Data Protection Policy

Thank you for your interest in our website. The protection of your privacy is very important to us. Therefore, we will process your data carefully, for a specific purpose and on the basis of your consent, and only in accordance with the legal requirements for data protection.

In this data protection policy we inform you about the aspects of data processing within our website.

The responsible body within the meaning of the data protection laws is:

Villeroy & Boch AG<br/> Saaruferstraße<br/> 66693 Mettlach<br/> Tel. +49 (0) 68 64 / 8 10<br/> E-mail information(at)villeroy-boch.com<br/> (hereinafter “Villeroy & Boch”)

I. When and for what purpose does Villeroy & Boch collect personal data?

It is generally possible to use our websites without submitting personal data.

If you use one of our services (e.g. our newsletter, the Bathroom Planner, our online shop or our contact form), you enter your data voluntarily. We use this data (such as name, address, e-mail address, telephone and fax number) exclusively for the purpose for which you provide it (e.g. for processing contact requests, processing orders and payments, delivery of goods and provision of services such as, in particular, the dispatch of newsletters or bathroom planning) and only for the execution of our own business purposes. Information we receive from you helps us process your order as smoothly as possible, improve our service for you and prevent misuse and fraud.

When you access our website, information of a general nature is automatically recorded. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider and such like. This is only information that does not allow conclusions to be drawn about you. This information is technically necessary in order to correctly deliver the contents of websites requested by you and is mandatory when using the internet. Anonymous information of this kind is statistically evaluated by us, in order to optimise our internet appearance and the technology behind it.

We do not sell your data, nor do we use it for unspecified purposes.

Your personal data will only be used within the Villeroy & Boch Group and by our business partners who may be commissioned to fulfil your wishes.

Below we inform you in detail about the handling of your data.

II. General information about our services

If you use our services, we will ask you for personal data (at the time of collection, we will explain which information is required and which you may voluntarily provide).

To protect the security of your data during transmission, we use state-of-the-art encryption techniques (such as SSL) over HTTPS.

For users who have signed up for one or more of the following services, it is possible to change or delete the information provided at registration at any time. Of course, we will also provide you with information about the personal data we hold about you at any time. We are happy to correct or delete this at your request, as long as no statutory retention requirements prevent this. To contact us in this context and to revoke your consent, please use the contact details provided at the end of this data protection policy.

III. Our services in detail

In the following, we would like to explain our services to you in detail, and in particular the legal basis for and purpose of the data processing.

1. Shopping in our online shop<br/> Our website also offers the possibility of convenient online shopping. We use the data provided by you without your separate consent exclusively for the fulfilment and processing of your order. With complete processing of the contract and full payment of the purchase price, your data will be blocked for further use and deleted after expiry of the tax and commercial regulations, unless you have expressly consented to its further use.

Purpose of data processing: Implementation and processing of the purchase process initiated by you as well as compliance with legal requirements such as, in particular, customs provisions.

Legal basis: Article 6 (1) (b) GDPR (required to fulfil the contract) and Article 6 (1) (c) GDPR (fulfilment of a legal obligation)

For shopping in the online shop, provision of the data is required by you. Without this data no contract can be concluded. Failure to provide the data would result in your being unable to shop on our website.

1.1 With a customer account <br/> A free and password-protected customer account gives you the opportunity to take full advantage of our website. When you register to use personalised services via a customer account, some of your personal information is collected, such as your name, address, contact and communications data (e.g. telephone number and e-mail address). If you are registered with us, you can access content and services that we only offer to registered users.

1.2 Without a customer account <br/> Of course, you can also use the online shop without a customer account. In this case, you will need to enter the information required to process your order into the ‘Personal Data’ order form integrated on the website. You complete each entry by clicking the ‘Next’ button, which takes you to the payment screen. In order to avoid typing errors and to ensure that you have entered the correct address, the completeness and correctness of your address will be checked during entry.

