Privacy Policy
UNITED KINGDOM AND EUROPEAN UNION PRIVACY POLICY
Last Updated: 08/01/2026
Effective Date: 08/01/2026
PERUVIAN CONNECTION® PRIVACY POLICY
Your privacy is important to Peruvian Connection ("we", "us", or "our"). We developed this United Kingdom ("UK") and European Union ("EU") Privacy Policy ("Privacy Policy" or "Policy") to provide our UK and EU customers, potential customers, and website users with information concerning our UK and EU personal data collection and usage practices, as well as our privacy and security practices, when they visit our websites (collectively, "Site" or "Sites") or otherwise communicate with us regarding the Site (collectively, the "Services"). For purposes of this Privacy Policy, "you" and "your" means you as the user of the Services, whether you are a customer, website visitor, or another individual whose information we have collected pursuant to this Privacy Policy. "Personal data" is any information relating to an identified or identifiable natural person.
Please contact us using the contact information at the end of this Privacy Policy if you are an employee or job applicant and are interested in additional information about our employee and job applicant privacy practices. If you reside in the United States, please review our United States Privacy Policy for information about our U.S. data collection, usage, and transfer practices and data protection and privacy practices.
"Personal data" is any information relating to an identified or identifiable natural person. "You" and "your" refer to the person reading this Privacy Policy, which may include Peruvian Connection customers and potential customers, as well as other individuals visiting our Sites.
To jump to a specific section of this Privacy Policy, please click on a link below:
- Personal Data We Collect
- Sources from Which Personal Data is Collected
- Purposes for Collecting Personal Data
- Legal Grounds for Collecting and Processing Personal Data
- Third-Party Recipients of Personal Data
- Cookies & Similar Technologies
- Interest-Based Advertising
- Third-Party Privacy Practices
- Cross-Border Transfers of Personal Data
- Children’s Privacy
- Retention of Personal Data
- Protecting Your Personal Data
- GDPR Rights
- Data Privacy Rights
- Other Rights
- Updating Account Information and Unsubscribing from Emails
- Exercising Privacy Rights
- Data Controller
- Privacy Policy Updates
- How to Contact Us
I. PERSONAL DATA WE COLLECT
How We Collect and Use Your Personal Information:
To provide the Services, we collect and have collected over the past 12 months personal information about you from a variety of sources, as set out below. The information that we collect and use varies depending on how you interact with us.
In addition to the specific uses set out below, we may use information we collect about you to communicate with you, provide or improve or improve the Services, comply with any applicable legal obligations, enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
What Personal Information We Collect
The types of personal information we obtain about you depends on how you interact with our Site and use our Services. When we use the term "personal information", we are referring to information that identifies, relates to, describes or can be associated with you. The following sections describe the categories and specific types of personal information we collect.
Information We Collect Directly from You
Information that you directly submit to us through our Services may include:
- Contact details including your name, address, phone number, and email.
- Order information including your name, billing address, shipping address, payment confirmation, email address, and phone number.
- Account information including your username, password, security questions and other information used for account security purposes.
- Customer support information including the information you choose to include in communications with us, for example, when sending a message through the Services.
Some features of the Services may require you to directly provide us with certain information about yourself. You may elect not to provide this information, but doing so may prevent you from using or accessing these features.
Information We Collect about Your Usage
We may also automatically collect certain information about your interaction with the Services ("Usage Data"). To do this, we may use cookies, pixels and similar technologies ("cookies"). Usage Data may include information about how you access and use our Site and your account, including device information, browser information, information about your network connection, your IP address and other information regarding your interaction with the Services.
Information We Obtain from Third Parties
We use Shopify's ad services such as Shopify Audiences to help personalize the advertising you see on third party websites. To opt out of personalized advertising with third-party services supported by Shopify, visit https://privacy.shopify.com/en.
Finally, we may obtain information about you from third parties, including from vendors and service providers who may collect information on our behalf, such as:
- Companies who support our Site and Services, such as Shopify.
- Our payment processors, who collect payment information (e.g., bank account, credit or debit card information, billing address) to process your payment in order to fulfill your orders and provide you with products or services you have requested, in order to perform our contract with you.
- When you visit our Site, open or click on emails we send you, or interact with our Services or advertisements, we, or third parties we work with, may automatically collect certain information using online tracking technologies such as pixels, web beacons, software developer kits, third-party libraries, and cookies.
