Wootbox is a service of SURPRIZEMI SAS, a French company whose registered office is located at 2 rue Paul Vaillant Couturier – 92300 Levallois-Perret, France, the companies of the group to which it belongs and notably the Webedia SA company, together with its technical processors are concerned with respecting your privacy and attach great importance to the confidentiality of your data on the Internet (hereafter the “Company”, “Us” or “us”).
This personal data protection policy (hereafter the “Data protection policy”) implemented by the Company applies to all the services that are offered to the persons using or browsing (hereafter the “Users”, “You” or “you”) the https://www.wootbox.co.uk/ website (hereafter the “Website”).
The purpose of the Data protection policy is to inform you on how we process the personal data that are collected through the services that are available on the Website.
As soon as you access another website from a link located on the website, the Data protection policy no longer applies. The Company reserves its right to amend this Data protection policy at any time and to inform you by any adequate means. The last update indicated below indicates the date on which these last amendments were made.
This Data protection policy is subject to the Act n° 78-17 of 6 January 1978 on information technology, data files and civil liberties as amended in 2004 (hereafter the “Information technology and civil liberties Act”) as well as the European General Data Protection Regulation of 27 April 2016.
What amounts to Personal Data?
Within the framework of this Data protection policy, “Personal Data” refers to any piece of information that allows for the identification of a User directly or indirectly, notably, for instance, by reference to his name, his email address, his IP address (hereafter the “Personal Data”).
Anonymised information, that is to say personal data that have been adequately processed for the purposes of making them non-identifiable in order to irreversibly prevent their identification, are excluded from the Personal Data.
When do we collect Personal Data and what are the data that we collect?
We may collect Personal Data when you use the services that are available on the Website, such as:
- Browsing the Website
- Creating and managing an account on the Website
- Subscribing to a newsletter
- Registering for games, competitions or any other event
- Contacting our teams
Regardless of the Service you use, we only collect the information that are strictly necessary (i) for the provision of the Services; (ii) for the performance of a contract to which you are party; (iii) for which you have given your consent, or (iv) in order to comply with a legal obligation to which we are subjected.
The Personal Data which are collected therefore vary from a User to another, depending on the number of the Services that are used by each User.
The Personal Data that we may collect through the Services include for example: your IP address, your name, your electronic address (email), or your home address.
When you browse the Website or when you use certain Services, we may place one or several cookie(s) on your terminal equipment (for example: your computer, your mobile phone). A cookie is a text file which implants itself in your terminal equipment and which stocks information that may be reread by the server afterwards.
Cookies are often used to make the users’ browsing easier (for instance in order to temporarily memorize your session in order not to ask you to provide this information once again every time you visit the Website or you browse from a page to another). Other cookies also allow for statistics to be made or your preferences to be memorized. The text file of the cookie will include diverse information such as your unique identification number without, however, allowing for your personal identification.
What are the aims of the collection of your personal data?
Your Personal Data can be collected for the following purposes, depending on the Services you use:
- Provision of Services or of the information that you request
- Allowing for the smooth technical and administrative functioning of the Website
- Management of your user’s account and of the related preferences
- Provision of social networks’ sharing tools
- Monitoring and analysis of the use of the Services by the Users
- Audience measurement on the Website
- Sending targeted commercial offers by email
- Management of your subscriptions to our newsletter, email notification
- Conducting surveys
- Setting up advertising and competition games, by lot or by any other means
- Information sharing with commercial partners
- Answering requests from administrative authorities or legal requisitions, in accordance with the applicable laws
Prior to any direct commercial marketing operation (for example for the purposes of sending partner offers), we will first collect your consent, either when you create your account on the website or afterwards when you indicate your choice in the account’s settings). You may withdraw your consent at any time directly via the unsubscribe link which is included in each of the emails you receive; you can amend your account’s settings; or contact us at the following address: service-client(at)wootbox.fr.
What are your rights and how to exercise them?
Your rights.. In accordance with the applicable laws, you have a right of access, a right of rectification and a right to object to the data concerning you. You can access the information that you have provided at the time of the creation of your account and modify them via your account page or you can contact us to this end at the address set forth below
Your rights as from the 25th of May 2018. AAs from the 25th of May 2018 and in accordance with the 2016/679 Regulation of 27 April 2016, you can also exercise your right to the limitation of the processing, to the erasure of your data, to the portability of your Personal Data and not to be subject to an automated individual decision.
Right to object. Within the limits of the applicable laws, except for the processing for which there exists legitimate and compelling grounds for the processing of your Personal Data, you can, at any time, object to the processing of your Personal Data, notably when your data are processed for direct marketing purposes.
