Spa-Plus B.V. cares a lot to your privacy. We therefore only process data that we need for (improving) our services and we carefully handle the information we have collected about you and your use of our services. We never make your data available to third parties for commercial purposes.
About data processing
Below you can read how we process your data, where we store it (or have it stored), what security techniques we use and who can view the data.
Web shop software
Our website/product catalog has been developed with OpenCart software.
No personal data is shared with OpenCart.
Our website/product catalog has been developed with Opencart software, we have opted for One.com for our web hosting. Personal data that you make available to us for the benefit of our services will be shared with this party. One.com has access to your data to provide us (technical) support, they will never use your data for any other purpose. One.com is obliged to take appropriate security measures based on the agreement we have with them. These security measures consist of the application of SSL encryption and a strong password policy. Backups are made on a regular basis to prevent the loss of data.
For order processing, we use software from Zoho. Personal data that you make available to us for the benefit of our services will be shared with this party. Zoho has access to your data to provide us (technical) support, they will never use your data for any other purpose. Zoho is obliged to take appropriate security measures based on the agreement we have with them. These security measures consist of the application of SSL encryption, a strong password policy and secure data storage. Backups are made on a regular basisl to prevent the loss of data.
We use web hosting and e-mail services from One.com. One.com processes personal data on our behalf and does not use your data for its own purposes. However, this party can collect metadata about the use of the services. This is not personal data. One.com has taken appropriate technical and organizational measures to prevent loss and unauthorized use of your personal data.
E-mail and mailing lists
We use the services of One.com for our regular business e-mail traffic. This party has taken appropriate technical and organizational measures to prevent abuse, loss and corruption of your and our data as much as possible. One.com has no access to our mailbox and we treat all our email traffic confidentially.
Shipping and logistics
UPS, DPD, MainFreight, Rotra, Rabelink and van der Heijden
If you place an order with us, it is our job to have your order delivered to you. We use the services of UPS and DPD (parcel services) and MainFreight, Rotra, Rabelink and van der Heijden (carriers) to carry out the deliveries. It is therefore necessary that we share your name and address details with these parcel services and carriers. These parcel services and carriers use this data only for the purposes of executing the delivery. In the event that these parcel services and carriers engage subcontractors, these parcel services and carriers also make your data available to these parties.
Invoicing and accounting
For our administration and accounting we use the services of Zoho. We share your name and address and details regarding your order. This data is used for managing sales invoices. Your personal data is transmitted and stored in a protected manner. Zoho is obliged to maintain secrecy and will treat your information confidentially. Zoho does not use your personal data for purposes other than those described above.
Purpose of data processing
General purpose of processing
We process your data for the following purposes:
- For the benefit of our services
- To inform you about changes to our products and services
Automatically collected data
Data that is automatically collected by our website is processed with the aim of further improving our services. This information (eg your IP address, web browser and operating system) is not personal data.
Participation in tax and criminal investigation
In some cases, Spa-Plus can be required on the basis of a legal obligation to share your data in connection with government tax or criminal investigations. In such a case, we are forced to share your information, but we will oppose it within the possibilities that the law offers us.
We retain your information for as long as you are our client. This means that we keep your customer profile until you indicate that you no longer wish to use our services. If you indicate this to us, we will also consider this as a request to be forgotten. On the basis of applicable administrative obligations, we must keep invoices with your (personal) data, so we will keep this data for as long as the applicable term requires us to so. However, employees no longer have access to your client profile and documents that we have produced as a result of your orders.
Based on the applicable Dutch and European legislation, you as a data subject have certain rights with regard to the personal data processed by or on behalf of us. We explain below which rights these are and how you can invoke these rights.
In principle, in order to prevent abuse, we will send transcripts and copies of your data only to the e-mail address that we have on file for you. In the event that you wish to receive the data at another e-mail address or for example by post, we will ask you to identify yourself. We keep records of completed requests, in the case of a request to be forgotten we will keep anonymous data. You will receive all transcripts and copies of data in the machine-readable data format that we use within our systems.
You have the right to file a complaint with the Dutch Data Protection Authority at any time if you suspect that we are using your personal data in the wrong manner.
Right of inspection
You always have the right to access the data that we process (or have processed) and that relate to your person or that can be traced back to you. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you a copy of all data with an overview of the processors who have this data, to the e-mail address we have on file for you, stating the category under which we have stored this data.
Right to rectification
You always have the right to have the data modified that we process (or have processed) and that relate to your person or that can be traced back to you. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you a confirmation that the details have been changed to the e-mail address we have on file for you.
Right to restriction of processing
You always have the right to limit the data that we process (or have processed) and that relate to your person or that can be traced back to you. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you a confirmation to the e-mail address we have on file for you that the data will no longer be processed until you cancel the restriction.
Right of transferability
You always have the right to have the data that we process (or have processed) and that are related to your person or that can be traced back to you, be carried out by another party. You can submit a request to that effect to the e-mail address below. You will receive a response to your request within 30 days. If your request is granted, we will send you transcripts or copies to the e-mail address we have on file for you, of all information about you that we have processed or that have been processed for us by other processors or third parties. In all likelihood, we will no longer be able to continue our services in such a case, because the secure linking of data files can no longer be guaranteed.
Right of objection and other rights
In certain cases you have the right to object to the processing of your personal data by or on behalf of Spa-Plus. If you object, we will immediately stop the data processing pending the handling of your objection. If your objection is well-founded, we will make transcripts and/or copies of data that we process (or have processed) available to you and then permanently discontinue the processing. You also have the right not to be subject to automated individual decision making or profiling. We do not process your data in such a way that this right applies. If you are of the opinion that this is the case, please contact us via the e-mail address below.
Through our website, cookies of the American company Google are pleaced as part of the "Analytics" service. We use this service to track and get reports on how visitors use the website. This processor may be obliged to provide access to these data on the basis of applicable laws and regulations. We have not allowed Google to use the obtained analytics information for other Google services.
Cookies from third parties
5571 LJ Bergeijk