1.3 Purchase on account <br/> When purchasing on account, the invoice amount will be due for payment to our external partner: eWirecard Bank AG, Einsteinring 35, 85609 Aschheim, on the calendar day specified in the invoice. The method of purchase on account is not available for all offers and requires, among other things, a successful credit check by Wirecard Bank AG. In order for you to make a purchase on account, you must consent to the transfer of your personal data, the credit and identity verification for the purpose of the order and the contract processing to Wirecard AG. You will find more information on this when selecting the appropriate payment method.

1.4 Security<br/> Your payment details are protected during transmission to our servers through the use of SSL security procedures. You can check the security of the connection using the information in your browser's URL display. If the beginning of the address line changes from ‘http’ to ‘https’, there is a secure connection. In addition, all service providers used for payment processing are certified and comply with the highest safety regulations of e-commerce industry standards.

1.5 Compliance with customs legislation <br/> Due to several EU regulations (2580/2001/EC, 881/2002/EC and 753/2011/EC) as well as other legal requirements, we as a company are required to check our customers' data against publicly available foreign trade and embargo lists before concluding a sales contract. We carry out this comparison to fulfil legal requirements. We carry out the comparison only when you order a product in our online shop and are liable to pay. Only the following stock data is compared: First name, surname and address.

2. Personal newsletter <br/> If you have specifically subscribed to our newsletter, we will use your information to periodically send you personalised information about new products, promotions, competitions and our many customer services.

For a successful registration we need a valid e-mail address. In order to verify that an application is actually made by the owner of an e-mail address, we use the ‘double opt-in’ procedure. For this purpose we record the order of the newsletter, the dispatch of a confirmation e-mail and the receipt of the requested answer. The data will be used exclusively for the newsletter and will not be shared with third parties.

In order to always provide you with a personally tailored offer and to anticipate which products of ours you may be interested in, we will create a customer profile for you based on the information we have about you. We use existing information, such as your shopping history, preferences and interests that you actively share with us via your customer account or that we derive from your recorded interactions with our newsletter. Standard technologies such as cookies or tracking pixels are used in our newsletter. The messages we send you will be personalised and customised according to your individual preferences and interests.

Your consent to the storage of your personal data and its use for newsletter distribution can be revoked at any time. Each newsletter has a corresponding link for this purpose. In addition, you can unsubscribe at any time via the contact options indicated at the end of this data protection notice.

Purpose of data processing: Regular dispatch of newsletters by e-mail to the e-mail address provided by you.

Legal basis: Article 6 (1) (a) GDPR (consent)

3. Privilege Club <br/> As a member of the Privilege Club you have chosen to participate in the Villeroy & Boch customer loyalty programme. For this purpose, a corresponding registration is required, stating the requested personal data. We store your password for your Privilege Club account and the purchases you make in addition to the personal data you provide when registering. Your membership gives you many benefits, which you can read about in detail in the Privilege Club’s conditions of participation. You also receive bonus points on all eligible purchases, which are sent to you once a year in the form of a shopping voucher. In addition, every two months you will receive information about exclusive Privilege Club promotions and events via a special newsletter.

Purpose of data processing: Sending special offers and information about Villeroy & Boch AG products.

Legal basis: Article 6 (1) (a) GDPR (consent)

4. Bathroom Planner and Bathroom Inspirator <br/> You can create a plan of your personalised bathroom using the Bathroom Planner area of our website. This plan will be sent to you by e-mail. You can also have the plan forwarded to the retailer of your choice, who can then consult with you on the bathroom you’ve chosen via e-mail or by phone.

Purpose of data processing: Sending a bathroom plan you’ve created and sharing your contact information with the retailer of your choice for the purpose of bathroom consulting with them via e-mail/phone.

Legal basis: Article 6 (1) (a) GDPR (consent)

5. After-sales service <br/> If your porcelain should ever be discontinued, you can have our after-sales service notify you ahead of time — up to 12 months before the series is phased out. This leaves plenty of time to buy replacements or complete the set. You will only receive a message if the decor you’ve registered is expiring.

