Privacy policy
About our Privacy Policy
Xapat highly values your privacy. We therefore only process data that we need for (the improvement of) our services and handle the information we have collected about you and your use of our services with care. We never make your data available to third parties for commercial purposes.
This privacy policy applies to the use of the website and the services offered thereon by Xapat. The effective date for the validity of these terms is 29/10/2018; with the publication of a new version, the validity of all previous versions expires. This privacy policy describes which data about you is collected by us, what these data are used for, and with whom and under what conditions these data may potentially be shared with third parties. We also explain to you how we store your data, how we protect your data against misuse, and what rights you have regarding the personal data provided by you to us.
If you have questions about our privacy policy, you can contact our Data Protection Officer; you will find the contact details at the end of our privacy policy.
Information on Data Processing
Below you can read how we process your data, where we store (or have it stored), which security techniques we use, and for whom the data is accessible.
Webshop Software
WooCommerce
Our webshop was developed with software from WooCommerce; we host our webshop on our own servers under our own management. We have taken appropriate technical and organizational measures to prevent misuse, loss, and corruption of data as much as possible. These security measures include at least the application of SSL encryption and a strong password policy. Regular backups are made to prevent data loss.
Webhosting
Cloudways
We obtain web hosting and email services from Cloudways. Cloudways processes personal data on our behalf and does not use your data for its own purposes. However, this party may collect metadata about the use of the services. These are not personal data. Cloudways has taken appropriate technical and organizational measures to prevent loss and unauthorized use of your personal data. Cloudways is obliged to maintain confidentiality based on the agreement.
Email and Mailing Lists
Cloudways
For our regular business email communication, we use the services of Cloudways. This provider has taken appropriate technical and organizational measures to prevent misuse, loss, and damage to your and our data as much as possible. Cloudways has no access to our mailbox, and we treat all our email communication confidentially.
Payment Processors
Mollie
For processing (a part of) the payments in our webshop, we use the platform of Mollie. Mollie processes your name, address and place of residence data, and your payment data such as your bank account number or credit card number. Mollie has taken appropriate technical and organizational measures to protect your personal data. Mollie reserves the right to use your data to further improve its service and in this context to share (anonymized) data with third parties. All the aforementioned guarantees regarding the protection of your personal data also apply to the parts of Mollie’s service for which they engage third parties. Mollie does not store your data longer than permitted by legal retention periods.
Reviews
WebwinkelKeur
We collect reviews via the platform of WebwinkelKeur. If you leave a review via WebwinkelKeur, you are obliged to provide a name and an email address. WebwinkelKeur shares this data with us so that we can link the review to your order. WebwinkelKeur also publishes your name on its own website. In some cases, WebwinkelKeur may contact you to obtain an explanation for your review. In the event that we invite you to leave a review, we share your name and email address with WebwinkelKeur. They use this data solely for the purpose of inviting you to leave a review. WebwinkelKeur has taken appropriate technical and organizational measures to protect your personal data. WebwinkelKeur reserves the right to engage third parties for the purpose of providing the service; for this, we have given WebwinkelKeur our consent. All the aforementioned guarantees regarding the protection of your personal data also apply to the parts of the service for which WebwinkelKeur engages third parties.
Shipping and Logistics
PostNL
When you place an order with us, it is our task to have your package delivered to you. We use the services of PostNL for carrying out the deliveries. For this purpose, it is necessary that we share your name, address, and place of residence data with PostNL. PostNL uses this data solely for the purpose of executing the agreement. In the event that PostNL engages subcontractors, PostNL also makes your data available to these parties.
DHL
When you place an order with us, it is our task to have your package delivered to you. We use the services of DHL for carrying out the deliveries. For this purpose, it is necessary that we share your name, address, and place of residence data with DHL. DHL uses this data solely for the purpose of executing the agreement. In the event that DHL engages subcontractors, PostNL also makes your data available to these parties.
(Translator’s note: The German text here incorrectly says “PostNL” instead of “DHL”. The translation above corrects this to “DHL” to match the section heading, assuming this was an error in the source text provided for German translation.)
Bpost
When you place an order with us, it is our task to have your package delivered to you. We use the services of Bpost for carrying out the deliveries. For this purpose, it is necessary that we share your name, address, and place of residence data with Bpost. Bpost uses this data solely for the purpose of executing the agreement. In the event that Bpost engages subcontractors, PostNL also makes your data available to these parties.
(Translator’s note: The German text here incorrectly says “PostNL” instead of “Bpost”. The translation above corrects this to “Bpost” to match the section heading, assuming this was an error in the source text provided for German translation.)
DPD
When you place an order with us, it is our task to have your package delivered to you. We use the services of DPD for carrying out the deliveries. For this purpose, it is necessary that we share your name, address, and place of residence data with DPD. DPD uses this data solely for the purpose of executing the agreement. In the event that DPD engages subcontractors, PostNL also makes your data available to these parties.
(Translator’s note: The German text here incorrectly says “PostNL” instead of “DPD”. The translation above corrects this to “DPD” to match the section heading, assuming this was an error in the source text provided for German translation.)
GLS
When you place an order with us, it is our task to have your package delivered to you. We use the services of GLS for carrying out the deliveries. For this purpose, it is necessary that we share your name, address, and place of residence data with GLS. GLS uses this data solely for the purpose of executing the agreement. In the event that GLS engages subcontractors, PostNL also makes your data available to these parties.
