Privacy Policy

1. What is the purpose of this Privacy Policy

DDB Group Hong Kong uses information from our interactions with you and other customers and from certain third parties, to help us achieve our goal of providing the highest quality products and services.

We respect the privacy rights of our online visitors and recognize the importance of protecting the information collected about them. For this reason, we have established procedures to ensure that your personal information is handled in a responsible manner. This Privacy Policy provides you with information on what kind of information we collect, the purposes for which we collect and use the information, how it is handled, with whom it may be shared, and what choices you have regarding our use of your information.

By visiting the Crafted by My Heart website at http://www.craftedbymyheart.com and/or using the “Crafted by My Heart” mobile application, you accept the content of this Privacy Policy together with DDB Group Hong Kong’s Terms and Conditions, Cookie Policy, and any other documents referred to in this Privacy Policy. This Privacy Policy set out the basis on which we will process any information we collect from you or that you provide us with. Please carefully read the following to understand our views and practices regarding your information and how we will treat it.

Certain parts of this Privacy Policy apply specifically to the collection and processing of your personal data in relation to your use of website, mobile application and services, which is required for you to purchase with “Crafted by My Heart” mobile application.

If you have any privacy questions or concerns, or if you have any enquires as to the personal information you have given us, you may contact DDB Group Hong Kong at any time. For details on how to contact us, please see “Contact Information”.

2. Who is in charge of the protection of your information

DDB Group Hong Kong determines the purposes and means of the processing of your data.

3. What personal data is collected?

All our activities are based on stringent ethical principles and legal requirements, and we are committed to protect the privacy of all visitors to our websites and users of our (mobile) applications. For this reason, the way in which we collect and store information is dependent on how our website and related services are used.

3.1 Data collected through your interaction with us

Various technologies may be used on our website and our mobile applications in order to improve them, make them more user-friendly, effective and secure. Such technologies may lead to data being collected automatically by us or by third parties on behalf of us. Examples of such technologies are cookies, flash cookies and web analytics.

3.1.1 Click-stream data

When you visit our website, data is sent from your browser to our server. This data makes it possible for us to optimize our services and improve your experience on our website and mobile application. The data is automatically collected and stored by us or by third parties on our behalf.

We may collect information about your computer for system administration and to report aggregate information for internal marketing analysis purposes. This is statistical data about our users' browsing actions and patterns.

In particular, this data may include the following:

3.1.2 Cookies

We use cookies on our website. Please read our Cookie Policy to find out more about our use of cookies and the privacy policies of the parties from which we use web analysis tools or of which we have integrated plug-ins on our websites.

3.2 Data provided by you

Besides the data collected by automated means, we also process data which you have provided to us. This includes, but is not limited to:

We may also ask you to complete surveys that we use for research purposes, although you do not have to respond to them. All of these data are characterized by the fact that you have provided this information yourself. We use this information for the purposes described in this Privacy Policy. You can always have your personal data corrected or object to further processing (please see subsection 6).

4. How is the collected data used?

We may use information held about you in the following ways:

With your explicit consent, we may contact you via the contact details provided by you (e.g. per regular mail, email, SMS, telephone or any other electronic means) for marketing, advertising and opinion research purposes. For example, this includes information related to DDB Group Hong Kong products, e-commerce activities, special offers, and promotions. In order to be able to contact you with information which is of special interest for you, your overall interaction with DDB Group Hong Kong (such as, but not limited to, your shopping behaviour in our mobile application, your use of loyalty programmes, your ratings and reviews of products, your contact history with our customer service, your newsletter clicks/ opening results, your surfing behaviour (web tracking), the newsletter types you are subscribed to, your participation in promotions or events, your interactions with and use of mobile applications), will be combined analysed and used. We may use your personal data for marketing, advertising and opinion research purposes. In section 6 you will find information on your rights, e.g. on how to withdraw your consent or correct your personal details The period of use of the personal data supplied by you will not be longer than we deem necessary but may be unlimited.

