Itsapark

PRIVACY NOTICE

Data privacy is of high importance for Itsapark and we want to be open and transparent with our processing of your personal data.

We therefore have a policy setting out how your personal data will be processed and protected.

Who is the controller of your personal data?

The Swedish company, H & M Hennes & Mauritz GBC AB (“Itsapark”), is the controller of the personal data you submit to us and responsible for your personal data under applicable data protection law.

H & M Hennes & Mauritz GBC AB

Mäster Samuelsgatan 46106 38 Stockholm

SwedenCompanies register:

Bolagsverket/Swedish Companies Registration Office

Company registration number: 556070-1715

Authorised representative: Karl-Johan Persson

VAT registration number: VAT NO. SE556070171501

Where do we store your data?

The data that we collect from you is stored within the European Economic Area (“EEA”) but may also be transferred to and processed in a country outside of the EEA. Any such transfer of your personal data will be carried out in compliance with applicable laws.

For transfers outside the EEA, Itsapark will use Standard Contractual Clauses and Shields as safeguards for countries without adequacy decisions from the European Commission.

Who can access your data?

Your data may be shared within the H&M group (for details on the companies within the H&M group, please refer to our annual report which may be found at about.hm.com). We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group.

Data that is forwarded to third parties, is only used to provide you with our services. You will find categories of third parties under every specific process below.

What is the legal ground for processing?

For every specific process of personal data we collect from you, we will inform you whether the provision of personal data is statutory or required to enter a agreement and whether it is an obligation to provide the personal data and possible consequences if you choose not to.

What are your rights?

Right to access:

You have the right to request information about the personal data we hold on you at any time. You can contact Itsapark and we will provide you with your personal data via e-mail.

Right to portability:

Whenever Itsapark processes your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.

Right to rectification:

You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed. If you have an Itsapark account you can edit your personal data under your account and account pages.

Right to erasure:

You have the right to erase any personal data processed by Itsapark at any time except for the following situations:

* if you are suspected or have misused our services within the last four years

Your right to object to processing based on legitimate interest:

You have the right to object to processing of your personal data that is based on Itsapark's legitimate interest. Itsapark will not continue to process the personal data unless we can demostrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.

Your right to object to direct marketing:

You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes.You can opt out from direct marketing by the following means:

* following the instructions in each marketing email

* by editing the settings of your Itsapark account

Right to restriction:

You have the right to request that Itsapark restricts the process of your personal data under the following circumstances:

* if you object to a processing based Itsapark´s legitimate interest, Itsapark shall restrict all processing of such data pending the verification of the legitimate interest.

* if you have claim that your personal data is incorrect, Itsapark must restrict all processing of such data pending the verification of the accuracy of the personal data.

* if the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data instead.

* if Itsapark no longer needs the personal data but it is required by you to defend legal claims.

How can you exercise your rights?

We take data protection very seriously and therefore we have dedicated service personnel to handle your requests in relation to your rights stated above. You can always reach them at aiste.povilaikaite@hm.com.

Data Protection Officer:

We have appointed a Data Protection Officer to ensure that we continuously process your personal data in an open, accurate and legal manner. You can contact our Data Protection Officer at aiste.povilaikaite@hm.com and write DPO as subject matter.

Right to complain with a supervisory authority:

If you consider Itsapark to process your personal data in an incorrect way you can contact us. You also have the right to raise a complaint to a supervisory authority.

Updates to our Privacy Notice:

We may need to update our Privacy Notice. The latest version of the Privacy Notice is always available on our website. We will communicate any material changes to the Privacy Notice, for example the purpose of why we use your personal data, the identity of the Controller or your rights.

DIRECT MARKETING

Why do we use your personal data?

We will use your personal data to send you marketing offers, information, surveys and invitations through e-mails, text messages, phone calls and postal mail. In order to optimise your experience at Itsapark we will provide you with relevant information, recommended products, send you reminders of products and send you personalised offers. All these great services are based on what you have clicked on and information you have submitted to us.

What types of personal data do we process?

We will process the following categories of personal data and related to your Itsapark account we will also process your personal data submitted in relation to the account such as:

* name

* contact information such as e-mail address, telephone number and postal code

* age

* photo

* gender

* how you navigated and clicked on the site

Who has access to your personal data?

