Privacy Notice

 

1.     Introduction

This Privacy Notice describes the way we treat all the personal data you provide or that we have obtained through our Dufry Websites and Applications and in our Stores.

  Summary of provisions:

                                                                                                      

2. Controller of Personal Data, Sources of Personal Data and What Personal Information about Customers do Dufry Websites and Applications collect?

  • Controller and Processors of Personal Data

Dufry International AG and the local Dufry entity which owns the local Store that you are visiting or from whom you are purchasing goods are joint controllers of the personal data that you (as data subject) provide us or we received in our Stores and Dufry Websites and Applications.

  • Types of Personal Data collected and Sources of Personal Data

We collect personal data directly from our customers through Dufry Websites and Applications and our Stores.

We collect the following types of personal data about you from the following sources:

Information that you provide to us: We receive and store any information you enter on Dufry Websites and Applications and Stores or give us in any other way such as during registration, accessing your account or profile, submitting queries or as part of a survey or competition or utilising gift coupons or customer support or communicate with us or purchasing in Stores or using our products or services.

Due to such actions, you may supply us with your (i) name, postal address, email address, phone numbers, (ii) data necessary to process your payment (including the credit card/payment instrument  information and personal security code associated with your credit card) for Store purchases or  on line purchase of gift vouchers, to reserve purchases (under the Dufry Reserve & Collect Websites), to apply for a refund,  or to communicate with customer services regarding a refund to the credit card/payment instrument, (iii) flight departure/destination, flight date and delivery address for the subscriber and airport location to collect any pre ordered reserve & collect products or make purchases of our products and services in Stores.  Demographical data such as your age, gender, country, nationality, preferred language, passport number and citizenship, date of birth, country of residence, country of registration to Dufry Websites and Applications, photos with your image (including selfies of your skin or other parts of your body), information about your health including your skin condition, purchases history and  other travel information including travel date, preferred departure airport and airline loyalty membership details are also collected. You must hold a valid flight ticket to be able to make duty free or duty paid purchases from Dufry. Such information is collected to meet our contractual obligations with airport authorities and legal obligations towards customs and other regulatory authorities.

When you register for membership, subscribe for services or the newsletter or other marketing communications including blogs or customer comments or use the Dufry Websites and Applications or purchase in our Stores, we collect log in details, passwords, any password questions and hints, similar security information used for authentication and account access is also collected for the access into your personal account and profile and to utilise the Reserve and Collect elements  or the RED customer loyalty elements of  Dufry Websites and Applications or  in our Stores.

You can choose not to provide certain information, but then you might not be able to utilise many of the features of the Dufry Websites and Applications. See What Are Your Choices section below.

Information collected automatically through interaction with usOnly if you agree, we receive and store information  where you interact with us through using our products and services, including online technologies (ie. Cookies) and receiving error reports or usage data from software applications on your devices online or via Wi-Fi communications in Stores.

We collect and analyse device, connectivity and configuration data including the Internet protocol (IP) address used to connect your computer or device to the internet as described in the Online Technology and Cookies section below.

We may operate CCTV in our Stores and collect video footage and images of you and others when you visit our Stores (including your/their location and physical appearance). For more information please contact the Store staff.

Mobile or Dufry Applications: When you choose to use or download Dufry Websites and Applications or allow connectivity via WiFi connections to your device, we receive information about your location and mobile device, including a unique identifier for your personalised device, information obtained from browser cookies, your GPS data or wireless networks data (WLAN). Location data is neither stored nor transmitted to third parties.  If you agree with the localisation function, we can provide you with location-based services including advertising, search results and personalised content. When you are near one of our Stores or you have added a retail coupon in your Wallet, then we can use push email communications to you if you have provided your consent to receive such communications and advertising. We may derive information from the personal data you provide to us when using Dufry Websites or Applications e.g. a health diagnosis and tailored product recommendations based on that diagnosis, or statistical or aggregated data that does not identify you which we use for analytics and insight purposes.

If we make product recommendations to you (including based on a diagnosis of your health data), you are not obliged to purchase the recommended products. The products recommended to you will be products available for purchase without a prescription and you should always check with a healthcare professional if you have any doubts regarding the effect of using any skincare or other product.

Most mobile devices allow you to turn off location services and/or push notifications. For more information, see What are Your Choices section below.

E-Mail Communications: To provide more personalised and interesting email communications, we receive a confirmation when you open email from Dufry Websites and Applications or your device is near one of our Stores, if your computer or device supports this capability and if you have agreed with the localisation function though your device. If you choose not to receive any emails or other mail from us, please adjust your customer communication preferences in your account profile.

Information from other Sources: We receive information about you from other sources and add it to our account information. The third party sources include:

  • Updated delivery and contact address data from third parties which are used to update our records and deliver your next purchase more easily;
  • Social networks when you grant permission to Dufry Websites and Applications to access your data on one or more networks;
  • Service providers that help us determine a location based on your IP address to allow customisation of certain products to your location;
  • Our partners which we offer co-branded services or conduct joint marketing activities;
  • Publicly-available sources from open government databases or other data in the public domain;
  • Information (including CCTV footage and images, as the case shall be) from third parties including the police, tribunals, courts, regulators, airports or other authorities in connection with security incidents or actual or suspected unlawful acts, which may include information relating to actual, alleged or suspected criminal offences.
  • Your employment status with your current employer, which is used to either activate or deactivate your employee discount.

 

3. Lawful basis and purposes for processing and using your personal data

Lawful purposes

Your personal data is processed by the Group on the basis of a lawful “justification” for such processing, to the extent required by law. In the majority of cases, the processing of your personal data will be justified on one of the following bases:

  • It is provided for in your contract of providing products and services requested by you to be provided by us;
  • It is necessary for us to comply with a legal obligation;
  • It is with your freely provided unequivocal and informed consent for specified processing purposes and, in relation to data relating to your health, with your explicit consent;
  • It is necessary to protect your or someone else’s life; or
  • It is in our legitimate interests as a business and as your supplier of contractually requested goods, and our interests are not overridden by your interests, fundamental rights or freedoms including legitimate interests as set out below.

The processing of personal data relating to actual, alleged or suspected criminal offences and convictions will be justified by one of the above bases and normally one of the following special conditions:

  • It is necessary for the purposes of preventing or detecting crime or other unlawful acts;
  • It is necessary to protect the public against dishonesty; or
  • We have obtained consent from the relevant individuals involved for the processing.

Purposes of processing personal data

We obtain, use, disclose and otherwise process personal data about customers, based on the execution of a contract to:

  • process transactions they request, including e-commerce Reserve and Collect selection and mobile transactions;
  • process information from the RED loyalty programme to verify the identity of the cardholder is the owner of the RED loyalty card and to ensure that the collection or redemption of RED points and confirm the status of a customer to allow for the correct discount to be applied to the sales of goods purchased in Stores or goods reserved for collection under the Reserve & Collect application and purchased in person in Stores;

 This information will enable us to provide access to all areas of the loyalty programme including the employee discount, the Reserve and Collect and Red by Dufry applications contained in Dufry Websites and Applications.

  • review and collect data from the boarding pass, nationality, destination and holder of the valid boarding pass to ensure that the passenger is part of the travelling public to allow Dufry or the Group to provide duty free goods under the terms of the contractual agreement with our landlords or airport authorities;
  • provide payment services including credit cards for online purchases and in Stores purchases;
  • provide goods and services to the customers that they have requested (ie provided an email address to allow the regularly newsletter to be provided to the customer);
  • protect the log in details of the subscribers and system integrity of the Dufry Websites and Applications;
  • communicate with you and personalize our communications with you. i.e. respond to your queries or accommodate your preferences and registration for program membership. We communicate with you by email or phone or SMS to inform you about our services, how to keep your subscription or account active, to communicate regarding a refund or customer inquiry or assisting with web site or Dufry Websites and Applications access or technical queries;
  • to carry out your contractual transactions with us and to provide our products (including the reserving of and pre-selection of duty free products listed in the Reserve and Collect website for collection at the requested Store) to you as requested by you. This includes using your personal information to register or subscribe to any services provided thorough Dufry Websites and Applications; fulfil our legal obligations;  

We also collect personal data to comply with legal obligations, especially the following:

  • passenger name, boarding card to ensure that the consumer reserving the products is a valid traveller to meet our contractual obligations to our landlord and long term concession agreement as well to allow the calculation of the VAT or similar tax allowances to be calculated for the customs authorities; comply with legal obligations, policies and procedures and for internal administrative and analytics purposes; process information or claims in connection with incidents at Stores;
  • protect the rights or property or safety of Dufry Websites and Applications or Stores, including our customers and visitors; and
  • assist third parties including the police, tribunals, courts, regulators, airports or other authorities with their investigations or requests or to report security incidents or suspected or actual unlawful acts. This assistance is provided for the purposes of preventing or detecting unlawful acts, the apprehension or prosecution of offenders, protecting the safety of our customers or visitors or in connection with other lawful requests to disclose personal data that we received from or make to third parties (for example missing persons investigations).

Where we process your personal data on the basis of our legitimate interests, those will be our interests in:

  • providing and improving the products we offer and perform essential business operations. This includes operating the products, maintaining and improving the performance of the products, developing new features, conducting research and providing customer support;
  • protecting the security and safety of our products and our customers, to detect and prevent unlawful acts including fraud and to confirm the validity of the subscriber logging into Dufry Websites and Applications;
  • implementing cookies (and similar technologies) and processing your personal data obtained from those cookies where they are essential to the operation of Dufry Websites or Applications;
  • using personal data for statistical and analytical purposes. Whenever reasonably possible we will anonymize such information before using it for statistical or analytical purposes. Such information is processed in the legitimate interests of Dufry International AG to maintain the efficiency, relevancy and availability of the Dufry Websites and Applications;
  • effective management and operation of Dufry and the Group companies;
  • to maintain our business relationship, where you are a user or subscriber of our Dufry Websites and Applications;
  • carry out a health and other diagnoses and recommend products to you based on your personal data. Such diagnosis and recommendations may be produced using advanced technologies including artificial intelligence, and may use algorithms and statistical methods to analyse your personal data in combination with each other to produce results, in some cases, without human involvement;
  • improve Dufry Websites and Applications, Stores, quality of service and customers shopping experience;
  • advertising : Sending you communications regarding our products, services, campaigns, special offers promotions, contests and customer surveys, newsletters related to Dufry Websites and Applications and Stores and  to provide invitations to attend events;
  • to commence, protect or defend Dufry in actual or threatened legal proceedings.

