unsubscribe option in any of our marketing communications. 

Your rights

You can exercise your rights by sending us an email.

You have the right to access information we hold about you. This includes the right to ask us supplementary information about:

  • the categories of data we’re processing
  • the purposes of data processing
  • the categories of third parties to whom the data may be disclosed
  • how long the data will be stored (or the criteria used to determine that period)
  • your other rights regarding our use of your data

We will provide you with the information within one month of your request, unless doing so would adversely affect the rights and freedoms of others (e.g. another person’s confidentiality or intellectual property rights). We’ll tell you if we can’t meet your request for that reason.

You have the right to make us correct any inaccurate personal data about you. 

You can object to us using your data for profiling you or making automated decisions about you

We will use your data to determine whether we should let you know information that might be relevant to you (for example, tailoring emails or social media advertising to you based on your behaviour). 

You have the right to port your data to another service. We will give you a copy of your data in CSV format so that you can provide it to another service. 

If you ask us and it is technically possible, we will directly transfer the data to the other service for you. We will not do so to the extent that this involves disclosing data about any other individual. 

You have the right to be ‘forgotten’ by us. You can do this by asking us to erase any personal data we hold about you, if it is no longer necessary for us to hold the data for purposes of your relationship with us or any other law.

These rights apply to all of the data categories listed in the ‘Data we collect and how we collect it’ section

Security

We do everything we can to ensure the security of your data.

In today’s data driven and connected world the security of your data is more important than ever. We recognise this and have implemented security to keep your data safe.

All staff are bound by confidentiality and will never disclose or share your data unless authorised to do so. 

Our data protection role

We are a controller in relation to your data, we are not a processor or a sub processor of any other brand of company. As a controller we use 3rd parties to process data, please see below in the 3rd parties section.

Where is your data stored?

Like most companies we utilise 3rd parties to provide services to our customers and to store data. A list of the 3rd parties who process personal data is listed below.

These 3rd parties will be based in the UK, EEA and in some cases outside of the both the UK and EEA. 

We conduct thorough reviews of all of its 3rd parties, including data protection agreements, where possible to ensure that every possible safeguard is in place and that the data is secure. Should there be a possibility that data could be exposed to a high level of risk a Data Protection Impact Assessment will be completed and will be available upon request. 

3rd parties

We work with a number of 3rd parties to offer ecommerce solutions in order to be able to offer online shopping to our customers, most of which do not process customer data in any way, below is a list of those who have access to or process your data and a brief description of what they do.

3rd Party

Brief Description

Vvast

Vvast manages the full ecommerce solution for HUF Europe in the UK and EEA. When you shop online with us, Vvast will process and fulfil your order.

Brightpearl

Digital operations platform that integrates with Shopify

Meta

Advertising of brand products via lookalike audiences, cookies/pixels and custom audiences

Google

Analytics via cookie/pixel information

Hectic Numbers

Provides trade reporting 

Klaviyo

Marketing via brand website sign up

PayPal

Payment processor. We do not share data with Paypal, you will be re-directed to Paypal when using this service

RIF

Warehouse, stock and delivery fulfilment

Shiptheory

Shipping integration and label printing

Shopify

The platform that this website is built upon, Shopify also allows us to via Analytics of customer spend and habits via necessary cookies

 

Marketing

We would love to keep in touch with you and when you sign up to receive marketing and/or open an account with us we will send you emails, SMS messages (where you have submitted your phone number) and will also display customised Facebook advertising when you log in to your Facebook profile. 

These messages will be specific to activities of HUF, we do not sell your data or share it with other brands for advertising purposes, your data is used only to promote our goods and offers when signing up to marketing.

Our marketing messages are sent via Klaviyo, a specialist ecommerce marketing tool. You can opt out of marketing at any time by clicking the unsubscribe link in your emails and SMS messages or by contacting us directly. 

There will be occasions when we send administrative messages such as order updates, these messages are not deemed to be marketing and cannot be opted out of.

Marketing and administration emails that you receive from us will contain a tracking pixel. This pixel lets us know things such as the open rates and click rates of our email campaigns.

The pixel also lets us know if an email has not been delivered so that we are able to update our records and keep them current.

