7. EU DATA AND SWISS SUBJECT RIGHTS
If you are a resident in the EU or Switzerland, you have certain rights in relation to the Customer Data we hold about you, which we detail below. Some of these only apply in certain circumstances as set out in more detail below. We also set out how to exercise those rights.
These rights include:
- The right of data portability.
- The right of rectification.
- The right to restrict processing.
You have the right to revoke your consent at any time. This means that we can no longer continue the data processing based on this consent in future. However, the revocation of consent does not affect the lawfulness of the processing carried out on the basis of the consent prior to such revocation.
Please note that we will require you to provide us with proof of identity before responding to any requests to exercise your rights. We will respond to a request by you to exercise those rights without undue delay and at least within one month (although this may be extended by a further two months in certain circumstances).
In order to process your request promptly, we kindly ask you to include the necessary identification details with your request as well as any other information necessary to confirm your identity or to process your request. Such information may include the following:
- KrisFlyer or HighFlyer number (if applicable).
We kindly ask that you send all data subject requests to dpo@krisshop.com, marked for the attention of the Data Protection Officer. However, you are not obligated to do so. In order to exercise your rights as described here, you may also contact us at any time using the contact details provided in the first section above. Please note that requests which do not contain sufficient supporting information may take longer to process and/or we may not be able to respond within the prescribed timelines.
In the event that you wish to make a complaint about how we process your Customer Data, please contact us and we will endeavour to deal with your request as soon as possible. This is without prejudice to your right to lodge a claim with your data protection authority.
You have the right to know whether we process Customer Data about you, and if we do, to access Customer Data we hold about you and certain information about how we use it and who we share it with.
If you require more than one copy of the Customer Data we hold about you, we may charge an administration fee.
We may not provide you with certain Customer Data if providing it would interfere with another’s rights (e.g. where providing the Customer Data we hold about you would reveal information about another person) or where another exemption applies.
You have the right to receive a subset of the Customer Data we collect from you in a structured, commonly used and machine-readable format and a right to request that we transfer such Customer Data to another party.
The relevant subset of Customer Data is data that you provide us with your consent or for the purposes of performing our contract with you. Please refer to section (3) on “How we use your Customer Data”.
If you wish for us to transfer the Customer Data to another party, please ensure you detail that party and note that we can only do so where it is technically feasible. We are not responsible for the security of the Customer Data or its processing once received by the third party. We also may not provide you with certain Customer Data if providing it would interfere with another’s rights (e.g. where providing the Customer Data we hold about you would reveal information about another person).
You have the right to correct any Customer Data held about you that is inaccurate. Please note that whilst we assess whether the Customer Data we hold about you is inaccurate or incomplete, you may exercise your right to restrict our processing of the applicable data by submitting a data subject request to dpo@krisshop.comas detailed above.
You may request that we erase the Customer Data we hold about you in the following circumstances:
(i) you believe that it is no longer necessary for us to hold the Customer Data we hold about you;
(ii) we are processing the Customer Data we hold about you on the basis of your consent (please refer to section (3) on “How we use your Customer Data”), and you wish to withdraw your consent and there is no other ground under which we can process the Customer Data;
(iii) we are processing the Customer Data we hold about you on the basis of our legitimate interest and you object to such processing (please refer to section 3 to on “How we use your Customer Data”). Please provide us with detail as to your reasoning so that we can assess whether there is an overriding interest for us to retain such Customer Data;
(iv) you no longer wish us to use the Customer Data we hold about you in order to send you promotions, special offers, marketing and lucky draws; or
(v) you believe the Customer Data we hold about you is being unlawfully processed by us.
Also note that you may exercise your right to restrict our processing of the Customer Data whilst we consider your request as described below.
Please provide as much detail as possible on your reasons for the request to assist us in determining whether you have a valid basis for erasure. However, we may retain the Customer Data if there are valid grounds under law for us to do so (e.g. for tax reasons) but we will let you know if that is the case. Please note that after deleting the Customer Data, we may not be able to provide the same level of services to you.
Where you have requested that we erase Customer Data that we have made public and there are grounds for erasure, we will use reasonable steps to tell others that are displaying the Customer Data or providing links to the Customer Data to erase the Customer Data too.
You may exercise your right to restrict our processing of the applicable data by submitting a data subject request to dpo@krisshop.com as detailed in the first section above. If you are a registered user, you may correct or delete any Customer Data by logging into your account.
- Restriction of Processing to Storage Only.
You have a right to require us to stop processing the Customer Data we hold about you other than for storage purposes in certain circumstances. Please note, however, that if we stop processing the Customer Data, we may use it again if there are valid grounds under data protection law for us to do so (e.g. for tax reasons).
You may request we stop processing and just store the Customer Data we hold about you where:
(i) you believe the Customer Data is not accurate, for the period it takes for us to verify whether the Customer Data is accurate;
(ii) we wish to erase the Customer Data for compliance with applicable laws but you want us to just store it instead;
(iii) we wish to erase the Customer Data as it is no longer necessary for our purposes but you require it to be stored for the establishment, exercise or defence of legal claims; or
(iv) you have objected to us processing Customer Data we hold about you on the basis of our legitimate interest and you wish us to stop processing the Customer Data whilst we determine whether there is an overriding interest in us retaining such Customer Data.
At any time you have the right to object to our processing of Customer Data about you in order to send you promotions, special offers, marketing messages, including where we build profiles for such purposes and we will stop processing the Customer Data for that purpose.
You may object where we are processing the Customer Data we hold about you (including where the processing is profiling) on the basis of our legitimate interest and you object to such processing (please refer to section (3) on “How we use your Customer Data” to see the types of Customer Data we process on that basis).
Please provide us with detail as to your reasoning so that we can assess whether there is a compelling overriding interest in us continuing to process such data or we need to process it in relation to legal claims. Also note that you may exercise your right to request that we stop processing the Customer Data whilst we make the assessment on an overriding interest by indicating this in our Data Privacy Rights Form,