Printable Version as PDF Download

DATA PROTECTION INFORMATION

HUGO BOSS Newsletter

 

HUGO BOSS AG, Dieselstraße 12, 72555 Metzingen, Germany (hereinafter „HUGO BOSS“ or „we”) offer visitors to the HUGO BOSS website (www.hugoboss.com) (hereinafter „Website“) and visitors to the HUGO BOSS Outlet Stores (hereinafter „Outlets“) the possibility to subscribe to the HUGO BOSS Newsletter (hereinafter „Newsletter“).

In the following we are providing you with the information required in accordance with Articles 13 and 14 of the General Data Protection Regulation („GDPR”) regarding the processing of personal data in connection with your Newsletter subscription.

You can find additional information about the processing of personal data in the Data Privacy Policy of the HUGO BOSS Website.

If you take part in the HUGO BOSS EXPERIENCE customer loyalty programme (hereinafter „Customer Loyalty Programme“), we also store your subscription to our Newsletter in your My HUGO BOSS customer account. You can find detailed information on the processing of personal data in connection with the Customer Loyalty Programme in the Data Privacy Policy for Participation in HUGO BOSS EXPERIENCE.

 

A. Name and contact details of the controller

The controller for the Newsletter is:

HUGO BOSS AG
Dieselstraße 12, 72555 Metzingen, Germany
Telephone: +49 7123 94-0
Fax: +49 7123 94-80259
E-mail: info@hugoboss.com

 

B. Contact details of our data protection officer

The contact details of our data protection officer are as follows:

HUGO BOSS AG
Data Protection Officer
Dieselstraße 12, 72555 Metzingen, Germany
Telephone: +49 7123 94 – 85122
Fax: +49 7123 94 885122
E-mail: datenschutz@hugoboss.com

 

C. Categories and sources of personal data

We process the following (categories of) personal data:

Categories of personal data that are processed Types of personal data within the category Source of the personal data
(and, if applicable, whether the source is publicly accessible)
Data that we collect when you register for the Newsletter (“Registration Data”) E-mail address (mandatory), title, first name, surname (voluntary).
When registering on the website, we also record the country-specific version of HUGO BOSS Website via which you subscribe to the Newsletter.
When registering in an Outlet, we also record the Outlet and the country in which you subscribe to the Newsletter.
Newsletter subscribers
Protocol data that are generated technically when subscribing or unsubscribing to the Newsletter (“Subscription and Unsubscription Data”) Date and time of subscription confirmation in double opt-in process, as well as the IP address of the terminal device used for confirmation, data and time of any unsubscription from the Newsletter. Newsletter subscribers
Protocol data that are generated technically via the Hypertext Transfer Protocol (HTTP) using the web beacons** contained in the Newsletter when our Newsletter is accessed (“Newsletter HTTP Data”) IP address, date and time of access Newsletter subscribers
Data that are stored in cookies* in the Newsletter subscriber’s browser when our Newsletter is accessed („Newsletter Cookie Data“). Unique ID to (re)identify Newsletter subscribers Newsletter subscribers
Data in usage profiles that we create by analysing usage behaviour in the Newsletter using pseudonyms (“Newsletter Usage Profile Data”). Data on usage of the Newsletter, in particular visits, visit frequency and click behaviour in accessed Newsletters Generated autonomously
Protocol data that are generated technically via the Hypertext Transfer Protocol (HTTP) when the HUGO BOSS Website is visited (“Website HTTP Data”). IP address, type and version of your Internet browser, operating system used, page visited, page visited beforehand (referral URL), date and time of visit. Newsletter subscribers
Data that are stored in cookies* in the Newsletter subscriber’s browser when the HUGO BOSS Website is accessed (“Website Cookie Data”). Unique ID to (re)identify Newsletter subscribers and aggregated Segment Data with objective of improving campaign content. Newsletter subscribers
Data in usage profiles that we create by analysing the usage behaviour of Newsletter subscribers on the website by using pseudonyms (“Website Usage Profile Data”). Data about the use of the Website, in particular visits, visits frequency and visit duration on the pages visited. Generated autonomously
Subscriber segments that we create by combining and analysing Newsletter Usage Profile Data using pseudonyms (“Segment Data”). Data about affinity to HUGO BOSS brands, their products or content. Generated autonomously
 

* Cookies are small text files with information stored on the user’s terminal device via its browser when a website is visited. When the website is visited again using the same terminal device, the cookie and the information stored in it can be accessed. Depending on storage duration a differentiation is made between transient and persistent cookies. Transient cookies, already called session cookies, are deleted automatically when you close your browser. Persistent cookies are stored on your terminal device for a defined period even after you close your browser.

** Web beacons (also called tracking pixels) are small images that enable a log file to be recorded and analysed when e-mails or websites are accessed.

 

D. Purpose and legal basis of processing personal data

We process the (categories of) personal data specified in C. above for the following purposes and on the legal bases.

