Privacy policy

THIS PRIVACY POLICY

This privacy policy describes how information, including personal information, is collected from you (including you and any person acting on your behalf or with your authorization, collectively “you”) and subsequently used, shared, secured and otherwise processed by Book & Ear Ventures S.L. (“Oktaaf”, “Oktaaf.com”, “us”, “our”, or “we”).

“Personal information”, is any information that enables us to identify you, directly or indirectly, such as your email address, name, shipping and billing address, telephone number, company name, credit card information, any form of identification number, or one or more factors specific to your physical, physiological, mental, economic, genetic, cultural or social identity.

This privacy policy sets out the information we collect, the reasons why we do it, and how we use and share this data. It is an integral part of our legal terms. By accessing this website and making use of our services you explicitly agree to the terms of this privacy policy and the legal terms. 

Oktaaf is not designed nor intended to be attractive to use by children under the age of 13. Our legal terms require that users must be 18 years old or older in order to register on our website and use our services. If you are under the age of 18, please do not submit any information to us.

For the purposes of the EU General Data Protection Regulation 2016/679 (the “GDPR”), the controller of your personal information is Book & Ear Ventures S.L. (Company No. B87412235), C/ de los Pinos 12, 28669 Boadilla del Monte, Spain.

For any issues regarding privacy, or to exercise your rights under GDPR please contact our privacy officer at privacy<at>oktaaf.com, or send us your request in physical form, addressed to the data protection officer, at the following address: 

Data protection officer

Book & Ear Ventures S.L.

C/ de los Pinos 12

28669 Boadilla del Monte

Spain

WHAT DATA WE COLLECT, AND HOW WE COLLECT IT

When you interact with us, either through our website or by communicating with us, we may collect the following information about you:

> Information that you provide us: you can give us information about yourself by registering on our website, placing an order for products, completing any online form (such as registration forms, contests and surveys), opting to receive our newsletters and special offers, participating in contests or promotions, interacting on social networks with our website, or when communicating with us (via email, telephone, messaging apps, social networks or others).

Depending on the data you provide, this information may include your name, address or location, telephone number and email address, date of birth, gender, purchase information, purchase preferences, pictures, and financial information (including details of your credit and debit card, even though we do not process them, as our payment processors do).

> Information we receive from other accounts or sources: We may receive information about you from other sources, such as from your other accounts (such as when you use Apple ID to access our website) or other websites, including data brokers, our partners, social media providers –such as Facebook and Twitter–, advertiser networks and analytics partners, as well as payment and messaging service providers.

We complement the data you provide us with data from aggregated data services, such as public or social graphic data, in order to offer you content and promotions that are of benefit to you. We will add this data to your customer account information to better understand the interests of users and to provide more relevant product recommendations and advertisements, to increase the safety of our customers when using our website and to comply with our legal obligations, such as sanctioning laws. This information can be associated with your personal data, such as your name, email, address, physical address or telephone number.

> Information that our IT systems collect about you: each time you visit our website, certain information will be created and automatically recorded by our IT systems. This information includes:

- Cookies: you can read more information about cookies in our cookie policy. These small text files can help improve your experience on our website and facilitate your interaction with us. This may include storing your localization or language preferences, so that you do not have to re-enter this information when you return; or to ensure that the items you want to buy do not disappear while you browse the pages of our website. We also use cookies to serve you advertisements of interest to you;

- Information about devices: the information that comes from your device may differ, depending on your operating system (PC, Mac, iPhone, Android or other) and configuration, but it also depends on the type of device you have (an iPhone 6s or a Samsung Galaxy S7, for example), the IP address of the device and location, the browser you use, your mobile network provider (in the case of mobile devices), the pages you have visited, your time zone and country, as well as download error and crash reports.

WHAT WE USE YOUR INFORMATION FOR

To offer you our services and the website itself - which includes allowing you to place an order and receive products through our website, manage your account and optimize your experience - we need to use the information collected in different ways.

We also use this data for marketing and advertising purposes. When you have indicated to us that you would like to receive our marketing communications or when you have made a purchase using our services, we and our partners will use your personal information (which includes your name, email and address) to, from time to time, send you updates, news and offers. via email, postal mail or other means. We may use your data (which includes supplementary information received from our partners that we append to our existing customer data, as described below), to send you tailored messages. You can unsubscribe from our marketing communications following the options to leave that appear in our promotional emails, or letting us know via the “Contact us” section at the website.

