Data Protection Information

HUGO BOSS Investor Relations Newsletter

HUGO BOSS AG, Dieselstraße 12, 72555 Metzingen, Germany (hereinafter “HUGO BOSS” or “we”) offer visitors to the HUGO BOSS group website (https://group.hugoboss.com) (hereinafter “Website”) the possibility to subscribe to the HUGO BOSS Investor Relations Newsletter (hereinafter “Newsletter”).

In the following we are providing you with the information required in accordance with Articles 13 and 14 of the General Data Protection Regulation (“GDPR”) regarding the processing of personal data in connection with your Newsletter subscription.

You can find additional information about the processing of personal data in the Data Privacy Policy of the HUGO BOSS Website.

A.        Name and contact details of the controller

The controller for the Newsletter is:

HUGO BOSS AG

Dieselstraße 12, 72555 Metzingen, Germany

Telephone: +49 7123 94-80903

E-mail: info@hugoboss.com 

B.        Contact details of our data protection officer

The contact details of our data protection officer are as follows:

HUGO BOSS AG

Data Protection Officer

Dieselstraße 12, 72555 Metzingen, Germany

Telephone: +49 7123 94 – 80999

Fax: +49 7123 94 880999

E-mail: datenschutz@hugoboss.com 

C.        Categories and sources of personal data   

We process the following (categories of) personal data:

Categories of personal data that are processedTypes of personal data within the category

Source of the personal data

(and, if applicable, whether the source is publicly accessible)

Data that we collect when you register for the Newsletter (“Registration Data”)

E-mail address (mandatory), title, first name, surname (voluntary).

When registering on the website, we also record the language-specific version of Website via which you subscribe to the Newsletter. 

Newsletter subscribers

Protocol data that are generated technically when subscribing or unsubscribing to the Newsletter (“Subscription and Unsubscription Data”)

Date and time of subscription confirmation in double opt-in process, as well as the IP address of the terminal device used for confirmation, data and time of any unsubscription from the Newsletter.

Newsletter subscribers

Protocol data that are generated technically via the Hypertext Transfer Protocol (HTTP) using the web beacons** contained in the Newsletter when our Newsletter is accessed (“Newsletter HTTP Data”

IP address, date and time of access

Newsletter subscribers

Data that are stored in cookies* in the Newsletter subscriber’s browser when our Newsletter is accessed („Newsletter Cookie Data“).

Unique ID to (re)identify Newsletter subscribers 

Newsletter subscribers

Data in usage profiles that we create by analysing usage behaviour in the Newsletter using pseudonyms (“Newsletter Usage Profile Data”).

Data on usage of the Newsletter, in particular visits, visit frequency and click behaviour in accessed Newsletters

Generated autonomously 

Protocol data that are generated technically via the Hypertext Transfer Protocol (HTTP) when the HUGO BOSS Website is visited (“Website HTTP Data”). 

IP address, type and version of your Internet browser, operating system used, page visited, page visited beforehand (referral URL), date and time of visit. 

Newsletter subscribers

Data in usage profiles that we create by analysing the usage behaviour of Newsletter subscribers on the website by using pseudonyms (“Website Usage Profile Data”).

Data about the use of the Website, in particular visits, visits frequency and visit duration on the pages visited. 

Generated autonomously 

Cookies are small text files with information stored on the user’s terminal device via its browser when a website is visited. When the website is visited again using the same terminal device, the cookie and the information stored in it can be accessed. Depending on storage duration a differentiation is made between transient and persistent cookies. Transient cookies, already called session cookies, are deleted automatically when you close your browser. Persistent cookies are stored on your terminal device for a defined period even after you close your browser.

** Web beacons (also called tracking pixels) are small images that enable a log file to be recorded and analysed when e-mails or websites are accessed.

D.        Purpose and legal basis of processing personal data

We process the (categories of) personal data specified in C. above for the following purposes and on the legal bases.

If processing is based on Article 6 (1) (f) GDPR, we also specify the legitimate interests pursued by us or any third party.

Purpose of processing (and, if applicable, the legitimate interests pursued with the processing)

(Categories of) personal data (see point C. above for details on the individual categories)

Legal basis for processing in accordance with GDPR (as of 25.05.2018)

(Categories of) recipients (see E. below for details)

Web applications made available on the Website in which you can provide data to us regarding your subscription or unsubscription of our Newsletter.

