NorthQ ApS Principles of Personal Data Processing


Read also: General Terms and Conditions | Terms of Service | Refund Policy | Privacy Policy


GENERAL INFORMATION

We attach great importance to the protection and handling of your personal data in accordance with the applicable law, in particular in accordance with the General Data Protection Regulation of 27 April 2016 ("GDPR"). Our goal is to provide you with full information and control regarding the processing of your data and the availability of tools that allow you to take advantage of the rights arising from the law.


Below we present information on how we process your personal data, how we care for their security and who we share it with. If you have additional questions about how we use your personal data, write to us at the following e-mail address: dpo@northq.com.

HOW HAVE WE ACQUIRED YOUR DATA?

We use your personal data because you:

  • have decided to make purchases in our online store www.store.northq.com ("Store") or agreed to receive commercial information by e-mail to the e-mail address provided by the Store or otherwise you gave us your data using the Store's website. The store operates based on the Regulations, which you can read here.
  • set up an account on our platform HomeManager (“Platform”). The platform operates based on the Regulations, which you can read here.
  • send us a support request (“Ticket”).

WHO IS THE ADMINISTRATOR OF YOUR DATA?

The personal data administrator is NorthQ ApS, Bryggervangen 19, 2.sal, 2100 København Ø, Denmark, VAT DK31048850, which will be further called "Administrator" or "NorthQ".

HOW CAN YOU CONTACT THE DATA PROTECTION OFFICER?

You can send an email to: dpo@northq.com
or a regular mail to:
NorthQ ApS
Att.: Data Protection Officer
Bryggervangen 19, 2.sal
2100 København Ø
Denmark

HOW ARE WE PROCESSING YOUR DATA?

  1. If you use our Store, we will process your personal data for the following purposes:
    1. In order to carry out the sales contracts concluded with you from the Store - the basis for processing your data will be in this case, the contract concluded with the Administrator by accepting the Store's rules. In this respect, we will require the largest amount of data from you, but only to the extent necessary to implement the contract of sale and delivery of purchased goods to you; providing your personal data for this purpose is not mandatory but necessary for the performance of the contract.
    2. In order to keep your account on the Store's website - the basis for processing your data will be the contract concluded with the Administrator by creating an account and accepting the Store's terms and conditions. Creating an account in the Store will also allow you to access the data you have provided, including the history of your purchases, and to exercise certain rights related to data processing; providing your personal data for this purpose is not mandatory but necessary for the performance of the contract.
    3. In order to conduct complaint processes - in this case the basis for processing is the Administrator's obligation resulting from the provision of the law regarding the warranty for defects in the item sold. Providing data in the complaint form is mandatory for the proper consideration of your complaint.
    4. If you express your separate consent, we will send to the e-mail address provided by you commercial information regarding the goods offered for sale in the Store, including promotional offers - in this case the basis for processing is your consent, which is not mandatory and you can withdraw at any time by contacting the above data or clicking on the link that we send in each email containing commercial information. Withdrawal of consent does not affect the correctness of data processing in the period before its withdrawal.
    5. If you express your separate consent, we will send commercial information on the mobile phone number provided by you to the store, including promotional offers - in this case the basis for processing is your consent, which is not mandatory and you can withdraw it at any time, contacting us, for example, on the data given above. Withdrawal of consent does not affect the correctness of data processing in the period before its withdrawal.
    6. For marketing purposes - we may send information on the offer of the NorthQ Store or the offer of our trading partners from time to time to the delivery address provided by you. The basis for the processing of your data in this respect will be the legitimate interest of our or our partners in the marketing of the goods indicated in the offer. You can object to the processing of your data at any time, and we will stop doing so. You can express your opposition by contacting us at newsletter@northq.com.
    7. For statistical purposes for internal needs of the Administrator - in this case, the basis for processing will be the legitimate interest of the Administrator consisting in collecting information enabling the development of activities and customizing services to the needs of the Store's users.
    8. In order to confirm the performance of our obligations and assert claims or defend against claims that may be directed against us, prevent or detect fraud - the basis for processing your data in this case will be the legitimate interest of the Administrator, which is the protection of rights, confirmation of performance and obtaining in this respect due remuneration from the Administrator's clients.
  2. If you use our HomeManager Platform, we will process your personal data for the following purposes:
    1. Service availability - setting up the HomeManager account, from which you will have an access to the services,
    2. Identification of you as a user on the platform,
    3. Service-related communication with you,
    4. Normal operation of the system,
    5. Sending you notifications from the installed devices (e.g. motion detection from the Q-Motion),
    6. Quality of service and reliability,
    7. Identification of your resources and providing budget information to you.