We use third-party service providers in order to serve you more relevant ads on your various devices and on our own or other websites and mobile applications. In addition to information about your visits to our website, our service providers may use data about your interactions with other websites or applications to present you with advertisements for products available from Oktaaf or our partners. For more information on how to abandon these targeted ads and control the use of cookies, please read the cookies policy in these legal terms.

We also carry out studies, analyzes and surveys on the use of our website and the visits it receives. We keep track of the time you spend on our website to validate how we can better serve your interests. Finally, we use your information to confirm your identity and perform anti-fraud credit checks, in order to ensure your financial security and ours.

Scroll down to find out in detail the purposes for which we collect your data, what specific information is collected and the legal basis that supports it.

> To register and manage your account on our website: we collect your name, email, password and other additional details that you want to add to your account, such as phone number, address and gender. The legal basis is in the execution of a contract with you.

> To complete the orders you place through our website: we collect your name, address, phone number and order details, such as the products you are buying, the size and the price. The legal basis is in the execution of a contract with you.

> To receive your payment: we collect your payment information, which includes the credit / debit card number, holder name and CVV. We do not store this data and only transfer it to our authorized payment providers. The legal basis is in the execution of a contract with you.

> To provide you with our customer service services (including helping you resolve any problems you may have with our services, updating you on any changes to the terms of our services, or contacting you to find out how your experience with us has been): we collect your name , email, password, telephone number and address and your contact history with us. The legal basis is in the execution of a contract with you and our legitimate interests in retaining you as a client.

> To monitor the quality of our customer service services: we collect your name, email, password, telephone number and addresses, your response to our email or whatsapp inquiries about the quality of the service you received and your contact history with us (including the phone records of our conversations and conversations via email or other instant messaging applications). The legal basis is in our legitimate interests in running our business.

> To manage, maintain and optimize our website and our services: we collect information from your devices (such as the IP address and the type of device you use), cookie identifiers and browsing information. The legal basis is in our legitimate interests in running our business.

> To perform fraud and credit checks, and assess if we can do business with you: we collect your name, email, addresses, credit / debit card details, browsing history, purchase history, date of birth, gender, cookie behavior specific information about your devices (such as the IP address and the type of device you use), any type of identity documentation and any public information available (such as social media profiles or news) . The legal basis is in our legitimate interests to protect Oktaaf and its clients from fraudulent activities, and to comply with legal obligations.

> To send you marketing communications and personalized offers: we collect your name, email, phone number, address, date of birth, purchase history, browsing history and behavior, information about your devices, purchase preferences, cookie identifiers, internal identifiers and country. The legal basis is our legitimate interests in direct electronic marketing of similar products and services that you have purchased using our website or - where this cannot be applied - your consent to send you special offers and campaigns powered by Oktaaf in cooperation with exclusive partners.

> To manage our loyalty programs: we collect your name, email, phone number, address, date of birth, purchase history, browsing history and behavior, information about your devices, purchase preferences, username, cookie identifiers , internal identifiers, country, level of expenditure and purchasing power. The legal basis is our legitimate interests in running our business and improving your shopping experience.

> To offer you personalized recommendations and enhance your experience: we collect your name, email, phone number, address, date of birth, purchase history, browsing history and behavior, interactions in stores with products, information about your devices, preferences of purchase, username, cookie identifiers, internal identifiers, country, spending level and purchasing power. The legal basis is our legitimate interests in running our business and improving your shopping experience.

> To carry out studies, analysis, surveys and questionnaires about the use you give our website: we collect your name, address, email, information about your devices, demographic information (which includes gender, country of residence and family income) and content of survey responses. The legal basis is in our legitimate interests in running our business and in improving our website and your user experience.

> To advertise and redirect the advertising of our products and services, we collect your email, cookie identifiers and information from your devices. The legal basis is in our legitimate interests in running our business.

> To produce aggregated statistical reports: we use your order history, making sure that the results of these reports do not identify you. The legal basis is in our legitimate interests in running our business and improving our website.

SHARING YOUR PERSONAL INFORMATION

To facilitate our services and the website as such, we work with a select number of third parties. To do so, we may share your information with them in the following circumstances, duly limited:

> Business purpose service providers: In order to function properly, we rely on a select number of third parties who offer their services and products to us. We allow these companies to use your information only for what is strictly necessary, for the purpose of providing us with their services and products. Below you will find the types of providers we have, some may and some may not be involved in the processing of your information:

- Carrier companies that we use to deliver the products and, therefore, they need to have access to the information of your order, which includes your name and address. These providers have a global reach, with several local companies that can be involved in the delivery process, depending on your shipping address.

