Loyalty program Privacy Policy[AA1]
The date this privacy policy was last revised was February
2021.
This Privacy Policy explains how the data controllers [referred to in
this Privacy Policy as the Data
Controller, we, us or our] (as defined below)collects and process your personal data in the
context of the provision of our Loyalty Program (including the access to your
loyalty account within the website and shopping center applications, together,
the “Services”).
This Privacy Policy covers the following:
1/ Contact
details of the Data Controller
2/ How do
we collect your personal data
3/ Details about the processing of your personal
data
4/ How
do we share your personal data
5/ How do we keep your personal
data secure
6/ Do we transfer your personal
data outside the European Economic Area
7/Your rights in
relation to your personal data
8/ Geolocation
9/ Automated decision making /
profiling
10/Transfer
in case of change of ownership.
11/Update of this
Privacy Policy
1/ Contact
details of the Data Controller
The local Data Controller :
Espace Expansion
Simplified joint stock company with a capital of 464 910€
Having its registered office at 7 place du Chancelier Adenauer 75016
Paris
Registered within the Paris Register under number 323 998 690
The local Data Controller will process your personal
data in the context set out below.
The group Data Controller :
Unibail Management
Simplified joint stock company with a capital of
20 000 000€
Having its registered office at 7 place du Chancelier Adenauer 75016
Paris
Registered within the Paris Register under number 414 878 389
Espace Expansion and Unibail Management Data Privacy Team
(including its DPO) may be contacted by email at data.protection@urw.com or via post at 7 place du
Chancelier Adenauer 75116 PARIS.
In a general manner, the group data controller will
process your personal data in order to assist the local data controller and to
ensure a general governance at group level.
Some roles are specifically assigned to the local
Data Controller or the group Data Controller as follows :
Role
of the local Data Controller:
The
local Data Controller will process your personal
data in order to send you communication to inform you about specific offers and
events of the respective shopping centre and to provide you with offers.
Role
of the group Data Controller :
The
group Data Controller has concluded several data processing agreements and
service agreements with service providers to provide you with the technical
opportunity to register you to the Loyalty Program or download and use the shopping
center application.
The
group Data Controller will also handle the preparation of some communication,
coordinated at group level, that will be sent by local Data Controller.
Furthermore, the group Data Controller will negotiate with third parties
special offers which will be accessible for loyalty members.
The
group Data Controller will process your personal data in order to :
-
Manage your registration to the
Loyalty Program
-
analyse your behaviour within the
shopping center as further detailed in the table below (3.1) to provide you
with customised offers and events you might be interested in.
The local data controller and the group data
controller are acting as joint data controllers and will hereinafter be
referred to together as “Data Controller”, “we”, “us” or “our”.
2/ How do
we collect your personal data
We collect personal data about you through the
following means :
- directly
from you; and/or
- from
your use of the Services
a) When you use the Loyalty Card, including the
virtual one, if scanned during your visit, we collect information related to
the type of service your Loyalty Card was used for (example : events, birthday
present) and therefore your presence within our shopping center.
b) When you use our shopping center application
or website as authenticated user, we collect :
information
about the frequency of your visits, your itineraries within the shopping centre
provided that we have obtained your prior written consent to collect these
information (only for shopping center application - see article 8 Geolocation).
c) When you use the website and accept the use of cookies, we collect the
cookies you have accepted. You will find all details about cookies uses and
policy in the Terms of Use accessible by clicking on the following link: https://fr.westfield.com/termsofuse
Details about those
different way of collection are given in section “Personal data involved” in
the table reproduced in article 3 below.
3/
Details about the processing of your personal data
3.1 -
You will find in the table below all information in relation with :
-
Why we
are processing your personal data (Specific purpose)
-
Which
personal data are involved (Personal data involved)
-
On
which legal basis we are processing your personal data (Legal basis)
-
How long
we are storing your personal data (Retention period)
-
What
rights you can exercise in relation to your personal data (Rights)
3.2
Specific provisions – Loyalty Points Collection
As part of a special
functionality of the Loyalty Program to activate, please note that you have the
possibility to subscribe to the Loyalty Points Collection. Under the Loyalty
Points Collection, you may be entitled to get cashbacks, depending upon
purchases you make in the shopping centre. The activation of the Loyalty Points
Collection is optional and you remain
completely free to activate this feature of your Loyalty Program or not. For
further information, please see the Terms of Use of the Loyalty Program https://fr.westfield.com/termsofuse
For the purposes of
organizing, managing and implementing the cashback payments resulting from your
transactions as well as analyzing the payment flows resulting from your use of
the Loyalty Points Collection, please note that Transaction Connect (a French company with headquarters at 86, rue
du faubourg St Denis 75010 Paris, and registered with the Registry of Commerce
and Companies of Paris under number 822 619 185) alone shall be deemed acting as independent data
controller with respect to the concerned processing
of your personal data. For sake of clarity, both us and Transaction Connect are
individually responsible for the processing of your Personal data for the
purpose of the Loyalty Points Collection.
