Privacy Statement for Business Partner Data

The General Data Protection Regulation (GDPR) (EU) 2016/679 is a regulation in EU law on data protection and privacy for all individuals within the European Union and the European Economic Area. It also addresses the export of personal data outside the EU and EEA. The GDPR aims primarily to give control to citizens and residents over their personal data and to simplify the regulatory environment for international business by unifying the regulation within the EU.

Elektra Limited takes privacy seriously, and according to GDPR would like to clarify how Elektra Limited collects, uses, discloses, transfers and stores your personal data. Elektra Limited Privacy Notice provides an overview of the way in which your data is used.

1. INTRODUCTION

This Privacy Statement is applicable to the processing by Elektra Limited, based at Qormi (hereafter referred to as “Our Company”, we or us) of all personal data belonging to consumers, customers, suppliers and business partner data (“Business Partner”). This Privacy Statement is not applicable to business related data and/or data on companies. Our Company is the controller for the processing of Business Partner’s personal data. In this statement we describe who we are, how and for which purposes we process your personal data and all other information that may be relevant to you. In case you have any additional questions, you can contact us via the contact details provided at the bottom of this statement.

This Privacy Statement applies since 25 May 2018. The last modifications were made on 25 May 2018. This statement may change over time and the most up-to-date version is published on our website. If significant changes are being made, we will actively inform you.

2. FOR WHICH PURPOSES DO WE PROCESS YOUR PERSONAL DATA?

Our Company will process your personal data when you do business with us, when you use our website or apps or when you interact with us.

A. For answering your questions

If you get in touch with us, we will use your personal data to reply and answer your question(s).

For this purpose

  • we process your personal data for this purpose based on your consent when you provide us with your personal data
  • we process your name, contact details, your correspondence with us, your question, and all other personal data which are necessary to answer your question.

B. For Online Advertisement

Online Analytics

We may use third-party web analytics services on our web solutions, such as those of Google Analytics. These service providers use the sort of technology described in the Automatically- Collected Information section above to help us analyse how users use the Services, including by noting the third-party website from which you arrive. The information collected by the technology will be disclosed to or collected directly by these service providers, who use the information to evaluate your use of the Services. We also use Google Analytics for certain purposes related to online marketing, as described in the following section.

Online Advertising

We do not serve third party advertisements to you while using Elektra.com.mt. However, we do work with website analytics and advertising partners, including Google and Facebook, to deliver advertisements on third party publisher websites – these partners may set cookies on your computer’s web browser. These cookies allow our partners to recognize your computer so that the ad server can show you our Elektra advertisements elsewhere on the Internet, and so that our analytics software can measure your engagement and interactions while using Elektra.com.mt.

In this way, ad servers may compile anonymous, de-identified information about where you, or others who are using your computer, saw our advertisements, whether or not you interacted with our advertisements and actions performed on subsequent visits to Elektra.com.mt. This information allows an ad network to deliver targeted advertisements that they believe will be of most interest to you, and it allows us to optimize the performance of our advertising campaigns and the usability of our website.

Do Not Track

Please note that we do not alter our Site’s data collection and use practices when we see a Do Not Track signal from your browser. If you are a European resident, you have the right to access the personal information we hold about you and to ask your personal information to be corrected, updated, or deleted. If you would like to exercise this right, please contact us through the contact information at the end of the privacy policy. Additionally, if you are a European resident we note that we are processing your information in order to fulfil contracts we might have with you (for example if you make an order through the Site), or otherwise to pursue our legitimate business interests listed above.