Any information we obtain from third parties will be treated in accordance with this Privacy Policy.
II. SOURCES FROM WHICH PERSONAL DATA IS COLLECTED
We may collect the above-described categories of personal data from one or more of the following sources:
- Information You Provide. We collect personal data that you provide to us, such as when you create an account on our Sites, purchase a product from us, leave a review on a product, agree to receive our newsletter, or participate in a survey that we offer.
- In-Store Technologies. We may use cameras in and around our stores for fraud, theft prevention, and security purposes.
- Automated Information Collection. We also collect personal data, such as your browsing history and shopping activity, through our use of automated information collection technologies. We may use such data for various purposes, including marketing and advertising purposes and reporting and analytics purposes. For example, we consider metrics such as how you and others shop on our website, how easy our website is to navigate, and the performance of our marketing efforts. For additional information, see the Cookies & Similar Technologies and Interest-Based Advertising sections of this Policy.
- Your Friends. We may receive information about you from your friends and other third parties that use our Sites, and we may combine or link that information with other information we have concerning you (e.g., fulfillment of a wish list).
- Social Media Platforms and Networks. If you connect or interact with us on social media platforms and networks such as Facebook, Pinterest, or Instagram ("Social Media Platforms"), for example, by liking our page or sharing something we post, the Social Media Platforms may provide us with information about you, such as your name and location information. In addition, the Social Media Platforms will have access to information about you and your use of the Social Media Platforms. The information that we collect relating to your connections or interactions with us on Social Media Platforms is subject to this Privacy Policy. The information collected by the Social Media Platforms remains subject to the Social Media Platforms’ privacy practices.
- Third-Party Service Providers. We may receive personal data about you from our third-party service providers, such as marketing networks and cooperatives, analytics providers, and online chat service providers.
- Other Third Parties. We may collect personal data about you from other sources to enhance the personal data that we already maintain about you and to improve the accuracy of our records. This improves our ability to contact you and increases the relevance of our marketing. We also may collect personal data from third parties or from publicly available sources.
III. PURPOSES FOR COLLECTING PERSONAL DATA
How We Use Your Personal Information
- Providing Products and Services. We use your personal information to provide you with the Services in order to perform our contract with you, including to process your payments, fulfill your orders, to send notifications to you related to your account, purchases, returns, exchanges or other transactions, to create, maintain and otherwise manage your account, to arrange for shipping, facilitate any returns and exchanges and other features and functionalities related to your account. We may also enhance your shopping experience by enabling Shopify to match your account with other Shopify services that you may choose to use. In this case, Shopify will process your information as set forth in its Privacy Policy and Consumer Privacy Policy.
- Marketing and Advertising. We may use your personal information for marketing and promotional purposes, such as to send marketing, advertising and promotional communications by email, text message or postal mail, and to show you advertisements for products or services. This may include using your personal information to better tailor the Services and advertising on our Site and other websites. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in selling our products, according to Art. 6 (1) (f) GDPR.
- Security and Fraud Prevention. We use your personal information to detect, investigate or take action regarding possible fraudulent, illegal or malicious activity. If you choose to use the Services and register an account, you are responsible for keeping your account credentials safe. We highly recommend that you do not share your username, password, or other access details with anyone else. If you believe your account has been compromised, please contact us immediately. If you are an EEA resident, the legal basis for these data processing activities is our legitimate interest in keeping our website secure for you and other customers, according to Art. 6 (1) (f) GDPR.
- Communicating with You and Service Improvement. We use your personal information to provide you with customer support and improve our Services. This is in our legitimate interests in order to be responsive to you, to provide effective services to you, and to maintain our business relationship with you according to Art. 6 (1) (f) GDPR.
IV. LEGAL GROUNDS FOR COLLECTING AND PROCESSING PERSONAL DATA
- Consent. The legal ground for processing your personal data that we collect when you provide us with permission to do so is your consent, which you may withdraw at any time by clicking on any unsubscribe link that we provide or by emailing privacy@peruvianconnection.com without affecting the lawfulness of processing based on consent before its withdrawal.