Website HTTP Data, Registration Data, Subscription and Unsubscription Data

Point (f) of Article 6(1) GDPR

Hosting service providers

Newsletter service providers

“Double opt-in” procedure to confirm subscription.

For this purpose we send you an e-mail message requesting you to confirm the e-mail address specified when subscribing to the Newsletter A subscription does not take effect until the e-mail address has been confirmed by clicking on the confirmation link in the e-mail.

Registration Data, Subscription and Unsubscription Data

Point (f) of Article 6(1) GDPR 

Newsletter service providers

Sending the Newsletter to Newsletter subscribers.

We use the title and name you specified when subscribing to the Newsletter to personalise your Newsletter.

To determine the language and the content of the Newsletter we use the language-specific version of the Website used when registering for the Newsletter on the Website. When registration takes place in an Outlet, we use the language of the Outlet in which the registration took place for this.

Registration Data, Newsletter HTTP Data, Newsletter Cookie Data, Segment Data

Point (a) of Article 6(1) GDPR

Newsletter service providers

Creation of anonymised reports analysing and determining Newsletter strategy.

Registration Data, Segment Data

Point (f) of Article 6(1) GDPR

E.        Recipients who receive personal data

For the purposes set forth in D. we use a contract data processor that supports us in the handling of our business processes. The following service providers and/or categories of service providers to whom we disclose personal data belong to these:

·                Hosting service providers

·                Newsletter service providers 

F.        Duration for which personal data are stored

The duration for which the personal data are stored is set forth below and determined based on the following criteria:

(Categories of) personal data (see C. above for details on individual categories) 

Duration for which personal data are stored / criteria for determining this duration

Registration Data, Subscription and Unsubscription Data

We store this data for as long as you subscribe to our Newsletter. In addition, we store this data as an exception beyond this if and as long as we are subject to statutory retention or documentation obligations for such data or to the extent this is necessary for evidence purposes.

Newsletter HTTP Data, Newsletter Cookie Data, Newsletter Usage Profile Data, Website HTTP Data, Website Usage Profile Data

We only store this data as long as you subscribe to our Newsletter. We delete such data as soon as you have unsubscribed our Newsletter.

G.        Necessity or obligation to provide personal data and possible consequences of not providing such data

The provision of the following personal data is required/mandatory by law/contract or in order to conclude a contract:

(Categories of) personal data (see C. above for details on individual categories)

Necessity/Obligation

Possible consequences of not providing such data

Registration Data

You must provide your e-mail address when registering in order to receive the Newsletter.

Not providing your e-mail address means that we cannot send you the Newsletter.

H.           Rights of the data subject

I. Access, correct, deletion, restriction, data portability  

You have the following rights with respect to the processing of your personal data:

·               To request us to grant you access to your personal data in accordance with Article 15 DSGVO.

·               To request us to correct your personal data in accordance with Article 16 GDPR.

·               To request us to delete your personal information in accordance with Article 17 GDPR.

·               To request us to restrict the processing of your personal information in accordance with Article 18 GDPR.

·               The right to data portability in accordance with Article 20 GDPR.

II. Right to object

You have the right to object, on grounds relating to your particular situation, at any time to processing of personal data concerning you which is based on point (e) or (f) of Article 6(1) GDPR (see D. above).

If personal data are processed for the purposes of direct marketing (see D. above), you have the right to object at any time to the processing of personal data concerning you for the purposes of such marketing.

III. Right to withdraw consent

If processing is based on point (a) of Article 6(1) or point (a) of Article 9(2) GDPR (see D. above), you have the right to withdraw your consent at any time without the legality of processing based on your consent which has taken place up to withdrawal being affected.

IV. Right to lodge a complaint with the supervisory authority

You have the right to lodge a complaint with a supervisory authority in accordance with point (f) of Article 57(1) GDPR.

Last modified: 19 April 2018

Connect With Us
Contact

HUGO BOSS AG
Dieselstrasse 12
72555 Metzingen

Phone: +49 7123 94-0
Fax: +49 7123 94-80259

Follow us on: