1. Introduction Zamalia Experience Privacy Statement
This is the Zamalia Experience privacy statement. This privacy statement applies to all privacy sensitive information or personal data that you provide to us, for example when you create a Zamalia Experience account or purchase a Zamalia Experience product. In this Privacy Statement we clearly explain how we store your data, how long it will be stored and what exactly the purpose of the data processing is. In addition, we provide clear insight into how you can exercise your rights with regard to data processing.
What exactly does Zamalia Experience do?
Zamalia Experience offers you a variety of CBD products.
All our products are of the highest CBD quality and are exclusively made by a certified producer.
We have opted for an extensive privacy statement because we process personal data or have it processed in different situations.
There are often situations where Zamalia Experience needs to collect and process/use your personal data. It is important that you know what happens to your personal data and how you can inform us of your wishes regarding the handling of your personal data.
Zamalia Experience takes your privacy very seriously and will use and process personal information in a secure manner.
All articles in this privacy statement are in accordance with the applicable (General Data Protection Regulation GDPR legislation). This European privacy legislation has been applicable in the Netherlands since 25 May 2018.
Do you have the impression that your personal data is not being handled correctly?
Then you can contact Zamalia Experience directly!
2. Categories of personal data
For us it is necessary to request certain personal data in order to help our customers and users as well as possible. Personal data is data that can be traced back to a natural person, such as you as a consumer. The personal data that we (generally) request:
- First and last name;
- E-mail address;
- Address data.
We only keep and use the personal data that is provided directly by you, or of which it is clear that they are provided for processing by Zamalia Experience.
3. Basis and purpose for data processing
Based on the GDPR legislation, we have established lawful bases for the processing of your personal data. A basis is the lawful reason on which we process your data. Article 6 paragraph 1 sub a, sub b and sub c of the GDPR apply to Zamalia Experience: the processing of your personal data is done on the basis of consent, because it is necessary for the performance of an agreement between you and Zamalia Experience or because it is necessary to comply with legal obligations.
Article 13 paragraph 1 sub c of the GDPR prescribes that we clearly indicate for which ‘processing purposes’ the personal data are intended. The processing purposes can be seen as the concrete purposes for processing the personal data. Below is therefore an overview with various processing purposes.
- There are a number of purposes for which Zamalia Experience collects your personal data;
3.1 Use of the Zamalia Experience website and account
To use the Zamalia Experience website you must indicate that you have reached the age of 18 years.
You can create an online account at Zamalia Experience. With this account you can, for example, keep track of your orders. To create an account, you must at least provide your e-mail address. You can add additional information to the account yourself, including your payment details and address. Under no circumstances is it mandatory to store this additional information in your account.
3.2 Contact us
If you have contacted Zamalia Experience in any way, the data you have provided will be stored and used for the further contact. This could be because you have sent an email to Zamalia Experience. In this case, your name (if provided) and your e-mail address will be processed together with any other data that you have provided to us. This also applies to contact related to Zamalia Experience’s complaints policy.
3.3 Placing an order
When you place an order with Zamalia Experience, it is necessary that certain data is processed. Before an order is completed, you must at least provide us with your first and last name, e-mail address, home/delivery address and payment details.
3.4 Shipping product
For the shipment of a product, the same personal data is collected as shown in ‘place order’. After all, the same process is used for this.
Zamalia Experience guarantees that the accounting is done in a complete and thorough manner. In addition, our accounting always meets the legal requirements. In order to comply with this, certain data may be required for processing. No more data is ever processed than the data provided when placing an order.
4. Period of storage
We have indicated above for which processing purposes we use your personal data. According to Article 13 paragraph 2 sub a of the GDPR, we must then indicate the storage period of the personal data.
4.1 Contact us
If you have contacted once, the data you provide will be stored for a maximum period of 2 years, after the last contact moment has taken place. If the contact moment turns into another processing purpose, the term of the relevant purpose will be adhered to. If the contact relates to a return, the retention period may be longer than indicated above. This only applies if the return involves administrative work.
4.2 Placing an order
When you place an order, your data will be stored for a maximum of 2 years, unless this data is intended for the administration of Zamalia Experience. You will find this period under the heading “administration” of this chapter.
4.3 Shipping product
The same term is used for the shipment of a product as indicated in “placing an order”.
For the administration of Zamalia Experience we are obliged to keep data for a minimum period of 7 years, as stated by the tax authorities.
5. Recipients of personal data
Zamalia Experience shares personal data with third parties: this only happens when it is strictly necessary. In all cases Zamalia Experience will comply as controller with the GDPR legislation, specifically article 28 and further of the GDPR.
