We are committed to continuously improving the sleep experience of individuals across the globe in a manner that respects, preservers, and protects the personal data of our customers. The protection of your personal data is important to us, and we want you to feel safe when using our website.
Should you have any concerns or inquiries about how we are handling your personal data, you may reach out to our Data Protection Officer through firstname.lastname@example.org.
Controller as per the applicable data protection law is:
Emma Sleep Canada Inc.
1055 West Georgia Street, 1500 Royal Centre,
P.O. Box 11117, Vancouver BC, V6E 4N7, Canada
You can reach our Data Protection Officer (“DPO”) through the following details:
Emma Sleep GmbH
Wilhelm-Leuschner-Street 78 60329
Frankfurt am Main, Germany
Personal Information we collect and how we use it
“Personal Information” means information that alone or when in combination with other information may be used to readily identify, contact, or locate you, such as: name, address, email address, or phone number. We do not consider Personal Information to include information that has been anonymized such that it does not allow a third party to easily identify a specific individual.
We collect and process your personal information in connection with your order. In individual cases, we may also receive information about you in official procedures.
Personal information we collect about you
We collect the personal information listed below.
- Identifiers such as your name, email address, shipping or billing address, phone number, IP address, username, payment information, and other contact information used to register for an account, make a purchase on our website or participate in our quizzes or surveys.
- Commercial information such as your purchase information from our website, username, password or account information used to access, make an account or purchase in our website, and information about consumer preferences and behavior that we collect when you access our website for advertising purposes.
- Internet or other electronic network activity information, such as your browsing history, online behavior (interactions with our website and advertisements), IP address, date and time of your visit, time zone different to Greenwich Mean Time (GMT), content of query (specific site visited), access status / HTTP status code, amount of transferred data, operating system, device and its user interface, search history, and information regarding your interaction on a website or advertisement. This information may also include, but is not limited to: browser type, unique device identifier, advertising identifiers, referring website, information on your activity related to your use of our website.
- Geolocation data such as your device location
- Audio information from when you make a call with our customer service which may be recorded. We may also collect your chat information when you reach out to our customer support via email or chat on the website.
We collect this information when you provide us with you information, for example when you interact with our website, create an account, purchase our products, or when you contact our customer support, or when you join our quizzes, surveys, or competitions.
Use of your personal information
Regarding the use of your personal information for business purposes, this may include the following:
- Audit and reporting purposes
- Ensuring the security and integrity of your personal information (e.g. for detection and protection against security incidents, fraud, etc.)
- Management of our website (e.g. debugging for identification and system error repairs, maintaining the website, providing customer support, fulfilling purchases, processing payments and orders, etc.)
- Personalization of advertisements (e.g. customization of ads)
Furthermore, we may collect and process your personal information for the following purposes:
- Registration of an account. The website gives you the option of creating a user account (“account”). If you decide to create an account, you will provide us with certain personal information, such as your username and password. There is no requirement to register in order to use the website and this is based on your voluntary choice or consent. We may send email to the email address you provide to us to verify your account and for informational and operational purposes, such as account management, customer service, or system maintenance.
- Purchase of an Emma product. When you purchase our products using the website, you are given the option of logging into an account or proceeding as a guest. In either case, when you purchase our products, it is necessary for you to provide us with personal information such as your name, email address, and shipping address for the purpose of processing your order and returns if applicable. To manage the delivery of goods to you, and due to the nature of the transaction, we will need to share your delivery address and contact details (email and phone number) with our logistics partners. If you want to make a product return, we will also need to share your personal data (delivery address and contact details) with the assigned non-governmental/charitable organization or delivery company for the pick-up and collection of the product.
The legal basis is that the processing is necessary for the performance of a contract to which the data subject is party and our legitimate interest in managing product returns. Only the strictly necessary data will be shared for the purpose of coordination of delivery, protection against fraud and clarification of urgent issues. This is necessary for the conclusion of the contract of sale and for us to process your order. Additionally, the essential information for the conclusion of the contract is marked, further information is given on a voluntary basis.
- Making a payment for your order. When you make a payment through the website, you may need to provide your personal information to our third-party payment service providers. For charging and order processing purposes, we may pass on your payment data to our bank or to the selected payment service provider. Such payment data may include sensitive personal information, such as your credit card number. Your personal information is processed to fulfill the contract of sale with you.
- Submission of information to the website. We may collect the information you submit on the website. For example, when you post a review of an Emma product on the website or refer a friend to Emma using the website, the website will collect the information in your submission to the website including any personal information. If you choose to submit content to any public area of the website, such content will be considered public and will not be subject to the privacy protections set forth herein. The content you post to the website may be displayed on said website. Other users of the website may be able to see information about you, for instance your name if you submit a review. We are not responsible for privacy practices of our other users who will view and possibly use the posted information. Providing your information for public display on the website is based on your consent.