- Contractual Necessity. We may process your personal data when it is necessary in order to take steps at your request prior to entering into a contract with you (e.g., processing personal data in order to respond to a question about a particular product) or when it is necessary for the performance of a contract to which you are a party (e.g., processing credit card details in order to effect payment).
- Compliance with Legal Obligations. We also may conduct certain personal data processing activities for purposes of meeting our legal obligations in the UK, the EU, and in EU member states (e.g., in order to meet our regulatory retention obligations). Under certain circumstances, we may also be legally obliged to assist with crime and fraud prevention efforts.
- Vital Interests. Under special circumstances (e.g., in connection with natural disasters or emergency situations), we may need to process your personal data in order to protect the vital interests of you or one or more persons.
-
Legitimate Interests. The last legal ground for processing the personal data that we collect for other purposes identified above are Peruvian Connection’s legitimate interests in conducting business activities, including the following:
- Providing products and services to customers;
- Providing quality support to customers, potential customers, and Site users;
- Providing customers and potential customers with marketing materials to promote our services and products;
- Providing more relevant content for users of our Sites;
- Identifying and fixing problems with our Sites;
- Understanding how our customers interact with our products, services, and Sites so we can enhance the customer experience and functionality of our products, services, and Sites;
- Improving the overall user experience on our Sites;
- Administering promotions, competitions, drawings, sweepstakes, and surveys;
- Managing our network and store security;
- Operating our business, including by identifying and implementing improvements to our business operations; creating and maintaining our programs, accounts, and records; and conducting business-related research;
- Protecting the rights, property, or safety of Peruvian Connection, our customers, our employees, and/or others;
- Managing corporate transactions, including providing information pertinent to an actual or potential merger, acquisition, or other reorganization; and
- Maintaining compliance with applicable global laws and regulations.
V. THIRD-PARTY RECIPIENTS OF PERSONAL DATA
How We Disclose Personal Information
In certain circumstances, we may disclose your personal information to third parties for contract fulfillment purposes, legitimate purposes and other reasons subject to this Privacy Policy. Such circumstances may include:
- With vendors or other third parties who perform services on our behalf (e.g., IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
- With business and marketing partners, including Shopify, to provide services and advertise to you. For example, we use Shopify to support personalized advertising with third-party services. Our business and marketing partners will use your information in accordance with their own privacy notices.
- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products or through your use of social media widgets or login integrations, with your consent.
- With our affiliates or otherwise within our corporate group, in our legitimate interests to run a successful business.
- In connection with a business transaction such as a merger or bankruptcy, to comply with any applicable legal obligations (including to respond to subpoenas, search warrants and similar requests), to enforce any applicable terms of service, and to protect or defend the Services, our rights, and the rights of our users or others.
We have in the past 12 months disclosed the following categories of personal information and sensitive personal information about users for the purposes set out above in "How we Collect and Use your Personal Information" and "How we Disclose Personal Information":
Category:
- Identifiers such as basic contact details and certain order and account information
- Personal information categories listed in the California Customer Records statute such as basic contact details and certain order and account information
- Commercial information such as order information, shopping information and customer support information
- Internet or other similar network activity, such as Usage Data
- Geolocation data such as locations determined by an IP address or other technical measures
Categories of Recipients:
- Vendors and third parties who perform services on our behalf (such as Internet service providers, payment processors, fulfillment partners, customer support partners and data analytics providers)
- Business and marketing partners
- Affiliates
We do not use or disclose sensitive personal information without your consent or for the purposes of inferring characteristics about you.
With your consent we share personal information for the purpose of engaging in advertising and marketing activities, as follows.
We have “sold” and “shared” (as those terms are defined in applicable law) personal information over the preceding 12 months for the purpose of engaging in advertising and marketing activities, as follows:
Category of Personal Information:
- Identifiers such as name, e-mail address and phone number
- Commercial information such as records of products or services purchased
- Usage data
Categories of Recipients:
- Business and marketing partners
In connection with the purposes set forth in this Privacy Policy, we may share your personal data with one or more of the following categories of third parties:
- Social Media Platforms. Social Media Platforms (e.g., Facebook, Instagram, YouTube, and Pinterest) may offer functionalities, plugins, widgets, or tools in connection with our Sites (e.g., to share our products with your friends and followers on Social Media Platforms). If you choose to use these functionalities, plugins, widgets, or tools, your personal data may be shared with or collected by such Social Media Platforms and is subject to such Social Media Platforms’ privacy practices and you should review such Social Media Platforms’ privacy notices.