- Payment providers, which we use to process your payment information (such as your credit / debit card details) so that we can receive your payment. These are based in the European Union, the United States and China, and are involved in the process depending on your location.

- Anti-fraud and credit validation providers, to keep you and us safe. They have access to your information and associated orders, and process them in order to verify any fraudulent behavior. Our current suppliers are in the United States, Canada and Europe.

- Analytics and search engine providers, such as Google, that we use to help you improve and optimize the website. These providers are located in the United States and Europe.

- Customer service management providers, to offer you our customer service services and improve and manage your customer experience. Our current supplier is in the United States.

- Marketing tools that help us boost our marketing. These providers are located in the United States and Europe.

- Study companies, which we can involve to help us carry out surveys on the use you give to our website and our services. These providers are mostly located in Europe or the United States.

- IT / technology providers that we use to support, maintain and offer our technology and IT infrastructure that supports our website and that stores our information. These include Shopify - which we use to host your information. These providers are located in Canada.

> Ads for marketing purposes: we may give your information to our advertising partners and social networks of your choice (including Facebook and Google), whenever they require this data to select and use relevant ads about our products and services, directed at you and others;

> Service providers to enrich data: we may enrich, join or combine the information we have about you with information from other sources, in principle, by sharing part of your personal data with selected business partners. These partners are located in the United States. We do this to better understand your customer profile and interests, so that we can give you offers especially for you, as well as specialized services;

> Role of third parties when considering a corporate transaction: Oktaaf is always looking for new directions and opportunities for growth. This means that, on some occasions, we may consider corporate transactions, such as mergers, acquisitions, reorganizations, sale of assets or the like. In this way, we can transfer your information to allow the appreciation and completion of this transaction. If we buy or sell any business or asset, your personal information may be one of the assets to be transferred;

> To comply with legal requirements: on occasion, we may be asked to cooperate with various regulators and security agencies in different countries, whether due to legal requirement, court order or any other legal process. Although we dispute the requirements whenever possible, in some cases we will have to share your information with regulators or law enforcement agencies. When we deem it appropriate, and taking into account that we are not prohibited from doing so by law or court order, we will attempt to notify you of these legal claims;

> Information aggregated with third parties: we may aggregate your data with those of other clients, creating a database with information on the use of our website, product purchases and other general grouped data about our clients. Our legitimate interest is to understand the use of our service and demand for our product. Although this data set is aggregated and anonymous, which means that it cannot identify you individually, it provides value in terms of the use of our website and can be shared with selected third parties. These third parties may include providers of plugins or similar technologies to help measure traffic; and our investors.

TRANSFER OF YOUR DATA

You are advised to be aware that the personal information we receive from you and about you may be held on our computers and systems in the European Union and in the computers and systems of our offices and data centers in the United States and may be accessed by or given to our staff working outside the European Union.

Your personal information may be processed by us in the United States or Canada, where laws regarding data protection may be less stringent than the laws in your country. By using this website and by providing any personal information to the website, all users, including without limitation users in Canada, the UK and the European Union, acknowledge Oktaaf’s collection and processing of such personal information in the United States.

When disclosing personal information from the EU and the UK to a third party (e.g. our shipping agents) located in a country  not recognized by the European Commission as ensuring an adequate level of protection (e.g., the United States), we will take appropriate steps to safeguard such personal information, such as by implementing the European Commission-approved standard contractual clauses.

For the avoidance of doubt, Oktaaf does not rely upon the now invalidated U.S. Department of Commerce Privacy Shield Framework in order to receive EU personal information in the U.S.  For further details, please contact us at privacy<at>oktaaf.com.

USE OF COOKIES

The website uses cookies to distinguish you from other users. This helps us to analyze the use of the website to customize and improve the content and the layout of the website. 

When you first access our website from certain jurisdictions, you may receive a message advising you that cookies and similar technologies are in use.

For detailed information on the cookies we use and the purposes for which we use them, please visit the cookie policy in these legal terms.

SECURITY

As a registered user of the website, you are responsible for maintaining the confidentiality of your username and password. Please keep your user ID and password confidential.

If you share your computer, we recommend that you log-out and close your browser window after visiting the website in order to protect the confidentiality of your personal information including your credit card information, your offer status and buying history.