C. Do we use cookies?

Yes. Cookies are small files that a site or its service provider transfers to your computer’s hard drive through your Web browser (if you allow) that enables the site’s or service provider’s systems to recognize your browser and capture and remember certain information. We use cookies to help us remember and process the items in your shopping cart, understand and save your preferences for future visits, keep track of advertisements and compile aggregate data about site traffic and site interaction so that we can offer better site experiences and tools in the future. Some of our business partners may use cookies on our site (for example, advertisers). However, we have no access to or control over these cookies. If you prefer, you can choose to have your computer warn you each time a cookie is being sent, or you can choose to turn off all cookies via your browser settings. Like most websites, if you turn your cookies off, some of our services may not function properly. However, you can still place orders over the telephone or by contacting customer service.

What Are Cookies

As is common practice with almost all professional websites this site uses cookies, which are tiny files that are downloaded to your computer, to improve your experience. This page describes what information they gather, how we use it and why we sometimes need to store these cookies. We will also share how you can prevent these cookies from being stored however this may downgrade or ‘break’ certain elements of the site’s functionality. Cookies do not typically identify you as an individual, just the device you are using.

For further information on cookies, including how to see what cookies have been set on your device and how to manage and delete them, visit http://www.allaboutcookies.org.

How We Use Cookies

We use cookies for a variety of reasons detailed below. Unfortunately, in most cases, there are no industry standard options for disabling cookies without completely disabling the functionality and features they add to this site. It is recommended that Login related cookies this site offers email and newsletter subscription services and cookies may be used to remember if you are already registered and whether to show certain notifications which might only be valid to subscribed/unsubscribed users.

Login related cookies

This site offers email and newsletter subscription services and cookies may be used to remember if you are already registered and whether to show certain notifications which might only be valid to subscribed/unsubscribed users.

Email newsletters related cookies

This site offers newsletter or email subscription services and cookies may be used to remember if you are already registered and whether to show certain notifications which might only be valid to subscribed/unsubscribed users. Orders processing related cookies this site offers e-commerce or payment facilities and some cookies are essential to ensure that your order is remembered between pages so that we can process it properly.

Orders processing related cookies

This site offers e-commerce or payment facilities and some cookies are essential to ensure that your order is remembered between pages so that we can process it properly.

Third party cookies

Google Analytics (Analytics)
Google Analytics uses cookies to help us analyze how our users use our websites and services. You can find out more about this service and how Google uses your data at http://www.google.com/analytics and www.google.com/policies/privacy/partners/

Google Adwords (Advertising)
We use Google Adwords to target advertisements or marketing communications we believe may be of interest to you. You can opt out of targeted advertising by: https://www.google.com/settings/ads/anonymous

Google Tag Manager (Analytics)
Google Tag manager enables us to manage JavaScript and HTML tags used for tracking and analytics on websites.

Hotjar (Analytics)
We use Hotjar to understand how our visitors use our website and optimize their site journey. You can learn more about their privacy policy from here. https://www.hotjar.com/legal/policies/privacy

Zendesk (Live Chat)
We use Zendesk to manage and respond to customer inquiries via chat on https://www.elektra.com.mt. Learn more about their privacy policy from here. https://www.zendesk.com/company/customers-partners/privacy-policy/

Facebook (Analytics & Advertising)
We use Facebook as a medium to talk to customers and to measure the effectiveness of our advertising campaigns. You can opt out of targeted advertising by: https://www.facebook.com/settings/?tab=ads

LinkedIn (Analytics)
We use LinkedIn as a medium to talk to customers and to measure the effectiveness of campaigns.

Twitter (Analytics)
We use Twitter as a medium to talk to customers and to measure the effectiveness of campaigns. MailChimp We use MailChimp to send email campaigns to our subscribers. You can unsubscribe from our emailing platform.

