Privacy policy

Roostr (located at Bertus Meijerstraat 10, 3059 TR in Rotterdam, telephone number 06-46765674, e-mail address service@roostr.nl) ("Roostr")) is responsible for respecting the privacy of its customers and the users of its website. Roostr ensures that the personal information you provide to us and that we collect from you is treated confidentially. Roostr will not sell your personal information to third parties.

The purposes for which we use your personal data

We use the following personal data to provide our customers and visitors to our website with the following services and to carry out the following activities:

We collect and process the name, address, e-mail address, telephone number and purchased products from visitors who register their product in order to provide the warranty;
We collect and process the name, address, e-mail address and password of visitors who create a My Roostr Account to personalize the website and give you insight into the products and services you purchase from us;
We collect and process the name, address, e-mail address, telephone number and the content of the message from visitors who send a message via our contact form in order to handle the relevant question or complaint;
from customers who write a review about a Roostr product and agree to it being published online, we post a review that can be traced back to a natural person;
of visitors who purchase a Roostr product, we process their contact details, delivery address and financial data (such as IBAN or credit card details) for the assessment of an order, in order to be able to make payment via the webshop and deliver the purchased product;
of persons who assemble or order a Roostr product, we process the data provided by them in addition to the execution of an order, also for marketing, research and advertising purposes;
We use the e-mail address of visitors and users of Roostr products who have given permission for this or with whom there is already an existing customer relationship, to inform them about Roostr products or similar products and services, their orders, and about special offers and actions.

You are not obliged to provide us with personal data, but if you do not do so, we may not be able to provide you with a product and/or service. For example: if you wish to create an account, enter into an agreement with us or want us to respond to a request from you, we need your information.

Legal basis of data processing

The legal basis of our data processing depends on the purpose of the processing.

For most personal data that we collect via the website for the purposes mentioned above under a) to e) and h) in the case of a customer relationship, our basis is that this processing is necessary for the pursuit of our legitimate interests such as promoting van Roostr and promoting our products and services, improving your experience on our website or your contact with us (Article 6(1)(f) General Data Protection Regulation, "GDPR"). We have weighed these interests against your interests and fundamental rights and freedoms. We have concluded that your interests and fundamental rights and freedoms do not outweigh our interests, taking into account the generally non-sensitive nature of the personal data processed and the safeguards we have put in place.

The personal data that we collect for the purposes under f) and g) are necessary for the execution of an agreement to which you are a party (Article 6(1)(b) GDPR) and to comply with our statutory administrative retention obligation (Article 6(1) sub c GDPR).

If you provide health data in the Mattress Advisor or register for our newsletter as referred to in the purpose mentioned above under h), the basis for processing your data is your consent (Article 6(1)(a) GDPR and Article 9(1)(a) GDPR respectively. a GDPR). You have the right to withdraw your consent at any time by sending an email to: service@roostr.eu without affecting the lawfulness of the processing based on consent before its withdrawal.

Disclosure to third parties

We may use third parties to support our services. This includes parties involved in handling financial transactions, hosting providers, application providers, research agencies, parties that assist with the installation of our products and delivery service providers and other service providers that process personal data in the context of the delivery of products and services by Roostr. . In most cases, such parties will act under our responsibility as processors of Roostr, and are therefore obliged to maintain confidentiality regarding your personal data. We have made written agreements with all processors about the way in which they process personal data on our behalf. We monitor compliance with these agreements. We also share personal data with supervisors, investigative services or other government agencies if we are legally obliged to do so.

Transfer of data

Your personal data is stored exclusively in the Netherlands. If personal data is processed by or for the benefit of our services in third countries, you will be informed of this.

Third party websites

Roostr bears no responsibility with regard to the use of your data by third parties of websites to which Roostr websites refer. Please read the privacy statement of the website you visit.

Security

We take appropriate technical and organizational measures to protect your personal data against loss or any form of unlawful processing. Our systems and programs are well secured to prevent unauthorized persons within and outside our organization from gaining access to your personal data. Access to your personal data is limited to persons who necessarily have access to it. The website is secured by an SSL certificate (Https). Furthermore, Roostr provides, for example, firewall protection and monthly security patches.

Cookies

We, or our service providers, may process your personal data when cookies are placed via our website or app. For more information about how we use cookies, please refer to our cookie policy on our website.

 

Retention period

We do not store personal data for longer than is necessary, given the provision of our services, the type of personal data, and our legitimate interests related thereto. The retention period may differ per purpose and is in line with legal retention periods.