- Your Friends. We share your wish list information with individuals that you designate when you use our Site’s wish list sharing functions. Additionally, if you choose to make your wish list public, individuals may find your wish list using our Site’s "find a friend’s wish list" function.
- Our Site Visitors and Online Trunk Show Participants. When you leave a product review on our Sites, your review is accessible by other members of the public when they visit our Sites. When you choose to participate in an online trunk show hosted by our stylists, your personal information may be shared with and viewed by other online trunk show participants.
-
Third-Party Recipients of Customer Lists. We make our customer list (including names, customer IDs, mailing addresses, email addresses, and phone numbers) available to third-party service providers assisting us with marketing efforts.
From time to time, we also make our customer list (including names, customer IDs, mailing addresses) and purchasing history available to list brokers and retailers whose products we believe may be of interest to you. As one example, we work with Epsilon Abacus ("Epsilon"), a company that manages the Abacus Alliance on behalf of participating retailers active in the clothing, collectibles, food, wine, gardening, gadgets, entertainment, health, beauty, household goods, and home interiors categories. Retailers share customer information with Epsilon, which is then combined with information provided by other retailers, analyzed by Epsilon, and used for marketing purposes. Similarly, we are working with Experian ("Experian Information Solutions, Inc.") in a similar capacity for similar reasons. Retailers can utilize this information to identify individuals who are likely to be interested in their products, and to tailor their communications to such individuals by providing them with offers likely to be of interest to them.
If you place an order with us, you will have the option to have your name, mailing address, and purchasing history shared with companies whose products may be of interest to you, as described above. If you would like to have your information shared with these companies, please tick the opt-in box when you place your order. If you do not want to have your information shared, please leave the opt-in box blank. Additionally, if at any point in time you decide that you do not want your information shared, you can request that we do not share information with these companies by contacting us using the contact methods described in the Exercising Privacy Rights section below. - Third Parties in Connection with a Competition, Sweepstakes, or Drawing. If you choose to enter a competition, sweepstakes, or drawing that we offer on our Sites, your personal data may be disclosed to third parties or to the public in connection with the administration of such competition, sweepstakes, or drawing, including in connection with winner selection, prize fulfillment, and as required by law or permitted by the competition, sweepstakes, or drawing’s terms and conditions.
- Third-Party Service Providers, Partners, Suppliers, and Subcontractors that Perform Services on Our Behalf. We may share personal data with third-party service providers, partners, suppliers, and subcontractors that perform services on our behalf, including but not limited to billing and payment processing, marketing, advertising, data analysis and insight, research, web hosting, technical support, customer service, online text and video chat, shipping and fulfilment, printing, data storage, security, fraud prevention, and legal services.
- Governmental Entities and Third Parties in Connection with Legal Matters. We may disclose personal data to governmental entities, such as regulatory agencies, law enforcement, and judicial authorities, as well as other third parties under any of the following conditions: (a) if we have your valid consent to do so; (b) to comply with a valid subpoena, legal order, court order, warrant, legal process, or other legal obligation, including to meet national security or law enforcement requirements; (c) to enforce or apply any of our terms and conditions, policies, or other agreements; (d) to exchange information with other companies and organizations for the purposes of fraud protection and credit risk reduction; or (e) as necessary to pursue available legal remedies or defend legal claims.
- Third Parties in Connection with a Potential Reorganization. We may share personal data to a prospective seller or buyer in the event of a potential reorganization, merger, sale, joint venture, assignment, transfer or other disposition of all or any portion of Peruvian Connection’s assets or stock, including, without limitation, in connection with any bankruptcy or similar proceeding.
VI. COOKIES & SIMILIAR TECHNOLOGIES
Cookies
Like many websites, we use cookies on our Site. For specific information about the cookies that we use related to powering our store with Shopify, see https://www.shopify.com/legal/cookies. We use cookies to power and improve our Site and our Services (including to remember your actions and preferences), to run analytics and better understand user interaction with the Services (in our legitimate interests to administer, improve and optimize the Services). We may also permit third parties and services providers to use cookies on our Site to better tailor the services, products and advertising on our Site and other websites.