MailChimp
We use MailChimp to send email campaigns to our subscribers. You can unsubscribe from our emailing platform Mailchimp – by clicking unsubscribe link on the footer part in each of our campaigns or reaching us through info@elektra.com.mt You can have more information about the privacy policy of Mailchimp from https://www.mailchimp.com/legal/privacy

Optinmonster 
We use Optinmonster campaigns to collect leads for offering a newsletter sign on our website. We will only add you to our newsletter list, if you have given specific consent for that purpose. Optinmonster does not collect any personal data. You can read more information about the privacy policy of Optinmonster on https://optinmonster.com/privacy/

D. For the development and improvement of products and/or services

We process your personal data to assess, analyse and improve our products and (customer) services. We use aggregated personal data to analyse customer behaviour and to adjust our products and services accordingly. When you use a Website or the App, enter or search data through this Website or the App; we also process your personal data to compile analytics reports. We use aggerated personal data to analyse customer behaviour and to adjust our products and services accordingly, to ensure that it is relevant to our customers. This means that we analyse how often your read our newsletters, how often you visit our Website or Apps, which pages you click on and what goods you purchase through our Website or Apps. We may purchase supplementary data from public source to complement our database for the above purposes.

For this purpose

  • we process your information based on our legitimate interest to develop and improve our products and services
  • we process your contact details such as your address and email address, personal details such as your name and date of birth, payment and credit information, and correspondence with us. In addition, we process the personal data you may have entered into a Website or that were generated by the functionalities you used in a Website and the technical data from your device such as its IP-address, the pages you visited on our Websites, your click- and surf behaviour and the length of your session
  • If you choose to participate in our surveys, we may ask you to provide us with personal data. We may also use the personal data that you have provided in the survey for this purpose

E. For the assessment and acceptance of a customer, supplier or business partner

When you get in contact with us, we will process your personal data for assessment and acceptance purposes, for example to confirm and verify your identity. Our Company will further process your personal data for other administrative purposes such as due diligence and screening against publicly available government and/or law enforcement agency and sanctions lists.

For this purpose

  • We process personal data because this is necessary for the conclusion of a contract between you and us. Our Company cannot enter into contracts without obtaining the required information
  • We process your contact details such as your address and email address, personal details such as your name and date of birth, payment and credit information and details of your correspondence with us.

F. For the conclusion and execution of agreement

When you have purchased a product or service form us as a customer, or when you work together with us as a supplier or business partner, we process your personal data for administrative purposes such as sending invoices and making payments. We also use your personal data to deliver or receive and administer our or your products or services. Our Company will process your personal data to further execute our agreement, inclduing for the delivery of customer services. When you require access to Our Company’s premises, we process your personal data for screening purposes.

For this purpose

  • We process personal data because this is necessary for the conclusion of a contract between you and us. Our Company cannot enter into contracts without obtaining the required information
  • We process your contact details such as your address and email address, personal details such as your name and date of birth, payment and credit information and details of your correspondence with us

G. For relationship management and marketing

We use the information stored in our customer database to send you suitable offers and newsletters, as well as to provide customer services, perform account management and communicate recalls. We also use your personal data for the development, execution and analysis of market surveys and marketing strategies.

For this purpose

  • When sending you newsletters and/or other relationship management and marketing communications, we process personal data based on your consent. In addition, we process personal data based on our legitimate interest to improve our marketing strategies
  • We process your contact details such as your address and email address, personal details such as your name, contact preferences, payment information, order history and correspondence with us.

H. For business process execution and internal management

We process your personal data in the performance and organisation of our business. This includes general management, order management and management of our assets. Our Company also processes your personal data for its internal management. We provide central processing facilities to work more efficiently. We conduct audits and investigations, implement business controls, and manage and use customer, supplier and business partner directories. Also, we process your personal data for financing and accounting, archiving and insurance purposes, legal and business consulting and in the context of dispute resolution.

For this purpose

  • We process personal data based on our legitimate interest to maintain and improve sound business operations
  • We process your contact details such as your address and email address, personal details such as your name, payment and credit information, payment and order history, correspondence with Our Company and data generated during the performance of the agreement between you and Our Company

I. For organizational analysis and development, management reporting and acquisition and divestures

At Our Company, we process your personal data in the preparation and performance of management reporting and analysis. We use aggregated/anonymised personal data to create management reports and to analyse our business. We conduct customer, supplier and business partner surveys to learn more about your views and opinions in preparation of our management reporting. We also process your personal data for management reporting purposes in the context of mergers, acquisitions and divestitures and to manage such transactions.