We focus on the transparency of processing your personal data. If you have any question about the process or rules of processing, please contact us.

We process your data in accordance with the law, ensuring that it remains current and correct. Therefore, from time to time we will remind you about the need to update the data by sending a message to the e-mail address provided by you.

Your personal data will not be processed for automated decision making without your consent.

IS PROVIDING PERSONAL DATA MANDATORY?

It is up to you to decide whether and what data you provide us with, but remember that when making purchases in the Store, providing certain data will be mandatory to perform the contract of sale, because without them we will not be able to process your order.

Failure to provide the data we require results in failure to place an order. It is not obligatory to express your consent to receive commercial information at the email address provided or the telephone number provided for the performance of the Goods sales contract concluded. If you give your consent, you will be able to withdraw it at any time.

It is up to you to decide whether and what data you provide us with on HomeManager, but remember that when setting up an account on the Platform, providing certain data will be mandatory to provide you the service, because without them you will not be able to login to your secure account, have access to the functionalities of the Platform, manage and control your integrated devices and/or receive notifications from the devices.

WHO WILL WE SHARE YOUR PERSONAL INFORMATION WITH?

  1. We will pass your data to entities that cooperate with us in the performance of the contract for the sale of goods purchased by you:
    1. We will share your data necessary for the delivery of goods to LEMAN International System Transport A/S (Leman’s Privacy and Cookie Policy: http://leman.dk/cookies) who will share your data with one of the following entities, depending on your choosing how to deliver the goods:
      1. GLS (General Logistics Systems),
      2. DHL Express,
      3. FedEx,
      4. UPS
      5. Other entities that will provide delivery services for goods purchased by you in the Store in the future.
    2. Depending on your choice of payment method for purchased goods, we will share your data necessary for collection or payment for purchased goods to the following entities:
      1. PAYPAL - if you have chosen the PayPal.com payment system as the payment method (PayPal’s Privacy Policy: https://www.paypal.com/en/webapps/mpp/ua/privacy-full),
      2. BAMBORA (EPAY.EU) - if you have chosen the epay payment system as the payment method,
      3. BAMBORA (EPAY.EU) - if you have chosen the embedded credit card payment solution as the payment method (Bambora’s Privacy Policy: https://www.bambora.com/en/en/compliance/privacy-policy/), If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.

All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover. PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers. For more insight, you may also want to read Shopify’s Terms of Service (https://www.shopify.com/legal/terms) or Privacy Statement (https://www.shopify.com/legal/privacy).

    1. If you have agreed to receive commercial information on the e-mail address or telephone number provided by you, we will share your information with the entities providing on our request with the service of sending commercial information, such as:
      1. MailChimp (MailChimp’s Privacy Policy: https://mailchimp.com/legal/privacy/)
      2. HubSpot (HubSpot’s Privacy Policy: https://legal.hubspot.com/legal-stuff)
    2. Your data will be transferred to entities that process our clients' personal data at our request, to the extent necessary to host the Store's website: Shopify (Shopify’s Privacy Policy: https://www.shopify.com/legal/privacy),
    3. In addition, your data will be transferred to entities that process our clients' personal data at our request, to the extent necessary to provide support to our customers via NorthQ’s websites: Zendesk (Zendesk’s Privacy Policy: https://www.zendesk.com/company/customers-partners/privacy-policy/),
    4. We may also share your personal data with other entities from the above categories with which we will establish cooperation.

HOW LONG WILL WE BE PROCESSING YOUR PERSONAL DATA?

The personal data provided by you will be processed by you in the period:

  • Necessary for the implementation of the contract of sale, as well as your claims for claims, as well as confirmation of our obligations and pursuing claims or defending against claims that may be directed against us - however not longer than 10 years from the date you provided us with your data,
  • In the event that you submit a request to delete your account in the store, we may process your data within the time necessary to confirm our obligations and claim or defend against claims that may be directed against us - no longer than 10 years from the date of transferring us by you your data.
  • Necessary for the use of HomeManager Platform, we will be processing your data as long as the service is required.