Most browsers automatically accept cookies by default, but you can choose to set your browser to remove or reject cookies through your browser controls. Please keep in mind that removing or blocking cookies can negatively impact your user experience and may cause some of the Services, including certain features and general functionality, to work incorrectly or no longer be available. Additionally, blocking cookies may not completely prevent how we share information with third parties such as our advertising partners.
-
What are cookies?
- Cookies are small computer files sent or accessed from your browser on the hard drive of your computer, mobile device, or tablet that contain information about your computer, such as your user ID, user settings, browsing history, and activities conducted while browsing websites (e.g., pages viewed; navigation around a Site; and products purchased).
- Cookies are used to "remember" when your computer or devices access our Sites.
-
How do we use cookies?
- Cookies are essential for the effective operation of our Sites, and help you shop online with us. Cookies also are used to tailor the products offered and advertised to you, both on our Sites and elsewhere. Web browsing histories collected through cookies may be used for purposes of interest-based advertising, which is discussed in the following section. Peruvian Connection and its third-party service providers can use cookies to monitor your browsing and purchasing behavior.
- The primary purposes for which cookies are used are: (1) For the effective operation of our Sites, especially in connection with Site navigation and online transactions; (2) For purposes of Interest-Based Advertising, which is addressed in the next section of this Policy; (3) To assist Peruvian Connection in detecting and preventing fraud; (4) To monitor the success of our advertising campaigns and marketing-related activities (e.g., promotions); and (5) To enable Peruvian Connection to meet its contractual obligations to third parties when one or more of our products are purchased by someone who has visited our Site from a site operated by such third parties.
-
How can you manage cookies?
- If you do not want Usage Data collected through the use of cookies and similar technologies, there is a procedure in most browsers that allows you to automatically decline many of these technologies, or to be given the choice of declining or accepting them. Be aware though that you may also lose some saved information (e.g., saved login details, saved shopping bag, site preferences), some services and functionalities may not work properly at all (e.g., profile logging-in), and you may have to manually adjust some preferences every time you visit a site/page. Cookies that are required to enable core site functionality cannot be disabled.
- To assist in controlling site-specific cookies, check the privacy and cookie settings in your preferred browser.
- If you are in the United Kingdom, the European Union, or another country that requires your consent before processing your Usage Data, we process your Usage Data based on the consent you provide when you click the box noting that you "agree" to the processing of your personal data obtained through cookies and other data collection tools. You may withdraw your consent by contacting us via email at privacy@peruvianconnection.com.
VII. INTEREST-BASED ADVERTISING
Like many retailers, Peruvian Connection works with third parties ("Advertising Partners"), including Social Media Providers and search engines, such as Google (e.g., Google Ads), who serve or send advertisements on our behalf and assist us in delivering more relevant advertising to you. These Advertising Partners may place or recognize a cookie or similar technology on your computer, device, or directly in our emails/communications, and collect information, such as Usage Data and demographic or shopping information. We may share personal data (such as your email address) with such third parties, who may link this information to cookies and other proprietary IDs, which are used for purposes of predicting your preferences and sending interest-based advertising in order to show you ads that are more likely to be of interest to you. These third parties may use this information to recognize you across different channels and platforms over time to assist us with our operations including for advertising, analytics, attribution, and reporting purposes. These third parties Advertising Partners are responsible for all processing of personal data that they conduct as Controllers, including international transfers of personal data (if any).
We neither have access to, nor does this Privacy Policy govern the use of cookies and similar technologies that may be placed on the device you use to access our Sites by third parties.
VIII. THIRD-PARTY PRIVACY PRACTICES
Our Sites may provide links to other third-party Internet websites as a service to you. We are not responsible for the privacy practices of such other third-party Internet websites. If you link to such a site through our Sites, you should always review any privacy notice that is available for that site.
When we share your personal information with third-party service providers, we will only do so for the limited purposes outlined in this policy and will ensure that they are contractually obligated to protect your data with the same level of care as we do, including appropriate safeguards to prevent unauthorized access, use, or disclosure. We remain liable for any onward transfers of your personal data to third parties and will take reasonable steps to address any concerns you may have regarding such transfers.