5. Disclosure of information

One of our core principles is the fact that we will treat your data with care and confidentiality. We will not disclose your data to any third parties aside from what is stated in this Privacy Policy without your prior consent. If required by law, your data may be disclosed to third parties. Provided that this is allowed under applicable law, we may transfer your data to other parts of DDB Group Hong Kong

We may use service providers and data processors working on behalf of DDB Group Hong Kong. The services may include hosting and maintenance services, analysis services, e-mail messaging services, delivery services, handling of payment transactions, solvency check and address check, etc. These third parties are granted access to such personal data they require in order to be able to carry out the particular service. The service providers and data processors are contractually obliged to treat such information in the strictest confidence. They are contractually not allowed to use the data in any other way than required. The necessary steps are taken to ensure that our service providers, and the processors working on behalf of DDB Group Hong Kong, protect confidentiality of your data.

There may be occasions on which we disclose non-personal data to our partners in an anonymous form. Such non-personal data may include information about the number of visitors to a website or a mobile application during a certain period of time.

We may disclose your information to the extent that we are under a duty to disclose or share your personal data in order to comply with any legal obligation or the directions of the Court or any other body of competent jurisdiction, or in order to enforce or apply our Privacy Policy and other agreements; or to protect the rights, property, or safety of DDB Group Hong Kong, our employees, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of fraud protection and credit risk reduction.

6. Use of Personal Information in Direct Marketing; and your rights

DDB Group Hong Kong intends to use information collected from you through our websites or applications and through the other channels described herein, including your name, email address, postal address and contact number, gender and birth date to send you communications (including electronic newsletter and mobile marketing) on or in relation to our products and services. DDB Group Hong Kong may transfer your personal information to our group companies, affiliates and business partners who provide the same products and services for direct marketing purposes, including companies outside the jurisdiction your personal data was collected in. Your prior consent is required before we may use or disclose your personal information for direct marketing purposes. You may withdraw your consent any time by contacting us as specified in the “Contact Information” section below or by changing your email preferences in the relevant section or feature of our websites or by using any other unsubscribe facilities provided in our electronic marketing communications.

If you provide us with personal data via our website, mobile application or other channels, this is done on an entirely voluntary basis. If you choose not to provide requested information, various customer benefits may not be available. In certain cases, only those people that have submitted the necessary personal data to us are able to order products, use certain services and in other ways avail themselves of the activities and offers available on our website and mobile application. We provide various options, depending on the exact circumstances, in order to help you retain control over your data. These options may include displaying and editing your data online. It may also be possible to unsubscribe from services or delete user accounts or to receive information about the data held.

You have the right to ask us not to process your personal data for marketing purposes. We will inform you (before collecting your data) if we intend to use your data for such purposes, or if we intend to disclose your information to any third party for such purposes. You can choose not to give your consent to such processing by not checking certain boxes on the forms we use to collect your data.

Our site may, from time to time, contain links to and from the websites of our partner networks and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these websites.

6.1 Right to object and unsubscribe

Emails that DDB Group Hong Kong sends to you that for instance contain a newsletter or marketing content include the option to unsubscribe to the receipt of such emails by following the relevant instructions in the respective email. If you do not wish to receive any emails from us, you can simply click on the unsubscribe hyperlink and we will stop sending you emails in future.

If you are not interested in any information about your behaviour at our website being collected and assessed, you can opt-out of the gathering of the web analytics data as described below in subsection 11.

If you wish to withdraw your consent to receiving promotional information and offers in general, including by regular mail, email, per SMS, by telephone or by any other electronic means, you may do so at any time by writing to us an email. In case we have any doubt about your identity, we may ask you to identify yourself (e.g. by sending a copy of your passport ID). Other than regular costs for communication, this is free of charge.

With regard to other types of messages you may receive, such as maintenance announcements or administrational notifications, receipt of such messages can only be terminated by deleting your account, as such messages are a mandatory part of user accounts and the related use of our website and mobile applications. You can have your account deleted by writing an email to support@craftedbymyheart.com

6.2 Right to request information

You are entitled to get access to your personal data. By writing to us (at the address stated below), you may request details of the information which we hold about you and the purposes for which it is being held. We will provide this information within 40 days of your request, subject to any routine processing continuing between that time and the time of response. You may be charged a reasonable fee (as permitted by the applicable data processing law) for this information.

6.3 Right to request correction

You have the right to request correction, supplementing, deleting or blocking of the personal data stored about you. Within four weeks of receipt of the request, we will notify you as to whether and, if so, to what extent, we will comply with your request. If, for any reason we do not comply with your request, we will provide you with the reasons for this.