Data that is forwarded to third parties is only used to provide you with the service mentioned above, to media agencies and technical suppliers for distribution of physical and digital direct marketing.

We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group.

What is the legal ground to process your personal data?

The processing of your personal data is based on agreement when you enter in to Itsapark account.

Your right to withdraw your consent:

You have the right to withdraw your given agreement for the processing of your personal data at any time and also object to direct marketing.

When you do so, Itsapark won't be able to send you any further direct marketing offers or information based the agreement.

You can opt out from direct marketing by the following means:

* following the instructions in each marketing post

* by editing the settings of your Itsapark account

How long do we save your data?

We will keep your data for direct marketing until you opt out from the service.

After this time period your personal data will be deleted.

ITSAPARK ACCOUNT

Why do we use your personal data?

We will use your personal data to create and manage your personal account and to give you a personalised and relevant experience at Itsapark.

We will enable you to handle your account settings (including marketing preferences). We will also provide you with easy ways to maintain accurate and updated information such as contact details.

We will also use your personal data for invitations for events and competitions and Itsapark account additional services.

We will provide you with your order history and details around your orders and enable you to handle your account settings (including marketing preferences). We will also provide you with easy ways to maintain accurate and updated information such as contact details and payment information. Furthermore, we will enable you to save items in your shopping bag and enable you to rate and review the products you've purchased from us.

In order to provide you with relevant product recommendations Itsapark account will process your navigation and browsing on our digital platforms (including website and app), your shopping history and product reviews as well as the data you have submitted to us through your account.

If you have not opted-out for direct marketing we will use your personal data to send you marketing offers, information surveys and invitations through e-mails, text messages, phone calls and mail.

What types of personal data do we collect?

We will always process your e-mail address and password that you submit to us when you sign up for Itsapark account.

We will process the following categories of personal data that you submit to us when you sign up for Itsapark account:

* identification data such as e-mail address and password

* contact information such as name, postal code, e-mail address

* date of birth

* gender

* Account membership ID

* photo

* telephone number (if you choose to provide it to us)

* address (if you choose to provide it to us)

* account settings

* country

We will also process the following categories of personal data connected to your cookies:

* click history

* navigation and browsing history

Who has access to your personal data?

Data that is forwarded to third parties, is only used to provide you with the services mentioned above, links to third party sites and vendors, web agencies, account signing up with Facebook and Google accounts, to optimise the website we use, website agencies and analysis tools for product rating. Data that is forwarded to third parties, is only used to provide you with the services mentioned above and for event booking as we use event booking tools and to optimise the website, as we use website agencies. For product ratings we use analysis tools and moderating and publishing agencies. To distribute marketing we use communication and marketing distribution suppliers.

What is the legal ground to process your personal data?

The processing of your personal data is necessary to fulfil the service of the Itsapark account.

Collecting your personal data when creating and managing you Itsapark account is required to fulfil our commitments according to the account agreement.

If you don't submit your personal data we won't be able to provide you with the account or the services of the Itsapark account.

The processing of your personal data provides you with relevant product information is based on our legitimate interest.

How long do we save your data?

We will keep your data for as long as you have an active Itsapark account.

You have the right to terminate your Itsapark account at any time. If you choose to do so your account will cease to exist.

After the account has been terminated your personal data will be deleted.

We will keep your personal data in there are any legal requirements and if there is an open dispute.

Your right to object to direct marketing:

You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes. If you object to direct marketing we will cease to process your personal data for that purpose and will cease to send out marketing material based on the Itsapark account.

DEVELOPMENT AND IMPROVEMENT

Why do we use your personal data?

We will use data to evaluate, develop and improve our services, products and systems for all of our Itsapark account owners. For this purpose we will not analyse your data on an individual level, all processing will be done on pseudonymised data.

This includes analysis to make our services more user-friendly, such as modifying the user interface to simplify the flow of information or to highlight features that are commonly used by our account owners in our digital channels and to improve IT systems in order to increase the security for our visitors and account owners in general.

What types of personal data do we process?

We will process the following categories of personal data if you have chosen to provide it to us:

* account number

* date of birth

* gender

* country

* account settings

We will also process the following categories of personal data connected to cookies:

* click history

* navigation and browsing history

Who has access to your personal data?

Data that is forwarded to third parties, is only used to provide you with the services mentioned above. We use web-analysis companies to analyse our customer online behaviour on a general level.