If processing is based on Article 6 (1) (f) GDPR, we also specify the legitimate interests pursued by us or any third party.

Purpose of processing
(and, if applicable, the legitimate interests pursued with the processing)
(Categories of) personal data
(see point C. above for details on the individual categories)
Legal basis for processing in accordance with GDPR
(as of 25.05.2018)
(Categories of) recipients
(see E. below for details)
Web applications made available on the Website in which you can provide data to us regarding your subscription or unsubscription of our Newsletter. Website HTTP Data, Registration Data, Subscription and Unsubscription Data Point (f) of Article 6(1) GDPR Hosting service providers Newsletter service providers
(Digital) subscription forms made available in the Outlets, in which you can provide data to us regarding the subscription of our Newsletter. Registration Data, Subscription and Unsubscription Data Point (f) of Article 6(1) GDPR Newsletter service providers
“Double opt-in” procedure to confirm subscription.
For this purpose we send you an e-mail message requesting you to confirm the e-mail address specified when subscribing to the Newsletter A subscription does not take effect until the e-mail address has been confirmed by clicking on the confirmation link in the e-mail.
Registration Data, Subscription and Unsubscription Data Point (f) of Article 6(1) GDPR Newsletter service providers
Sending the Newsletter to Newsletter subscribers.
We use the title and name you specified when subscribing to the Newsletter to personalise your Newsletter.
To determine the language and the country-specific content of the Newsletter we use the country-specific version of the HUGO BOSS Website used when registering for the Newsletter on the Website. When registration takes place in an Outlet, we use the language of the Outlet in which the registration took place for this.
When registration takes place in an outlet we also use the recorded information on the individual outlet in which you registered for the Newsletter to determine the country-specific and outlet-specific content of the Newsletter.
Registration Data, Newsletter HTTP Data, Newsletter Cookie Data, Segment Data Point (a) of Article 6(1) GDPR Newsletter service providers
Analysis of usage behaviour of Newsletter subscribers in our Newsletter and on our Website and creation of usage profiles using pseudonyms and Subscriber Segments based on these for the purposes of personalising and designing the Newsletter in accordance with user preferences. Registration Data, Newsletter HTTP Data, Newsletter Cookie Data, Newsletter Usage Profile Data, Website HTTP Data, Website Cookie Data, Website Usage Profile Data, Segment Data Point (a) of Article 6(1) GDPR Newsletter service providers
Creation of anonymised reports analysing and determining Newsletter strategy. Registration Data, Segment Data Point (f) of Article 6(1) GDPR  
 

E. Recipients who receive personal data

For the purposes set forth in D. we use a contract data processor that supports us in the handling of our business processes. The following service providers and/or categories of service providers to whom we disclose personal data belong to these:

  • Hosting service providers
  • Newsletter service providers

F. Duration for which personal data are stored

The duration for which the personal data are stored is set forth below and determined based on the following criteria:

(Categories of) personal data
(see C. above for details on individual categories)
Duration for which personal data are stored / criteria for determining this duration
Registration Data, Subscription and Unsubscription Data We store this data for as long as you subscribe to our Newsletter. In addition, we store this data as an exception beyond this if and as long as we are subject to statutory retention or documentation obligations for such data or to the extent this is necessary for evidence purposes.
Newsletter HTTP Data, Newsletter Cookie Data, Newsletter Usage Profile Data, Website HTTP Data, Website Cookie Data, Website Usage Profile Data, Segment Data We only store this data as long as you subscribe to our Newsletter. We delete such data as soon as you have unsubscribed our Newsletter.
 

G. Necessity or obligation to provide personal data and possible consequences of not providing such data

The provision of the following personal data is required/mandatory by law/contract or in order to conclude a contract:

(Categories of) personal data
(see C. above for details on individual categories)
Necessity/Obligation Possible consequences of not providing such data
Registration Data You must provide your e-mail address when registering in order to receive the Newsletter. Not providing your e-mail address means that we cannot send you the Newsletter.
 

H. Rights of the data subject

I. Access, correct, deletion, restriction, data portability

You have the following rights with respect to the processing of your personal data:

  • To request us to grant you access to your personal data in accordance with Article 15 DSGVO.
  • To request us to correct your personal data in accordance with Article 16 GDPR.
  • To request us to delete your personal information in accordance with Article 17 GDPR.
  • To request us to restrict the processing of your personal information in accordance with Article 18 GDPR.
  • The right to data portability in accordance with Article 20 GDPR.

II. Right to object

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR (see D. above).

If personal data are processed for the purposes of direct marketing (see D. above), you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing.

III. Right to withdraw consent

If processing is based on point (a) of Article 6(1) or point (a) of Article 9(2) GDPR (see D. above), you have the right to withdraw your consent at any time without the legality of processing based on your consent which has taken place up to withdrawal being affected.

IV. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a supervisory authority in accordance with point (f) of Article 57(1) GDPR.

Last modified: 20 March 2018