Purpose of data processing: Information about product cycles and the availability of certain products on the market.

Legal basis: Article 6 (1) (a) GDPR (consent)

6. Sweepstakes and competitions <br/> Every so often you will have the opportunity to participate in sweepstakes and competitions on our website. Personal data (e-mail address, name, address and other information as needed) may likewise be collected and stored during these campaigns for the purpose of implementation, depending on the respective terms and conditions of participation that apply. The personal information we collect from you during these campaigns will only be used to run the campaign (e.g. determining the winner of sweepstakes, notifying the winner and sending the prize) and will be deleted after it is finished.

If you have given your express consent as part of the campaign, we will send you our newsletter as described under III. 2. If you choose to revoke your consent later, this will not negatively impact your chances of winning or your participation in sweepstakes.

Purpose of data processing: Implementing and executing the sweepstakes/contest.

Legal basis: Article 6 (1) (a) GDPR (consent)

7. Gift list <br/> You have the option to transfer the products available in our online shop to a gift list and manage them there. A customer account must be created in order to do this. You can then send the gift list you created to the people you specify. As creator of the gift list, you’ll receive a greeting message, a reminder before the event date you set passes, and a shopping voucher after the gift list expires based on the information you provided.

Purpose of data processing: Sending a selection of products from Villeroy & Boch AG to a group of recipients defined by you, with your e-mail address as the sender.

Legal basis: Article 6 (1) (a) GDPR (consent)

8. Contact form<br/> If you contact us via e-mail or our contact form, the information you provide will be stored for the purposes of processing the request as well as for any follow-up questions and sending you any requested information, if applicable.

Purpose of data processing: Responding to your request.

Legal basis: Article 6(1)(b) of the GDPR (required for implementing pre-contractual measures that are made at the request of the person in question)

9. Right to revoke your consent <br/> If you use one of the described services that is based on consent, the following applies to this consent:

Revoking consent: Consent that you grant is always voluntary and may be revoked at any time with effect for the future, without giving reasons. You can contact Villeroy & Boch at the address above to do this.

IV. Collecting data during your visit to our website

Along with the information that you submit yourself, we collect other data from you during your visit through cookies and tracking. We would like to clarify this in the following.

1. Cookies <br/> Some of our websites use “cookies”. This standard technology refers to small text files that are stored on the device you use and allow your visit to a website to be made more convenient or more secure, among other things. Via the cookies, we automatically receive certain data about your computer and your internet connection, such as your IP address, the browser used and operating system,. Cookies may also be used to better tailor the offerings on a website to the visitor’s interests or generally improve the site based on statistical analysis.

You can decide yourself whether the browser you use permits cookies or not. Please note that website features may be restricted or even suspended if cookies are disabled.

Cookies cannot be used to start programs or transmit viruses to a computer. Using the information in the cookies, we can make navigation easier for you and allow our web pages to be displayed correctly.

Please see our cookie policy for more information about this.

2. Use of Optimizely <br/> To continually improve our web presence, we conduct tests on individual pages. We likewise collect statistical data for the purpose of conducting these tests, and use the web analysis service “Optimizely” of Optimizely, Inc. (https://www.optimizely.com).

Optimizely does not collect any personal data because we have enabled IP anonymisation in Optimizely. The information generated about your use of this website is transmitted anonymously to an Optimizely server in the United States and stored there. You can deactivate Optimizely by following the instructions on this page: https://www.optimizely.com/opt_out

3. Use of Google Analytics <br/> This website uses Google Analytics, a web analysis service provided by Google Inc, (hereafter referred to as “Google”). Google Analytics uses "cookies", or text files stored on your computer that permit analysis of your use of the website. The information generated by the cookie about your use of this website is generally transmitted to a Google server in the United States and stored there. If IP anonymisation is activated on these websites, however, your IP address will first be abbreviated within member states of the European Union or in other signatory states of the Agreement on the European Economic Area. Only in exceptional cases will the full IP address be transmitted to a Google server in the United States and abbreviated there. Google will use this information on behalf of the operator of this website to evaluate your use of the website, compile reports about website activity and provide other services to the website operator related to the use of the website and internet usage. The IP address transmitted by your browser as part of Google Analytics will not be combined with other Google data.