To guarantee the best service from Zamalia Experience, we work together with certain external parties. Think of parties that arrange our financial affairs. Below we provide you with an overview of external parties that receive personal data from you.
Overview of third parties who receive personal data from you:
– Tax authorities/government agencies
To comply with our tax obligation and/or any other legal requirement, we share the necessary personal data with the Tax and Customs Administration and other government authorities, if we are legally obliged to do so.
– Third parties
Zamalia Experience uses third parties to perform the services. Consider, among other things, the suppliers. These parties only use the strictly necessary personal data.
The webmaster may have insight into certain data. These are only data related to the operation of the website.
Personal data is only accessible to authorized persons within Zamalia Experience. Devices that have access to your data are locked with a password and/or fingerprint scan and/or facial recognition. This naturally includes the necessary devices, such as computers, laptops and mobile phones.
Your visit to the Zamalia Experience website is also secured by “HTTPS” security. This means that your connection to Zamalia Experience is private. With this we ensure that your personal data remains safe during a website visit.
For the sake of completeness, more information about online security that Zamalia Experience uses:
- Security software, such as a virus scanner.
- We send your data via a secure HTTPS internet connection.
7. Your rights with regard to your personal data
Below we give you a clear overview of the rights you have with regard to your personal data and our use/processing thereof. Although at Zamalia Experience we collect and process personal data in a minimal way, we think it is important to point out the rights you have under the GDPR.
a. Right of access (Article 15 GDPR)
You have the right to request your personal data, which have been processed and stored by Zamalia Experience, at any time. This can be done by sending an e-mail to [email protected]. You will then receive a clear overview of your data.
b. Right to rectification (Article 16 GDPR)
Are your data (that we keep) no longer correct or have they changed? Then you have the right to have this rectified by Zamalia Experience.
c. Right to data portability (Article 20 GDPR)
Under the GDPR, you have the right, if reasonable and possible, to request Zamalia Experience to transfer data to another party.
d. Right to erasure of data (Article 17 GDPR)
In certain cases you have the right to ask Zamalia Experience to destroy data. You can do this by invoking the right to be forgotten. Zamalia Experience must destroy your personal data in the following situations:
- Zamalia Experience no longer needs your data for the purposes for which Zamalia Experience collected the data.
- You have explicitly given permission to Zamalia Experience to use data, but are now withdrawing it.
- You object to the processing of data. You have an absolute right to object to direct marketing. Are your interests overriding Zamalia Experience’s interests with regard to processing your data? Then you have a relative right of objection. This means that deletion does not have to take place immediately, but only when it has been established that your interest is more important.
- If Zamalia Experience would process your data unlawfully, you immediately have the option to request that the data be deleted. This is possible, for example, when there is no legal basis for the processing of your personal data.
- When Zamalia Experience has exceeded a legal retention period, Zamalia Experience is obliged to delete your data.
- If you as a data subject are younger than 16 and Zamalia Experience has collected your data via the website, you can ask Zamalia Experience to delete the data immediately.
There are exceptions to the right to be forgotten under the GDPR. For more information, see the following page.
e. Right to submit a complaint to the Dutch Data Protection Authority
You always have the right to file a complaint with the Dutch Data Protection Authority if you believe that Zamalia Experience has not properly handled your personal data. You can do that via this link (as of January of 2021 an English version does not exist). The Dutch Data Protection Authority will then deal with your complaint.
f. Right to stop data usage, objection (Article 21 GDPR)
You have the right to object to data use at any time. Certainly in the case of ‘direct marketing’.
Make use of the above rights?
An e-mail to [email protected] is in most cases enough to exercise your rights. Do we have any doubts whether you are actually who you claim to be? Then we have the option to request that you provide a copy of your proof of identity.
We always ask you for a copy of the identity document, in the manner prescribed by the national government.
However, in most cases a less invasive method of identifying information will suffice.
Zamalia Experience processes your personal data, as indicated, on the basis of a legitimate interest. Your personal data will never be sold to a third party.
The data that is required is the minimum required personal data that is necessary for purchasing and delivering our products. If you do not provide us with this mandatory information, Zamalia Experience will not be able to provide the services (properly).
If it is necessary to share your personal data with parties other than the parties mentioned above, your permission will of course be requested first by changing our privacy statement. Therefore we implore you to consult it regularly.
Zamalia Experience reserves the right to disclose information when required to do so by law, or when Zamalia Experience deems it justified to comply with a legal request or process. Also when it comes to ownership or protecting Zamalia Experience. We try to respect your right to privacy as much as possible.
Please feel free to contact us using the details below.
Chamber of Commerce Number: 80383270