You agree to accept responsibility for all activities that occur under your account or password. You agree to notify us immediately of any unauthorized use of your account or any other breach of security. We reserve the right to refuse service, terminate accounts, or remove or edit content at our sole discretion.

We use reasonable physical, electronic, and administrative safeguards to help us protect the security, integrity and confidentiality of data stored on our system, and to provide for the secure transmission of the personal information from your PC to our servers.

Except as specified in this privacy policy, we use commercially reasonable efforts to limit access to your personal information to the employees, officers, third-party contractors, and strategic partners of Oktaaf who need the personal information in order to perform their duties.

While no system is 100% secure, we believe that the measures we have implemented minimize the risk of a security breach to an appropriate level given the types of personal information involved. Please note that any personal information you provide us by email is unencrypted.

Please note that transmission of personal information via the internet is not completely secure and although we will endeavor to protect your information, we cannot guarantee the security of your information transmitted to our website; any transmission is therefore at your own risk. However, once we have received your information, we will use procedures and security features to try to prevent unauthorized access.

HOW LONG WE KEEP YOUR DATA

We will keep the data you provide us for as long as you have your account with us and, from that moment on, for the period in which you have questions or complaints in relation to our services, in addition to any additional maintenance period to which we are obliged, in accordance with the legal requirements that are applied to us.

In some circumstances, you can ask us to delete your data as explained below. When you have finished using our services, we may store your information in an aggregated and anonymous format.

OPT-OUT

If you do not wish to receive offers or other notices from us in the future, you can “opt-out” by sending an email to privacy<at>oktaaf.com or by contacting us at the address indicated at the beginning of this policy.

We will try to complete your request as promptly as possible. You can elect not to receive emails from us either by “unsubscribing” to an email you receive or by contacting us as indicated above. Any changes will affect only future uses of your information.

PRIVACY RIGHTS (GDPR)

For individuals within the EEA only. Under the GDPR, in certain circumstances, you may have rights in relation to your personal information – specifically to:  

> Request access to your personal information. You may have the right to request access to any personal information we hold about you as well as related information, including the purposes for processing the personal information, the recipients or categories of recipients with whom the personal information has been shared, where possible, the period for which the personal information will be stored, the source of the personal information, and the existence of any automated decision making.

> Request the rectification of any inaccurate personal information. You may have the right to obtain without undue delay the rectification of any inaccurate personal information we hold about you.

> Request erasure of your personal information. You may have the right to request that personal information held about you be deleted, provided that such personal information is not required by Oktaaf for compliance with a legal obligation under European or Member State law or for the establishment, exercise or defense of a legal claim. 

> Request restriction of processing of your personal information. You may have the right to prevent or restrict processing of your personal information, except to the extent processing is required for the establishment, exercise or defense of legal claims.

> Request transfer of your personal information. You may have the right to request transfer of your personal information directly to a third party where this is technically feasible.

You can exercise any of these rights by emailing our privacy officer at privacy<at>oktaaf.com, or by sending us your request in physical form, addressed to the data protection officer, at the following address:  

Data protection officer

Book & Ear Ventures S.L.

C/ de los Pinos 12

28669 Boadilla del Monte

Spain

In addition, where you believe that Oktaaf has not complied with its obligation under this privacy policy or EU or UK law, you have the right to make a complaint to an appropriate data protection authority.

PRIVACY RIGHTS (CCPA)

This section provides more information about the personal information we collect about California consumers and the rights afforded to you under the California Consumer Privacy Act (“CCPA”).  

You have certain rights in relation to your data, including the right to have your personal data deleted, and the right to object to your personal data being sold to third-parties. 

> For details about the personal information we have collected over the last 12 months, including the categories of sources, please see the “What data we collect, and how we collect it” section above.

> We collect this information for the purposes set out in the “What we use your information for” section above.

> We share this information with the categories of third parties described in the section “Sharing your personal information”.

> We do not sell (as defined in the CCPA) the personal information we collect.

> We use third-party cookies for our advertising purposes as described in the cookie section included in these legal terms.

Subject to certain limitations, the CCPA provides California consumers the right to request more details about the categories or specific pieces of personal information we collect, such as how we use and disclose this information and to delete their personal information.

California consumers may make a request pursuant to their rights in the CCPA by contacting us at privacy<at>oktaaf.com. We will verify your request using the information you have previously submitted to us, including your email address.