By using this website or any of our services, you consent to the use of your personal data in the manner contained in this policy, to the extent permitted by law. Please read this policy carefully and note that the English version of this policy is binding, all other translations are only for convenience purposes.
Please note that if you are in the European Economic Area, United Kingdom, Switzerland or any other country that the EU General Data Protection Regulation (“GDPR”) applies (hereinafter referred to as “Europe”), you will not be required to consent to this Policy, however, by using Namsû, you acknowledge that you have read and understood its terms. The provisions of Section 12 of this policy apply to you specifically.
Please note that if you live in California, the California Consumer Privacy Act applies to you. The provisions of Section 13 of this policy apply to you specifically.
We are Namsû (Hereinafter referred to as “Namsû” “we” “our platform” and “us”), a company registered in the United Kingdom but operating services globally. We are a lifestyle brand that is all about indulgent bathing experiences, balancing ancient wisdom and rituals with the latest science and sustainability.
We are based in London, United Kingdom. Regarding any issue related and connected to your privacy on our platform, we can be contacted through firstname.lastname@example.org. We have a dedicated team who would endeavour to respond to your email timeously.
HOW WE COLLECT YOUR INFORMATION
To maximize your experience on our website, we collect information in the following ways:
- When you provide them to us either by access, use or purchasing our goods and services, registering for our platform (including but not limited to when you connect your profile on a third-party platform with your registration details), request certain information from us, join or participate in any of our promotional services, use our review, ratings or scoring feature, interact with any of our social media platforms, install or use any of our applications, access any third party links on our platform or interact with us either online or offline in any manner whatsoever.
- We also passively collect information when you use our service. This collection of information can be from information in your browser or device.
- As you interact with any of our platforms, we may automatically collect Technical information about your equipment, browsing actions and patterns. We collect this personal data by using cookies, server logs and other similar technologies. We may also receive technical information about you if you visit other websites or when you visit our sites and applications or use our applications on third-party sites or platforms using one or more devices that employ our cookies whether or not you are logged in or registered. To disable cookies, please refer to our cookies policy here.
- We also collect information through analytics tools including but not limited to Google Analytics, etc. This collection happens when you use any of our services or visit our platforms.
INFORMATION WE COLLECT
- Through the mediums stated in Section 3, either from those provided to us by you, through third parties or through passive and automated means, we collect the following information from you.
- Registration Information: When you create an account with us, link your profile through a third party platform. We collect your contact or log-in details which include but are not limited to name, email address, country of residence, zip/postcode, phone number any other information you choose to share with us such as bio, etc.
- Transaction Information: This is collected when you contact us about a transaction on the platform. The information that will be collected includes but is not limited to banking information, contact information such as your phone number, email address, mailing address, billing address, card number or payment details or any other information you provide to us. Our payment processors also collect and retain information related to your transaction. Please note that in many cases, Namsû cannot view or access all of the information you provide to us for compliance purposes, such as complete bank account numbers or payment information, as this may be transmitted in an automated manner directly to the party that requires that compliance information. Transaction information is not needed to register on our Platform, they are only collected when a purchase is made or a financial transaction is initiated.
- Compliance Information: Information provided needed for compliance purposes as required for our services as needed or required by law.
- Information about your visits to and use of our platform including the referral source, length of visit, page views, and website navigation paths.
- Location Information: This is information about your location provided by a mobile or other device interacting with our platforms, or associated with your IP address, where we are permitted by law to process this information.
- Information, such as your name and email address, that you enter in order to set up subscriptions to our emails, promotional and campaign updates and/or newsletters.
- Usage, viewing, technical, and device data when you visit our sites, use our applications on third-party sites or platforms, or open emails we send, including your browser or device type, unique device identifier, and IP address. We collect some of this information by using “cookies” or other similar technologies directly from your device.
- Information that you post to our website with the intention of publishing it on the internet, which includes your username, and the content of your posts, such as reviews.
- Information contained in any communications that you send to us by email or through our website, including its communication content and metadata.
- Activity information about your use, and the use by any person(s) you authorize through your account, of our sites and applications, such as the content you view or post, how often you use our services, and your preferences.