You can find additional
information about the processing activities implemented by Transaction Connect,
including information about your rights as a data subject, by clicking on this link[link to TC’s documentation] .
Please note that, in any
event, we are not responsible for the processing activities implemented by
Transaction Connect acting as data controller. Consequently, any claims or
requests relating to the processing carried out by Transaction Connect shall be
directed to Transaction Connect directly subject to their respective privacy
policy https://tc-front.transactionconnect.com/resources/4t/fr/POLICY.pdfand terms of use https://tc-front.transactionconnect.com/resources/4t/fr/CGU.pdf , which you will be
required to read and accept when subscribing to the Loyalty Points Collection.
Once you have activated the
Loyalty Points Collection, the Data Controllers will receive confirmation and
the relevant purchases you conduct within the shopping centre as detailed in
the table above, so that the Data Controllers can manage and account your
Loyalty Points to benefit thereof under the Loyalty Points Collection. Under no
circumstances, we will have access to or receive any information related to you
bank accounts, credit cards or any Personal data of financial nature.
4/ How do we share your personal data?
We
may share your personal data with:
·
our
processors as listed in Appendix 1; The
list of our current third-party processors is published in Appendix 1 below.
The list is regularly updated and includes company-name, company-address,
specific of purpose of processing of service provider.
·
any
competent authority or legal entity to answer to legal or regulatory requests,
court orders, subpoena or legal process, if necessary to comply with applicable
laws;
·
any
transferee, when personal data is transferred as part of the sale or otherwise
transfer of all or part of our assets to another company
·
with our insurers, lawyers, other advisers and courts when enforcing claims
and/or defending our position;
5/
How do we keep your personal data secure?
We take the security of all the
personal data we hold very seriously and we are committed to protecting your
personal data. We have therefore implemented all the necessary technical and
organizational security measures, and have chosen our providers accordingly.
We have entered into specific data processing
agreements with each service provider listed in Appendix 1 and have checked
their general technical and organizational measures. The service providers are
only authorized to process the data, as data processor, in compliance with the
provision of this Privacy Policy, only on our behalf and according to our
instructions.
However, we can't control all
the risks related to the use of the Internet, and data security also relies on
everyone's vigilance and good use of these technologies, therefore we invite
our customers to remain vigilant on potential inherent risks while using
Internet services.
6/ When do we transfer your personal data outside
the European Economic Area ?
We use third
party service providers that help us provide the Services to you and process
your personal data on our behalf. Such third party service providers will
always be subject to security and confidentiality obligations consistent with
this Privacy Policy and the applicable law.
Note that some third party service providers
are located outside the EEA (European Economic Area) and thus may access and
process your Personal data from countries which do not provide an adequate
level of data protection. In case of such transfer outside the EEA, we enter
into the model clauses adopted by the European Commission to ensure that your personal
data benefits from an adequate level of protection when accessed and processed
from there. Our processors may also rely on Binding Corporate Rules.
If you need
further information on this, please contact us
by e-mail at the address mentioned in article 7.5 below.
Information on the model clauses can be found here[AA2] .
Information
on the Binding Corporate Rules can be found here[AA3] .
7/ Your rights in relation to your personal data
7.1 Pursuant to all
applicable laws, and in accordance with the provisions of the table of article 3.1
above (column “Rights”) you have the right* :
- to access
to your personal data : we
will give you detailed information about your personal data being
processed.
- to
obtain rectification your personal data : if the personal data we are processing
are inaccurate;
- to
obtain erasure of your personal data : if you want us to erase some or all of
your personal data ;
- to object
to the processing of your personal information : if you want us to stop the processing of your personal
data until we demonstrate compelling legitimate grounds for the processing
which override your interests, rights and freedoms, or for the
establishment, exercise or defence of legal claims.
- to
obtain the restriction of the processing of your personal information if you contest the accuracy, lawfulness
or our need to process your personal data, we will limit the processing of
your personal data to the minimum (storage) and, if applicable, will
process them only for the establishment, exercise or defence of legal
claims or, where necessary, for protection of another natural or legal
person, or other limited reason dictated by applicable laws.
- to receive your personal data in a
structured and standard format or to ask for the transmission of such
information to other controller (portability)
- to give
instructions regarding the further processing of your personal data after
your death.
Please note that the available rights depend on the
legal basis of the processing. See provisions
of the table of article 3.1 above (column “Rights”) to see the rights you can
exercise specifically by processing activity.