For this purpose

  • We process personal data based on our legitimate interest to maintain and improve sound business operations
  • We process your contact details such as address and email address, personal details such as your name and date of birth, payment and order history, correspondence with us and the information you provide when responding to our surveys

J. When you use our websites or apps

If you use our Website, we process technical data to offer you our Website’s functionalities and to allow our Website’s administrators to manage and improve our Website’s performance. If you enter data in our Websites, such as a product preference of your location to receive relevant information or functionalities. Further, we process your personal data to allow you to save your data (such as preferences and products) to your saved items and to allow you to share these with others using the sharing options you have configured on your device.

For this purpose

  • We process your personal data based on our legitimate interest to offer technically adequately working Websites and to improve our Website’s performance
  • We process the personal data you have entered into our Websites or that is generated by the functionalities you have used in our Websites and the technical data from your device such as its IP address, the internet browser you use, the pages you have visited on our Websites, your click- and surf behaviour and the length of your session.

K. To allow you to connect with us

Our Company is active on social media platforms like Facebook. When you contact Our Company via social media, we process your personal data to answer your questions and to respond to your messages.

In addition, when you visit a ‘Connect with us’ screen on one of our Websites or Apps, you can contact us through a variety of communication channels. We provide you with our email address, for you to send us your feedback and suggested improvements, as well as our Website, trade website, LinkedIn, Facebook and YouTube details. When you click one of the corresponding icons we will refer you to the website or app of the applicable third party, whether this is your email provider or a social media platform.

For this purpose

  • We process personal data based on our legitimate interest to adequately respond to your questions and correctly refer you to our social media pages
  • We process the communication channel you have chosen to use to connect with us and the personal data you supply to Our Company. This includes your (user) name, address, email address and the personal date you have included in your message. In addition, when you click one of the buttons displayed, the relevant third party might place cookies on your device.

L. To monitor and investigate compliance

We monitor our processes to check compliance with our policies and regulations. During monitoring activities, your personal data may be accessed and viewed.

For this purpose

  • We may process your personal data based on our legitimate interest to monitor our internal processes and to comply with the law
  • Any personal data that is stored in our systems may be accessed and viewed for compliance purposes. The personal data that are accessed and viewed will not be stored for compliance purposes, unless we need them to further investigate potential non-complaint behaviour
  • We do not retain your personal data for this purpose, unless they are linked to non-compliant behaviour. We will then retain the relevant personal data until the investigation or proceedings have been concluded.

M. To protect health, safety and security and to ensure integrity

At Our Company, we value your health, safety, security and integrity highly. We process your personal data to safeguard our employees, customers, suppliers and business partners. As such, we authenticate your access rights to our premises and may screen your personal data against publicly available government and/or law enforcement agency sanctions lists. We also process your personal data to protect Our company and employee and customer assets.

For this purpose

  • We may process your personal data based on our legitimate interest to monitor our internal processes and to comply with the law
  • We process your contact details such as your address and email address, personal details such as your name and date of birth, payment and order history, and your visiting history to our premises.

N. To comply with the law

In some cases, we process your personal data to comply with the laws and regulations. This could, for example, be the case where tax or business conduct related obligations apply. To comply with relevant laws and regulations, we may need to disclose your personal data to government institutions or supervisory authorities.

For this purpose

  • We process your personal data to comply with the law
  • We process your contact details such as your address and email address, personal details such as your name and date of birth, payment information, payment and order history, and your chamber of commerce and VAT details and tax details.

O. When you participate in events or promotions

We send you emails with promotions and invitations to participate in events. If you choose to participate in one of these activities, we need your personal data to be able to announce and organise these. In addition, if you participate in any of these activities, we need your personal data to measure the response to events and/or promotions.