Your rights

You have the right to inspect the personal data we process, the right to rectify or delete this data, the right to request restriction of your processing and the right to portability of your data.

You also have the right to object to the processing of your data.

These rights are not absolute. Under the law, circumstances may arise in which you cannot, or cannot fully, claim the aforementioned rights.

Below we describe your rights in more detail and provide information about how you can exercise your rights. We will respond to your request within one month, but have the right to extend this period by two months. If we do this, we will inform you about this within one month of your request.

Right of access:

You can ask us to confirm whether we process your personal data. If this is the case, you can ask us for access.

If you have the right to access, we will also provide you with the following information:

the purpose of the processing
the categories of personal data that we process about you
any third parties to whom we have provided your personal data;
the expected retention period of your personal data, or, if that is not possible, the criteria we use to determine the retention period;
your right to request rectification or deletion of your personal data, or request restriction of processing;
your right to file a complaint with the supervisory authority;
if we have not received the personal data from you, all available information about the source of that personal data;
automated individual decision-making.
Right to rectification: You can ask us to correct your personal data if it is incorrect. Depending on the purpose of the processing, you can also ask us to complete incomplete personal data.

 

Right of objection:

You have the right to object to our processing of your personal data. However, you only have this right if we process your personal data on the basis that it is necessary for our legitimate purposes (see section “Legal basis of data processing” for more information) [insert hyperlink to section].

We will comply with your request unless we:

have compelling legitimate grounds to continue the processing and these grounds override your interests, rights and freedoms; or
need the personal data in connection with the establishment, exercise or substantiation of a legal claim.
Right to object to 'direct marketing':

If we process your personal data for direct marketing purposes, you have the right to object to this. If you exercise this right, we will stop processing your personal data for this purpose. In that case you will no longer receive our newsletter.

Right to restriction of processing:

You can request us to restrict our processing of your personal data. If we comply with your request, we will - in addition to storage - only process your personal data with your consent or for the establishment, execution or defense of legal claims, to protect the rights of others, or for important reasons of public interest for the European Union. Union or a Member State.

We will comply with your request if:

you contest the accuracy of the personal data, for the period to verify this;
the processing is unlawful and you oppose the deletion of the personal data, but instead request the restriction of the processing;
we no longer need the personal data, but you need it to establish, exercise or defend legal claims;
you object to our processing of your personal data for the period necessary to assess whether we have legitimate grounds for further processing that outweigh your interests.
If we have restricted the processing of your personal data, we will inform you before we lift the restriction.

Right to deletion:

You have the right to ask us to delete your personal data. This right is not absolute. We are only obliged to comply with your request under certain conditions.

We must delete your personal data if one of the situations below applies:

your personal data are no longer necessary for the purposes for which we collected or processed them;
you withdraw your consent and there is no other legal basis for further processing the personal data (only applicable if we process your personal data based on consent);
you object to the processing and we have no overriding legitimate grounds for the processing;
we have processed your personal data unlawfully; or
we must delete your personal data to comply with a legal obligation under European Union or Dutch law;
We are not obliged to comply with your request to the extent that the processing of your personal data is necessary for:

the exercise of the right to freedom of expression and information;
the fulfillment of a legal obligation laid down in European or Union law or Dutch law; or
establishing, exercising or substantiating a legal claim.

Right to data transfer:

You may ask us for a copy of your personal data. You may also ask us to transfer your personal data to a third party, if this is possible. You only have the latter right if the processing is based on your consent or because it is necessary for the execution of an agreement between you and us, and the processing is carried out by automated processes.

If we comply with your request, we will provide you with your personal data in a structured, commonly used and machine-readable format. If we believe that complying with your request would adversely affect the rights and freedoms of others, we have the right not to comply with your request.

To prevent abuse, we may ask you to adequately identify you when exercising your rights. When it concerns access to personal data linked to a cookie, you must send a copy of the cookie in question.

Complaint, right to file a complaint with a supervisory authority

We always strive to respond to your requests and complaints. You can report your requests and complaints by email to the following address: service@roostr.eu. In addition, you always have the right to contact the Dutch Data Protection Authority with requests and complaints. If you do not live in the Netherlands, you can also contact your local privacy supervisor. The details of the Dutch Data Protection Authority are:

Dutch Data Protection Authority

PO Box 93374

2509 AJ THE HAGUE

0900-2001 201

www.autoriteitpersoonsgegevens.nl

Amendments

This Roostr Privacy Policy was updated on May 15, 2021. Roostr reserves the right to make changes to it. Roostr will inform you about this. The most recent version will be available at all times on this website, together with a brief overview of the most important changes compared to the previous version.