 

Finally, if you have provided your consent via the Dufry Websites or Applications , we will process your personal data on the basis of consent to:

  • provide you with targeted advertising based on your purchase history (including items purchased, abandoned baskets, day and store of purchase), and profile (date of birth, gender, country of residence, country of registration, nationality, RED status);
  • provide you with targeted advertising based on the travel information you provide us (and including travel date, preferred departure airport, airline loyalty membership details), by answering the customers surveys you may receive from us from time to time;
  • send or make promotional offers on behalf of other companies that offer travel related servicesbut if we do this, then we do not give that business your personal data; and
  • carry out a health diagnosis and recommend products to you based on personal data relating to your health (e.g. details of your skin condition in connection with our Skincare Advisor Application). Such diagnosis and recommendations may be produced using advanced technologies including artificial intelligence, and may use algorithms and statistical methods to analyse your personal data in combination with each other to produce results, in some cases, without human involvement.

 

You can withdraw at any time all or any of the consents you provide that are listed above.

If you do not provide your personal data to us, you may not be unable to access some or all of the Dufry  Websites or Applications or their features, or may be unable to communicate or correspond with us.

 

4. Sharing your Personal Data

We will not transfer or disclose your personal information, other than as set out below:

  • Effective management and operation of Dufry and the Group companies, and only when certain services are centralized;
  • to third party service providers (companies or individuals) that we employ to perform functions on our behalf such as fulfilling orders, delivering to retail locations or Stores, sending postal mail and email, removing repetitive information from customer lists, analysing data, providing marketing assistance, providing search results and links, processing credit card payments and providing customer service. These providers have access to personal information needed to perform their functions, but may not use it for other purposes and include the following categories of data recipients:

    (i)  advertising and media consultants,

    (ii) market research consultants;

    (iii) providers of technical services;

    (iv) website designers and developers;

    (v) cloud computing service providers, including providers of Applications that use artificial intelligence to provide answers or results based on personal data you provide (e.g. the Skincare Advisor Application provided by our supplier, Revieve Oy);

    (vi) electronic storage providers;

    (vii) customer services; and

    (viii) with your current employer, as part of our ongoing checks to verify that you still remain eligible for the employee discount.

  • in releasing account and other personal data to comply with the law, undertaking litigation or other proceedings or to enforce or comply with or apply our terms of use and other agreements, or protect the rights, property or safety of Dufry Websites and Applications or Stores. This includes exchanging information with other companies for fraud prevention and credit risk reduction;
  • to comply with legal or regulatory requirements or obligations in accordance with applicable law, a court order or a subpoena;
  • with regulatory authorities, airport authorities, Dufry International AG and Group landlords and concession partners and customs and tax authorities to show the calculation of such tax exemptions;
  • to data analytical firms, Google Analytics Inc.;
  • in an emergency, such as to safeguard the life, health, or property of an individual; or
  • to third parties including the police, tribunals, courts, regulators, airports or other authorities to assist them with their investigations or requests or for us to report security incidents or suspected or actual unlawful acts. This includes allowing such third parties to access and take copies of CCTV images or other video footage where CCTV cameras are in place and  these relate to such incidents and acts;

 

5. Storing your Personal Data

Your personal information you have provided to the controller will be located in a Dufry  AG cloud based customer management database software tool located within data centres maintained in the territories of the EEA, the purpose of which is to manage the business relationship with you, in accordance with the provisions of the data protection laws.

Dufry International AG will manage the customer relationship with you and any marketing materials can be provided, by Dufry as Controller.

 

6. Security of personal data

Your personal data will be secured by taking security measures that are commensurate with the sensitivity of the personal data processed. To this end, Dufry and all Group entities maintain appropriate physical, technical, and administrative security measures with a view to protecting personal data against theft; accidental loss; unauthorised alteration; unauthorised or accidental access, processing, erasure, use, disclosure or copying; and/or accidental or unlawful destruction.

When we have provided (or you have chosen) a password allowing access to certain benefits of the Dufry Websites and Applications, you are responsible for safeguarding it and keeping it confidential and you undertake not  to allow it to be used by third parties. Unfortunately, the transmission of information thorough the internet is not completely secure. Although we will take all reasonable commercial measures to protect your personal data, we cannot guarantee the security of any personal information or data you disclose on line. You accept the inherent security implications of using the internet and to the extent permitted by law, we will not be responsible for any breach of security, unless we have been acting with gross negligence and only within the limitations as set out in the terms and conditions of use for Dufry Websites and Applications.  

 

7. Transfers of Data Outside of Your Country

Your personal data (as described above) may be transferred to other Group entities or to third parties described  above, only to the extent required for Dufry International AG and group companies to perform their obligations to you, or for you to access your Dufry Websites and Applications, or for the purposes described above in this Notice, provided such purposes are in accordance with applicable laws.  In particular:

  • Your profile and contact information contained in systems such as corporate communications systems, customer relationship management databases or directories will be accessible to all marketing, sales and customer support or customer care employees of Group companies worldwide.
  • Your personal data may be transferred to or accessed by Group employees located inside or outside your country, and/or a person or company that is not part of the Group located in or outside your country, on a need-to-know basis. Transfers outside the UK and EU may be made pursuant to the European Commission's Standard Contractual Clauses ("SCC") or other legally acceptable mechanisms which ensure an adequate level of protection. As permitted by law, you may be entitled, upon request to the Global Data Protection Co-Ordinator, to be informed about the appropriate safeguards that have been taken to protect your Personal Data for transfer outside the UK and EU.
  • Dufry International AG may process your personal data as a controller in order to administer and provide you with products and services that you requested, to administer global sales and customer programs, promotional and marketing activities and surveys, competitions and coupon and gift promotions, communications with customers, advertising campaigns with us, to manage sales and customer relationships and to prepare sales and customer relationship management and customer support reporting, consistent with the terms of this Notice. Dufry International AG is located in Switzerland, a country that benefits from an adequacy decision of the European Commission and the UK that has found Swiss law to afford adequate protection to personal data.
  • Transfers may be made to respond to law enforcement requests or discovery procedures, or where required or permitted by applicable laws, court orders, government regulations, or government authorities (including tax and employment). Such transfers may entail access by courts or governmental authorities outside your country, after having ensured that only your minimal necessary data is disclosed and transferred, or that such data is de-identified or that, where possible, appropriate stipulative court orders have been issued.

 

A list of the countries located outside the EU to which your Personal Data may be transferred, and an indication of whether they have been determined by the European Commission to grant adequate protection to Personal Data, can be found at https://ec.europa.eu/info/strategy/justice-and-fundamental-rights/data-protection/data-transfers-outside-eu_en. For the UK, you can find up to date information on countries that have been granted adequate protection to personal data by visiting the ICO website (www.ico.org.uk).

Transfers of Personal Data in accordance with this Section 7 are based on the same legal bases as applicable for the respective purposes of processing as set out  above.

 

8.      Retention of personal data

Dufry data retention policy requires that personal data be retained for no longer than required to fulfil the purposes for which it was collected. In general, personal data, or records containing personal data, will be retained for periods of time required in accordance with applicable legal, tax, or accounting obligations. In specific circumstances, and in accordance with applicable law, Dufry may retain your personal data for longer periods of time (such as for the duration of the relevant statute of limitation) so that we have an accurate record of our dealings with you or to protect the legitimate interests of Dufry International AG or local Dufry entity name, who owns this Dufry Website or Application.  In all cases, where your information is no longer required, Dufry will ensure it is disposed of in a secure manner.

If you use our Skincare Advisor Application, your selfies and any other data relating to your skin condition is promptly deleted after we carry out a diagnosis and make a product recommendation. Certain personal data is anonymised for analytical and insight purposes by aggregating the data so that it can no longer be linked to you.

 

9. Minors

Dufry Websites and Applications do not provide products and services to children. Whilst we may sell toys and confectionary which may appeal to children, any reservation for our products and services can only be provided to adults over the age of 18 years old. We do not knowingly collect personal information from children under the age of 18 years, without the consent of the child’s parent or guardian. Accordingly, the parent will need to complete and submit a fully completed and signed Parental Personal Data Consent Form along with evidence of the person’s identity, to the email address: privacy@dufry.com.

 

10.  Online Technologies including Cookies

a)Cookies

This website uses cookies and/or similar technologies that store and retrieve information when you browse. A “cookie” is a small text file that identifies your mobile device and/or computer on our server. 

In general, these technologies can serve many different purposes, such as, for example, recognizing you as a user, obtaining information about your browsing habits, or customizing the way content is displayed. The specific uses we make of these technologies are described below.

If you want more information about how it works, we recommend you visit www.allaboutcookies.org and www.youronlinechoices.eu

b)Authorization for the use of cookies

To use cookies on Dufry Websites and Applications, we request your express consent to accept cookies on the Dufry Websites and Applications by clicking "ACCEPT ALL" in the notice at the bottom of the Dufry Websites and Applications, so that they may be downloaded to your mobile device and/or computer hard drive.

Once you have provided your consent to the use of cookies, the file is added, and the cookie helps analyse web traffic and allows us to know when you visit a particular website. Cookies allow applications to respond in a personalized way. The web application can tailor its operation to your needs, collecting your likes and dislikes and remembering information about your preferences. We use traffic log cookies that identify which applications and/or pages are being used. This helps us analyze data about web traffic and improve our Dufry Web Sites and applications in order to tailor them to customer needs.

Overall, cookies help us deliver improved Dufry Web sites and applications, allowing us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to any information on your mobile device or computer or any other information about you, other than the data you choose to share with us. You can choose to accept, configure and/or customize your selection through the "CMP”.

Most web browsers automatically accept cookies, but you can change your browser's settings to reject cookies, if you wish. Cookies, including those already established, can be deleted from your hard drive, following the instructions that are described below.

c)Types of cookies used and their purpose

To access the complete list of cookies we use on this Website, please refer to the last section “Cookies Inventory” of this policy.

The cookies are then classified according to a series of categories. However, it is important to note that the same cookie may be included in more than one category.