Please note that the information we collect from you is categorized as follows: (a) identifiers (name, email address, IP address, location information, profile photographs); (b) commercial information (transaction data); (c) financial and transaction information (transaction details, payment details etc); (d) Internet and device information (browsing history; IP address, cookies, device details, browser information) (e) inference information about you; (f) sensory information (if you call us, send an email or leave a voicemail); (g) usage Information (such as information about how you use our website(s), products, and services); (h) marketing and communications information (This is linked to your preferences in receiving marketing from us and third parties and your communication preferences); and (i) other information that identifies or can be reasonably linked to you.
We do not collect any special categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). If you provide this information in our public forums such as reviews, we might not be able to protect such information. Please know that we will in no circumstance ask for this special category of personal data information.
You are not required to provide personal data to us. It is within your right to decline any request to provide information to us. However, your failure to do so may affect our ability to provide the services you request. It might also limit the use of our platform to its full potential. If you have an account with us, you may also review, change or remove certain types of your information provided to us by accessing your account section of the website.
HOW WE USE THE INFORMATION COLLECTED FROM YOU
In line with regulatory provisions, applicable laws, your preferences as set on our platform or third party platforms, we use information collected from you or related devices in the following manner or any other manner as stated on the relevant pages of our platform:
- Administering, improving or promoting our services and ensuring that we maximize the potentials of our platform for your use.
- Personalizing the use of our platform as selected and set by you.
- For processing purchases, transactions, understanding your interests and doing all that is needed and important to carry out our services to you.
- Internal use by our staff and contractors to ensure the maximization of your use of our platforms.
- Analyzing data usage trends and preferences in order to improve the accuracy, effectiveness, security, usability or popularity of our Services.
- Communicating with you regarding a) marketing communications relating to our business or the businesses of carefully-selected third parties which we think may be of interest to you (you can inform us at any time if you no longer require marketing communications either by clicking unsubscribe at the bottom of the email or contacting us in other ways provided); b) your account or transactions on our platform; (c) send you Know Your Customer (KYC) information or request feedback about features on our platform; (d) notify you of changes to our policies; and (e) sending you non-marketing commercial communications such as dealing with inquiries and complaints made by or about you relating to our platform or any other communication to us from you.
- Technical activities, such as bug detection and error reporting, etc.
- Providing third parties with statistical information about our users (but those third parties will not be able to identify any individual user from that information);
- Verifying compliance with the Terms of Service governing the use of our website; and
- Security, Fraud, and Legal Compliance, including to detect, investigate and prevent activities that may violate our policies or be illegal.
- If you are located in Europe, we process information as listed in this policy as necessary (i) to fulfil our obligations under our contract with you or in order to take steps at your request prior to entering into a contract, or (ii) for our legitimate interest, such as to maintain our relationship with you or to protect you when you use our platform.
- Your information for the purposes for which it was collected, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to obtain an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us. We will notify you if we need to use your information for unrelated purposes and we will explain the legal basis which allows us to do so. Please note that we may process your personal data without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.
DISCLOSURE OF INFORMATION COLLECTED FROM YOU
Except as provided in this policy, we will not provide your personal information to third parties. The way in which we may disclose information collected from you are:
- For compliance purposes like payment processing or identity verification.
- For legal purposes which includes but are not limited to; complying with the requirements of the law such as subpoenas, search warrants, court orders, and other legal processes; responding to enquiries or requests from government, regulatory, law enforcement, public authorities, or content protection organizations; defending the legal rights, privacy, safety or property of Namsû, its subsidiaries, employees, agents, contractors or users; permitting Namsû to pursue available remedies, commence, participate in or defend litigation, or limit the damages we may sustain; and to enforce this Policy or any applicable Terms of Service are complied with.
- We may also disclose to Third-party platforms needed to perform our services to you. This includes but is not limited to payment services providers e.g Paypal, Shopify Payments, Visa, Mastercard or any payment platform selected by you.
- To maximize our service to you, we might disclose to our partners and service providers which includes but are not limited to banks and payment providers, third-party identity checking or credit reference agencies, communication providers, marketing agencies, analytics tools, Information Technology, information security and cloud services providers, delivery personals.