You can prevent the storage of cookies by configuring your browser software accordingly; however, please note that in this case you may not be able to use all the features of this website to their full extent. You can also prevent the collection of data generated by the cookie related to your use of the website (including your IP address) by Google, as well as the processing of this data by Google, by downloading and installing the browser plugin available through the following link: Browser add-on for disabling Google Analytics.

4. Use of Google Maps <br/> This website uses Google Maps API to provide visual representations of geographical information. When using Google Maps, data about the visitor’s use of the map function will be collected, processed and used by Google. For more information about Google’s data processing, please refer to the Google privacy policy. You can also modify your personal data privacy settings in Google’s Safety Centre.

Detailed instructions about managing your own data in connection with Google products can be found here.

5. Use of Google reCAPTCHA <br/> To ensure sufficient data security when transmitting forms, in certain instances we use the reCAPTCHA service provided by Google Inc. This primarily serves to determine whether the submission is made by a natural person or as a result of misuse in the form of mechanical and automated processing. The service includes sending the IP address and any other data required by Google for the reCAPTCHA service to Google. However, your IP address will first be abbreviated by Google within member states of the European Union or in other signatory states of the Agreement on the European Economic Area. The IP addressed transmitted from your browser in the reCAPTCHA process will not be conflated with other Google data unless you are logged into your Google account when you use the “reCAPTCHA” plug-in. This service is subject to the separate privacy policies of Google Inc. More information about Google’s privacy policies can be found at http://www.google.de/intl/de/privacy or https://www.google.com/intl/de/policies/privacy/

6. Google AdWords <br/> Our website uses Google conversion tracking. If you reached our website through an ad placed on Google, Google Adwords will place a cookie on your computer. The cookie for conversion tracking is set when a user clicks an ad placed on Google. These cookies expire after 30 days and cannot be used for personal identification. If the user visits certain pages on our website and the cookie has not expired yet, we and Google can detect that the user clicked on the ad and was redirected to this page. Every Google AdWords customer receives a different cookie. Thus cookies cannot be used to trace AdWords customers through the websites. The information obtained using the conversion cookie serves to generate conversion statistics for AdWords customers who have opted for conversion tracking. The customer receives the total number of users that clicked on their ad and were redirected to a site with a conversion tracking tag. However, they will not receive any information that could be used to personally identify users.

If you do not want to participate in tracking, you can decline the setting of cookies required for this – for example through the browser setting that generally disables the automatic setting of cookies or by adjusting your browser so that cookies from the domain “googleadservices.com” are blocked.

Please note that you may not delete opt-out cookies as long as you do not want any measurement data recorded. If you have deleted all the cookies in your browser, you will need to reset the respective opt-out cookie.

7. Use of Google Remarketing <br/> This website uses the Remarketing feature provided by Google Inc. This feature serves to present website visitors within the Google advertising network with ads based on their interests. A “cookie” will be stored in the website user’s browser that makes it possible to recognise the visitor when they access websites that belong to Google’s advertising network. Visitors on this page can be shown ads related to content that the visitor previously accessed on websites that use Google’s remarketing function.

According to their own information, Google does not collect any personal data during this process. However, if you wish to opt out of Google’s Remarketing feature, you can always disable it by configuring the corresponding settings at http://www.google.com/settings/ads. Alternatively, you can disable the use of cookies for interest-based advertising via the Network Advertising Initiative by following the instructions at http://www.networkadvertising.org/managing/opt_out.asp.

Google is certified under the Privacy Shield Framework and as a result, offers a guarantee that complies with European data protection law.