Depending on the entity that manages the equipment or domain from which the cookies are sent and how the data obtained is processed, we can distinguish:

  • First-party cookies: Are those that are sent to the user's terminal equipment from a computer or domain managed by the editor itself and from which the service requested by the user is provided.
  • Third-party cookies: These are those that are sent to the user's terminal equipment from a computer or domain that is not managed by the editor, but by another entity that processes the data obtained through cookies.

Depending on the time they remain activated in the terminal equipment, we can distinguish:

  • Session cookies: These are types of cookies designed to collect and store data while the user accesses a website. They are often used to store information that is only of interest to be retained for the provision of the service requested by the user on a single occasion (e.g. a list of products purchased).
  • Persistent cookies: These are a type of cookie in which the data is still stored on the terminal and can be accessed and processed for a period defined by the person responsible for the cookie, and which can range from a few minutes to several years.

Depending on the purpose for which the data obtained through cookies are processed, we can distinguish between:

a) Strictly necessary cookies: are those that, managed by us or by third parties, allow you to browse through the Website, platform or application and the use of the different options or services that exist therein, as well as, for example, controlling traffic and data communication, to identify the session, access restricted access parts, to remember the elements that make up your order, to manage the payment, control fraud linked to service security, apply for enrolment or participation in an event, enable dynamic content or share content through social networks.

b) Preference cookies: the cookies that allow us to remember your information so that you can access the service with certain characteristics that may differentiate your experience from that of other users, such as, for example, the language, the number of results to display when you perform a search, the appearance or content of the service depending on the type of browser through which you access the service or the region from which you access the service, etc.

c) Performance cookies: those that, processed by us or by third parties, allow us to quantify the number of users and thus perform the statistical measurement and analysis of the use made by the users of the service offered. To do this, we analyse your browsing on our website in order to improve the offer of products or services we offer.

We use Google Analytics cookies to collect statistical data on users' activity on the Website and thus be able to improve the services provided to users.

The information generated by Google cookies about your use of Dufry websites and applications, including the IP address, may be transmitted and stored by Google on servers located in the United States. Google may use this information to evaluate how you use the website, to compile website application activity reports for us and to offer other services concerning website activity and internet use. Google may transfer this information to third parties when required to do so by law, or when said third parties process information on behalf of Google. Google will not associate your IP address with any other data in Google’s possession. The Google website has more information about Google Analytics, as well as a copy of Google’s privacy policy pages.

d) Marketing cookies: those cookies that, processed by us or by third parties, allow us to analyze your Internet browsing habits so that we can show you advertising related to your browsing profile.

We use Google, GoogleAdWords, Google DoubleClick, bing.com, atdmt.com, demdex.net, taboola.com, outbrain.com, eversttech.com, Blueknow and Facebook cookies, among other, to manage the spaces that Dufry advertising serves and accesses. These cookies allow us to measure the effectiveness of our online campaigns, provide information of interest to you and offer you advertising content of your choice. Information generated by some of these cookies about your use of Dufry Web Sites and applications, including your IP address, may be transmitted to and stored by the third party on servers located in the United States. Through its Privacy Policies you can obtain more information about how cookies work and how they are used.

        e) Unclassified cookies: these are cookies that are in the process of being classified.

d) Browser settings

a) If you wish, you can change your browser settings and choose the storage options or access to cookies, as well as activate, disable or delete them. These options must be applied following the instructions in your browser:

  • Google Chrome: https://support.google.com/chrome/answer/95647?hl=es
  • Internet Explorer: https://support.microsoft.com/es-es/help/17442/windows-internet-explorer-delete-manage-cookies#
  • Mozilla Firefox: https://support.mozilla.org/es/kb/cookies-informacion-que-los-sitios-web-guardan-en-
  • Safari: https://support.apple.com/es-es/guide/safari/sfri11471/mac
  • Android:https://support.google.com/accounts/answer/32050?co=GENIE.Platform%3DAndroid&hl=es
  • Apple (iOS): https://support.apple.com/es-es/HT201265

b) Social media connection and plug-ins:

On some websites in our online catalog we use social media plug-ins www.facebook.com ("Plug-in"), operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”).

Online catalog websites in the Dufry websites and applications may contain a plug-in and will be marked with a clearly visible Facebook logo (i.e., a white "f" in a blue icon) or may also display the "Facebook Plug-in".

If you access a website like this, containing the aforementioned plug-in, your browser will establish a direct connection to Facebook servers, and Facebook will transmit the plug-in content directly to your browser.

If you are registered on Facebook and you have logged in to your Facebook user account, you will receive any information you access on the corresponding website by integrating the plug-in. If you actively use the plug-in, either by clicking the “Like” or “Share” button, or by leaving a comment on the website in question, the corresponding information will be directly sent from your browser to Facebook and used on Dufry websites and applications.

To prevent Facebook from collecting the aforementioned information about you when accessing the website, you must follow the instructions contained in the settings on the Facebook website and/or log out of the Facebook website before visiting the website in question on Dufry websites and applications. You should also delete all Facebook cookies contained in your browser.

The purpose and scope of the data collection and subsequent use of data by Facebook, as well as the rights and setting options you have to protect your Personal Data or private space, can be found in the Facebook Privacy Policy. We assume no responsibility for the content of the aforementioned websites, nor the Facebook Privacy Policy.

On some of our websites, applications and \or mobile solutions, we use social plugins of the social network www.Linkedin.com (“Plug In”), which is operated by Microsoft Corporation, One Microsoft Way, Redmond, 98052 – 6399, USA (“LinkedIn”).

The websites and\or mobile solutions in Dufry Websites and Applications can contain a plug in are marked with a clearly visible LinkedIn logo or the addition of “LinkedIn Social Plugin”.

If you access a website and\or mobile solutions like this containing such a plugin, your browser will establish a direct connection with the LinkedIn servers and LinkedIn will transmit the content of the plugin directly to your browser.

If you are registered with LinkedIn and are logged into your LinkedIn user account, LinkedIn will receive the information that you accessed the respective website and\or mobile solutions by the integration of the plugin. If you use the plugin actively by activating the “share” button or placing a commentary on the respective website, the corresponding information will be transmitted from your browser directly to LinkedIn and used there in Dufry Websites and Applications.

In order to avoid LinkedIn collecting the above information about you when you access such a website, please following the instructions in settings on the LinkedIn website and/or log out of the LinkedIn website, before visiting the respective website and\or mobile solutions in Dufry Websites and Applications. Additionally, you should delete any LinkedIn cookies present from your browser.

The purpose and extent of data collection and further use and usage of data by LinkedIn as well as your rights and setting options in this regard for the protection of your Personal Data or private space can be found in the LinkedIn Privacy Policy.  We assume no responsibility for the contents of the websites and\or mobile solutions and the LinkedIn Privacy Policy.

 On some of our websites, applications and\or mobile solutions, we use social plugins of the social network youtube.com or other networks found at www.google.com (“Plug In”), which is operated by Google. Inc.,1600 Amphitheatre Parkway, Mountain View, CA 940439 United States.

The websites and\or mobile solutions in Dufry Websites and Applications can contain a plug in are marked with a clearly visible Google logo) or the addition of  “Google Social Plugin”).

If you access a website like this containing such a plugin, your browser will establish a direct connection with the Google servers and Google will transmit the content of the plugin directly to your browser.

If you are registered with Google and are logged into your Google or gmail user account, Google will receive the information that you accessed the respective website and\or mobile solutions by the integration of the plugin. If you use the plugin actively by activating the “share” button or placing a commentary on the respective website and\or mobile solutions, the corresponding information will be transmitted from your browser directly to Google and used there in Dufry Websites and Applications.

In order to avoid Google collecting the above information about you when you access such a website and\or mobile solutions, please following the instructions in settings on the Google websites and/or log out of the Google website, before visiting the respective website and\or mobile solutions in Dufry Websites and Applications. Additionally, you should delete any Google cookies present from your browser.

The purpose and extent of data collection and further use and usage of data by Google Analyticals)  as well as your rights and setting options in this regard for the protection of your Personal Data or private space can be found in the Google Privacy Policy.  We assume no responsibility for the contents of the websites and\or the mobile solutions and the Google Privacy Policy.

e) Opposing to the installation of cookies from third party providers

The user may, at any time, reject the installation of a certain type of cookies, such as advertising and third-party cookies. Some of our providers have a direct system to oppose the installation of their Cookies.

Below you will find a list of providers and links (you will easily find the “opt-out” button to object):

- Youtube and Google Analytics (“opt-out”): https://tools.google.com/dlpage/gaoptout?hl=None

- ADOBE Analytics and Marketing & Audience Manager (“opt-out”): http://www.adobe.com/es/privacy/opt-out.html

Keep in mind that if at any time you delete the cookies from your browser, your opt-out preferences from the previous providers may be deleted, so you will have to oppose their installation again.

f) Warning about the deletion of cookies

You may delete and block all cookies from this site, but part of the site will not work or the quality of the website may be affected.

If you have any questions about our cookies policy, you can contact this page through our Contact channels.

g) Revision

These lists will be updated as quickly as possible as the website services offered on the website change or evolve. However, occasionally during this update, the list may no longer include a cookie, although it will always refer to cookies for purposes identical to those recorded in these lists.

As a visitor, subscriber or continuing to access the Dufry Websites and Applications or via the WiFi network or location services in Stores, you consent to use of cookies and other online technologies as detailed in this Section and in accordance with this privacy statement. Dufry and its third party marketing partners may use cookies, invisible pixels and web beacons to obtain information about you while visiting the Dufry Websites and Applications and our Stores.

11.  What are your rights?

You have the right under applicable law to access, obtain a copy and correct personal data concerning you, subject to limited exceptions that may be prescribed by applicable laws.  Where permitted by applicable law, you may also require that your personal data be deleted or blocked, or you may be entitled to obtain information about the processing of your data, or object to further processing of your data. 

In the event your personal data is processed on the basis of your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You can do this by (i) in some cases deleting the relevant Personal Data from the relevant IT system (although note that in this case it may remain in back-ups and linked systems until it is deleted in accordance with our data retention policy) or (ii) contacting your Global Data Protection Co-Ordinator.

You also have the right to be informed about how your personal data is handled and from whom we receive your data.