- We may share your information internally for the performance of our services to you.
- We may transfer any information we have about you as an asset in connection with a proposed or completed merger or sale (including transfers made as part of insolvency or bankruptcy proceedings) involving all or part of Namsû or as part of a corporate reorganization or other change in corporate control.
- We may share your information with your consent, such as when you post personal information on platforms accessible to third parties, or you share your profile activities with third-party platforms.
- Please note that once we share your personal information with another company, the information received by the other company is controlled by that company and becomes subject to the other company’s privacy practices.
SECURITY OF YOUR PERSONAL INFORMATION
- We will take reasonable technical and organizational precautions to prevent the loss, misuse, or alteration of your personal information.
- We will store all the personal information you provide on our secure (password- and firewall-protected) servers.
- All electronic financial transactions entered into through our platform will be protected by encryption technology.
- You acknowledge that the transmission of information over the internet is inherently insecure, and we cannot guarantee the security of data sent over the internet, however, we undertake to take all reasonable steps to ensure the safety of your data.
- You are responsible for keeping the password you use for accessing our website confidential; we will not ask you for your password (except when you log in to our website).
YOUR RIGHTS AND CONTROLS ON YOUR INFORMATION
Under certain circumstances, you have rights under data protection laws in relation to your personal data. These rights are:
- The right to request access to your personal data (commonly known as a “data subject access request”): enables you to receive a copy of the personal data we hold about you and to check that we are lawfully processing it.
- The right to request correction of such personal data that we hold about you: this enables you to have any incomplete or inaccurate data we hold about you corrected. However, we may need to verify the accuracy of the new information you provide to us.
- Request erasure of your personal data: this enables you to ask us to delete or remove personal data where there is no good reason for us to continue to process it. You also have the right to ask us to delete or remove your personal data where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal data to comply with local law. Note, however, that we may not always be able to comply with your request of erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
- The right to object to the processing of your personal data, where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms: You also have the right to object where we are processing your personal data for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
- The right to request the restriction of processing of your personal data: this enables you to ask us to suspend the processing of your personal data in the following scenarios: (a) if you want us to establish the data’s accuracy; (b) where our use of the data is unlawful but you do not want us to erase it; (c) where you need us to hold the data even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your data, but we need to verify whether we have overriding legitimate grounds to use it.
- The right to request the transfer of your personal data to you or to a third party: we will provide to you, or a third party you have chosen, your personal data in a structured, commonly used, machine-readable format. Please note that this right only applies to automated information that you initially provided consent for us to use or where we used the information to perform a contract with you.
- The right to withdraw consent at any time where we are relying on consent to process your personal data. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.
- The right to opt-out - You can opt-out of receiving our marketing communications. However, you will still receive transactional messages from us. To opt-out of receiving our marketing communications, you can contact us at email@example.com
In ensuring that we address your requests:
- You will not have to pay a fee to access your personal data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive, or excessive. Alternatively, we may refuse to comply with your request in such circumstances.
- We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.
- We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex, requires additional efforts or you have made several requests. In this case, we will notify you and keep you updated.
- For the purpose of this clause 8, legitimate interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
We may update this policy from time to time by publishing a new version on our website. You should check this page occasionally to ensure you understand any changes to this policy. We may notify you of changes to this policy by email or through email or any other choice of communications as set by you.
The use of our website is reserved for adults under the relevant laws of the country of use. The use of our platform or any of our services must be through the use of an account owned and operated by a parent or legal guardian. The parent must also provide affirmative consent and supervise the use of their account. Users are solely responsible for any use of their account by a minor. If you are a child under the age where parental consent is required in your country, you should review the terms of this Policy with your parent or guardian to make sure you understand and accept them. If you have reason to believe that a child has provided personal information to Namsû through our platform, please contact us at firstname.lastname@example.org, and we will delete that information from our databases to the extent required by law.
HOW LONG DO WE KEEP YOUR INFORMATION?
We keep your personal data in an identifiable form for as long as we have a legitimate reason to use the data and as required by law.