IX. CROSS-BORDER TRANSFERS OF PERSONAL DATA
When you use our Sites or we otherwise receive your personal data, your personal data may be stored on servers located outside of the European Union/European Economic Area ("EU/EEA") and UK. Your personal data may be transferred to and processed by Peruvian Connection and its third-party service providers, partners, suppliers, and subcontractors not only in the EU/EEA and UK, but also in the United States. The data protection and privacy laws of the United States may not be as comprehensive as the laws of your country. For example, personal data transferred to the United States may be subject to lawful access requests by U.S. federal and state authorities. For transfers of UK and EU/EEA personal data to service providers in the United States, which has not been deemed to provide an adequate level of data protection for personal data by appropriate regulatory authorities, Peruvian Connection will rely on Standard Contractual Clauses as the lawful transfer mechanism to support such transfers.
Additionally, Peruvian Connection complies with the EU-U.S. Data Privacy Framework (EU-U.S. DPF) and the UK Extension to the EU-U.S. DPF, and the Swiss-U.S. Data Privacy Framework (Swiss-U.S. DPF) as set forth by the U.S. Department of Commerce. Peruvian Connection has certified to the U.S. Department of Commerce that it adheres to the EU-U.S. Data Privacy Framework Principles (EU-U.S. DPF Principles) with regard to the processing of personal data received from the European Union and the United Kingdom in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF. Peruvian Connection has certified to the U.S. Department of Commerce that it adheres to the Swiss-U.S. Data Privacy Framework Principles (Swiss-U.S. DPF Principles) with regard to the processing of personal data received from Switzerland in reliance on the Swiss-U.S. DPF. If there is any conflict between the terms in this privacy policy and the EU-U.S. DPF Principles and/or the Swiss-U.S. DPF Principles, the Principles shall govern. To learn more about the Data Privacy Framework (DPF) Program, and to view our certification, please visit https://www.dataprivacyframework.gov/.
Peruvian Connection is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission (FTC), which has jurisdiction over Peruvian Connection’s compliance with the Data Privacy Framework.
Peruvian Connection is committed to subject to the Data Privacy Framework Principles all personal data received from the European Union or Switzerland pursuant to the Data Privacy Framework Principles. Peruvian Connection will remain responsible for any processing of personal data in a manner inconsistent with the Data Privacy Framework Principles by third-party agents to which Peruvian Connection has transferred personal data unless Peruvian Connection proves it is not in any way responsible for the event giving rise to any damage.
In compliance with the Data Privacy Framework Principles, Peruvian Connection is committed to resolving complaints about our collection or use of your personal data. EU and Swiss individuals with inquiries or complaints regarding our Privacy Policy should first contact Peruvian Connection by one of the following methods:
- Email: privacy@peruvianconnection.com
-
Mail: Peruvian Connection, LLC
Canaan Farm
Box 990
Tonganoxie, KS 66086
USA - Phone: 0800 072 14 14 (UK), 0800 181 6326 (Germany), or +44 (0)1235 515 497 (other European countries)
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Peruvian Connection commits to refer unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF to JAMS Data Privacy Framework Program, an alternative dispute resolution provider based in the United States. If you do not receive timely acknowledgment of your DPF Principles-related complaint from us, or if we have not addressed your DPF Principles-related complaint to your satisfaction, please visit https://www.jamsadr.com/DPF-Dispute-Resolution for more information or to file a complaint. The services of JAMS are provided at no cost to you.
Additionally, under certain conditions you may invoke binding arbitration for Privacy Data Framework complaints that are not resolved by any of the other Privacy Data Framework dispute resolution mechanisms. For additional information, please see DFP Principles Annex I
X. CHILDREN'S PRIVACY
Our Sites are not directed to or intended to be used by children, and we do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
As of the Effective Date of this Privacy Policy, we do not have actual knowledge that we “share” or “sell” (as those terms are defined in applicable law) personal information of individuals under 16 years of age.
XI. RETENTION OF PERSONAL DATA
Security and Retention of Your Information
Please be aware that no security measures are perfect or impenetrable, and we cannot guarantee “perfect security.” In addition, any information you send to us may not be secure while in transit. We recommend that you do not use insecure channels to communicate sensitive or confidential information to us.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide the Services, comply with legal obligations, resolve disputes or enforce other applicable contracts and policies.
XII. PROTECTING YOUR PERSONAL DATA
We implement technical and organizational measures designed to assist in maintaining the security and confidentiality of personal data; safeguarding against anticipated threats to the confidentiality, integrity, and availability of personal data; and protecting your personal data against accidental or unlawful destruction, loss, alteration, and unauthorized access or disclosure.
