BACKGROUND
At Giant Europe B.V. (hereinafter referred to as "Giant", "we" or "us"), we protect your privacy and strive towards always maintaining a high level of data protection. This privacy notice describes how we collect and use Personal data that is provided to us via our website www.giant-bicycles.com/se or www.liv-cycling.com/se, your purchases of our products and your use of our apps, if any. It also describes your rights and how you can exercise them. If you have any questions, you are always welcome to contact us via the contact details stated at the end of this privacy notice.
Throughout this privacy notice, the term "processing" is used, which includes all operations involving Personal data, including without limitation, collection, handling, storage, sharing, access, use, transfer and deletion of Personal data.
"Applicable legislation" means applicable laws, ordinances and regulations, including regulations issued by relevant supervisory authorities, concerning the protection of the fundamental rights and freedoms of natural persons and in particular the right to the protection of their Personal data applicable to the processing in question; including Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) ("GDPR") as well as laws, ordinances and regulations supplementing the GDPR.
"Personal data" shall have the meaning ascribed to it under the GDPR and means any information relating to an identifiable or identified natural person.
WHO IS THE DATA CONTROLLER FOR THE PERSONAL DATA WE COLLECT?
Giant Europe B.V., company registration number 39042936 with its address at Pascallaan 66, 8218 NJ, Lelystad, the Netherlands, is the data controller for the company's processing of Personal data.
FROM WHERE DO WE COLLECT PERSONAL DATA?
We collect Personal data from:
- You, that you either provide to us yourself or that we collect from you based on e.g. your website visits, use of our apps or purchase orders.
- Your bank or credit card company
When and why do we process Personal data?
Handling of orders
We process your Personal data in order to manage the customer relationship with you in connection with you ordering our products and us handling your order. Such processing includes inter alia to carry out your order, organize the shipping or delivery of the products, provide invoices and/or order confirmations.
Categories of Personal data
- Identity information
- Contact information
- Purchase information
- Payment information
- (E-)bicycle details and settings
Legal basis: Contract. The processing is necessary in order to fulfill our obligations under the purchase agreement with you.
Retention period: Personal data is retained until the purchase has been completed (including delivery and payment) and for a period of one (1) year thereafter.
Manage guarantees, warranties and product recalls
We process your Personal data in order to manage warranties and guarantees for bikes and gear items and in order to contact you in case of a product recall or a safety announcement regarding a product.
- Categories of Personal data
- Identity information
- Contact information
- (E-)bicycle details and settings
- Purchase information
Legal basis: Contract. The processing is necessary in order to fulfill our obligations under a contract with you.
Retention period: Personal data is retained until the guarantee period expires or during the time which a product recall or safety announcement can be made, and thereafter for the time necessary for us to be able to establish, exercise and defend legal claims.
If you register your bike or gear items, we will store the registration until the guarantee period expires and for a period of one (1) year thereafter.
If you purchase our complete bike or bike frame products subject to a lifetime warranty, your personal data is retained for the period of time during which such lifetime warranty is valid.
Manage and respond to feedback, questions and potential complaints
If you contact us, e.g. via e-mail, social media or via our contact form to e.g. ask questions or make a request, we will process your Personal data that you provide us with to communicate with you and respond to and investigate any questions and/or complaints that you may have.
- Categories of Personal data
- Identity information
- Contact information
- Your communication
- Purchase information
Legal basis: Legitimate interest. The processing is necessary to fulfill our legitimate interest in managing and responding to your submitted feedback, questions and/or complaints.
Retention period: Personal data is retained until the customer service matter has been completed and thereafter for the time necessary for us to be able to establish, exercise and defend legal claims.
Provide you with information about our business and offers via newsletters
We may process your Personal data to handle and send out newsletters to you. These newsletters can e.g. contain information, updates and offers regarding our business, services and our products. You can unsubscribe from our newsletters at any time by clicking the unsubscribe link in the e-mail or by contacting us. If we have not collected your e-mail address in connection with your purchase, we will always ask for your consent in accordance with the Marketing Act (2008:486) where required before you receive our offers via e.g. e-mail.