GENERAL DATA PROTECTION REGULATION (“GDPR”) PROVISIONS
In addition to the clauses contained in this Policy, if you are a user in Europe, as directed by the GDPR, the following provisions apply to you. However, if you have doubts on whether the provisions in this (12) applies to you, please contact a legal practitioner for advice.
- Namsû is a data controller under the provisions of the GDPR, and we are responsible for how your information is collected, used and disclosed. Please note that - the information collected by us is controlled by the Terms of Service, this policy, and our cookies policy
- We only collect information to the extent needed and germane for the performance of our contract to you, provide services on our platform and perform all the rights, obligations, responsibilities and terms contained in our Terms of Service.
- We also collect information for our legitimate interest, on the basis of consent, to improve the quality of service provided to you, to respond to your questions, to provide marketing information to you, for legal reasons, to make and receive payment for the security of our platform, to enforce our Term and Conditions, to engage in business change, to comply with a legal or regulatory obligation and to create anonymous data.
- For the purpose of (e), legitimate interest means the interest of our business in conducting and managing our business to enable us to give you the best service/product and the best and most secure experience. We make sure we consider and balance any potential impact on you (both positive and negative) and your rights before we process your personal data for our legitimate interests. We do not use your personal data for activities where our interests are overridden by the impact on you (unless we have your consent or are otherwise required or permitted to by law). You can obtain further information about how we assess our legitimate interests against any potential impact on you in respect of specific activities by contacting us.
- For the purpose of (e), compliance with a legal or regulatory obligation means processing your personal data where it is necessary for compliance with a legal or regulatory obligation that we are subject to.
- Users in Europe have the right to opt-out of all of our processing of their data for direct marketing purposes, to do this you click “unsubscribe” at the bottom of a marketing email or edit your preferences in your account setting.
- Users in Europe also have the rights contained in 8 (a-g). In addition, they may also object to our uses or disclosures of personal data, request a restriction on its processing, or withdraw any consent, though such actions typically will not have a retroactive effect. They also will not affect our ability to continue processing data in lawful ways (for example, if you opt-out of the use of your telephone number for direct marketing, we might still decide to contact you by phone regarding potential fraud on your account).
- Users in Europe also have the right to lodge a complaint with the local data protection authority if you believe that we have not complied with applicable data protection laws. You also have the right to lodge a complaint with the supervisory authority of your residence, place of work or where the incident took place. However, please endeavour to contact us first at email@example.com
- We will only keep and retain the collected information as needed and pertinent for the collected data and as permitted by law. As soon as we no longer need to keep the data, we will remove it from our platforms and systems. We will also take the needed steps to anonymize the collected information.
- When we no longer need to use your information, we will remove it from our systems and records and/or take steps to anonymize it and take other steps to protect them. We regularly review our security procedures to consider appropriate protection methods. However, please be aware that despite our best efforts, no security measures are perfect or impenetrable.
- When determining the retention period, we take into account various criteria, such as the type of products and services requested by you or that you are provided with by us, the nature and length of our relationship with you, possible re-enrolment with our services, the impact on our platform if we delete the information about you, mandatory retention periods provided by law and the statute of limitations.
- For any transfer, wherever your personal data is transferred, stored or processed by us, we will take steps to safeguard the privacy of your personal information. For any information on your privacy, any question and these regulations, you can reach us at firstname.lastname@example.org
CALIFORNIA CONSUMER PRIVACY ACT
If you live in California, you may have the following rights over your information:
- For the period covering the 12 months preceding your request, you may request that we disclose to you the categories and specific pieces of information collected about you, the categories of sources from which we collected that information, and the purposes for which your information was collected.
- You may also request that we delete the information we collected from you.
- You have the right not to be discriminated against for exercising your rights over your information.
- You may submit a request to exercise your rights by sending us an email at email@example.com
Please do not hesitate to contact us if you have any questions regarding Namsû’s policy or our attitude to the protection of your information. You can reach us at firstname.lastname@example.org or through our live chat team that can be reached here. You can also contact us through our registered address which is 85 Great Portland Street, London, W1W7LT, United Kingdom.