When we analyse the data we do so from an aggregated perspective, meaning that we report upon an overall number of open rates and click rates. 

We use Klaviyo to send our marketing and administration emails and you can find out more about how Klaviyo secures your data by following this link: https://www.klaviyo.com/legal 

When a purchase is made or you add an item to your cart you will notice that the marketing preference box is pre ticked. This is because we rely on a soft opt in to promote further, similar goods to you. 

If you wish to opt out of these messages please untick this box at cart stage, of course, you can unsubscribe from marketing at any point.

Payment processing

We do not collect your payment details or process them in any way. Our payment platform is powered by Shopify Pay. The use of PayPal and/or Apple Pay is user defined based on a direct relationship with either or both companies, all data processed by PayPal and Apple is done by you as a customer with no processing from us. 

How long is your data stored?

Once per year we perform a full cleanse of data to ensure that we are only processing the data of those individuals who have an ongoing and active relationship with us. 

As part of our Record of Processing Activities we have defined the length of time we store all of our data, should your data be due for deletion it will be erased during the yearly data cleanse. 

To understand data retention in relation to your data please feel free to contact us at hello@hufworldwide.eu

Cookies

To further improve your shopping experience, we store information about you using cookies which are files sent by us to your computer or other access device which we can access when you visit our site at some point in the future.  

The cookies we use enable us to save your bag for later, track the opening of our emails, for example. We use a number of different cookies on our site. If you do not know what cookies are or how to control or delete them then we recommend that you visit http://www.aboutcookies.org for detailed guidance.

There are four main types of cookies we store – here’s how and why we use them.

(1) Site functionality cookies (necessary) – these cookies allow you to navigate the site and use our features, such as “Add to Bag” and “Save for Later”.

(2) Site analytics cookies – these cookies allow us to measure and analyse how our customers use the site, to improve both its functionality and your shopping experience.

(3) Customer preference cookies – when you are browsing or shopping on this website, these cookies will remember your preferences (like your language or location), so we can make your shopping experience as seamless as possible, and more personal to you.

(4) Targeting or advertising cookies – these cookies are used to deliver ads relevant to you. They also limit the number of times that you see an ad and help us measure the effectiveness of our marketing campaigns.

You can manage your cookie preferences via the cookie banner.

First Party Cookies

These are cookies that are set by this website directly.

We use Persistent Basket Cookie to remember what you have put into your shopping basket over an extended period of time. This Cookie only stores basic data about your basket strictly for use by our website.  The cookie has an expiration of 90 days to 24 months.

We use a session cookie to remember your log in for you if you are a registered user and we deem these as being strictly necessary to the working of the website. If these are disabled then various functionality on the site will be broken.

Third Party Cookies

Our website may also use a website recording service which may record mouse clicks, mouse movements, page scrolling and any text keyed into website forms. Data collected by this service is used to improve our website usability. The information collected is stored and is used for aggregated and statistical reporting, and is not shared with anybody else.

Governing Law

  1. The terms and conditions shall be governed by and construed in accordance with the laws of England and you irrevocably submit to the exclusive jurisdiction of the courts of England and Wales

We use a number of different cookies on our site. If you do not know what cookies are or how to control or delete them then we recommend that you visit http://www.aboutcookies.org for detailed guidance.

Further Information:

More information on session cookies and what they are used for can be found here, All About Cookies  

To view a list of the cookies that are present when browsing our site you can right click within the browser page, click inspect and then click application.

Breaches

Should a breach of your data occur that is likely to result in the harm to the rights and freedoms on an individual or group of individuals we will notify those involved within 72 hours along with the ICO, where applicable. 

Additional information

We have not appointed a statutory Data Protection Officer as we are not required to by law, however, we have the use of a dedicated Privacy and Compliance Manager to manage our compliance with all applicable EU Data Protection laws via Vvast, who manage our ecommerce solutions.

A Record of Processing Activities (ROPA), in which the lawful basis for processing all of our customer data in the EU is listed is maintained. Wherever Legitimate Interests is relied upon an impact assessment has been created which is available upon demand to those who’s data is included.

If you would like to speak to a human in regard to your data please feel free to email us at hello@hufworldwide.eu and we will be happy to talk further.