What is the legal ground to process your personal data?

The processing of your personal data, to develop and improve our services and products, is based on our legitimate interest.

How long do we save your data?

We will keep your data for as long as you have an active Itsapark account.

After your account or membership has been terminated your personal data will be deleted.

Your right to object to the processing of your data:

You have the right to object to the processing of your personal data that is based on Itsapark's legitimate interest, by contacting aiste.povilaikaite@hm.com. Your account will then be deleted and we will not be able to carry out our services to you.

FULFILMENT OF LEGAL OBLIGATIONS

Why do we use your personal data?

We will use your personal data to comply with obligations in laws, court rulings and decisions from authorities.

This includes using your personal data to collect and verify accounting data to comply with our book-keeping rules.

What types of personal data do we process?

We will process following categories of personal data:

*account number

*name

*e-mail address

Who has access to your personal data?

Your data will be shared within the H&M group (for details on the companies within the H&M group, please refer to our annual report which may be found at about.hm.com).

We will share your personal data with IT companies that provide book-keeping system solutions.

What is the legal ground to process your personal data?

The processing of your personal data is necessary for Itsapark to fulfil its legal obligation.

How long do we save your data?

We will save your data in compliance with the book-keeping rules in your country.

PREVENTION OF MISUSE AND CRIME

Why do we use your personal data?

We will use your personal data for loss prevention management by securing that terms and conditions are being followed and to detect and prevent misuse of our services.

Your personal data will be used to prevent and investigate abuse of our services online and losses and fraud, by analysing online behaviour.

What types of personal data do we process?

We will process the following categories of personal data:

*contact information such as name, address, telephone number and e-mail address

*account number

Who has access to your personal data?

Your personal data that is forwarded to third parties, is only used for purposes mentioned above. We will share your data with companies for exception based reporting.

Incidents and fraud may be shared with insurance companies, legal authorities or local and global law enforcement to complete investigations. Please be aware that such recipients will have an independent right or obligation to process your personal data.

What is the legal ground to process your personal data?

The processing of your personal data to prevent misuse of our services is based on our legitimate interest.

How long do we save your data?

We will keep your data for the time we need to prevent and/or report potential fraud and other offences.

Your right to object to the processing of your data:

You have the right to object to the processing of your personal data that is based on Itsapark's legitimate interest by contacting aiste.povilaikaite@hm.com. Your account will then be deleted and we will not be able to carry out our services to you.

COOKIES

A cookie is a small text file that is saved to, and, during subsequent visits, retrieved from your computer or mobile device. If you use our services, we will assume that you agree to the use of such cookie.

How do we use cookies?

We use permanent cookies to store your choice of start page and to store your details if you select "Remember me" when you log in.

We will use cookies to save your favourite products.

We use session cookies for example when you use the product filtration function and to check whether you are logged in.

We use both first- and third-party cookies to collect statistics and user data in aggregate and individual form in analysis tools to optimize our site and to present you with relevant marketing material.

Some third-party cookies are set by services that appear on our pages and are not in our control. They are set by social media providers such as Twitter, Facebook and Vimeo and relate to the ability of users to share content on this site, as indicated by their respective icon.

We also use third-party cookies which performs cross-site tracking in order for us to give you marketing in other sites/channels.

What types of personal data do we process?

We will only connect your cookie ID to your personal data submitted and gathered in relation to your Itsapark account, if you are logged in to your account.

Who has access to your personal data?

Data that is forwarded to third parties is only used to provide you with the services mentioned above, analysis tool in order to collect statistics to optimize our site and present you with relevant material.

What is the legal ground to process your personal data?

We will only connect your cookies to your personal data if you are logged in to your Itsapark account.

If you are logged in to Itsapark account the legal ground is fulfilment of the Itsapark account´s terms and conditions.

How long do we save your data?

Itsapark does not save your personal data. You can easily erase cookies from your computer or mobile device using your browser. For instructions on how to handle and delete cookies please look under "Help" in your browser. You can choose to disable cookies, or to receive a notification each time a new cookie is sent to your computer or mobile device. Please note that if you choose to disable cookies, you will not be able to take advantage of all our features.

Join Itsapark

Create an account to ask your own questions, answer those from the community, contribute to the wardrobe and keep track of products and topics that you love

Signing up is a breeze.

Continue with Email

or

Login