As permitted by law, you also have the following additional rights:

  • Data portability - where we are relying upon your consent or the fact that the processing is necessary for the performance of a contract to which you are party as the legal basis for processing, and that personal data is processed by automatic means, you have the right to receive all such personal data which you have provided to Dufry or the Group in a structured, commonly used and machine-readable format, and also to require us to transmit it to another controller where this is technically feasible.
  • Right to restriction of processing - you have the right to restrict our processing of your personal data where:
    • you contest the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
    • where the processing is unlawful but you do not want us to erase the personal data;
    • where we no longer need your personal data for the purposes of the processing, but you require such personal data for the establishment, exercise or defence of legal claims; or
    • where you have objected to processing based on legitimate interest from Dufry  (see below) and pending verification as to whether Dufry or the Group has compelling legitimate grounds to continue processing.

Where your personal data is subject to restriction in this way we will only process it with your consent or for the establishment, exercise or defense of legal claims.

  • Right to object to processing justified on legitimate interest grounds - where we are relying upon legitimate interest to process personal data, then you have the right to object to that processing. If you object, we must stop that processing unless we can either demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or where we need to process the personal data for the establishment, exercise or defence of legal claims. Where we rely upon legitimate interest as a basis for processing we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.
  • Right to object to processing for marketing purposes – you have the right to object to any  processing of your data for marketing purposes (including profiling). Additionally, see What are Your Choices?
  • You have the right to express your point of view and contest any decision we make about you that could have a significant impact on you where that decision is made using only automated methods. If you do so we will, at a minimum, arrange for human verification of the decision and notify you of the outcome.

Please contact us by submitting a Data Subject Access Request Form (available upon request) in writing or by email to either of the addressees listed below.

Some of these rights may not apply in certain circumstances. For example, you may not be entitled to know we have shared your personal data with the police or to receive a copy of your personal information if it relates to a police investigation and we have been informed by the police that notifying you or providing you with a copy will prejudice their investigations.

Dufry has appointed a Global Data Protection Co-Ordinator who may be contacted securely and confidentially at the following E – Mail address : privacy@dufry.com.  Alternatively, you can send your  Data Subject Access Request Form, written comments, questions or concerns to

Dufry International AG

Brunngässlein 12

Basel, 4052

Switzerland

Attention : Global Data Protection Co-Ordinator

12.  What are Your Choices ?

Dufry Websites and Applications provide you with access to a range of information about your account and your interactions with us. To ensure that your personal data is accurate and up to date, we encourage you to regularly review and update your information as appropriate, if or your contact details or address has changed. If you have subscribed to Dufry Websites and Applications, especially the Red by Dufry application or the Reserve and Collect  websites, then you can either access your account and make the changes or request the changes are made by sending an email request along with evidence of your identity to privacy@dufry.com.

We like to inform you about our products and services and those of our partners and to also send you surveys, promotional materials and invitations to events, to participate in competitions or receive coupons or gift certificates as well as communications on your birthday or other special events. If you choose not to receive such communications or modify what method of communications such as SMS, email, letter or phone  we use to contact you or you choose not to agree to the use of cookies or other on line technologies, then you to opt out of such activities by submitting the opt out provision which is the unsubscribe link to the website to allow the customer to unsubscribe (if an electronic communication), or for all other  non-electronic communications,  by submitting  an objection email or letter to specify your preferences to privacy@dufry.com. You can change your preferences or choices at any time or provide a new consent to such activities by providing  a signed consent form consenting to the use of cookies, advertising materials or preferred method of communication to privacy@dufry.com.

13.  Changes to our Privacy Notice

Changes and amendment to the terms of this Privacy Notice can be made at any time and shall apply as soon as they are published on any Dufry Websites and Applications. Should you not agree to any changes or amendments, then you should refrain from continuing to use our services or products or access Dufry Websites and Applications or our Stores.

14.   Where to make a Data Protection complaint?

You have the right to lodge complaints pertaining to the processing of your personal data with the relevant data protection supervisory authority.


Cookies Inventory

DUFRY Website (www.dufry.com)

Name

Category

Provider

Purpose

Expiry

Type

ak_bmsc

Strictly necessary

tools.investis.com

This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of the their website

1 day

HTTP

AWSELB

Strictly necessary

irs.tools.investis.com

Used to distribute traffic to the website on several servers in order to optimize response times

Session

HTTP

AWSELBCORS

 

Strictly necessary

irs.tools.investis.com

Registers which server-cluster is serving the visitor. This is used in context with load balancing. In order to optimize user experience

Session

HTTP

bm_sv

 

Strictly necessary

tools.investis.com

Used in the context with the website’s BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website

1 day

HTTP

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate  statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_gid

 

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

collect

 

Performance

Google Analytics

Used to send data to Google Analytics about the visitor´s device and behavior. Tracks the visitor across devices and marketing channels

Session

Pixel

r/collect

 

Performance

Doubleclick.net

This cookie is used to send data to Google Analytics about the visitor´s deice and behavior. It tracks the visitor across devices and marketing channel.

Session

Pixel

 

RED BY DUFRY

Name

Category

Provider

Purpose

Expiry

Type

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate  statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_git

 

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

pagevisit

 

Performance

r1.trackedweb.net

Registers statistical data on users ‘behavior on the website. Used for internal analytics by the website operator

Session

Pixel

_fbd

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

_gcl_au

Marketing

Google AdSense

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services

3 months

HTTP

AA003

 

Marketing

atdmt.com

Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website

3 months

HTTP

ads/ga-audiences

Marketing

Google

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor´s online behavior across websites

Session

Pixel

ATN

 

Marketing

atdmt.com

Targets ads based on behavioral profiling and geographical location

2 years

HTTP

dmSessionID

Marketing

Dufry

 

Collects information on what products the visitor has viewed and the content of the shopping-cart. This is used to increase the website conversion rate through targeted advertisement and product promotions through emails

1 day

HTTP

fr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

https://cx.atdmt.com/

Marketing

atdmt.com

Sets a unique ID for the visitor that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitate real-time bidding for advertisers

Session

Pixel

IDE

 

Marketing

Google/ Doubleclick.net

Used by Google DoubleClick to register and report the website user´s actions after viewing or clicking one of the advertiser´s ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user

1 year

HTTP

pagead/1p-user-list/#

Marketing

Google

Unclassified

Session

Pixel

r/collect

Marketing

Google/ Doubleclick.net

The cookie is used to send data to Google Analytics about the visitor´s device and behavior. It tracks the visitor across devices and marketing channels

Session

Pixel

recordID

Marketing

Dufry

Collects information on what products the visitor has viewed and the content of the shopping-cart. This is used to increase the website´s conversion rate through targeted advertisement and product promotions through emails

1 year

HTTP

test_cookie

Marketing

Google/ Doubleclick.net

Used to check if the user´s browser supports cookies

1 day

HTTP

tr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

Session

Pixel

_rollupGA

Unclassified

Dufry

(Google Tag Manager)

Unclassified

2 years

HTTP

_rollupGA_gid

Unclassified

Dufry

(Google Tag Manager)

Unclassified

1 day

HTTP

identity

Unclassified

r1.trackedweb.net

Unclassified

Session

Pixel

 

RESERVE & COLLECT (www.shopdutyfree.com)

 

Name

Category

Provider

Purpose

Expiry

Type

AKA_A2 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

1 day

HTTP

form_key

Strictly necessary

Dufry

Ensures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor

Session

HTTP

mage-banners-cache-storage

 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

1 day

HTTP

mage-banners-cache-storage

 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-banners-cache-timeout

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-cache-sessid

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage

 

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage

 

Strictly necessary y

Dufry

Used to optimize the loading speed on the website. This is done by pre-loading some procedures in the visitor´s browser

Persistent

HTML

mage-cache-storage-section-invalidation

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage-section-invalidation

Strictly necessary

Dufry

Used to optimize the loading speed on the website. This is done by pre-loading some procedures in the visitor´s browser

Persistent

HTML

mage-cache-timeout

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-messages

Strictly necessary

Dufry

Necessary for the functionality of the website´s chat-box function

1 day

HTTP

mage-translation-file-version

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Session

HTTP

mage-translation-file-version

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Persistent

HTML

mage-translation-storage

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Session

HTTP

mage-translation-storage

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Persistent

HTML

PHPSESSID

Strictly necessary

Dufry

Preserves user session state across page requests

1 day

HTTP

product_data_storage

Strictly necessary

Dufry

Necessary for the compare-products function on the website

Persistent

HTML

recently_compared_product

Strictly necessary

Dufry

Necessary for the compare-products function on the website

1 day

HTTP

RT

Strictly necessary

LinkedIn

This cookie is used to identify the visitor through an application. This allows the visitor to login to a website through their LinkedIn application for example

6 days

HTTP

test

Strictly necessary

Dufry

Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website

Persistent

HTML

section_data_ids

Preferences

Dufry

Used in a context with the shopping cart functionality. Remembers any wish-list products and visitor credentials when checking out

1 day

HTTP

store

Preferences

Dufry

Determines the preferred language of the visitor. Allows the website to set the preferred language upon the visitor´s re-entry

1  year

HTTP

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_gid

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

collect

 

Performance

Google Analytics

Used to send data to Google Analytics about the visitor´s device and behavior. Tracks the visitor across devices and marketing channels

Session

Pixel

product_data_storage

 

Performance

Dufry

Determines which products the user has viewed, allowing the website to promote related products

1 day

HTTP

recently_compared_product_previous

 

Performance

Dufry

Necessary for the compare-products function on the website

1 day

HTTP

recently_viewed_product

 

Performance

Dufry

Determines which products the user has viewed, allowing the website to promote related products

1 day

HTTP

recently_viewed_product_previous

Performance

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

1 day

HTTP

_boomr_akamaiXhrRetry

Marketing

Dufry

Collects information on user preferences and/or interaction with web-campaign content. This is used on CRM campaign platform used by the website owners for promoting events or products

Persistent

HTML

_fbp

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

_gcl_au

Marketing

Google AdSense

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services

3 months

HTTP

AA003

Marketing

atdmt.com

Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website

3 months

HTTP

ads/ga-audiences

Marketing

Google

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor´s online behaviors across websites

Session

Pixel

all

Marketing

Dufry

Tracks the user´s interaction with the website´s search-bar-function. This data can be used to present the user with relevant products or services

