Privacy Statement dundle
Introduction
Welcome to dundle! We understand the importance of handling your personal data with care when we Korsit B.V., trading under the name Korsit and dundle (dundle or we) process it while browsing our website (https://dundle.com) and our mobile application and providing our services which includes the distribution of payment, gift and gaming cards. In this Privacy Statement, we will set out in general terms how we process your personal data. In this context, personal data means any data that directly or indirectly identifies a natural person. Should it be necessary to inform you specifically of any processing, we will do so with reference to this Privacy Statement. For example, we inform you regarding the processing of personal data for certain payment processing purposes at the checkout section.
Controller
We are responsible for the processing activities described in this Privacy Statement. For these activities, we determine the purposes and means of processing. We always process personal data in accordance with applicable data protection laws and regulations, including the General Data Protection Regulation (GDPR).
Categories of persons
We process the personal data of the following categories of individuals:
Customers - persons who are (potential) customers and persons employed by (potential) customers.
Website visitors - individuals who visit the website.
Users – persons who create or have an account.
Third parties - persons from which we obtain products and/or services or persons whose personal data appears in our files; other persons with whom we have contact.
Minors
In general, we do not provide our services to persons under 16 years of age and do not knowingly process personal data of these minors. If we become aware that we have (inadvertently) processed the personal data of minors, we will take appropriate measures, such as requesting permission from parents or guardians or deleting the data immediately.
Categories of personal data
Customers
From customers we process - as far as reasonably necessary for providing the services - the following data:
Contact details: name, email address and telephone number.
Details of the goods and services: information about the goods and services.
Sensitive data: telephone bill, copy of personal identification document (passport/ID card/ driver’s license).
Invoicing data: payment or invoice details.
Identity and verification details, where required: address, date of birth, identification documents supporting verification documents.
Communications and customer support records: correspondence and other communications with us, including customer service requests, complaints, feedback and related records.
Loyalty points information: information relating to loyalty points earned through purchases, including the number of points earned, available and redeemed.
Other data: data whose processing is required by applicable laws or regulations or data that customers provide us with on their own initiative.
Users
From users we process - as far as reasonably necessary for providing the services - the following data:
Account credentials: e-mail address and user id.
Other data: data whose processing is required by applicable laws or regulations or data that customers provide us with on their own initiative.
Website visitors
From website visitors we process - as far as reasonably necessary for providing the services - the following data:
Technical and usage data: automatically generated data when accessing or using the website, i.e. IP address, device and browser information, operating system, unique or online identifiers, date and time of access, session information and, where applicable.
Third parties
From third parties, we process - as far as reasonably necessary for providing the services the following data:
Contact details: name, address, e-mail address, job title, title, telephone number, Chamber of Commerce number, VAT number, bank account number and nationality.
Other data: data that we receive from customers or third parties or collect from a public source, data whose processing is required by applicable laws or regulations, or data that third parties provide to us on their own initiative.
Obtaining personal data
We may obtain your personal data in three ways.
From you or your employer
We use data that you or your employer actively provide to us. For example, when you contact us to obtain information about our products.
Automatically obtained
We obtain some information about you in an automated way. For example, when you visit our website, we automatically obtain information about you via cookies.
Third-party sources
We also obtain information about you from third parties, including our business partners (Payment Service providers, suppliers and other third-party service providers). For example, we may request information about you.
Lawful basis and purposes
There are six possible lawful bases to process your personal data provided for in the GDPR:
Performance of a contract. If it is necessary for the performance of a contract with you, we may process your personal data for this purpose.
Legal obligation. If it is necessary to comply with a legal obligation, we may process your personal data for this purpose.
Legitimate interest. If it is necessary to process personal data about you for our or other legitimate interests, and those interests outweigh your interests or fundamental rights, we may process your personal data.
Vital interest. If it is necessary to process personal data about you to protect your vital interest, we may process your personal data.
Public interest. If it is necessary to process personal data about you for the performance of a task carried out in the public interest, we may process your personal data.
Consent. In principle, if the aforementioned bases do not apply, we may only process your data if you have given us your consent.
Of the six possible lawful bases, we generally process your personal data on four bases (i.e. performance of a contract, legal obligation, legitimate interest and consent).
Customers
If you are a customer of ours, we may process your personal data for the following purposes:
Performance of a contract to process and execute orders and handle customer inquiries
Legal basis: Performance of a contract.
Send you direct marketing including newsletters
Legal basis: Consent; legitimate interest (only if you have been a customer).
Calculating and recording fees, collecting and / or making payments.
Legal basis: Performance of a contract; legitimate interest.
Enforcing our rights and risk management, including fraud, theft and money laundering and terrorist financing detection and prevention.
Legal basis: Legitimate interest.
Complying with our legal and regulatory obligations including our tax and accounting obligations
Legal basis: Legal obligation.
Defend against claims
Legal basis: Legitimate interest.
Secure our systems.
Legal basis: Legitimate interest.
Users
If you are a user, we may process your personal data for the following purposes:
Authorization and authentication.
Legal basis: Performance of a contract; legitimate interest.
Resolving issues, errors and bugs.
Legal basis: Performance of a contract; legitimate interest.
Improving our products and services.
Legal basis: Legitimate interest.
Website visitors
If you are a website visitor, we may process your personal data for the following purposes:
Keeping our website functioning.
Legal basis: Legitimate interest.
Marketing activities, such as sending newsletters and invitations to events.
Legal basis: Consent.
Offering relevant information.
Legal basis: Legitimate interest; consent.
Complying with our legal and regulatory obligations.
Legal basis: Legal obligation.
Improving our products and services.
Legal basis: Legitimate interest.
Third parties
If you are a third party, we may process your personal data for the following purposes:
Keeping in contact.
Legal basis: Legitimate interest.
Marketing activities, such as sending newsletters and invitations to events.
Legal basis: Consent.
Placing orders.
Legal basis: Legitimate interest; performance of a contract.
Complying with our legal and regulatory obligations.
Legal basis: Legal obligation.
Sharing of personal data
We will only share your personal data with trusted third parties if they need this personal data to provide their services. We will ensure that your data is only used in a manner similar to, or for a purpose similar to, the purpose for which it was collected, and only in accordance with this Privacy Statement and any legal obligations.
We may share your personal data with the following parties:
Persons working for us, either directly or indirectly, and involved in the processing.
Persons working for any of our suppliers (incl. subcontractors or service providers) involved in the processing, such as hosting providers, fraud detection service providers and payment service providers.
Persons working for the customer who has engaged our services.
Persons working for competent authorities, if required by law, such as supervisory authorities, enforcement agencies and courts.
Sharing for Fraud Detection
We share your personal data and the third-party service provider collects your personal data for the detection of fraud and abuse. In particular:
For credit card transactions, we use Forter Solutions UK Ltd (“Forter”). Forter processes this data to identify and prevent fraudulent, illegal or unauthorized activities and to support payment authentication and optimization under PSD2 and 3-D Secure (3DS). For this purpose, Forter may use automated processing and advanced technologies, such as machine learning algorithms and artificial intelligence, to assist in detecting patterns indicative of fraud or misuse. For more information on how Forter processes personal data, please see Forter's Privacy Policy and Privacy FAQ.
For all other payment methods, we use Sift Science, Inc (“Sift”). Sift processes this information to identify and prevent fraudulent, illegal or unauthorized activities. For this purpose, Sift may use automated processing and advanced technologies, such as machine learning algorithms and artificial intelligence, to assist in detecting patterns indicative of fraud or misuse. For more information about how Sift processes personal data, please see Sift’s Service Privacy Notice and an explanation of Sift services to end-users (customers).
Security
We use various appropriate technical and organisational measures to ensure data security, including protection against a breach of security leading to the accidental or unlawful destruction, loss, alteration or unauthorised disclosure of, or access to, such data. In doing so, we take into account the state of the art, implementation costs, the nature, scope, context and purposes of the processing, as well as the risks the processing poses to you. The persons working for us are, of course, bound by confidentiality and must comply with our instructions aimed at protecting your personal data.
Cookies on our website
Cookies are small text files placed on your computer, laptop, tablet, smartphone or other internet-enabled device. These cookies can be stored and read through your web browser. After a cookie is placed, your device can be recognised as long as you use the same web browser and as long as the cookie is not deleted. This makes it possible, for example, to click back to the previously visited web page. Cookies can also be used to analyse browsing behaviour. Besides cookies, similar techniques may also be used, such as web beacons (also called "tags"), HTML5 Local Storage and Local Shared Objects (LSOs, also called "flash cookies"), and embedded scripts (also called "Javascripts").
We have a cookie banner on our website informing you about our cookies and allowing you to select your cookies preferences.
Transfer to countries outside the EEA
We may transfer your personal data to parties processing your personal data outside the European Economic Area (EEA). Transfer of your personal data to a country outside the EEA can be legitimised primarily on the basis of a so-called adequacy decision. This is a decision in which the European Commission declares that, for example, a certain country provides a comparable level of data protection to the GDPR.
If and to the extent we share personal data with parties in countries outside the EEA to which no adequacy decision applies, we will only transfer your personal data if the recipient provides appropriate safeguards and you have enforceable rights and effective remedies.
Storage of personal data
In principle, we do not store your personal data for longer than necessary to fulfil the purposes described in this Privacy Statement.
However, we may need to keep your personal data for longer because it is necessary to comply with a legal obligation or be allowed under a legal right. For example, we need to keep certain personal data for a period of at least 7 years after the end of a fiscal year or retain your personal data 5 years to the extent necessary for defending against a claim.
Privacy rights
In certain cases, you have the right to view the personal data that we process about you and, where applicable, you have the right to rectify any inaccurate or incomplete personal data. You have, in certain cases, also the right to object to the processing of your personal data and you can also ask us to limit the processing of your personal data, delete your data or transfer your data to another party. In order to exercise any of your privacy rights as to personal data controlled by us, please send a request to us and indicate that it concerns a personal data request.
Exercising the above privacy rights is in principle free of charge and can be done by e-mail using the contact details provided below. We will provide you with information on the action taken on your request without undue delay and, in principle, within one month of receiving the request. If the exercise of a privacy right is clearly unfounded or excessive, in particular due to its repetitive nature, we will charge you a reasonable fee or refuse to comply with the request. We may also ask you for certain additional information to help us confirm your identity before complying with such a request.
Right to make a complaint
You have the right to make a complaint with a supervisory authority at any time. We refer you to this webpage for an overview of the supervisory authorities and their contact details. In the Netherlands, this is the Personal Data Authority. We prefer to deal with your complaint ourselves first before referring you to the supervisory authority. Therefore, please contact us, in particular if you have a complaint about the way we handle your personal data, so that we can try to resolve the issue.
Contact details
Korsit B.V.
Zwembadweg 12
5611 KS Eindhoven
Chamber of Commerce no.: 69094438
Other
If we refer to websites, whether or not via hyperlinks from other parties, we are not responsible for the content of those websites or the services of those parties, or how they process your personal data.
Please note that we may make changes to this privacy notice from time to time. Where appropriate, we will notify you of such updates. The current version is always available on our website https://dundle.com/legal/privacy-policy/.