7.2 Withdrawal of your consent(s) When the legal basis of the processing is your
consent, as detailed in the table displayed in article 3.1 above (column “Legal
basis”), you may withdraw your given consent(s) at any time without any reason.
If you do so, we will stop
any further processing based on this consent. Please note that the withdrawal
of your consent does not affect lawfulness of any processing done on the
understanding that you have given your consent before.
To withdraw your consent to
receive commercial communication :
> send an e-mail as described in the section Exercise
of your rights below
> directly change the setting in your loyalty
account
> click on the unsubscribing link available in
all our communication
7.3 Unsubscribing to communication for information purpose in relation with the Loyalty
Program
As part of the Loyalty
Program and based on the legal basis of the execution of a contract formed
between us (the terms of Use of the Loyalty Program) we will send you
communication (that will only be about the Loyalty Program and that will not
contain any commercial offers).
If you do not want to
receive this kind of communication, you can ask us to stop sending them as
follows:
> send an
e-mail as described in the section Exercise of your Rights below; or,
> directly change the setting in your Loyalty account
or,
> click on the unsubscribing link available in
all our communication.
7.4 Deletion of your Loyalty Account
If you want to delete your
Loyalty Account, you can either :
> delete it directly in the setting of your Loyalty
Account; or,
> send an
e-mail as described in the section Exercise of your rights below.
7.5 Exercise
of your Rights
If
you wish to exercise these rights and/or obtain all relevant information,
please contact us at the following address: westfieldles4temps@urw.com
To ensure an effective exercise of your rights,
please note that you can send your request at the above mentioned address for
your questions and demands in relation
with processing to both data controllers (local Data
Controller and group Data Controller).
In order to avoid to infringe third party rights,
we reserve the right, in case of reasonable doubt, to proceed to prior verification of
your identity in asking you :
-
your number
of loyalty member, or, if you do not have it,
-
an ID
Document
We will respond within 1 month after
receipt of your request, but We retain, when necessary due to the complexity of
your request, the right to extend this
period by 2 months. We will in any event inform you within 1 month after
receipt of your request if We decide to extend the period to respond.
If needed, you can also address any
question at the welcome desk of your shopping centre.
7.6 Complaints
You have the right to make a complaint about the way We
process your Personal data to the data protection authority, aka The Commission
Nationale de l’Informatique et des Libertés, located 3 place de Fontenoy 75007 in
PARIS.
8/
Geolocation
8.1 General
principle
Subject to your prior express consent
given in the shopping center application, information related to your location
within our shopping centre may be collected and processed by Us while you are authenticated
on our shopping center Applications for the purposes of measuring the frequency
of your visits and your itineraries within our shopping centre and/or providing
location related services.
Geolocation will only take place if
you have activated the additional services/specific function in the settings of
your downloaded shopping centre application on your mobile device. You could
deactivate those additional services at any time in the settings latter one at
any time.
Please note that when given, your
consent will be effective immediately for any further connections on our shopping
center Application and for any further visits in our shopping centre within 12
months from first connection, unless you withdraw your consent.
8.2 How
to manage your geolocation preferences on your mobile device
In order to be located within the
shopping centre, you will be required to activate the Bluetooth feature on your
mobile device.
If you only want to check out the map the
activation of the Bluetooth feature is not required.
Please note that we will not locate
you outside our shopping centre. The location option is carried out by the
Bluetooth beacons which are installed in the common areas of the shopping
centre only.
You may disable the geolocation of
your mobile device through your mobile settings at any time.
9/
Automated decision making / profiling
There is currently no
automated decision-making process or profiling which would legally affect you
or otherwise significantly affects you. But we will provide you with specific
offers based on your individual Personal data and analysis of your user
behavior.
Indeed, as we do not want to bother you with information and promotions that
may not be relevant to you, we
assess your purchase profile, i.e. information such as your earlier purchases
and preferences that we collect through your use of our Services as detailed in
table (article 3.1), to send you only information and promotions we consider
interesting or relevant to you.
10/ Transfer in case of change of ownership
If Unibail-Rodamco-Westfield Group is involved in a merger, acquisition,
dissolution, or sale all or part of the shopping centre, or its managing
company or owner, where you are registered as a Loyalty Program member, we
reserve the right to transfer your personal data. You will be notified if such change requires notification or
consent under applicable law, you will be notified or given the opportunity to
consent.
11 /
Update of this Privacy Policy
We may revise
or update this Privacy Policy from time to time. Any change to this Privacy Policy
will become effective upon online publication on this website.
If such change requires notification or consent under applicable law,
you will be notified or given the opportunity to consent.
Appendix 1 – List of service providers : https://fr.westfield.com/les4temps/providers