HOW ARE WE PROTECTING YOUR DATA?

We use a range of IT and organizational security measures aimed at minimizing the risk of data leakage, their destruction and disintegration, such as: firewall system, cyber security good practices, internal access procedures, data processing and emergency recovery, as well as a multi-level backup system.

Our Platform and Apps are using: Amazon Web Services (AWS), Hetzner, Nabto, Push notification services (Google Cloud Messaging, Apple Push Notification service, Firebase Cloud Messaging), Google+ G Suite. All of the aforementioned services are trusted platforms with big communities. NorthQ is using latest security standards in order to use, build on top off and/or integrate with those services.

Our Store operates on a Shopify platform with a very high level of security and we use a high level of encryption HTTPS/SSL connection in accordance with accepted best practices, we work with a carefully selected hosting provider that has certificates in accordance with ISO 9001 quality management and AQAP-2110 requirements as well as the information security management certificate according to ISO/IEC 27001. Remember that using the Internet always brings with it the risk of certain security incidents, but we assure you that thanks to the implemented regular procedures reviews of information systems and their updates, and active monitoring of critical points of the system, we want to reduce this risk as much as possible.

WHAT RIGHTS DO YOU HAVE IN RELATION TO THE PROCESSING OF YOUR PERSONAL DATA BY US?

According to GDPR, you have a number of rights in connection with providing your personal data to us, such as:

  1. The right to know how your personal data is processed - if you have questions about whether and how we process your data, please contact us by sending information to dpo@northq.com, we will be happy to answer them,
  2. The right to access and update data - you always have access to your personal data on your account in the Store and on the Platform (or via App). You can edit the data provided to us and update it. If you have not created an account in the Store or on the Platform, please contact us by writing to our Data Protection Officer requesting access to your data - we will inform you about your data and update it at your request,
  3. Under the terms of GDPR, you also have the rights to:
    1. Data deletion - if you want us to stop processing your data, you can delete your account in the Store or on the Platform or report such a request to us. Remember, however, that this is not an absolute right and we may refuse to delete your data about which we have a basis for its processing (eg the fulfillment of a legal obligation or pursuing claims or defending against claims that may be directed against us),
    2. Request to limit the processing of your data,
    3. Object to the processing of your data if the basis for processing is a legitimate interest of the Administrator or performance of tasks in the public interest,
    4. Withdrawal of consent, if the data is processed on the basis of your consent,
    5. Data transfer, if the processing is based on a contract or your consent.

You can do all the above rights by contacting our Data Protection Officer (email: dpo@northq.com).

HOW LONG TIME WILL IT TAKE FOR YOU TO GET THE ANSWER FROM US?

We will try to complete your requests as quickly as possible and answer your questions about your data. In any case, you should receive a message from us not later than within 30 days of receiving your request. During this period we will give you an answer or inform you about the extension of the deadline and explain the reasons. If we have doubts as to whether you are making a specific request, we may ask a few more questions to verify your identity.

INFORMATION ON THE COMPETENT AUTHORITY TO BRING A COMPLAINT

If you feel that we are processing your personal data unlawfully, you can also file a complaint with Data Protection Agency in Denmark (https://www.datatilsynet.dk/).

If you have any questions related to the processing of your personal data by us or you want to use the rights resulting from the GDPR, please use the contact form or write directly to our Data Protection Officer: dpo@northq.com.

INFORMATION ON THE USE OF "COOKIES"

DEFINITIONS

  1. Administrator - means NorthQ ApS, Bryggervangen 19, 2.sal, 2100 København Ø, Denmark, VAT DK31048850 (CVR: 31048850), which provides electronic services and stores and gains access to information on User devices,
  2. Website - means a website or application under which the Administrator runs a website that operates in the following domains: http://northq.com/, https://store.northq.com, https://homemanager.tv.
  3. Cookies - means IT data, in particular small text files, saved and stored on devices through which the User uses the Website pages,
  4. Administrator's Cookies - means Cookies placed by the Administrator related to the provision of electronic services by the Administrator via the Website.
  5. External Cookies - means Cookies placed by the Administrator's partners via the Website,
  6. Device - means an electronic device through which the User gains access to the Website,
  7. User - means an entity for which services may be provided electronically or with which an Agreement for the provision of electronic services may be concluded in accordance with the Regulations and legal regulations.