- Communications with us. We may also collect your personal information when you contact us. For example, when you contact us through e-mail or via our communication channels (e.g. contact form, etc.), the information you provide will be processed for the purpose of processing your request and for the event that follow-up questions arise (e.g. your name, email address). If you are contacting us in relation to your purchase, our legal basis for the processing of your personal data is that it is needed to fulfill our contract of sale with you. If you are contacting us in relation to other matters, our legal basis for the processing of your personal data is our legitimate interest to address your concern and to enable you to contact us quickly and easily. The personal data collected by us in this context will be deleted when the request associated with the contact has been completely clarified and it is also not to be expected that the specific contact will become relevant again in the future, unless legal storage obligations stand against this.
- Newsletters and other electronic notifications. We may also collect and process your personal information if you choose to receive electronic notifications from Emma (e.g. Emma newsletters, etc). We send newsletters, e-mails and other electronic notifications containing promotional information. Our newsletters contain information about our products, offers, promotions and our company. With the following notes we inform you about the contents of our newsletter as well as the registration, dispatch and statistical evaluation procedure and your right of objection. To stop receiving our newsletters, you may withdraw your consent to or object to receiving the same at any time by clicking on the unsubscribe link provided in every newsletter e-mail or by reaching out to us through email@example.com.
If you sign up and agree to receive SMS marketing from us, we will collect and process your personal information to send you SMS. Our SMS contains information about our company, products, offers and promotions. In order to log your subscription to SMS marketing, we collect and process your phone number as well as the date and time you opted in. The purpose of this is to be able to prove your subscription, and if necessary, clarify any possible misuse of your personal information. Subscribing to our SMS marketing is voluntary and you can withdraw your consent at any time by following the unsubscribe instruction provided in every SMS sent by us.
- Surveys. From time to time, we may contact you to participate in online surveys. If you do decide to participate, you may be asked to provide certain information. For example, you may be asked to provide your contact information as well as information about your sleep habits, height, weight, gender, date of birth, etc.
- Information you provide about a third-party. If you choose to use our referral service to tell a friend about Emma, we may collect your friend’s personal information such as name and email address. We will automatically send your friend an email inviting him or her to purchase an Emma product. We store your friend’s information to send this email and to track the success of our referral program.
- Information collected when accessing the website. The website collects and stores information that is generated automatically as you use it, including your preferences and anonymous usage statistics. This information may include IP address, browser type, Internet service provider (ISP), referring/exit pages, the files viewed on our site (e.g., HTML pages, graphics, etc.), operating system, date/time stamp, and/or clickstream data. We use this data to analyze trends in the aggregate and administer the site. Furthermore, we process the data above for the following purposes: to ensure a smooth connection and comfortable use of our website, and to evaluate system security and stability as well as for other administrative purposes. This information is temporarily stored in so-called log files. When you visit this website, this information is automatically recorded without your intervention and stored until it is automatically deleted. If you don’t want the above personal information to be collected, you should not access our website as we will be unable to allow you access to our website without such information.
- Information provided by third-parties. Emma may collect information about you from third parties or supplement the information we collect from Payment Providers, Delivery services, Producers. We collect information from third parties in order to enhance our ability to serve you, to tailor our content to you, and to offer you information that we believe may be of interest to you.
- Internal and service-related usage. We use and retain information, including personal information, to improve and facilitate the website and our services. We may also use such data to help us deliver targeted advertising to consumers that is displayed on both Emma websites and unaffiliated websites, to analyze interactions with and performance of our website, to measure the effectiveness of advertising on behalf of our advertising partners, and to identify the audience most likely to respond to an advertisement. We may also use data from third parties (such as data vendors) according to their own privacy policies and enhance information (including Personal Information) that we have collected with such third-party data. We believe that the use of such information is helpful to providing users with better services. However, if you would like to opt out of these interest-based advertisements you may do so on the website.
- Use of non-personal information. We may use anonymized, aggregated, or other data that is not personal information for any purpose, including marketing. These uses may include but not limited to analyzing interactions with and performance of the website, facilitate improve our Site and services, and sharing such information with our business partners, affiliates, or any other third party. Similarly, we may enhance any such anonymized and aggregated data collected via our website with other information collected from our business partners.
- Sharing of your information to our service providers. On as a need basis, Emma may disclose your information with our third-party service providers for the following purposes: to fulfill our legal obligations, to protect and defend our rights and property, and to fulfill our contract of sale with you. Additionally, we may share personal information with our service providers who perform services on our behalf. These third parties are authorized to use your personal information only on a as needed basis to provide these services to us. These services are related to order fulfilment, order communication, package delivery, payment processing sending, evaluating, improving marketing, communications, fulfilling subscription services, conducting research and analysis, measuring and improving the performance of the website, verifying your identity and preventing fraud, developing and improving Emma products and services, registering your account, detecting, preventing and remediating fraud or other potentially prohibited or illegal activities.
- Sharing of your information as required by law and similar disclosures. To comply with law enforcement requests and legal process, such as a court order, government request, or subpoena we may access, preserve, and disclose your personal information, other account information, and content if we believe doing so is required or appropriate. We may also access, preserve, and disclose your personal information, other account information, and content if we believe in good faith that disclosure is necessary to protect yours’, ours’ or others’ rights, property, or safety, or investigate fraud.