For this purpose

  • We process personal data based on your consent. You can withdraw your consent at any time, without this affecting the lawfulness of processing based on consent before withdrawal
  • We process your name, address, email address and your entries in the relevant event

3. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?

Our Company generally shall retain Business Partner Data only for the period required to serve the applicable Business Purpose, to the extent reasonably necessary to comply with an applicable legal requirement or as advisable in light of an applicable statue of an applicable statute of limitations. Promptly after the applicable storage period has ended, the Data shall be:

(i) Securely deleted or destroyed;

(ii) Anonymised;

(iii) Transferred to an Archive (unless this is prohibited by law or an applicable records retention schedule)

4. WHO HAS ACCESS TO YOUR PERSOANAL DATA?

Access to your personal data within Our Company

As a global organisation, data we collect may be transferred internationally throughout Our Company’s worldwide organisation. Your personal data may be exchanged with the group that Our Company belongs to, shareholders and associated companies. We exchange your data for administrative purposes and so that we can have a complete overview of your contacts and contracts with the group that Our Company belongs to. We may also exchange your data to offer you a complete package of services and products.

Our Company’s employees are authorised to access personal data only to the extent necessary to serve the applicable purpose and to perform their jobs.

In some cases, your personal data may be transferred to a country that does not provide an adequate level of protection of personal data. However, Our Company has taken measures to ensure that your personal data is adequately protected as Binding Corporate Rules are applicable throughout the group that Our Company belongs to.

Access to your personal data by third parties

The following third parties may have access to your personal data where relevant for the provisioning of their products or services to Our Company: insurance companies, IT suppliers, auditors and consultants.

When third parties are given access to your personal data, Our Company will take the required contractual, technical and organisational measures to ensure that your personal data are only processed to the extent that such processing is necessary. The third parties will only process your personal data in accordance with applicable law.

If personal data is transferred to a third party in a country that does not provide an adequate level of protection of personal data, we will take measures to ensure that your personal data is adequately protected, such as entering EU Standard Contractual Clauses with these recipients. In other cases, your personal data will not be supplied to third parties, except when required by law.

5. HOW ARE YOUR PERSONAL DATA SECURED?

We have taken adequate safeguards to ensure the confidentiality and security of your personal data. We have implemented appropriate technical, physical and organisational measures to protect personal data against accidental or unlawful destruction or accidental loss, damage, alteration, unauthorised disclosure or access, and against all other forms of unlawful processing (including, but not limited to unnecessary collection) or further processing.

6. HOW CAN YOU EXERCISE YOUR PRIVACY RIGHTS?

You have the right to request access or an overview of your personal data, and under certain conditions, rectification and/or erasure of personal data. In addition, you may also have the right of restriction of processing concerning your personal data, the right to object to processing as well as the right to data portability.

To invoke your privacy rights, please contact us by using the contact details at the bottom of this Privacy Statement. Keep in mind that we may ask for additional information to verify your identity.

7. CAN YOU WITHDRAW YOUR CONSENT?

Once given, you may always withdraw your consent. Please keep in mind that withdrawal does not have retrospective effect and the withdrawal of your consent is only possible in case you first have given your consent. Please contact us to withdraw your consent by using the contact details at the bottom of this Privacy Statement.

8. HOW TO LODGE A COMPLAINT?

If you have a compliant about the use of your personal data by Our Company, you can lodge a complaint via the contact details at the bottom of this statement. Besides lodging a complaint with Our Company, you are also able to lodge a complaint with yur local data protection supervisory authority.

9. HOW CAN YOU CONTACT US?

If you have any questions about the way we process your personal data, please read this statement first. For additional questions, remarks, compliments or complaints, please contact us by telephone on +356 2546 3000, or by email at info@elektra.com.mt

25 May 2018