(Translator’s note: The German text here incorrectly says “PostNL” instead of “GLS”. The translation above corrects this to “GLS” to match the section heading, assuming this was an error in the source text provided for German translation.)
Invoicing and Accounting
Xapat
For maintaining our administration and accounting, we use the services of Xapat. We share your name, address and place of residence data, and details regarding your order. This data is used for the administration of sales invoices. Your personal data is securely transmitted and stored. Xapat is obliged to maintain confidentiality and will treat your data confidentially. Xapat does not use your personal data for purposes other than those described above.
External Sales Channels
Bol.com
We sell (a part of) our articles via the platform of Bol.com. If you place an order via this platform, Bol.com shares your order and personal data with us. We use this data to process your order. We handle your data confidentially and have taken appropriate technical and organizational measures to protect your data against loss and unauthorized use.
Amazon.com
We sell (a part of) our articles via the platform of Amazon.com. If you place an order via this platform, Amazon.com shares your order and personal data with us. We use this data to process your order. We handle your data confidentially and have taken appropriate technical and organizational measures to protect your data against loss and unauthorized use.
Purpose of Data Processing
General Processing Purpose
We use your data solely for the purpose of our service. This means that the purpose of processing is always directly related to the order you have placed. We do not use your data for (targeted) marketing. If you share data with us and we use this data to contact you at a later time β other than at your request β we will explicitly ask for your consent for this. Your data will not be shared with third parties, except for the purpose of fulfilling accounting and other administrative obligations. These third parties are all obligated to maintain confidentiality based on the agreement between them and us, or based on an oath or legal obligation.
Automatically Collected Data
Data that is automatically collected by our website is processed for the purpose of further improving our service. This data (e.g., your IP address, web browser, and operating system) is not personal data.
Cooperation in Tax and Criminal Investigations
Where applicable, Xapat may be obliged under a legal obligation to share your data in connection with tax or criminal investigations by government authorities. In such a case, we are forced to share your data, but we will resist this within the possibilities offered to us by law.
Retention Periods
We store your data as long as you are our client. This means that we store your customer profile until you indicate that you no longer wish to use our services. If you indicate this to us, we will also interpret this as a request for erasure. Due to applicable administrative obligations, we must retain invoices containing your (personal) data; we will therefore store this data for as long as the applicable period lasts. However, employees no longer have access to your client profile and documents we have created in connection with your order.
Your Rights
Pursuant to applicable Dutch and European legislation, you as a data subject have certain rights regarding the personal data processed by or on our behalf. Below, we explain which rights these are and how you can invoke these rights. In principle, to prevent misuse, we send transcripts and copies of your data exclusively to the email address already known to us. In the event that you wish to receive the data at a different email address or, for example, by mail, we will ask you to identify yourself. We keep a record of processed requests; in the case of a request for erasure, we record anonymized data. You will receive all transcripts and copies of data in the machine-readable data format that we use within our systems. You have the right at any time to file a complaint with the competent supervisory authority if you suspect that we are using your personal data incorrectly.
Right of Access
You have the right at any time to access the data concerning you, or traceable to you, which we process (or have processed). You can submit a request to this effect to our Data Protection Officer. You will receive a response to your request within 30 days. If your request is granted, we will send you a copy of all data to the email address known to us, along with an overview of the processors who hold this data, stating the category under which we have stored this data.
Right to Rectification
You have the right at any time to have the data concerning you, or traceable to you, which we process (or have processed) rectified. You can submit a request to this effect to our Data Protection Officer. You will receive a response to your request within 30 days. If your request is granted, we will send you a confirmation to the email address known to us that the data has been rectified.
Right to Restriction of Processing
You have the right at any time to restrict the processing of data concerning you, or traceable to you, which we process (or have processed). You can submit a request to this effect to our Data Protection Officer. You will receive a response to your request within 30 days. If your request is granted, we will send you a confirmation to the email address known to us that the data will no longer be processed until you lift the restriction.
Right to Data Portability
You have the right at any time to have the data concerning you, or traceable to you, which we process (or have processed) transferred to another party (Right to Data Portability). You can submit a request to this effect to our Data Protection Officer. You will receive a response to your request within 30 days. If your request is granted, we will send you transcripts or copies of all data about you that we have processed or that has been processed on our behalf by other processors or third parties, to the email address known to us. In all likelihood, in such a case, we will no longer be able to continue providing the service, as the secure linking of databases can then no longer be guaranteed.
Right to Object and Other Rights
Where applicable, you have the right to object to the processing of your personal data by Xapat or on our behalf. If you object, we will immediately cease data processing pending the handling of your objection. If your objection is well-founded, we will provide you with transcripts and/or copies of the data we process (or have processed) and then permanently cease the processing. Furthermore, you have the right not to be subject to a decision based solely on automated processing, including profiling. We do not process your data in a manner that this right is applicable. If you believe this is the case, please contact our Data Protection Officer.
Cookies
You can find everything about cookies on our Cookie Policy page.
Changes to the Privacy Policy
We reserve the right to amend our privacy policy at any time. However, you will always find the most recent version on this page. If the new privacy policy has consequences for the way we process data already collected about you, we will inform you by email.
Contact Details
Xapat
Absalon 4
1906JA Limmen
Netherlands
Tel: 0031 85888 1015
Email: info@ramfightinggear.com
Data Protection Officer
B. van der Schaaf