Right to restriction of processing. You can request that we restrict the processing of your Personal Data when one of the following elements applies or in any other circumstances provided for by the applicable laws:
- you oppose the erasure of your Personal Data and request the restriction of their use instead, in situations where you tell us that the processing is unlawful (for example in situations where an ill-intentioned person has created an account with your email address and personal data concerning you);
- you contest the accuracy of the Personal Data, for a period during which we will proceed to verify the accuracy of the data that we have collected;
- the Personal Data are no longer needed for the use of the Services but you wish that we store them for the establishment, exercise or defence of legal claims.
Where the restriction of processing is lifted, we shall inform you through the most adequate means (for example via email or postal mail).
Right to data portability.You have the right to receive your Personal Data in a structured, commonly used and machine-readable format. In order to exercise your rights, please visit your account page. These data only relate to the data that have provided in your account as well as the IP addresses you used.
Right to erasure.For the exercise of the right to erasure (“right to be forgotten”), the obligation to erase the data shall only apply to the Personal Data within the limits of the applicable laws and notably to the following Personal Data:
- which are no longer necessary in relation to the purposes for which they were collected or otherwise processed;
- whose processing is based on the consent of the data subject (for example: sending a newsletter, sending promotional offers)
We shall provide you with an answer within one month as from receipt of the request. In light of the complexity of the request or of the number of requests to be processed, we may inform you via email that this period may be extended to two months in exceptional circumstances.
Exercise of your rights.In order to exercise your rights, you can contact us via postal mail or via email at the following address:
Wootbox Surprizemi – Service Client
2 rue Paul Vaillant Couturier
email : email@example.com
If the answers are not satisfactory, you can also contact the data protection officer via postal mail or via email at the following address:
Wootbox Surprizemi – DPO
2 rue Paul Vaillant Couturier
email : firstname.lastname@example.org
In the interests of confidentiality and protection of personal data, a copy of a signed identity document shall be attached to the request.
Within the limits allowed by the applicable statutory provisions, when the requests of a person are manifestly unfounded or excessive, in particular because of their repetitive character, we may refuse to act on the requests or charge a reasonable fee taking into account the administrative costs of providing the requested information.
If the answer is not satisfactory, you may refer the matter to the CNIL.
What are the specificities regarding children’s rights?
In order to access or use our Services, children below the age of 15 years shall obtain their legal representative’s consent (for instance their father, mother, legal guardian or any other legal representative holding parental responsibility).
At the time of the registration of a child below the age of 15 years on the Website, we withhold the right to reasonably verify that the access and use of the Services have been authorized by the child’s legal representative.
How long are your data stored?
The Personal Data that you send to us are stored in a secured technical environment.
Depending on the processing carried out on your Personal Data, the data may be subject to a different storage period.
Most of the Personal Dara are stored for a period of three (3) years as from your last use of the Website, of a Service. At the expiration of the storage period the Personal Data are cleansed and therefore erased from our database.
However, the IP address that we collect when you visit the website is stored for a period of one year.
Who is the data protection officer?
Webedia has nominated a data protection officer who is in charge of assisting the data controller in compliance with the European Regulation. Any question concerning the protection of personal data within the Webedia group shall be addressed to his contact address: email@example.com
Are your data sent outside of the European Union?
For the use of certain Services, some of your Personal Data may be sent to partners or processors which are located on the European Union’s territory or in territories that offer an adequate level of personal data protection or to partners which are party to an agreement in the field of the law on personal data protection such as the data protection shield which is in force in the United States (EU-US Privacy Shield).
How do we protect your Personal Data?
We take diverse steps to maintain data security against the loss, abusive use, unauthorized access, disclosure, modification or destruction of your Personal Data and in particular:
- A password policy is implemented for the creation and management of the accounts
- The users’ passwords are subject to a strong encryption when they are saved to the databases
- The TLS protocol is used for the forms that contain Personal Data and allows for the encryption of the data on the network
- Access to personal data is strictly reserved to the persons who are authorized to view the data within the terms of their missions
- In accordance with the Information technology and civil liberties Act of 6 January 1978 and the European Regulation, Odyssée Interactive made sure that processors have committed themselves to data security and confidentiality
- All of Odyssée Interactive’s employees, working on the Website, are aware of personal data protection issues through trainings, newsletters and team meetings.
We reserve the right to amend this Data protection policy at any time. In cases of substantial amendment such as incorporating a new purpose, we shall provide you with information on that other purpose prior to that further processing. This ensures that you have a reasonable period to exercise your rights in accordance with the applicable laws
We however encourage you to regularly visit the Data protection policy so that you can be aware of the types of protection of your personal data that are provided for.
This Data protection policy was last updated on the date set forth below.
Any enquiry concerning our Data protection policy shall be addressed to us directly via email at info(at)wootbox.co.uk or via postal mail at Wootbox – Service Client – 2, rue Paul Vaillant Couturier – 92300 Levallois-Perret France.
Dernière mise à jour le 25 mai 2018.