Persistent

HTML

ATN

Marketing

atdmt.com

Targets ads based on behavioral profiling and geographical location

2 years

HTTP

_bkrmk

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect session information

24 hours

 

_bkrmku

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect user information

10 years

 

_bkrmkt

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect information related to event tracking

24 hours

 

eng_mt

Marketing

Dufry

Tracks the conversion rate between the user and the advertisement banners on the website. This serves to optimize the relevance of the advertisements on the website

Persistent

HTML

fr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

https://cx.atdmt.com/

Marketing

atdmt.com

Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers

Session

Pixel

MUID

Marketing

Microsoft/Bing.com

Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronizing the ID across many Microsoft domains

1 year

HTTP

pixel

Marketing

outbrain.com

Unclassified

Session

Pixel

recently_compared_product

Marketing

Dufry

This cookie is used to determine which products the visitor has viewed. This information is used to promote related products and optimize ad-efficiency

Persistent

HTML

Recently_compared_product_previous

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

recently_viewed_product

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

recently_viewed_product-previous

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

tr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

Session

Pixel

trctestcookie

Marketing

Dufry

Detects whether partner data synchronization is functioning and currently running. This function sends user data between third party advertisement companies for the purpose of targeted advertisements

Session

HTTP

used

Marketing

Dufry

Tracks the user´s interaction with the website’s search bar function. This data can be used to present the user with relevant products or services

Persistent

HTML

_uetsid

Unclassified

Dufry

Unclassified

1 day

HTTP

_uetsid

Unclassified

Dufry

Unclassified

Persistent

HTML

_uetsid_exp

Unclassified

Dufry

Unclassified

Persistent

HTML

 

Privacy Notice

 

1.     Introduction

This Privacy Notice describes the way we treat all the personal data you provide or that we have obtained through our Dufry Websites and Applications and in our Stores.

  Summary of provisions:

                                                                                                      

2. Controller of Personal Data, Sources of Personal Data and What Personal Information about Customers do Dufry Websites and Applications collect?

  • Controller and Processors of Personal Data

Dufry International AG and the local Dufry entity which owns the local Store that you are visiting or from whom you are purchasing goods are joint controllers of the personal data that you (as data subject) provide us or we received in our Stores and Dufry Websites and Applications.

  • Types of Personal Data collected and Sources of Personal Data

We collect personal data directly from our customers through Dufry Websites and Applications and our Stores.

We collect the following types of personal data about you from the following sources:

Information that you provide to us: We receive and store any information you enter on Dufry Websites and Applications and Stores or give us in any other way such as during registration, accessing your account or profile, submitting queries or as part of a survey or competition or utilising gift coupons or customer support or communicate with us or purchasing in Stores or using our products or services.

Due to such actions, you may supply us with your (i) name, postal address, email address, phone numbers, (ii) data necessary to process your payment (including the credit card/payment instrument  information and personal security code associated with your credit card) for Store purchases or  on line purchase of gift vouchers, to reserve purchases (under the Dufry Reserve & Collect Websites), to apply for a refund,  or to communicate with customer services regarding a refund to the credit card/payment instrument, (iii) flight departure/destination, flight date and delivery address for the subscriber and airport location to collect any pre ordered reserve & collect products or make purchases of our products and services in Stores.  Demographical data such as your age, gender, country, nationality, preferred language, passport number and citizenship, date of birth, country of residence, country of registration to Dufry Websites and Applications, photos with your image (including selfies of your skin or other parts of your body), information about your health including your skin condition, purchases history and  other travel information including travel date, preferred departure airport and airline loyalty membership details are also collected. You must hold a valid flight ticket to be able to make duty free or duty paid purchases from Dufry. Such information is collected to meet our contractual obligations with airport authorities and legal obligations towards customs and other regulatory authorities.

When you register for membership, subscribe for services or the newsletter or other marketing communications including blogs or customer comments or use the Dufry Websites and Applications or purchase in our Stores, we collect log in details, passwords, any password questions and hints, similar security information used for authentication and account access is also collected for the access into your personal account and profile and to utilise the Reserve and Collect elements  or the RED customer loyalty elements of  Dufry Websites and Applications or  in our Stores.

You can choose not to provide certain information, but then you might not be able to utilise many of the features of the Dufry Websites and Applications. See What Are Your Choices section below.

Information collected automatically through interaction with usOnly if you agree, we receive and store information  where you interact with us through using our products and services, including online technologies (ie. Cookies) and receiving error reports or usage data from software applications on your devices online or via Wi-Fi communications in Stores.

We collect and analyse device, connectivity and configuration data including the Internet protocol (IP) address used to connect your computer or device to the internet as described in the Online Technology and Cookies section below.

We may operate CCTV in our Stores and collect video footage and images of you and others when you visit our Stores (including your/their location and physical appearance). For more information please contact the Store staff.

Mobile or Dufry Applications: When you choose to use or download Dufry Websites and Applications or allow connectivity via WiFi connections to your device, we receive information about your location and mobile device, including a unique identifier for your personalised device, information obtained from browser cookies, your GPS data or wireless networks data (WLAN). Location data is neither stored nor transmitted to third parties.  If you agree with the localisation function, we can provide you with location-based services including advertising, search results and personalised content. When you are near one of our Stores or you have added a retail coupon in your Wallet, then we can use push email communications to you if you have provided your consent to receive such communications and advertising. We may derive information from the personal data you provide to us when using Dufry Websites or Applications e.g. a health diagnosis and tailored product recommendations based on that diagnosis, or statistical or aggregated data that does not identify you which we use for analytics and insight purposes.

If we make product recommendations to you (including based on a diagnosis of your health data), you are not obliged to purchase the recommended products. The products recommended to you will be products available for purchase without a prescription and you should always check with a healthcare professional if you have any doubts regarding the effect of using any skincare or other product.

Most mobile devices allow you to turn off location services and/or push notifications. For more information, see What are Your Choices section below.

E-Mail Communications: To provide more personalised and interesting email communications, we receive a confirmation when you open email from Dufry Websites and Applications or your device is near one of our Stores, if your computer or device supports this capability and if you have agreed with the localisation function though your device. If you choose not to receive any emails or other mail from us, please adjust your customer communication preferences in your account profile.

Information from other Sources: We receive information about you from other sources and add it to our account information. The third party sources include:

  • Updated delivery and contact address data from third parties which are used to update our records and deliver your next purchase more easily;
  • Social networks when you grant permission to Dufry Websites and Applications to access your data on one or more networks;
  • Service providers that help us determine a location based on your IP address to allow customisation of certain products to your location;
  • Our partners which we offer co-branded services or conduct joint marketing activities;
  • Publicly-available sources from open government databases or other data in the public domain;
  • Information (including CCTV footage and images, as the case shall be) from third parties including the police, tribunals, courts, regulators, airports or other authorities in connection with security incidents or actual or suspected unlawful acts, which may include information relating to actual, alleged or suspected criminal offences.
  • Your employment status with your current employer, which is used to either activate or deactivate your employee discount.

 

3. Lawful basis and purposes for processing and using your personal data

Lawful purposes

Your personal data is processed by the Group on the basis of a lawful “justification” for such processing, to the extent required by law. In the majority of cases, the processing of your personal data will be justified on one of the following bases:

  • It is provided for in your contract of providing products and services requested by you to be provided by us;
  • It is necessary for us to comply with a legal obligation;
  • It is with your freely provided unequivocal and informed consent for specified processing purposes and, in relation to data relating to your health, with your explicit consent;
  • It is necessary to protect your or someone else’s life; or
  • It is in our legitimate interests as a business and as your supplier of contractually requested goods, and our interests are not overridden by your interests, fundamental rights or freedoms including legitimate interests as set out below.

The processing of personal data relating to actual, alleged or suspected criminal offences and convictions will be justified by one of the above bases and normally one of the following special conditions:

  • It is necessary for the purposes of preventing or detecting crime or other unlawful acts;
  • It is necessary to protect the public against dishonesty; or
  • We have obtained consent from the relevant individuals involved for the processing.

Purposes of processing personal data

We obtain, use, disclose and otherwise process personal data about customers, based on the execution of a contract to:

  • process transactions they request, including e-commerce Reserve and Collect selection and mobile transactions;
  • process information from the RED loyalty programme to verify the identity of the cardholder is the owner of the RED loyalty card and to ensure that the collection or redemption of RED points and confirm the status of a customer to allow for the correct discount to be applied to the sales of goods purchased in Stores or goods reserved for collection under the Reserve & Collect application and purchased in person in Stores;

 This information will enable us to provide access to all areas of the loyalty programme including the employee discount, the Reserve and Collect and Red by Dufry applications contained in Dufry Websites and Applications.

  • review and collect data from the boarding pass, nationality, destination and holder of the valid boarding pass to ensure that the passenger is part of the travelling public to allow Dufry or the Group to provide duty free goods under the terms of the contractual agreement with our landlords or airport authorities;
  • provide payment services including credit cards for online purchases and in Stores purchases;
  • provide goods and services to the customers that they have requested (ie provided an email address to allow the regularly newsletter to be provided to the customer);
  • protect the log in details of the subscribers and system integrity of the Dufry Websites and Applications;
  • communicate with you and personalize our communications with you. i.e. respond to your queries or accommodate your preferences and registration for program membership. We communicate with you by email or phone or SMS to inform you about our services, how to keep your subscription or account active, to communicate regarding a refund or customer inquiry or assisting with web site or Dufry Websites and Applications access or technical queries;
  • to carry out your contractual transactions with us and to provide our products (including the reserving of and pre-selection of duty free products listed in the Reserve and Collect website for collection at the requested Store) to you as requested by you. This includes using your personal information to register or subscribe to any services provided thorough Dufry Websites and Applications; fulfil our legal obligations;  

We also collect personal data to comply with legal obligations, especially the following:

  • passenger name, boarding card to ensure that the consumer reserving the products is a valid traveller to meet our contractual obligations to our landlord and long term concession agreement as well to allow the calculation of the VAT or similar tax allowances to be calculated for the customs authorities; comply with legal obligations, policies and procedures and for internal administrative and analytics purposes; process information or claims in connection with incidents at Stores;
  • protect the rights or property or safety of Dufry Websites and Applications or Stores, including our customers and visitors; and
  • assist third parties including the police, tribunals, courts, regulators, airports or other authorities with their investigations or requests or to report security incidents or suspected or actual unlawful acts. This assistance is provided for the purposes of preventing or detecting unlawful acts, the apprehension or prosecution of offenders, protecting the safety of our customers or visitors or in connection with other lawful requests to disclose personal data that we received from or make to third parties (for example missing persons investigations).

