Privacy policy
1. In General
We are committed to protecting the data privacy and security of our customers and those who visit our website, and we therefore take great care to ensure that your personal data is handled responsibly. This Privacy Policy describes how ENVII ApS (hereinafter “ENVII”, "we", "us" or "our") collects and processes information about you.
The data controller responsible for your personal information is:
ENVII ApS
CVR 29781135
Ryesgade 19A
2200 København N
Denmark
If you have any questions regarding our processing of your personal data, please contact our Customer Care team here: customercare@envii.com.
2. WHAT PERSONAL DATA WE COLLECT, FOR WHAT PURPOSE, AND ON WHAT LEGAL BASIS
ENVII only process your personal data when there’s a purpose and legal basis for it.
2.1 VISITORS OF ENVII.COM AND USERS OF ONLINE SERVICES
When you visit ENVII’s website (envii.com), we may process information about you and your visit. This includes information about how you access our websites, how you navigate around them, which pages you visit, content you view, your searches, advertisements you have seen, your IP address, information about your computer, etc. Personal data is collected through cookies, log files, and other technologies (you can read more about our use of cookies here).
We also process personal data that you provide to us in connection with your use of our online services or contact form on envii.com, including your name, phone number, email, order number, case information and transaction history, and any other information you provide to us.
2.1.1 The purpose is to improve your experience of our websites and online services by making relevant products, supplies, benefits, and services available to you. We also use personal data to show you content on our and other sites based on your activities and preferences, and to limit the number of times you see the same content.
2.1.2 The legal basis for the processing is your consent of our use of cookies (Article 6(1)(a) of the General Data Protection Regulation and Section 3 of the Danish Executive Order on Cookies), and our legitimate interest in improving our website and being as relevant to you as possible (Article 6(1)(f) of the General Data Protection Regulation).
2.2 Customers of ENVII
When you are a customer of ENVII, and purchase a product via our webshop, we collect and process the personal information you provide. This information includes your first name, last name, address, phone number, email, country, city, zip code, your purchases, payment method, transaction history, case information, and other information that you provide to us.
2.2.1 The purpose is to comply with legal requirements and fulfil the agreement with our customers, including being able to deliver the products you have ordered, manage your rights to return and complain, and provide the services, invoicing, statistics, and analyses to improve our products and services, maintaining our customer records and providing general service, marketing and sales to our customers.
2.2.2 The legal basis for the processing is the fulfilment of our mutual agreement on purchases from ENVII (Article 6(1)(b) of the General Data Protection Regulation), our obligation to comply with legal requirements for returns and bookkeeping (Article 6(1)(c) of the General Data Protection Regulation), and our legitimate interest in managing your information as a customer (Article 6(1)(f) of the General Data Protection Regulation).
2.3 Visitors of ENVIIs stores
When you visit one of our physical ENVII stores or our other locations (head office and warehouse), CCTV surveillance may be set up. If there’s CCTV surveillance, a pictogram (with a picture of a camera) will be displayed in a visible place at the location. The recordings are reviewed by random checks, specific suspicions or other irregularities and passed on to the police if there is suspicion of a criminal offence.
2.3.1 The purpose of the CCTV surveillance is to give us the opportunity to prevent, detect and document offences in relation to both visitors and staff (robbery, theft, assault, fraud, disagreements regarding payment, etc.), irregularities in connection with cash transactions and similar in the stores, as well as to provide safety and security for the staff.
2.3.2 The legal basis for the processing is our legitimate interest in preventing the types of crime mentioned in section 2.3.1 in our physical stores and other locations (Article 6(1)(f) of the General Data Protection Regulation).
2.4 Recipients of targeted marketing
When you receive targeted marketing communication, including newsletters from ENVII, we process personal data that you have shared with us such as your first name, last name, email, country, gender and birthday.
We will only send you marketing material by email, text messages or other electronic means if you have given your consent where this is required under the Danish Marketing Practices Act.
2.4.1 The purpose is marketing of our company and services and setting up and managing your marketing subscription. We use personal data to show you content on our and other sites based on your activities and preferences, and to limit the number of times you see the same content, as well as to measure the effectiveness of our content and marketing.
2.4.2 The legal basis for the processing is our legitimate interests in complying with your wish to receive marketing communications from us to which you have consented under the Danish Marketing Practices Act (Article 6(1)(f) of the General Data Protection Regulation).
2.5 Members of ENVII
When you create an account on envii.com and become a member of ENVII, we process personal data that you have shared with us such as your first name, last name, address, phone number, email, country, gender, birthday, order information, purchase history and case number, membership number, information about earning and using benefits (including vouchers), information you provide in connection with the use of services, including when booking personal shopper and in connection with our events, information collected in connection with our communication with you about your membership. When you make a purchase on our website, our Privacy Policy applies to you regardless of whether you are logged in as a member or not.
When creating an account and becoming a member, you have the option to consent to us sending you marketing material by email, text messages or other electronic means. If you consent to receive marketing, we also process information about your preferences in relation to marketing or communications and your use of the marketing messages we send to you (including, for example, whether you have opened an email from us, whether the email has been read and which links you have opened) and information that you otherwise provide to us.
2.5.1 The purpose is to provide you with the benefits associated with being a member of ENVII, such as receiptless returns, email receipts in store, invitations to events, invitations to private sales and members week, early access to sales, exclusive offers, welcome 10% discount and birthday treat (as a start). In addition, we use personal data about you to manage our ENVII memberships.
2.5.2 The legal basis for the processing is our legitimate interests in managing your membership (Article 6(1)(f) of the General Data Protection Regulation) and/or your consent (Article 6(1)(a) of the General Data Protection Regulation and Section 10 of the Danish Marketing Practices Act).
2.6 Visitors of ENVII's social media
When you visit one of ENVII’s social media profiles (Facebook, Instagram, LinkedIn, TikTok, Pinterest), we may process information about you and your visit, including information you have made available via social media settings, and your reactions to, comments on, and sharing of our posts.
When you participate in competitions on our social media profiles, we process personal data that are publicly available or that you have shared with us such as your first name, last name, email, country, gender, birthday, and responses to the competition.
2.6.1 The purpose of processing your personal data is to market ENVII on social media, including answering your inquiries, allowing you to participate in our competitions and drawing winners, etc.
2.6.2 The legal basis for the processing is our legitimate interest in marketing ENVII via our presence on the mentioned social media platforms, and meeting/interacting with our customers on social media (Article 6(1)(f) of the General Data Protection Regulation).
2.7 Business partners and/or suppliers to ENVII
When you are a business partner or supplier to ENVII or are a contact person of a business partner or supplier, we process personal data about your name, company name, work phone number, and email as well as publicly available information and other information you provide to us.
2.7.1 The purpose is to manage our cooperative relationship and contract, receive goods and services from our suppliers and business partners, and to be able to fulfil our contractual obligations.
2.7.2 The legal basis for the processing is the contractual relationship established or in the process of being established between you and/or the company you represent and ENVII (Article 6(1)(b) of the General Data Protection Regulation), and our legitimate interest in managing the relationship with you and/or the company you represent as a business partner or supplier (Article 6(1)(f) of the General Data Protection Regulation).
3. Storage and Deletion of Personal Data
We process the personal data you provide to us, and which is collected automatically through your digital behaviour (e.g. cookies). When your personal data is no longer needed, we will ensure that it is deleted in a secure manner. Below you can see the purpose and retention period for your personal data.
Purpose: Management of customer relationship, including management of your purchases as well as provision of customer service.
Retention period: Information about your transactions and returns is stored for 5 years from the end of the financial year to which the material relates, in accordance with the Danish Bookkeeping Act’s chapter 4 on storage of accounting material.
Purpose: Management of your ENVII membership.
Retention period: Information about your ENVII membership is stored as long as you’re a member. The information will be deleted 30 days after you cancel your membership by deleting your account.
Purpose: Social media and competitions.
Retention period: Information you provide on ENVII’s social media profiles will generally remain on the profiles as part of the site’s history unless you delete it yourself. The data we process about you in connection with your participation in competitions, and which is copied to our own systems, will be deleted after 3 months.
Purpose: Personalisation of the content displayed on our platforms based on your search history and your purchases.
Retention period: For 12 months after the specific personal information has been collected.
Purpose: Targeted marketing based on consent to direct marketing.
Retention period: Until you withdraw your consent or (if the consent is not withdrawn) after a period of 12 months with no communication. However, we will keep documentation of your consent for a period up to 5 years after your consent has been withdrawn.
Purpose: Targeted marketing regarding products similar to those you have purchased from us.
Retention period: Until you opt-out from further inquiries from us or (if you do not opt-out) after a period of 12 months with no communication.
Purpose: Cookies on envii.com.
Retention period: Until you withdraw your cookie consent or (if the consent is not withdrawn) until the cookies in question expire after the period stated in our Cookie Policy. In the Cookie Policy you can also read more about how to change and revoke your cookie consent.
Purpose: CCTV Surveillance.
Retention period: Automatically deleted no later than 30 days after the recording took place unless the information is part of an investigation of a specific case. The information will be deleted when the case is completed, and the purpose of the processing no longer exists.
Purpose: Legal obligations.
Retention period: We process the information included on your invoice for the purpose of fulfilling our legal obligations in accordance with the Danish Bookkeeping Act’s chapter 4 on storage of accounting material, i.e. companies must safely store the accounting material for 5 years from the end of the financial year to which the material relates.
Purpose: Legal claims.
Retention period: We process the information included on your invoice for the purpose of fulfilling our legal obligations in accordance with the Danish Bookkeeping Act’s chapter 4 on storage of accounting material, i.e. companies must safely store the accounting material for 5 years from the end of the financial year to which the material relates.
4. Disclosure of Your Personal Data to Others
ENVII may disclose your personal data to other suppliers and/or service providers, as well as to our group affiliates, in the ordinary course of our business.
