DrChill BV ("we", "us", or "our") is committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website or purchase our products. Please read this policy carefully. If you do not agree with its terms, please discontinue use of our site.
1. Who We Are
DrChill BV is a company incorporated under the laws of Belgium, specialising in advanced personal cooling technology and performance wear. Our registered office is located at:
DrChill BV
Windmolenstraat 117
3500 Hasselt, Belgium
Email: support@drchill.cool
DrChill BV is the data controller responsible for your personal data.
2. What Data We Collect
We may collect and process the following categories of personal data:
- Identity data: first name, last name, username or similar identifier
- Contact data: email address, telephone number, billing and delivery address
- Transaction data: details about purchases and payments made through our website
- Technical data: internet protocol (IP) address, browser type and version, time zone, operating system and platform
- Usage data: information about how you use our website and products
- Marketing and communication data: your preferences in receiving marketing from us and your communication preferences
We do not collect any special categories of sensitive personal data (e.g., health data, racial or ethnic origin, political opinions) unless expressly required and consented to.
3. How We Collect Your Data
We collect data through various means, including:
- Direct interactions: when you fill in forms, make a purchase, contact us by email or phone, or subscribe to our newsletter
- Automated technologies: as you interact with our website, we automatically collect technical data using cookies, server logs, and similar technologies
- Third parties: we may receive data from analytics providers, advertising networks, and payment providers
4. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we use it to:
- Process and fulfil your orders, including managing payments, delivery, and after-sales service
- Manage your account and relationship with us
- Send you important information, such as order confirmations and updates
- Send marketing communications where you have opted in or where we have a legitimate interest to do so
- Improve our website, products, and customer experience
- Comply with our legal obligations and resolve disputes
- Detect and prevent fraud or misuse of our services
5. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation (GDPR), we process your personal data on the following legal bases:
- Performance of a contract: to fulfil your orders and manage your account
- Legitimate interests: to operate and improve our business, provided these are not overridden by your rights
- Consent: where you have given clear consent, such as for marketing emails or non-essential cookies
- Legal obligation: where we are required to process data to comply with the law
6. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to distinguish you from other users and to provide you with a better browsing experience. We use the following types of cookies:
- Strictly necessary cookies: essential for the website to function and cannot be switched off
- Performance/analytics cookies: help us understand how visitors interact with our website (e.g., Google Analytics)
- Functional cookies: enable enhanced functionality and personalisation
- Targeting/marketing cookies: used to deliver relevant advertisements and track campaign effectiveness
You can manage your cookie preferences at any time through your browser settings. Please note that blocking cookies may affect the functionality of our website. Where required by law, we will ask for your consent before placing non-essential cookies.
7. Sharing Your Data
We do not sell your personal data. We may share your data with carefully selected third parties, including:
- Payment processors (e.g., Stripe, PayPal) — to process transactions securely
- Logistics and shipping partners — to fulfil and deliver your orders
- IT and technology service providers — to support our website and systems
- Email marketing platforms — to send communications where you have opted in
- Analytics providers — to help us understand website usage
All third parties are contractually required to process your data securely and only for the purposes we specify. We may also disclose your data to regulatory authorities or law enforcement where required by law.
8. International Data Transfers
Some of our third-party service providers may be based outside the European Economic Area (EEA). Where we transfer your data internationally, we ensure appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Transfers to countries recognised by the European Commission as providing an adequate level of data protection
9. Data Retention
We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically:
- Customer order and transaction data is retained for up to 7 years for accounting and legal compliance
- Marketing data is retained until you withdraw your consent or unsubscribe
- Technical and usage data may be retained for up to 2 years
When data is no longer needed, we securely delete or anonymise it.
10. Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, alteration, or disclosure. These include:
- Secure SSL/TLS encryption for data transmission
- Access controls and authentication procedures
- Regular security reviews and updates
While we take all reasonable steps to protect your data, no method of internet transmission or electronic storage is 100% secure. We cannot guarantee absolute security.
11. Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of access: to request a copy of the personal data we hold about you
- Right to rectification: to correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): to request deletion of your data where there is no compelling reason for us to continue processing it
- Right to restriction of processing: to ask us to suspend processing of your data in certain circumstances
- Right to data portability: to receive your data in a structured, commonly used, machine-readable format
- Right to object: to object to processing based on legitimate interests or for direct marketing purposes
- Rights related to automated decision-making: to not be subject to decisions made solely by automated processing that significantly affect you
To exercise any of these rights, please contact us at support@drchill.cool. We will respond within 30 days. We may need to verify your identity before fulfilling your request.
12. Children's Privacy
Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a child, please contact us immediately and we will take steps to delete it.
13. Links to Third-Party Websites
Our website may contain links to third-party websites. These sites have their own privacy policies, and we do not accept any responsibility or liability for them. We encourage you to read the privacy policy of every website you visit.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. We will notify you of any material changes by posting the updated policy on our website with a new "Last updated" date. We encourage you to review this page periodically.
15. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit — GBA):
- Website: www.dataprotectionauthority.be
- Address: Rue de la Presse 35, 1000 Brussels, Belgium
- Tel: +32 (0)2 274 48 00
We would, however, appreciate the chance to address your concerns before you approach the authority, so please contact us first.
Contact Us
For any questions, requests, or concerns about this Privacy Policy or our data practices, please contact our Data Protection contact:
DrChill BV
Windmolenstraat 117, 3500 Hasselt, Belgium
Email: support@drchill.cool