Where we process your personal data on the basis of our legitimate interests, those will be our interests in:

  • providing and improving the products we offer and perform essential business operations. This includes operating the products, maintaining and improving the performance of the products, developing new features, conducting research and providing customer support;
  • protecting the security and safety of our products and our customers, to detect and prevent unlawful acts including fraud and to confirm the validity of the subscriber logging into Dufry Websites and Applications;
  • implementing cookies (and similar technologies) and processing your personal data obtained from those cookies where they are essential to the operation of Dufry Websites or Applications;
  • using personal data for statistical and analytical purposes. Whenever reasonably possible we will anonymize such information before using it for statistical or analytical purposes. Such information is processed in the legitimate interests of Dufry International AG to maintain the efficiency, relevancy and availability of the Dufry Websites and Applications;
  • effective management and operation of Dufry and the Group companies;
  • to maintain our business relationship, where you are a user or subscriber of our Dufry Websites and Applications;
  • carry out a health and other diagnoses and recommend products to you based on your personal data. Such diagnosis and recommendations may be produced using advanced technologies including artificial intelligence, and may use algorithms and statistical methods to analyse your personal data in combination with each other to produce results, in some cases, without human involvement;
  • improve Dufry Websites and Applications, Stores, quality of service and customers shopping experience;
  • advertising : Sending you communications regarding our products, services, campaigns, special offers promotions, contests and customer surveys, newsletters related to Dufry Websites and Applications and Stores and  to provide invitations to attend events;
  • to commence, protect or defend Dufry in actual or threatened legal proceedings.

 

Finally, if you have provided your consent via the Dufry Websites or Applications , we will process your personal data on the basis of consent to:

  • provide you with targeted advertising based on your purchase history (including items purchased, abandoned baskets, day and store of purchase), and profile (date of birth, gender, country of residence, country of registration, nationality, RED status);
  • provide you with targeted advertising based on the travel information you provide us (and including travel date, preferred departure airport, airline loyalty membership details), by answering the customers surveys you may receive from us from time to time;
  • send or make promotional offers on behalf of other companies that offer travel related servicesbut if we do this, then we do not give that business your personal data; and
  • carry out a health diagnosis and recommend products to you based on personal data relating to your health (e.g. details of your skin condition in connection with our Skincare Advisor Application). Such diagnosis and recommendations may be produced using advanced technologies including artificial intelligence, and may use algorithms and statistical methods to analyse your personal data in combination with each other to produce results, in some cases, without human involvement.

 

You can withdraw at any time all or any of the consents you provide that are listed above.

If you do not provide your personal data to us, you may not be unable to access some or all of the Dufry  Websites or Applications or their features, or may be unable to communicate or correspond with us.

 

4. Sharing your Personal Data

We will not transfer or disclose your personal information, other than as set out below:

  • Effective management and operation of Dufry and the Group companies, and only when certain services are centralized;
  • to third party service providers (companies or individuals) that we employ to perform functions on our behalf such as fulfilling orders, delivering to retail locations or Stores, sending postal mail and email, removing repetitive information from customer lists, analysing data, providing marketing assistance, providing search results and links, processing credit card payments and providing customer service. These providers have access to personal information needed to perform their functions, but may not use it for other purposes and include the following categories of data recipients:

(i)  advertising and media consultants,

(ii) market research consultants;

(iii) providers of technical services;

(iv) website designers and developers;

(v) cloud computing service providers, including providers of Applications that use artificial intelligence to provide answers or results based on personal data you provide (e.g. the Skincare Advisor Application provided by our supplier, Revieve Oy);

(vi) electronic storage providers;

(vii) customer services; and

(viii) with your current employer, as part of our ongoing checks to verify that you still remain eligible for the employee discount.

  • in releasing account and other personal data to comply with the law, undertaking litigation or other proceedings or to enforce or comply with or apply our terms of use and other agreements, or protect the rights, property or safety of Dufry Websites and Applications or Stores. This includes exchanging information with other companies for fraud prevention and credit risk reduction;
  • to comply with legal or regulatory requirements or obligations in accordance with applicable law, a court order or a subpoena;
  • with regulatory authorities, airport authorities, Dufry International AG and Group landlords and concession partners and customs and tax authorities to show the calculation of such tax exemptions;
  • to data analytical firms, Google Analytics Inc.;
  • in an emergency, such as to safeguard the life, health, or property of an individual; or
  • to third parties including the police, tribunals, courts, regulators, airports or other authorities to assist them with their investigations or requests or for us to report security incidents or suspected or actual unlawful acts. This includes allowing such third parties to access and take copies of CCTV images or other video footage where CCTV cameras are in place and  these relate to such incidents and acts;

 

5. Storing your Personal Data

Your personal information you have provided to the controller will be located in a Dufry  AG cloud based customer management database software tool located within data centres maintained in the territories of the EEA, the purpose of which is to manage the business relationship with you, in accordance with the provisions of the data protection laws.

Dufry International AG will manage the customer relationship with you and any marketing materials can be provided, by Dufry as Controller.

 

6. Security of personal data

Your personal data will be secured by taking security measures that are commensurate with the sensitivity of the personal data processed. To this end, Dufry and all Group entities maintain appropriate physical, technical, and administrative security measures with a view to protecting personal data against theft; accidental loss; unauthorised alteration; unauthorised or accidental access, processing, erasure, use, disclosure or copying; and/or accidental or unlawful destruction.

When we have provided (or you have chosen) a password allowing access to certain benefits of the Dufry Websites and Applications, you are responsible for safeguarding it and keeping it confidential and you undertake not  to allow it to be used by third parties. Unfortunately, the transmission of information thorough the internet is not completely secure. Although we will take all reasonable commercial measures to protect your personal data, we cannot guarantee the security of any personal information or data you disclose on line. You accept the inherent security implications of using the internet and to the extent permitted by law, we will not be responsible for any breach of security, unless we have been acting with gross negligence and only within the limitations as set out in the terms and conditions of use for Dufry Websites and Applications.  

 

7. Transfers of Data Outside of Your Country

Your personal data (as described above) may be transferred to other Group entities or to third parties described  above, only to the extent required for Dufry International AG and group companies to perform their obligations to you, or for you to access your Dufry Websites and Applications, or for the purposes described above in this Notice, provided such purposes are in accordance with applicable laws.  In particular:

  • Your profile and contact information contained in systems such as corporate communications systems, customer relationship management databases or directories will be accessible to all marketing, sales and customer support or customer care employees of Group companies worldwide.
  • Your personal data may be transferred to or accessed by Group employees located inside or outside your country, and/or a person or company that is not part of the Group located in or outside your country, on a need-to-know basis. Transfers outside the UK and EU may be made pursuant to the European Commission's Standard Contractual Clauses ("SCC") or other legally acceptable mechanisms which ensure an adequate level of protection. As permitted by law, you may be entitled, upon request to the Global Data Protection Co-Ordinator, to be informed about the appropriate safeguards that have been taken to protect your Personal Data for transfer outside the UK and EU.
  • Dufry International AG may process your personal data as a controller in order to administer and provide you with products and services that you requested, to administer global sales and customer programs, promotional and marketing activities and surveys, competitions and coupon and gift promotions, communications with customers, advertising campaigns with us, to manage sales and customer relationships and to prepare sales and customer relationship management and customer support reporting, consistent with the terms of this Notice. Dufry International AG is located in Switzerland, a country that benefits from an adequacy decision of the European Commission and the UK that has found Swiss law to afford adequate protection to personal data.
  • Transfers may be made to respond to law enforcement requests or discovery procedures, or where required or permitted by applicable laws, court orders, government regulations, or government authorities (including tax and employment). Such transfers may entail access by courts or governmental authorities outside your country, after having ensured that only your minimal necessary data is disclosed and transferred, or that such data is de-identified or that, where possible, appropriate stipulative court orders have been issued.

 

A list of the countries located outside the EU to which your Personal Data may be transferred, and an indication of whether they have been determined by the European Commission to grant adequate protection to Personal Data, can be found at https://ec.europa.eu/info/strategy/justice-and-fundamental-rights/data-protection/data-transfers-outside-eu_en. For the UK, you can find up to date information on countries that have been granted adequate protection to personal data by visiting the ICO website (www.ico.org.uk).

Transfers of Personal Data in accordance with this Section 7 are based on the same legal bases as applicable for the respective purposes of processing as set out  above.

 

8.      Retention of personal data

Dufry data retention policy requires that personal data be retained for no longer than required to fulfil the purposes for which it was collected. In general, personal data, or records containing personal data, will be retained for periods of time required in accordance with applicable legal, tax, or accounting obligations. In specific circumstances, and in accordance with applicable law, Dufry may retain your personal data for longer periods of time (such as for the duration of the relevant statute of limitation) so that we have an accurate record of our dealings with you or to protect the legitimate interests of Dufry International AG or local Dufry entity name, who owns this Dufry Website or Application.  In all cases, where your information is no longer required, Dufry will ensure it is disposed of in a secure manner.

If you use our Skincare Advisor Application, your selfies and any other data relating to your skin condition is promptly deleted after we carry out a diagnosis and make a product recommendation. Certain personal data is anonymised for analytical and insight purposes by aggregating the data so that it can no longer be linked to you.

 

9. Minors

Dufry Websites and Applications do not provide products and services to children. Whilst we may sell toys and confectionary which may appeal to children, any reservation for our products and services can only be provided to adults over the age of 18 years old. We do not knowingly collect personal information from children under the age of 18 years, without the consent of the child’s parent or guardian. Accordingly, the parent will need to complete and submit a fully completed and signed Parental Personal Data Consent Form along with evidence of the person’s identity, to the email address: privacy@dufry.com.

 

10.  Online Technologies including Cookies

a)Cookies

This website uses cookies and/or similar technologies that store and retrieve information when you browse. A “cookie” is a small text file that identifies your mobile device and/or computer on our server. 