(https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active)

8. Embedded YouTube videos 
We embed YouTube videos on some of our websites. The operator of the corresponding plug-in is YouTube, LLC, 901 Cherry Ave., San Bruno, CA 94066, USA. If you visit a page that includes the YouTube plug-in, a connection to the YouTube servers will be established. This will inform YouTube which pages you visit. If you are logged into your YouTube account, YouTube can match your surfing behaviour to you personally. You can prevent this by logging out of your YouTube account beforehand.

If a YouTube video starts playing, the provider will set cookies that collect information about user behaviour.

If you have disabled the storing of cookies for the Google Ad program, you also do not need to anticipate these cookies when viewing YouTube videos. However, YouTube also stores non-personal usage information in other cookies. If you would like to prevent this, you will need to block the storing of cookies in your browser.

You can find more information about data protection on “YouTube” in the provider’s data privacy policy: https://www.google.de/intl/de/policies/privacy/

9. Social plugins
We offer you the option of using “social media buttons” on our website. We rely on the “Shariff” solution to protect your data during use of these features. As a result, these buttons are only integrated onto the website as graphics that contain a link to the corresponding website of the button’s provider. Clicking this graphic will redirect you to the respective provider’s services. Your data will not be sent to the respective provider until then. As long as you do not click the graphic, there will be no exchange of any kind between you and the provider of the social media button. Information about the collection and use of your data in social networks can be found in the relevant provider’s respective terms and conditions of use.

We have integrated social media buttons for the following companies on our website:

Facebook Inc. (1601 S. California Ave - Palo Alto - CA 94304 - USA)<br/> Twitter Inc. (795 Folsom St. - Suite 600 - San Francisco - CA 94107 - USA)<br/> Pinterest (808 Brannan Street, San Francisco, CA 94103, USA)<br/> Instagram (601 Willow Rd - Menlo Park CA 94025 - USA)

10. Mynewsdesk 
To display press releases, we use a service provided by Mynewsdesk AB, company register code 556634-1276, based in Rosenlundsgatan 40, 118 53 Stockholm, Sweden.

The website www.mynewsdesk.com, which is incorporated as an inline frame on our website when the press area is accessed, also uses cookies. More information about cookies at www.mynewsdesk.com is available at https://www.mynewsdesk.com/de/about/terms-and-conditions/cookies?locale=de.

11.Villeroy & Boch Fan Pages on social networks/ platforms

We use our fan pages on social networks and platforms for active communication with customers and users. When you visit these fanpages, your data may be collected and stored for market research and advertising purposes in order to create user profiles using pseudonyms. We use these in order to be able to display advertising to you within and outside the platforms, which is based on your presumed interests. For this purpose, cookies are used when visiting our fan pages, which store the usage behavior of the pseudonymous user.

You will find a complete description of the respective processing and the possibilities for objection in the details of the respective providers.

They can also best support you with information requests and the assertion of user rights. Should you require our help in this regard, please do not hesitate to contact us.

12. Purpose of processing, legal basis and legitimate interests
The following applies to the above items:

Purpose of data processing: Secure operation of the website as well as allowing targeted communication with customers.

Legal basis: Article 6 (1) (f) GDPR (legitimate interest)

Legitimate interests:

  • Ensuring proper function of our website
  • Optimisation of our website
  • Collecting statistics related to use of our website
  • Processing for the purposes of direct advertising

V. Recipients/categories of recipients

1. Other companies in the Villeroy & Boch group<br/> Personal data that you provide during registration (your name, e-mail address, password, and date of birth) will be shared with other companies in the Villeroy & Boch group in order to allow the respective company to provide customer service for you.

We can share the data from your profile with other companies in the Villeroy & Boch group if both companies are responsible for your personal data or if the other companies act as our service provider and your personal data is processed according to our instructions or on our behalf.

We share anonymised and aggregated information with other companies in the Villeroy & Boch group to use for trend analysis.

2. V&B Fliesen GmbH <br/> We have incorporated the product range of V&B Fliesen GmbH on our website under the heading “Tiles.” https://www.villeroy-boch.de/produkte/fliesen.html

You likewise have the option of making a contact request there. All contact requests that concern tiles will be promptly forwarded to V&B Fliesen GmbH, who will then get in touch with you. We will delete these requests from our systems after forwarding them.