TYPES OF COOKIES USED

  1. Cookies used by the Administrator are safe for the User's Device. In particular, it is not possible for viruses or other unwanted software or malicious software to enter User Devices. These files allow to identify the software used by the User and adjust the operation of the Website individually to each User. Cookies usually contain the name of the domain from which they originate, their storage time on the Device and the assigned value.
  2. The administrator uses two types of cookies:
  3. a) SESSION COOKIES: they are stored on the User's Device and remain there until the session of the given browser ends. The saved information is then permanently removed from the Device's memory. The mechanism of session cookies does not allow the collection of any personal data or any confidential information from the User's Device,
  4. b) PERMANENT COOKIES: they are stored on the User's Device and remain there until they are deleted. Ending the session of a given browser or turning off the Device does not delete them from the User's Device. The mechanism of persistent cookies does not allow the collection of any personal data or any confidential information from the User's Device.
  5. The User has the ability to limit or disable the access of cookies to his Device. If you use this option, the use of the Website will be possible, in addition to functions that, by their nature, require cookies.

THE PURPOSES FOR WHICH COOKIES ARE USED

  1. THE ADMINISTRATOR USES OWN COOKIES IN FOLLOWING PURPOSES:
    1. SERVICE CONFIGURATION
      1. adjusting the content of the Website pages to the User's preferences and optimizing the use of the Website pages,
      2. recognize the Website User's device and its location and properly display the website, adapted to his individual needs.
    2. AUTHENTICATION OF THE USER ON THE WEBSITE AND PROVIDING THE USER'S SESSION ON THE SERVICE
      1. maintaining the Website User's session (after logging in), thanks to which the User does not have to re-enter their login and password on every subpage of the Website;
      2. correct configuration of selected Website functions, allowing in particular verification of the authenticity of the browser session,
      3. optimizing and increasing the efficiency of services provided by the Administrator.
    3. IMPLEMENTATION OF PROCESSES NECESSARY FOR FULL FUNCTIONALITY OF WEBSITES
      1. adjusting the content of the Website pages to the User's preferences and optimizing the use of the Website pages. In particular, these files allow to recognize the basic parameters of the User's Device and properly display the website, tailored to his individual needs;
      2. proper operation of the affiliate program, allowing in particular verification of sources of Users' redirects to the Website's websites,
      3. enabling the use of the "Clipboard" and "Cart" functions on the Website.
    4. ANALYSIS AND TESTS AND WATCH AUDIT
      1. creating anonymous statistics that help to understand how the Website Users use Website pages, which allows improving their structure and content.
    5. ENSURING SAFETY AND RELIABILITY OF THE SERVICE
  2. THE SERVICE ADMINISTRATOR USES EXTERNAL COOKIES IN FOLLOWING PURPOSES:
    1. presenting multimedia content on the Website, which is downloaded from an external website, e.g. youtube,
    2. collecting general and anonymous static data via analytical tools, e.g. Google Analytics,
    3. logging in to the website using a social website, e.g. Facebook.com,
    4. use interactive functions to popularize the Website using social networking sites, including such as Facebook.com, Twitter.com,
    5. using the functions to facilitate communication via the Website, which are downloaded from an external internet service such as Zendesk Chat.

THE POSSIBILITY OF DETERMINING THE CONDITIONS FOR STORING OR ACCESSING COOKIES

  1. The User may independently and at any time change the settings for Cookies, specifying the conditions for their storage and access to the User's Device via Cookies. Changes to the settings referred to in the previous sentence, the User can make using the web browser settings. These settings can be changed in particular in such a way as to block the automatic handling of cookies in the web browser settings or to inform them whenever Cookies are placed on the User's device. Detailed information about the possibilities and ways of handling cookies are available in the software (web browser) settings.
  2. The User may at any time delete cookies using the functions available in the web browser he uses.
  3. Limiting the use of cookies may affect some of the functionalities available on the websites of the Services.

Published on 24.05.2018