In general, these technologies can serve many different purposes, such as, for example, recognizing you as a user, obtaining information about your browsing habits, or customizing the way content is displayed. The specific uses we make of these technologies are described below.

If you want more information about how it works, we recommend you visit www.allaboutcookies.org and www.youronlinechoices.eu

b)Authorization for the use of cookies

To use cookies on Dufry Websites and Applications, we request your express consent to accept cookies on the Dufry Websites and Applications by clicking "ACCEPT ALL" in the notice at the bottom of the Dufry Websites and Applications, so that they may be downloaded to your mobile device and/or computer hard drive.

Once you have provided your consent to the use of cookies, the file is added, and the cookie helps analyse web traffic and allows us to know when you visit a particular website. Cookies allow applications to respond in a personalized way. The web application can tailor its operation to your needs, collecting your likes and dislikes and remembering information about your preferences. We use traffic log cookies that identify which applications and/or pages are being used. This helps us analyze data about web traffic and improve our Dufry Web Sites and applications in order to tailor them to customer needs.

Overall, cookies help us deliver improved Dufry Web sites and applications, allowing us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to any information on your mobile device or computer or any other information about you, other than the data you choose to share with us. You can choose to accept, configure and/or customize your selection through the "CMP”.

Most web browsers automatically accept cookies, but you can change your browser's settings to reject cookies, if you wish. Cookies, including those already established, can be deleted from your hard drive, following the instructions that are described below.

c)Types of cookies used and their purpose

To access the complete list of cookies we use on this Website, please refer to the last section “Cookies Inventory” of this policy.

The cookies are then classified according to a series of categories. However, it is important to note that the same cookie may be included in more than one category.

Depending on the entity that manages the equipment or domain from which the cookies are sent and how the data obtained is processed, we can distinguish:

  • First-party cookies: Are those that are sent to the user's terminal equipment from a computer or domain managed by the editor itself and from which the service requested by the user is provided.
  • Third-party cookies: These are those that are sent to the user's terminal equipment from a computer or domain that is not managed by the editor, but by another entity that processes the data obtained through cookies.

Depending on the time they remain activated in the terminal equipment, we can distinguish:

  • Session cookies: These are types of cookies designed to collect and store data while the user accesses a website. They are often used to store information that is only of interest to be retained for the provision of the service requested by the user on a single occasion (e.g. a list of products purchased).
  • Persistent cookies: These are a type of cookie in which the data is still stored on the terminal and can be accessed and processed for a period defined by the person responsible for the cookie, and which can range from a few minutes to several years.

Depending on the purpose for which the data obtained through cookies are processed, we can distinguish between:

a) Strictly necessary cookies: are those that, managed by us or by third parties, allow you to browse through the Website, platform or application and the use of the different options or services that exist therein, as well as, for example, controlling traffic and data communication, to identify the session, access restricted access parts, to remember the elements that make up your order, to manage the payment, control fraud linked to service security, apply for enrolment or participation in an event, enable dynamic content or share content through social networks.

b) Preference cookies: the cookies that allow us to remember your information so that you can access the service with certain characteristics that may differentiate your experience from that of other users, such as, for example, the language, the number of results to display when you perform a search, the appearance or content of the service depending on the type of browser through which you access the service or the region from which you access the service, etc.

c) Performance cookies: those that, processed by us or by third parties, allow us to quantify the number of users and thus perform the statistical measurement and analysis of the use made by the users of the service offered. To do this, we analyse your browsing on our website in order to improve the offer of products or services we offer.

We use Google Analytics cookies to collect statistical data on users' activity on the Website and thus be able to improve the services provided to users.

The information generated by Google cookies about your use of Dufry websites and applications, including the IP address, may be transmitted and stored by Google on servers located in the United States. Google may use this information to evaluate how you use the website, to compile website application activity reports for us and to offer other services concerning website activity and internet use. Google may transfer this information to third parties when required to do so by law, or when said third parties process information on behalf of Google. Google will not associate your IP address with any other data in Google’s possession. The Google website has more information about Google Analytics, as well as a copy of Google’s privacy policy pages.

d) Marketing cookies: those cookies that, processed by us or by third parties, allow us to analyze your Internet browsing habits so that we can show you advertising related to your browsing profile.

We use Google, GoogleAdWords, Google DoubleClick, bing.com, atdmt.com, demdex.net, taboola.com, outbrain.com, eversttech.com, Blueknow and Facebook cookies, among other, to manage the spaces that Dufry advertising serves and accesses. These cookies allow us to measure the effectiveness of our online campaigns, provide information of interest to you and offer you advertising content of your choice. Information generated by some of these cookies about your use of Dufry Web Sites and applications, including your IP address, may be transmitted to and stored by the third party on servers located in the United States. Through its Privacy Policies you can obtain more information about how cookies work and how they are used.

        e) Unclassified cookies: these are cookies that are in the process of being classified.

d) Browser settings

a) If you wish, you can change your browser settings and choose the storage options or access to cookies, as well as activate, disable or delete them. These options must be applied following the instructions in your browser:

  • Google Chrome: https://support.google.com/chrome/answer/95647?hl=es
  • Internet Explorer: https://support.microsoft.com/es-es/help/17442/windows-internet-explorer-delete-manage-cookies#
  • Mozilla Firefox: https://support.mozilla.org/es/kb/cookies-informacion-que-los-sitios-web-guardan-en-
  • Safari: https://support.apple.com/es-es/guide/safari/sfri11471/mac
  • Android:https://support.google.com/accounts/answer/32050?co=GENIE.Platform%3DAndroid&hl=es
  • Apple (iOS): https://support.apple.com/es-es/HT201265

b) Social media connection and plug-ins:

On some websites in our online catalog we use social media plug-ins www.facebook.com ("Plug-in"), operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”).

Online catalog websites in the Dufry websites and applications may contain a plug-in and will be marked with a clearly visible Facebook logo (i.e., a white "f" in a blue icon) or may also display the "Facebook Plug-in".

If you access a website like this, containing the aforementioned plug-in, your browser will establish a direct connection to Facebook servers, and Facebook will transmit the plug-in content directly to your browser.

If you are registered on Facebook and you have logged in to your Facebook user account, you will receive any information you access on the corresponding website by integrating the plug-in. If you actively use the plug-in, either by clicking the “Like” or “Share” button, or by leaving a comment on the website in question, the corresponding information will be directly sent from your browser to Facebook and used on Dufry websites and applications.

To prevent Facebook from collecting the aforementioned information about you when accessing the website, you must follow the instructions contained in the settings on the Facebook website and/or log out of the Facebook website before visiting the website in question on Dufry websites and applications. You should also delete all Facebook cookies contained in your browser.

The purpose and scope of the data collection and subsequent use of data by Facebook, as well as the rights and setting options you have to protect your Personal Data or private space, can be found in the Facebook Privacy Policy. We assume no responsibility for the content of the aforementioned websites, nor the Facebook Privacy Policy.

On some of our websites, applications and \or mobile solutions, we use social plugins of the social network www.Linkedin.com (“Plug In”), which is operated by Microsoft Corporation, One Microsoft Way, Redmond, 98052 – 6399, USA (“LinkedIn”).

The websites and\or mobile solutions in Dufry Websites and Applications can contain a plug in are marked with a clearly visible LinkedIn logo or the addition of “LinkedIn Social Plugin”.

If you access a website and\or mobile solutions like this containing such a plugin, your browser will establish a direct connection with the LinkedIn servers and LinkedIn will transmit the content of the plugin directly to your browser.

If you are registered with LinkedIn and are logged into your LinkedIn user account, LinkedIn will receive the information that you accessed the respective website and\or mobile solutions by the integration of the plugin. If you use the plugin actively by activating the “share” button or placing a commentary on the respective website, the corresponding information will be transmitted from your browser directly to LinkedIn and used there in Dufry Websites and Applications.

In order to avoid LinkedIn collecting the above information about you when you access such a website, please following the instructions in settings on the LinkedIn website and/or log out of the LinkedIn website, before visiting the respective website and\or mobile solutions in Dufry Websites and Applications. Additionally, you should delete any LinkedIn cookies present from your browser.

The purpose and extent of data collection and further use and usage of data by LinkedIn as well as your rights and setting options in this regard for the protection of your Personal Data or private space can be found in the LinkedIn Privacy Policy.  We assume no responsibility for the contents of the websites and\or mobile solutions and the LinkedIn Privacy Policy.

 On some of our websites, applications and\or mobile solutions, we use social plugins of the social network youtube.com or other networks found at www.google.com (“Plug In”), which is operated by Google. Inc.,1600 Amphitheatre Parkway, Mountain View, CA 940439 United States.

The websites and\or mobile solutions in Dufry Websites and Applications can contain a plug in are marked with a clearly visible Google logo) or the addition of  “Google Social Plugin”).

If you access a website like this containing such a plugin, your browser will establish a direct connection with the Google servers and Google will transmit the content of the plugin directly to your browser.

If you are registered with Google and are logged into your Google or gmail user account, Google will receive the information that you accessed the respective website and\or mobile solutions by the integration of the plugin. If you use the plugin actively by activating the “share” button or placing a commentary on the respective website and\or mobile solutions, the corresponding information will be transmitted from your browser directly to Google and used there in Dufry Websites and Applications.

In order to avoid Google collecting the above information about you when you access such a website and\or mobile solutions, please following the instructions in settings on the Google websites and/or log out of the Google website, before visiting the respective website and\or mobile solutions in Dufry Websites and Applications. Additionally, you should delete any Google cookies present from your browser.

The purpose and extent of data collection and further use and usage of data by Google Analyticals)  as well as your rights and setting options in this regard for the protection of your Personal Data or private space can be found in the Google Privacy Policy.  We assume no responsibility for the contents of the websites and\or the mobile solutions and the Google Privacy Policy.

e) Opposing to the installation of cookies from third party providers

The user may, at any time, reject the installation of a certain type of cookies, such as advertising and third-party cookies. Some of our providers have a direct system to oppose the installation of their Cookies.

Below you will find a list of providers and links (you will easily find the “opt-out” button to object):

- Youtube and Google Analytics (“opt-out”): https://tools.google.com/dlpage/gaoptout?hl=None

- ADOBE Analytics and Marketing & Audience Manager (“opt-out”): http://www.adobe.com/es/privacy/opt-out.html

Keep in mind that if at any time you delete the cookies from your browser, your opt-out preferences from the previous providers may be deleted, so you will have to oppose their installation again.

f) Warning about the deletion of cookies

You may delete and block all cookies from this site, but part of the site will not work or the quality of the website may be affected.