However, whenever personal data is processed, there is always a risk that such information could be lost, misused, modified, hacked, breached, and/or otherwise accessed by an unauthorized third party. No system or online transmission of data is completely secure. In addition to the technical and organizational measures that we have in place to protect your personal data, you should use appropriate security measures to protect your personal data. If you believe that any personal data you provided to us is no longer secure, please notify us immediately by phone at 0800 072 14 14 (UK), 0800 181 6326 (Germany), or +44 (0)1235 515 497 (other European countries); or by email at privacy@peruvianconnection.com.
XIII. GDPR RIGHTS
If you reside in the European Union or the United Kingdom, you have the following rights under the General Data Protection Regulation ("GDPR") or the UK GDPR (as applicable) regarding the processing of your personal data:
- Right to Request Access. You have the right to receive a copy of the personal data that we hold about you.
- Right to Rectification. You have the right to correct or complete any inaccurate or incomplete personal data that we hold about you.
- Right to Deletion. In certain circumstances, you have the right to request that we erase the personal data that we hold about you.
- Right of Data Portability. In certain circumstances, you have the right to request that we supply you with the personal data that we hold about you in a structured, commonly used and machine-readable format and/or, where technically feasible, to transmit such personal data to another organization.
- Right to Restrict Processing. In certain circumstances, you have the right to restrict our processing of the personal data that we hold about you.
- Right to Bring a Complaint to Supervisory Authority. You have the right to lodge a complaint with the relevant supervisory data protection authority.
- Right to Withdraw Consent. If our lawful basis for processing your personal data is your consent, you have the right to withdraw your consent at any time.
-
Right to Object. You have the right to object to the processing of your personal data for certain purposes, including:
- Processing for Direct Marketing Purposes. The right to object to the processing of your personal data for direct marketing purposes, including profiling related to direct marketing; and
- Processing for Legitimate Interests. The right to object to the processing of your personal data that is based on our or a third party’s legitimate interests, including profiling related to such legitimate interests.
Please see the Exercising Privacy Rights section of this Privacy Policy to learn how to exercise your rights related to personal data that is in our possession and/or under our control. For more information about your rights under the GDPR or the UK GDPR, including information about the circumstances under which different rights are applicable, please visit the Your Data Protection Rights Page from the UK Information Commissioner’s Office site or the European Commission’s My Rights Page, which can be viewed in a number of languages.
XIV. DATA PRIVACY FRAMEWORK RIGHTS
If you reside in the European Union or Switzerland, and if Peruvian Connection processes your personal data in the United States, you also have the following rights under the Data Privacy Framework:
- Right to Access, Correct, Amend, or Delete. You have the right to access and to correct, amend, or delete your personal data where it is inaccurate or where it has been processed in violation of the Data Privacy Framework Principles, except where the burden or expense of providing access would be disproportionate to the risks to your privacy or where the rights of other individuals would be violated.
- Right to Choose. You have the right to receive notice of the choices and means that Peruvian Connection offers you for limiting the use and disclosure of your personal data. Peruvian Connection provides you with the opportunity to choose how your personal data may be used under certain circumstances. If your personal data is to be used for a new purpose that is materially different from that for which your personal data was originally collected or subsequently authorized, or if your personal data is to be disclosed to a third-party controller, Peruvian Connection will provide you with an opportunity to choose whether to have your personal data so used or disclosed. When sharing your personal data with third-party processors that Peruvian Connection has retained to perform services on its behalf and pursuant to its instructions, Peruvian Connection may disclose your personal data without offering an opportunity to opt out.
-
Rights Related to Sensitive Data
- "Sensitive Data" under the EU-U.S. Data Privacy Framework is defined as personal data specifying medical or health conditions, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, or information specifying the sex life of an individual.
- "Sensitive Data" under the Swiss-U.S. Data Privacy Framework is defined as personal data specifying medical or health conditions, personal sexuality, racial or ethnic origin, political opinions, religious, ideological or trade union-related views or activities, or information on social security measures or administrative or criminal proceedings and sanctions, which are treated outside pending proceedings.