Your rights as a data subject
- Access. Upon request Emma will provide you with details as to what information we may hold regarding personal information that we have obtained about you. If you would like to access, update, correct, or delete any information that you have provided to us through your use of the website, you may contact us at firstname.lastname@example.org. We will respond to your request within a reasonable timeframe. We reserve the right to save transaction data as is necessary to comply with legal obligations or for purposes of standard business operations.
- Choice. As noted above, you may stop or restrict the placement of cookies and or targeted advertising on your computer or remove them from your browser by adjusting your web browser preferences. Please note that cookie-based opt-outs are not effective on mobile websites. However, on many mobile devices, application users may opt out of certain mobile ads via their device settings. To manage our advertising on other sites, we engage third party advertising partners. These third-party partners may use technologies such as cookies to gather information about your activities on the Site and other sites in order to provide you advertising based on your past browsing activities and interests. Select third party advertising partners participate in self-regulatory organizations, and those organizations operate websites that give you the ability to opt-out of receiving targeted ads from those partners. You can access these websites, and learn more about targeted advertising and privacy, at Network Advertising or AboutAds. You can also choose not to be included in Google Analytics here. Please note that we do not respond to nor honor “do not track” (DNT) signals or similar mechanisms transmitted by web browsers. If you receive an unwanted email from us, you can use the unsubscribe link found at the bottom of the email to opt out of receiving future emails. We will process your request within a reasonable time after receipt. We are not responsible for removing your personal information from the lists of any third party who has previously been provided with your information in accordance with this policy. If you would like to opt-out of Emma sharing your information with third parties (for example, data vendors) for non-Emma related marketing purposes, send an email to email@example.com.
For inquiries regarding your rights as a data subject, you can direct to us through firstname.lastname@example.org.
Third-party sites and social media platforms
The website may contain links to other websites and other websites may reference or link to our website. These other domains and websites are not controlled by us. We encourage our users to read the privacy policies of every website and application that they interact with. We do not endorse, screen, or approve, and are not responsible for the privacy practices or content of such other websites or applications. Visiting these other websites or applications is at your own risk. The website also contains links and interactive features with various social media platforms. If you already use these platforms, their cookies may be set on your device when using our website. You should be aware that personal information which you voluntarily include and transmit online in a publicly accessible blog, chat room, social media platform or otherwise online, or that you share in an open forum may be viewed and used by others without any restrictions. We are unable to control such uses of your information when interacting with a social media platform, and by using such services you assume the risk that the personal information provided by you may be viewed and used by third parties for any number of purposes.
Security of your information
We keep your personal data for the period of the customer relationship with you or for the legally required period after termination of such relationship or agreement in order to defend our legal claims, to protect and enforce our rights, or to comply with laws and regulations. In general, the legal retention period for documents important for taxation (such as accounting receipts) is ten (10) years while other documents that can be considered as commercial or business transaction documents is six (6) years.
Transfers and categories of recipients
External service providers who may receive personal information generally fall into the following categories of recipients:
- Emma Sleep GmbH’s subsidiaries and affiliates
- IT service providers to maintain our IT infrastructure
- Cloud providers
- Service providers for the optimization of the website services and functions
If your personal data is processed and transferred to countries outside Canada, we will ensure that your personal data is processed in accordance with your country’s data protection level. In the absence of an adequacy decision, we only transfer data to service providers from third countries that offer suitable guarantees and put the appropriate data processing agreements and standard contractual clauses in place. If you are visiting from the European Union and if you provide us with your information, we will process it in accordance with the General Data Protection Regulation and the applicable measures for data transfers. Your data may be transferred to our subcontractors outside the EEA in order to process your order and/or inquiry. In this case, the appropriate legal measures have been concluded with the companies. For more information on these measures, please visit the European Data Protection Supervisor’s site, accessible at https://edps.europa.eu/data-protection/data-protection/reference-library/international-transfers_en.
The personal information we process varies depending on our business relationship with you and/or your activities on our website. We may also disclose your personal information described above for business purposes. The recipients to whom we may disclose your personal information (and that may have received such information during the last twelve months) for business purposes include: our affiliates and subsidiaries; our trusted partners for order processing, fulfillment, shipping, and logistics services; payment service providers and financial institutions; information technology vendors; fraud prevention and security vendors; partners supporting legal, compliance, accounting, audits and other internal functions; and certain marketing and advertising service providers.
In certain cases, we may share certain information such as email address and pseudonymized identifiers, information about the use of our websites and apps, and inferences drawn about you to our social media, advertising, and analytics partners via automated technologies on our websites for cross-context behavior advertising or other advertising marketing, or analytics purposes (on as a need basis). Under certain state laws, this may be considered to be a “sale” of personal information for consideration and/or the “sharing” of personal information for cross-context behavioral advertising. We do not disclose, sell, share, nor rent your personal information to third parties in exchange for money or compensation. Moreover, we do not “sell” nor “share” sensitive personal information about individuals who we know are under the age of 16.
Last Updated: 18 May 2023