7. Security of the information and data integrity

We take appropriate technical and organizational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized use, disclosure or access, in particular where the processing involves the transmission of data over a network, and against all other unlawful forms of processing and misuse. DDB Group Hong Kong uses third party data processors in relation to the collection and processing of your personal data. Any third party data processors engaged by DDB Group Hong Kong will only undertake processing of your personal data in accordance with DDB Group Hong Kong’s instructions and will be contractually obliged to adhere to strict security procedures when handling your personal data.

7.1 Keeping information secure

DDB Group Hong Kong may employ third party business partners to collect personal information on DDB Group Hong Kong's behalf. In such cases, these third parties will be subject to confidentiality agreements and be instructed by DDB Group Hong Kong to comply fully with the DDB Group Hong Kong Privacy Policy.

Unfortunately, transmission of information via the Internet and/or mobile application is not completely secure. Although we will do our best to protect your personal data, we cannot guarantee the security of your data transmitted to our site; any transmission is at your own risk. Once we have received your information, we will use strict procedures and security features to try to prevent unauthorized access.

8. Social Networks

Our website and mobile application provide you with Social Plug-ins from various social networks. If you choose to interact with a social network, your activity on our website or via our mobile application will also be made available to social networks such as Facebook and Twitter.

If you have logged in to one of these social network sites during your visit to one of our website or mobile application, the social network site might add this information to your profile. If you are interacting with one of the Social Plug-ins, this information will be transferred to the social network site. In case you do not wish such a data transfer, please log out of your social network site before entering our website or mobile application.

We cannot influence this data collection and data transfer via the Social Plug-ins. Please read the privacy policies of those social networks for detailed information about the collection and transfer of personal data, what rights you have and how you can achieve satisfactory privacy settings.

In addition, to improve your user and brand experience, your data may be passed to a third party (e.g. Facebook) for processing in accordance with data protection and privacy regulations.

9. Usage analytics by Google

The analytic services on our website and mobile application are provided by Google Analytics. This means that visiting our website or mobile application will cause a cookie by Google to be stored on your computer or mobile device, except when your browser settings do not allow for such cookies (see DDB Group Hong Kong Cookie Policy).

This further means that when visiting our website or mobile application, the analytics data described above in chapter 2 – including the “click-stream data”, the data from “web beacons and tracking links” and information stored in Google Analytics’ cookies – will be sent to Google for analysis for and on behalf of DDB Group Hong Kong. Please note that if you have created an online profile at our website or (mobile) application, and if you are logged in to this profile, a unique number identifying this profile is also being sent to Google in order to be able to match the web analytics data to this profile.

Google acts as an agent to DDB Group Hong Kong, which means that DDB Group Hong Kong solely determines the purposes for which the data is being used. In privacy terms, this means that DDB Group Hong Kong is the “controller” and Google the “processor”. You can find out more about the relationships between DDB Group Hong Kong and Google in the Google’s privacy policy.

If you do not wish for information about your behaviour on our website or mobile application to be collected and assessed by Google, you can apply for a visitor opt-out. This means that Google, depending on the type of opt-out you choose, will either anonymize the information it collects (but keep collecting the data) or completely stop collecting information about your visit. This visitor opt-out requires for you to accept a cookie being stored on your computer by Google. You can apply for the visitor opt-out via the link in the privacy policy section of the Google website.

11. Contact Information

Should you have any questions about the processing of your personal details or about our privacy policy, please feel free to contact us. The contact details are: DDB Group Hong Kong support@craftedbymyheart.com Alternatively you can contact DDB Group Hong Kong at 12/F, Core E, Cyberport 3, 100 Cyberport Road, Hong Kong

13. Changes to this policy

DDB Group Hong Kong has pledged to adhere to the fundamental principles of privacy and data protection. We therefore regularly review our privacy policy in order to keep it up to date and compliant with privacy and data protection principles. This privacy policy may be changed from time to time in order to keep pace with new developments and opportunities relating to the Internet and to stay in line with prevailing legislation. Significant changes to the policy will be publicized on our website along with an updated version of the privacy policy.

Any changes we may make to our privacy policy in the future will be posted on this page and, where appropriate, may be notified to you by e-mail.