Categories of Personal data
- Identity information
- Contact information
Legal basis: Consent. The processing is based on your consent.
Retention period: We process your Personal data for this purpose until you no longer want to receive the newsletters.
You also always have the right to say no to continued marketing, in which case we will stop sending you our newsletter.
Conducting surveys
We will process your Personal data to conduct customer satisfaction surveys, to evaluate our services and products. Based on the information we collect, we analyze the data on an anonymized level, without any connection to you as an individual.
Categories of Personal data
- Your communication
- Information about feedback
Legal basis: Legitimate interest. The processing is necessary to fulfill our legitimate interest to conduct surveys, to evaluate our services and products.
Retention period: Personal data processed for the purpose of conducting surveys will be retained for a period of 2 years.
Evaluate and monitor the use of our website
In order to analyze and better understand how you use our website, we process your Personal data, which we e.g. has collected via cookies and similar technologies. This is done by e.g. collecting visitor and click statistics, which pages you visited on our website and for how long time/number of times.
Categories of Personal data
- User-generated data
- Identity information
- Geographical information
Legal basis: Legitimate interest. The processing is necessary to fulfill our legitimate interest in evaluating and monitoring the use of our website.
Retention period: Reports at an aggregative level that do not contain any Personal data and statistics are stored for an indefinite period.
Establish, exercise and defend legal claims
For the purposes of establishing, exercising and defending legal claims e.g. in connection with a dispute or legal process, we process your Personal data (where applicable).
Categories of Personal data: All information necessary to manage and address the legal claim.
Legal basis: Legitimate interest. The processing is necessary to fulfill our legitimate interest in managing and addressing legal claims, e.g. in connection with a dispute or legal process.
The processing of personal identity number is necessary in view of the purpose of the processing.
Exceptions for sensitive Personal data
Special categories of personal data, including criminal data, are only processed to fulfil our legitimate interest in establishing, exercising or defending legal claims.
Retention period: Personal data is retained during the statutory limitation period for the purpose of establishing, exercising and defending legal claims. The general statutory limitation period in Sweden is ten (10) years.
Fulfill legal obligations
We will process your Personal data for the purposes of fulfilling legal obligations within the area of e.g. book-keeping, accounting and requirements under Applicable Data Protection Laws.
Categories of Personal data
All information that is necessary to fulfill the respective legal obligation.
Legal basis: Legal obligation. The processing is necessary to fulfill legal obligations to which we are subject.
Retention period: Personal data is retained for the period necessary in order for us to fulfill legal obligations to which we are subject.
Manage a recruitment process
When you apply for a job at Giant, we process the Personal data that you have provided us with to handle the recruitment process, e.g. to receive and review application documents (such as CVs and personal letters), evaluate applications (including reference taking) and to communicate with you during the recruitment process.
Categories of Personal data
- Identity information
- Contact information
- Information relating to the job application
Legal basis: Contract. The processing is necessary in order to take steps at your request prior to entering into an employment contract.
Legitimate interest. The processing is necessary to fulfill our legitimate interest in managing the recruitment process.
Exceptions for sensitive Personal data
We process any sensitive Personal data, e.g. information about union membership, on the basis of your explicit consent. We only process such personal data if you voluntarily provide such information to us, however, we ask you to avoid providing us with any such information.
Retention period: Personal data is retained for six (6) weeks after the application procedure.
Future recruitments
If you give your consent, we will save your application documents for future recruitments. We can then e.g. contact you if a position becomes available with us that we deem fits your profile and might be of interest to you. It is completely voluntary to give your consent to this and you can revoke the consent at any time.
Categories of Personal data
Same information as under "Manage a recruitment process" above.
Legal basis: Consent. The processing is based on your consent.
Exceptions for sensitive Personal data
We process any sensitive Personal data, e.g. information about union membership, on the basis of your explicit consent. We only process such personal data if you voluntarily provide such information to us, however, we ask you to avoid providing us with any such information.
Retention period: Personal data is retained for a period of 12 months if you give your consent to this.
Recipients who we share personal data with
When necessary, we share Personal data with the recipients specified below. Unless otherwise stated, named recipients are independent data controllers for their own processing of Personal data.
Recipient: Authorities (e.g. the Police, the Swedish Public Health Agency and the Swedish Tax Agency)
Purpose: In order to fulfil any legal obligations to which we are subject, e.g. in connection with requests from authorities or other legal claims.
Legal basis: Legal obligation. The processing is necessary to fulfil legal obligations to which we are subject.
Recipient: Authorities (incl. courts) and legal representatives
Purpose: To establish, exercise and defend legal claims.
Legal basis: Legitimate interest. The processing is necessary to fulfill our legitimate interest in disputes and cases being managed by competent courts and legal representatives.
Recipient: Buyers, sellers and external advisors/other parties involved
Purpose: To enable business changes, e.g. sale or merger of the business or investments in general.
Legal basis: Legitimate interest. The processing is necessary to fulfill our legitimate interest in conducting and executing business changes.
Recipient: Payment service providers
Purpose: To enable your payment of ordered products and thus enter into a purchase agreement with you.
Legal basis: Contract. The processing is necessary in order to take steps at your request prior to entering into a purchase agreement.
Recipient: Deliver, order processing or product return service providers
Purpose: To enable processing your order or to handle product return relative matters for you.
Legal basis: Contract. The processing is necessary in order to fulfill our obligations under the purchase agreement with you.
Recipient: Delivery companies that provide transportation of goods
Purpose: In order to be able to deliver your ordered product and thereby fulfill our obligations under the purchase agreement with you.
Legal basis: Contract. The processing is necessary in order to fulfill our obligations under the purchase agreement with you.
Recipient: Other companies within the Giant Group
Purpose: In order to carry out your order, organize the shipping or delivery of the products, provide invoices and/or order confirmations.
Legal basis: Contract. The processing is necessary in order to fulfill our obligations under the purchase agreement with you.
Service providers
To fulfill the purposes of the processing of Personal data, we share your Personal data with service providers that we have engaged. These suppliers provide services within e.g. IT services (companies that manage necessary operations, technical support and maintenance of our services provided to you and ICT service providers). The service providers we have engaged are only allowed to process your Personal data in accordance with our explicit instructions and may not use your data for their own purposes. They are also required by law and agreement to take the appropriate technical and organizational security measures in order to protect your information.
Appropriate safeguards for the transfer of Personal data to third countries
Giant may share Personal data with other companies within the Giant Group. These companies may be located outside the EEA. In cases where Giant transfers or discloses your Personal data to a recipient in a country outside the EU/EEA (third country), Giant will ensure that appropriate safeguards have been taken (such as the EU Commission's standard contract clauses and other necessary measures) in order to protect Personal data.
Giant transfers Personal data to the following countries outside the EU/EEA: Taiwan.
Pursuant to applicable data protection legislation, you have the right, upon request, to receive a copy of the documentation demonstrating that the necessary protective measures have been taken in order to protect your Personal data when transferring it to a third country.
If you would like to know more about the processing of your Personal data and if your Personal data is transferred to a third country, please contact us by using the contact information below.
SECURITY
We will ensure that access to your information is adequately protected by having appropriate security measures implemented and, depending on the circumstances, taking into account the state of the art, the cost of implementation and the nature, scope, context and purposes of processing as well as the risks. To uphold this warranty, we have also implemented appropriate technical, physical and organizational measures to protect your Personal data from unlawful or accidental destruction, alteration or disclosure, misuse, damage, theft or loss by accident or unauthorized access.
We take the following measures in particular:
- we use secure connections (Secure Sockets Layer of SSL) to encrypt all information between you and our website when entering your personal data;
- we keep logs of all requests for personal data;
- access to personal data is restricted to those persons who need the personal data for fulfilling their tasks.