3. Other third parties<br/> We will only share the data you provide for the purposes of contract fulfilment, such as with shipping companies or payment service providers, or in cases where we are legally obliged to do so. Examples of these recipients include

  • Authorities and courts (legal duty of disclosure)
  • Lawyers (assertion of claims)
  • Credit institutes (processing payment transactions)
  • Credit agencies (for checking credit history)
  • Auditors and income tax auditors/accountants (legal audit assignment)
  • Insurance companies, insurance agents
  • Tax consultants
  • Expert/appraiser
  • Health insurance providers/pension funds (social insurance carriers)

4. Data transmission to third countries <br/> If we process data in third countries (meaning countries outside the European Union (EU) or the European Economic Area (EEA)) or this occurs in the process of utilising the services of third parties or transmitting data to third parties, this will only be done for the purpose of fulfilling our contractual obligations, on the basis of your consent, due to a legal obligation or based on our legitimate interests.

In doing so, we ensure that your personal data is processed in compliance with the European level of data protection, based on special guarantees or due to corresponding contractual obligation including adequate technical and organisational measures.

VI. Information about children

We do not knowingly collect any personal data about children under 13 years old as a matter of principle. If we become aware that we have unintentionally collected personal data about children under 13 years old, we will take steps to delete this information as quickly as possible insofar as we are not obliged to retain it under the applicable law.

VII. Obligation to provide data, automatic decision making, profiling

1. Do I have an obligation to provide data? <br/> In the context of the contractual relationship, you must provide the personal data that is necessary for acceptance, implementation and completion of the contractual relationship and for fulfilment of the duties related to the contract, or that we are obliged by law to collect. Without this data, we will generally not be able to conclude or implement the contract with you.

2. To what extent is there automated decision making/profiling: <br/> There is no automated decision making in accordance with art. 22 of the GDPR or profiling within the meaning of Art. 4(4) of the GDPR.

VIII. Deleting or locking data

We abide by the principles of data reduction and data economy.

We therefore only store your personal data as long as necessary to achieve the purposes described here or for the retention period stipulated by the legislator. Once the respective purpose has ceased to exist or this period has lapsed, the relevant data is routinely locked or deleted in accordance with legal regulations. If processing is based on consent, the respective purpose generally is considered to cease to exist when the consent becomes invalid due to revocation or passage of time. If processing is necessary for fulfilment of the contract, this will generally occur when the contract has been completed in full and after the retention period expires, as required in particular under the German Commercial Code (HGB) and the German Fiscal Code (Abgabenordnung).

IX. What data protection rights do you have?

You have the right to information under Article 15 of the GDPR, the right to correction under Article 16 of the GDPR, the right to erasure under Article 17 of the GDPR, the right to restriction of processing under Article 18 of the GDPR, the right to objection under Article 21 of the GDPR, and the right to data portability under Article 20 of the GDPR.

You can contact our data protection commissioner to exercise these rights.

You also have the right to file a complaint with a competent data protection supervisory authority (Article 77 of the GDPR in conjunction with Section 19 of the German Federal Data Protection Act, BDSG). A list of supervisory authorities (for the non-public sector) with addresses can be found here:

https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html

X. Our data protection officer

If you have questions about this statement or about data protection at Villeroy & Boch, you can contact our data protection officer directly:

Contact details for our data protection officer:

Villeroy & Boch AG<br/> Datenschutzbeauftragter<br/> Saaruferstraße<br/> 66693 Mettlach<br/> Tel. +49 (0) 68 64 / 8 10<br/> service.datenschutz(at)villeroy-boch.com

XI. Changes to our data protection provisions

We reserve the right to adjust this data privacy notice occasionally to ensure it always meets the current legal requirements or to reflect changes to our services in the data privacy notice, e.g. when introducing new services. In this case, the new data privacy notice will apply to your next visit to our website.

Date: 24/05/2018