- If Peruvian Connection ever collected your Sensitive Data, Peruvian Connection would provide you with specific rights related to any Sensitive Data that Peruvian Connection may process. Additionally, if any such Sensitive Data were to be used for a new purpose that is different from that for which it was originally collected or subsequently authorized, or is to be disclosed to a third party, Peruvian Connection would obtain your affirmative express consent prior to such use or such disclosure.
In compliance with the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF, Peruvian Connection commits to cooperate and comply respectively with the advice of the panel established by the EU data protection authorities (DPAs) and the UK Information Commissioner’s Office (ICO) and the Swiss Federal Data Protection and Information Commissioner (FDPIC) with regard to unresolved complaints concerning our handling of personal data received in reliance on the EU-U.S. DPF and the UK Extension to the EU-U.S. DPF and the Swiss-U.S. DPF.
XV. OTHER RIGHTS
If you reside in the United States, you may have privacy rights that are addressed in our United States Privacy Policy. If you reside in other parts of the world, you may have other privacy rights. Please reach out to us using the contact information below if you would like to request to exercise any privacy rights to which you are entitled.
XVI. UPDATING ACCOUNT INFORMATION AND UNSUBSCRIBING FROM EMAILS
In this section, we provide an explanation of our processes for permitting individuals to update their account information and opt out of marketing emails.
- Updating Account Information. You may request to withdraw consent to have your name, mailing address, and purchasing history shared with companies whose products may be of interest to you, and change your account information at any time by logging into the My Account section of our Site. Deleting your online account does not delete any stored personal data. However, in certain circumstances, you may request that we delete your personal data by using the submission methods described in the Exercising Privacy Rights section of the Privacy Policy, below.
- Unsubscribing from Emails. You may opt-out of Peruvian Connection’s use of your personal data for purposes of marketing emails. Every marketing email you receive from Peruvian Connection will have an unsubscribe link at the bottom that enables you to opt-out of receiving future Peruvian Connection marketing email messages. Our customer service team can also assist with any requests to opt-out if you contact them using the contact information below.
XVII. EXERCISING PRIVACY RIGHTS
In this section, we provide an explanation of our processes for permitting individuals to exercise any privacy rights to which they are entitled by law. To exercise your rights described in this Privacy Policy, please submit a verifiable consumer request to us through one of the following methods:
-
Submission Methods. You may submit requests to exercise your privacy right(s) by:
- Calling us at 0800 072 14 14 (UK), 0800 181 6326 (Germany), or +44 (0)1235 515 497 (other European countries)
- Emailing us at privacy@peruvianconnection.com.
-
Submission Contents. Requests to exercise your privacy right(s) should include the following information:
- Your name;
- The country in which you currently reside;
- Which privacy right(s) you are exercising;
- Details that will assist us in responding to your request, including:
- If you are exercising access rights, the information to which you are requesting access;
- If you are exercising deletion rights, the information for which you are requesting deletion;
- Any other relevant information about your personal data and/or the right you are exercising; and
- A phone number and/or email address at which we can reach you.
XVIII. DATA CONTROLLER
Personal data used by Peruvian Connection for its business purposes, as well as personal data collected by and on behalf of Peruvian Connection, is controlled by:
Peruvian Connection, LLC
Canaan Farm
Box 990
Tonganoxie, KS 66086
USA
XIX. PRIVACY POLICY UPDATES
We may update this Privacy Policy from time to time as we add new services or offerings; as we improve our current services and offerings; and as technologies and laws change. It is our policy to post any changes we make to our Privacy Policy on our Sites. Any changes will become effective thirty (30) days after our posting of the revised Privacy Policy on the Sites. The date this Privacy Policy was updated and the date it became effective are identified at the top of the first page. If we make material changes to how we treat personal data that falls within the scope of this Privacy Policy, we will notify you through a prominent notice on the homepage of our Site.
XX. HOW TO CONTACT US
If you have any questions about this Privacy Policy or our privacy practices, any complaints, or need assistance relating to your personal data, you may contact us via email at privacy@peruvianconnection.com; by calling us at 0800 072 14 14 (UK), 0800 181 6326 (Germany), or +44 (0)1235 515 497 (other European countries); or by writing us at the following address: Peruvian Connection, LLC, Attention Privacy Officer, Canaan Farm, Box 990, Tonganoxie, KS 66086, USA.