4.1 Data processors
We have entered into written data processing agreements with all data processors who process personal data on our behalf. The agreement provides instructions on confidentiality and security and stipulates how the information may be processed. The data processors may not use the information for any purpose other than fulfilment of the agreement. We use the following categories of data processors:
Partners for data storage, hosting and other IT services including technical operation of systems and improvements of envii.com
Partners that assist with marketing communications, such as specific emails and SMS, if you have given your consent to targeted marketing.
In case the personal data is transferred to countries outside the EU/EEA (third countries), you can read about how we secure your personal information below in section 6.
4.2 Data controllers
We also use services from or enter into cooperation agreement with companies that are independent data controllers and where the processing of your personal information, after our transfer, is fully or partially processed by this company and is their responsibility. This applies to processing that takes place in the following categories of recipients:
Partners who assist with transport and distribution to ensure that your items arrive to you quickly and safely.
Providers who assist with marketing if you have given your consent to this or if we have a legitimate interest in disclosing your personal information for marketing purposes.
Providers assisting with payment.
It is important to us to ensure that you’re informed about the transfer of your personal data to other data controllers. This way, you have the opportunity to contact these companies to understand their data processing and exercise your rights under the GDPR. For example, when you complete an order on envii.com, we refer to the chosen distributor, or when using a payment service, we require the provider to disclose information about the data needed for secure payment and how you can ask questions regarding this. All independent data controllers receiving your data are accountable for providing you with the necessary information about their methods.
4.3 Public authorities and transfers based on legal obligations
We may disclose your personal data to public authorities, the police or others, in situations where we are specifically or legally obliged to, or in connection with notification obligations to which we are subject.
5. Security Measures
It is our policy to protect personal data by taking adequate technical and organisational security measures against personal data being accidentally or illegally destroyed, lost, altered or impaired, as well as them coming to the knowledge of unauthorized persons or being misused.
We have implemented security measures to ensure data protection for all personal data that we process. We conduct regular internal follow-ups on the adequacy of and compliance with policies and measures.
6. Third Country Transfers
In connection with our processing of your personal data, we may transfer such information to countries outside the EU/EEA (third countries). In those cases, we will ensure the necessary technical and organisational security measures so that the processing of personal data is carried out with the same level of security that you can expect when the processing takes place in the EU.
Your personal data may be transferred to countries where the European Commission has determined that the level of data protection is equivalent to that in the EU/EEA (secure third countries). You can read more about the transfer of personal data to countries outside the EU/EEA on the European Commission's website.
We use subcontractors and have partners outside the EU/EEA within the following functions:
CRM system, USA
Marketing, USA
Analytics, USA
Storage, USA
If you would like further information about our transfer of personal data to countries outside the EU/EEA, please contact us.
7. Your Rights in Relation to Your Personal Data
As a data subject, you have certain rights under the General Data Protection Regulation. To create transparency about the processing of your data, ENVII, as a data controller, must inform you of your rights. If you want to exercise your rights, please contact us at customercare@envii.com.
Your rights include the following:
7.1 Right to access
You have the right to gain access to the personal data collected about you.
We can reject requests that are unreasonably repeated, demands disproportional high technical intervention, or which affect another individual’s rights.
7.2 Right to rectification
You have the right to obtain rectification of any inaccurate and incomplete personal data about you.
Upon request, we will update, change or delete your personal data that we process, apart from personal data that still needs to be processed on the basis of a legal obligation or our continued legitimate interest.
7.3 Right to erasure (right to be forgotten)
In exceptional cases, you have the right to request erasure of information about you before the time when we would normally delete your personal data. To the extent that continued storage of your data is necessary, e.g. in order for us to comply with legal obligations or for legal claims to be established, exercised or defended, we are not obliged to delete your personal data.
7.4 Right to restriction of processing
the personal information is correct, or if the personal data is no longer necessary for processing, but it is required by you for legal claims to be established, exercised, or defended.
7.5 Right to object
In certain situations, you have the right to object to our processing of your personal data, and always, if the processing is for direct marketing purposes. Upon request, we will assess whether our legitimate interest overrides your interests, rights, and freedoms, or whether your personal data is necessary for legal claims to be established, exercised, or defended.
7.6 Right to data portability
In certain situations, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to have such personal data transferred from one data controller to another.
7.7 Right to revoke consent
You have the right at any time to revoke a consent you have given us for a given processing of personal data.
If you choose to withdraw your consent, it will not affect the lawfulness of our processing of your personal data based on your previously given consent up to the time of your withdrawal. If you withdraw your consent, it will only have effect from that time.
7.8 Right to lodge a complaint
You can lodge a complaint at any time with the Danish Data Protection Authority about our processing of personal data. See more at www.datatilsynet.dk where you can also find further information on your rights as a data subject.
8. Contact Us
Please contact us at customercare@envii.com or by +45 3528 5000 if you have any questions regarding our Privacy Policy.
9. Updates to This Policy
We will review our Privacy Policy on a regular basis in order to ensure that it is updated, valid, and in accordance with current legislation and the principles for processing of personal data. We will publish new versions of the Privacy Policy on our website.
This Privacy Policy is valid from 15. November 2023