Privacy Policy

This brand and website are owned and operated by FESTIBAX B.V.

Customer Service email: contact@festibax.com

Should you have any questions, please contact us via our Contact Us page or email.

We are committed to protecting and respecting our customers' privacy. This Privacy Policy identifies and documents the types of personal information we collect and how we use this information. We detail who the data is shared with and your rights. This policy applies to our websites and apps.

WHAT PERSONAL DATA WE USE

Our data is based on your use and interaction with our Services and Websites. For example, personal information is passed on to us for shopping with us online, booking a consultation service with our team, communicating with us on live chat, interacting with us on social media and when you participate in a competition with us, amongst other reasons. The types of personal data may include:

  • Name, address, email address & phone number
  • Age or date of birth
  • Payment Information
  • Location (geo-location, postal code, country, etc.)
  • Product History
  • Preferences
  • Survey information, review responses, questions, and images
  • Information submitted via social media networks.

    LAWFUL BASIS

    We will use the information you provide for the above purposes if:

    • We have obtained your consent; or
    • It is necessary to enter into or perform a contract with you, for example, to process your payment and deliver the goods you have ordered; or
    • It is required for compliance with a legal obligation that we are subject to.

    LEGITIMATE INTEREST PURSUED

    We will also use the information you provide to the extent that it is in the legitimate interest of our business in conducting and managing our business. This will enable us to give you the best service and most secure experience and to comply with applicable laws. We may also use the information for security, website optimisation, performance marketing activities, or data analytics.

    WITH WHOM WE SHARE YOUR PERSONAL DATA

      Third parties with your consent

    Our partners and providers are contracted to perform services on our behalf. For example, entities that process credit card payments, distribution partners that fulfil orders and partners that provide web-hosting and marketing services.

    We must disclose information about you by law or legal process to law enforcement or other government officials, or in connection with an investigation of suspected or actual fraudulent or illegal activity.

    HOW LONG WE STORE YOUR PERSONAL DATA

    We store the information you provide for the duration of our relationship and an appropriate period after to enable us to comply with legal requirements and applicable statute of limitation periods. If you have consented to marketing communication, we will store the necessary information to continue to send you these communications. If you have a request for data removal, you can submit a request to contact@festibax.com.

    IF YOU DON’T PROVIDE US YOUR PERSONAL DATA

    Where we need to collect personal information by law, or under the terms of a contract we have with you, and you fail to provide that data when requested, we may not be able to perform the contract we have or are trying to enter into with you (for example, to provide you with goods or services). In this case, we may have to cancel a product or service you have with us, but we will notify you if this is the case at the time.

    YOUR RIGHTS

    You have certain rights and choices concerning the personal data we collect from you. To update your preferences, ask us to remove your information from our mailing lists or submit a request. Please contact us as specified below.

      Email opt-out

    If you have registered for email alerts, you can tell us not to send you alerts by email at any time by clicking on the unsubscribe link within the emails you receive or by contacting us as indicated below.

      Withdrawing consent

    You may withdraw any consent you previously provided to us at any time by contacting us as indicated below. This will not affect the lawfulness of using your information based on your consent before withdrawal.

      Reviewing, updating or deleting personal data or restricting or objecting to their use

    Subject to applicable law, you may have the right to request access to and rectification or erasure of the personal data we maintain about you, or to request the restriction of our use of this information, as appropriate. You may object at any time to processing your personal data on grounds relating to your particular situation, per applicable law. These rights may be limited in some circumstances under applicable law. You may exercise these rights by contacting us as indicated below.

      Other Rights

    Subject to applicable law, you have the right to receive, in a structured, commonly used and machine-readable format, the personal data you provided us about you, with your consent. You also have the right to transmit this information to another data controller, where it is technically feasible. You may exercise this right by contacting us as indicated below. You may also complain to a data protection authority.

      No fee is usually required

    You will not have to pay a fee to access your data (or to exercise any of the other rights). However, we may charge a reasonable fee if your request is unfounded, repetitive or excessive. Alternatively, we could refuse to comply with your request in these circumstances.

      What we may need from you

    We may request specific information from you to help us confirm your identity and ensure your right to access your data (or to exercise any of your other rights). This security measure ensures that personal data is not disclosed to anyone without the right to receive it. We may also contact you to ask you for further information concerning your request to speed up our response.

      Time limit to respond

    We respond to all legitimate requests within one month. Occasionally, it could take us longer than a month if your request is particularly complex or you have made several requests. In this case, we will notify you and keep you updated.

    The data subject has the right to withdraw consent at any time, without affecting the lawfulness of the processing based on consent before withdrawal (art. 13.2.c GDPR)

    In this section, you should inform the data subjects whether an automated decision-making process exists. You should also include the logic involved and the envisaged consequences for the data subjects (for example: describing the logic used by artificial intelligence and what the outcomes could be for the data subject) (art. 13.2.f)

    INTERNATIONAL TRANSFER OF PERSONAL DATA

    Our primary operations are based in the UK, and your personal information is generally processed, stored and used within the UK and other countries in the European Economic Area. In some instances however we may transfer the personal data we collect about you to our affiliates and third party service providers in countries other than the country in which the information was initially collected (including the United States), where necessary to fulfil the purposes described in this Privacy Policy and your data will be subject to applicable foreign laws. When we transfer your information to other countries, we will protect that information and implement appropriate safeguards to ensure a level of data protection when transferring your data, including the conclusion of data transfer agreements incorporating the European Commission’s Standard Contractual Clauses under Article 46 of the GDPR or other applicable data transfer mechanisms. Please contact us if you want further information on the specific mechanism we use when transferring your data out of the UK. In this section, you inform the data subjects of their right to complain, possibly including the contact details and name of the relevant supervisory authority (art. 13.2.d).