(last updated: 19 July 2018)
  1. General
Respecting and protecting our customers’ privacy and personal data is important to Luxarity Limited and its related companies (including all holding, subsidiary and affiliate companies) (collectively, we or us). This policy will help you understand how we collect, use and safeguard your personal data in our interactions with you.
It also describes your data protection rights, including a right to object to some of the processing which we carry out. More information about your rights, and how to exercise them, is set out in the section What rights do I have?.
  1. What information do we collect?
We collect and process personal data about you when you:
  1. How do we use this information, and what is the legal basis for this use?
We process personal data for the following purposes:
We may market to you our goods and services, and the goods and services of: (a) our related companies (including our affiliate and subsidiary companies), (b) business partners, and (c) other third party providers. Such marketing communications may be in various forms, including advertisements, special events notifications or newsletters, and delivered via various methods in accordance with the personal data that you provide to us, such as by email, SMS, WeChat messages, smartphone app push notifications, notifications on your social media pages, in –app messaging or postal mail.
Such marketing communications may market or offer products or services (including special events and promotions) in the following categories: Dining, food and beverages, sports, music, film, television and other entertainment, clothing and accessories, jewellery, luggage and bags, cosmetics, personal health and hygiene, electronics, home furnishings, and housewares, automobiles, transport and travel, hotels, financial services, loyalty and reward programs, media services, entertainment services, social networking services, payment services, on-line advertising services, other e-commerce, information and communications and services, concierge services, and other products and services that we think may be relevant to you based on information you provide to us (for instance, via your participation in our surveys).
  1. Relying on our legitimate interests
We have carried out balancing tests for all the data processing we carry out on the basis of our business and legitimate interests, which we have described above. You can obtain information on any of our balancing tests by contacting us using the details set out later in this policy.
  1. Withdrawing consent or otherwise objecting to direct marketing
Wherever we rely on your consent, you will always be able to withdraw that consent, although we may have other legal grounds for processing your data for other purposes, such as those set out above. Specifically, in the case of customers from the European Economic Area (EEA), we are able to send you direct marketing without your consent, where we rely on our business or legitimate interests.  Irrespective of the legal basis on which we rely to send you direct marketing, you have an absolute right to opt-out of direct marketing, or profiling we carry out for direct marketing, at any time. You can do this by: (a) contacting our Privacy Officer at info@luxarity.com or mailing to; Privacy Officer, Luxarity, 30/F, One Island South, 2 Heung Yip Road Wong Chuk Hang, Hong Kong, or (b) in the case of emails, by clicking the unsubscribe link at the bottom of such emails.
  1. Who will we share this data with, where and when?
We will share your personal data with the related companies of Luxarity Limited.
Personal data may be shared with government authorities and/or law enforcement officials if required for the purposes above, if mandated by law or if required for the legal protection of our legitimate interests in compliance with applicable laws.
Personal data will also be shared with third party service providers, namely:
Some of your information may be used to conduct some level of automated decision-making – for example, using your IP addresses or payment information to automatically block certain potentially fraudulent transactions for a short period of time.
Shopify may further transfer your personal data to third parties for the purposes of:
  1. Prevention and investigation of or action against illegal activities, suspected fraud, situations involving potential threats to the physical safety of any person, violations of the Shopify Terms of Service or any other agreement related to Shopify’s services, or as otherwise required by law or
  2. Conforming to legal requirements, or responding to lawful court orders, subpoenas, warrants, or other requests by public authorities (including to meet national security or law enforcement requirements).
For more details please visit Shopify’s Privacy Policy at https://www.shopify.com/legal/privacy. Shopify uses cookies; please refer to our separate Cookies Policy for details
For more details please visit Mailchimp’s Privacy Policy at https://mailchimp.com/legal/privacy/. Mailchimp uses cookies; please refer to our separate Cookies Policy for details.
In the event that our business is sold or integrated with another business, your details will be disclosed to our advisers and any prospective purchaser’s adviser and will be passed to the new owners of the business.
If you are from the EEA, where information is transferred outside the EEA, and where this is to a stakeholder or vendor in a country that is not subject to an adequacy decision by the EU Commission, data will be adequately protected by EU Commission approved standard contractual clauses, an appropriate Privacy Shield certification or a vendor’s Processor Binding Corporate Rules.  A copy of the relevant mechanism can be provided for your review on request to the contact mentioned in the section “How do I get in touch with you” below. Your personal data may be transferred to Hong Kong Special Administrative Region, United States of America and Canada.
  1. What rights do I have?
Where permitted by law, you have the right to ask us for a copy of your personal data; to correct, delete or restrict (stop any active) processing of your personal data; and to obtain the personal data you provide to us in a structured, machine readable format, and to ask us to share (port) this data to another controller.
In addition, if you are from EEA you can object to the processing of your personal data in some circumstances (in particular, where we do not have to process the data for business or other legitimate interests, purposes for which consent has been given (including direct marketing) or other legal requirements).
These rights may be limited, for example if fulfilling your request would reveal personal data about another person, where they would infringe the rights of a third party (including our rights) or if you ask us to delete information which we are required by law to keep or have compelling legitimate interests in keeping.  Relevant exemptions are available under applicable laws. We will inform you of relevant exemptions we rely upon when responding to any request you make.
To exercise any of these rights, or to obtain other information, such as a copy of a legitimate interests balancing test, you can get in touch with us – or our privacy officer – using the details set out below. (Applicable only if you are from the EEA: If you have unresolved concerns, you have the right to complain to an EU data protection authority where you live, work or where you believe a breach may have occurred.)
  1. How do I get in touch with you?
We hope that we can satisfy queries you may have about the way we process your data. If you have any concerns about how we process your data, or would like to opt out of direct marketing, you can get in touch at info@luxarity.com or by writing to Privacy Officer, Luxarity, 30/F, One Island South, 2 Heung Yip Road, Wong Chuk Hang, Hong Kong.
  1. Who is the data controller?
The data controllers are Luxarity Limited, and its related companies; contact details can be found in the section How do I get in touch with you above.
 
  1. How long will my data be kept?
Where we process your data for fulfilling your order, we do this for as long as it is necessary to fulfil your order, and it is required for business and legitimate interests or legal requirement [(applicable if you are from the EEA only for 7 years after any business and legitimate interests or legal requirements no longer exist)].
Where we process personal data for marketing purposes (including for your participation in our events and promotion activities) or with your consent, we process the data until you ask us to stop and for a short period after this (to allow us to implement your requests). We also keep a record of the fact that you have asked us not to send you direct marketing or to process your data so that we can respect your request in future.
(Applicable if you are from the EEA only) Where we process personal data for site security purposes, we retain it for 7 years after any business and legitimate interests no longer exists, and where we process personal data in connection with performing a contract or for a competition, we keep the data for 7 years from your last interaction with us.