YOUR RIGHTS
Rights in relation to your Personal data
In connection with our processing of your Personal data, you may, under certain conditions, exercise the following rights:
Access
You can request confirmation of whether or not your Personal data is being processed and, if it is being processed, request access to your Personal data and additional information such as the purpose of the processing. You also have the right to receive a copy of the Personal data that is processed. If the request is submitted electronically, the information will also be obtained in a commonly used electronic form unless you request otherwise.
Rectification
If you notice that Personal data about you is inaccurate or incomplete, you have the right to have your Personal data rectified.
Object to specific processing
You can object to processing of your Personal data if it is based on a legitimate interest, on grounds relating to your particular situation or if the processing takes place for direct marketing purposes. If we are unable to demonstrate compelling legitimate grounds to continue processing, that override your interests, or if the processing is not necessary to establish, exercise and defend legal claims, we are obliged to cease the processing.
Erasure
You can have your Personal data erased under certain circumstances, e.g. when the Personal data is no longer needed to fulfill the purpose for which the Personal data was collected.
Restrict processing
Under certain circumstances, you can request that we restrict the processing of your Personal data to only involve the storage of your Personal data, e.g. when the processing is unlawful but you do not want your Personal data deleted.
Withdraw consent
To the extent that the processing of Personal data is based on your consent, you always have the right to withdraw your consent.
Data portability
You have the right to request a machine-readable copy of the Personal data processed based on your consent or when the processing is necessary to fulfill an agreement with you as well as when Personal data has been obtained from you (data portability), and to request that the information be transferred to another data controller (if possible).
Complaints to the supervisory authority
You are welcome to contact us with questions or complaints regarding the processing of your Personal data. However, you also always have the right to lodge a complaint regarding the processing of your Personal data to the Swedish Authority for Privacy Protection.
CONTACT US
If you have any questions regarding the processing of your Personal data or if you wish to exercise any of your rights pursuant to applicable data protection legislation, please contact Giant by using the contact details below. If needed, we have the right to change and supplement the privacy notice.
The Data Controller is:
Giant Europe B.V.
Pascallaan 66, 8218 NJ, Lelystad, the Netherlands
Email address: consumerservice@giant-europe.com
Categories of Personal data
Below you will find an explanation of the categories of Personal data that we may collect and store about you.
Categories of Personal data: User-generated data
Examples of Personal data: Click and visit history, technical data regarding used devices and their settings (e.g. language setting, IP address, browser settings, time zone, operating system, screen resolution and platform), information about how you interacted with us, login method, which pages and how long different pages have been visited, response times, download errors, how to access and leave the service, etc.
Categories of Personal data: Gender and age
Examples of Personal data: Marketing / target audience
Categories of Personal data: Your communication
Examples of Personal data: Personal data that you provide in your communication with us, e.g. in e-mails.
Categories of Personal data: Geographical information
Examples of Personal data: Location data from your device that e.g. may be collected via cookies
Categories of Personal data: Health information
Examples of Personal data: Information regarding your heartrate
Categories of Personal data: Identity information
Examples of Personal data: Name, IP-address
Categories of Personal data: Contact information
Examples of Personal data: Address, e-mail address, telephone number
Categories of Personal data: Purchase information
Examples of Personal data: Details of your order of products such as product purchased, time of purchase, order history, delivery address
Categories of Personal data: Payment information
Examples of Personal data: Payment method, payment details (such as card number, bank account details), billing/invoice address.
Categories of Personal data: Information about feedback
Examples of Personal data: Opinions and comments regarding our services and products, e.g. from customer satisfaction surveys
Categories of Personal data: Account information for Giant apps
Examples of Personal data: Login details such as username and password
Categories of Personal data: (E-)bicycle details and settings
Examples of Personal data: Registration information for bikes and gear products
Categories of Personal data: Ride history and overview
Examples of Personal data: Location data, ride history
Categories of Personal data: Information relating to the job application
Examples of Personal data: Information about e.g. competences, skills, former work experience, union membership and other information available in your cover letter and CV.