If you have any questions about our cookies policy, you can contact this page through our Contact channels.

g) Revision

These lists will be updated as quickly as possible as the website services offered on the website change or evolve. However, occasionally during this update, the list may no longer include a cookie, although it will always refer to cookies for purposes identical to those recorded in these lists.

As a visitor, subscriber or continuing to access the Dufry Websites and Applications or via the WiFi network or location services in Stores, you consent to use of cookies and other online technologies as detailed in this Section and in accordance with this privacy statement. Dufry and its third party marketing partners may use cookies, invisible pixels and web beacons to obtain information about you while visiting the Dufry Websites and Applications and our Stores.

11.  What are your rights?

You have the right under applicable law to access, obtain a copy and correct personal data concerning you, subject to limited exceptions that may be prescribed by applicable laws.  Where permitted by applicable law, you may also require that your personal data be deleted or blocked, or you may be entitled to obtain information about the processing of your data, or object to further processing of your data. 

In the event your personal data is processed on the basis of your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You can do this by (i) in some cases deleting the relevant Personal Data from the relevant IT system (although note that in this case it may remain in back-ups and linked systems until it is deleted in accordance with our data retention policy) or (ii) contacting your Global Data Protection Co-Ordinator.

You also have the right to be informed about how your personal data is handled and from whom we receive your data.

As permitted by law, you also have the following additional rights:

  • Data portability - where we are relying upon your consent or the fact that the processing is necessary for the performance of a contract to which you are party as the legal basis for processing, and that personal data is processed by automatic means, you have the right to receive all such personal data which you have provided to Dufry or the Group in a structured, commonly used and machine-readable format, and also to require us to transmit it to another controller where this is technically feasible.
  • Right to restriction of processing - you have the right to restrict our processing of your personal data where:
    • you contest the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
    • where the processing is unlawful but you do not want us to erase the personal data;
    • where we no longer need your personal data for the purposes of the processing, but you require such personal data for the establishment, exercise or defence of legal claims; or
    • where you have objected to processing based on legitimate interest from Dufry  (see below) and pending verification as to whether Dufry or the Group has compelling legitimate grounds to continue processing.

Where your personal data is subject to restriction in this way we will only process it with your consent or for the establishment, exercise or defense of legal claims.

  • Right to object to processing justified on legitimate interest grounds - where we are relying upon legitimate interest to process personal data, then you have the right to object to that processing. If you object, we must stop that processing unless we can either demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or where we need to process the personal data for the establishment, exercise or defence of legal claims. Where we rely upon legitimate interest as a basis for processing we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.
  • Right to object to processing for marketing purposes – you have the right to object to any  processing of your data for marketing purposes (including profiling). Additionally, see What are Your Choices?
  • You have the right to express your point of view and contest any decision we make about you that could have a significant impact on you where that decision is made using only automated methods. If you do so we will, at a minimum, arrange for human verification of the decision and notify you of the outcome.

Please contact us by submitting a Data Subject Access Request Form (available upon request) in writing or by email to either of the addressees listed below.

Some of these rights may not apply in certain circumstances. For example, you may not be entitled to know we have shared your personal data with the police or to receive a copy of your personal information if it relates to a police investigation and we have been informed by the police that notifying you or providing you with a copy will prejudice their investigations.

Dufry has appointed a Global Data Protection Co-Ordinator who may be contacted securely and confidentially at the following E – Mail address : privacy@dufry.com.  Alternatively, you can send your  Data Subject Access Request Form, written comments, questions or concerns to

Dufry International AG

Brunngässlein 12

Basel, 4052

Switzerland

Attention : Global Data Protection Co-Ordinator

12.  What are Your Choices ?

Dufry Websites and Applications provide you with access to a range of information about your account and your interactions with us. To ensure that your personal data is accurate and up to date, we encourage you to regularly review and update your information as appropriate, if or your contact details or address has changed. If you have subscribed to Dufry Websites and Applications, especially the Red by Dufry application or the Reserve and Collect  websites, then you can either access your account and make the changes or request the changes are made by sending an email request along with evidence of your identity to privacy@dufry.com.

We like to inform you about our products and services and those of our partners and to also send you surveys, promotional materials and invitations to events, to participate in competitions or receive coupons or gift certificates as well as communications on your birthday or other special events. If you choose not to receive such communications or modify what method of communications such as SMS, email, letter or phone  we use to contact you or you choose not to agree to the use of cookies or other on line technologies, then you to opt out of such activities by submitting the opt out provision which is the unsubscribe link to the website to allow the customer to unsubscribe (if an electronic communication), or for all other  non-electronic communications,  by submitting  an objection email or letter to specify your preferences to privacy@dufry.com. You can change your preferences or choices at any time or provide a new consent to such activities by providing  a signed consent form consenting to the use of cookies, advertising materials or preferred method of communication to privacy@dufry.com.

13.  Changes to our Privacy Notice

Changes and amendment to the terms of this Privacy Notice can be made at any time and shall apply as soon as they are published on any Dufry Websites and Applications. Should you not agree to any changes or amendments, then you should refrain from continuing to use our services or products or access Dufry Websites and Applications or our Stores.

14.   Where to make a Data Protection complaint?

You have the right to lodge complaints pertaining to the processing of your personal data with the relevant data protection supervisory authority.


Cookies Inventory

DUFRY Website (www.dufry.com)

Name

Category

Provider

Purpose

Expiry

Type

ak_bmsc

Strictly necessary

tools.investis.com

This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of the their website

1 day

HTTP

AWSELB

Strictly necessary

irs.tools.investis.com

Used to distribute traffic to the website on several servers in order to optimize response times

Session

HTTP

AWSELBCORS

 

Strictly necessary

irs.tools.investis.com

Registers which server-cluster is serving the visitor. This is used in context with load balancing. In order to optimize user experience

Session

HTTP

bm_sv

 

Strictly necessary

tools.investis.com

Used in the context with the website’s BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website

1 day

HTTP

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate  statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_gid

 

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

collect

 

Performance

Google Analytics

Used to send data to Google Analytics about the visitor´s device and behavior. Tracks the visitor across devices and marketing channels

Session

Pixel

r/collect

 

Performance

Doubleclick.net

This cookie is used to send data to Google Analytics about the visitor´s deice and behavior. It tracks the visitor across devices and marketing channel.

Session

Pixel

 

RED BY DUFRY

Name

Category

Provider

Purpose

Expiry

Type

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate  statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_git

 

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

pagevisit

 

Performance

r1.trackedweb.net

Registers statistical data on users ‘behavior on the website. Used for internal analytics by the website operator

Session

Pixel

_fbd

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

_gcl_au

Marketing

Google AdSense

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services

3 months

HTTP

AA003

 

Marketing

atdmt.com

Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website

3 months

HTTP

ads/ga-audiences

Marketing

Google

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor´s online behavior across websites

Session

Pixel

ATN

 

Marketing

atdmt.com

Targets ads based on behavioral profiling and geographical location

2 years

HTTP

dmSessionID

Marketing

Dufry

 

Collects information on what products the visitor has viewed and the content of the shopping-cart. This is used to increase the website conversion rate through targeted advertisement and product promotions through emails

1 day

HTTP

fr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

https://cx.atdmt.com/

Marketing

atdmt.com

Sets a unique ID for the visitor that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitate real-time bidding for advertisers

Session

Pixel

IDE

 

Marketing

Google/ Doubleclick.net

Used by Google DoubleClick to register and report the website user´s actions after viewing or clicking one of the advertiser´s ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user

1 year

HTTP

pagead/1p-user-list/#

Marketing

Google

Unclassified

Session

Pixel

r/collect

Marketing

Google/ Doubleclick.net

The cookie is used to send data to Google Analytics about the visitor´s device and behavior. It tracks the visitor across devices and marketing channels

Session

Pixel

recordID

Marketing

Dufry

Collects information on what products the visitor has viewed and the content of the shopping-cart. This is used to increase the website´s conversion rate through targeted advertisement and product promotions through emails

1 year

HTTP

test_cookie

Marketing

Google/ Doubleclick.net

Used to check if the user´s browser supports cookies

1 day

HTTP

tr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

Session

Pixel

_rollupGA

Unclassified

Dufry

(Google Tag Manager)

Unclassified

2 years

HTTP

_rollupGA_gid

Unclassified

Dufry

(Google Tag Manager)

Unclassified

1 day

HTTP

identity

Unclassified

r1.trackedweb.net

Unclassified

Session

Pixel

 

RESERVE & COLLECT (www.shopdutyfree.com)

 

Name

Category

Provider

Purpose

Expiry

Type

AKA_A2 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

1 day

HTTP

form_key

Strictly necessary

Dufry

Ensures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor

Session

HTTP

mage-banners-cache-storage

 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

1 day

HTTP

mage-banners-cache-storage

 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-banners-cache-timeout

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-cache-sessid

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage

 

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage

 

Strictly necessary y

Dufry

Used to optimize the loading speed on the website. This is done by pre-loading some procedures in the visitor´s browser

Persistent

HTML

mage-cache-storage-section-invalidation

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage-section-invalidation

Strictly necessary

Dufry

Used to optimize the loading speed on the website. This is done by pre-loading some procedures in the visitor´s browser

Persistent

HTML

mage-cache-timeout

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-messages

Strictly necessary

Dufry

Necessary for the functionality of the website´s chat-box function

1 day

HTTP

mage-translation-file-version

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Session

HTTP

mage-translation-file-version

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Persistent

HTML

mage-translation-storage

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Session

HTTP

mage-translation-storage

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Persistent

HTML

PHPSESSID

Strictly necessary

Dufry

Preserves user session state across page requests

1 day

HTTP

product_data_storage

Strictly necessary

Dufry

Necessary for the compare-products function on the website

Persistent

HTML

recently_compared_product

Strictly necessary

Dufry

Necessary for the compare-products function on the website

1 day

HTTP

RT

Strictly necessary

LinkedIn

This cookie is used to identify the visitor through an application. This allows the visitor to login to a website through their LinkedIn application for example

6 days

HTTP

test

Strictly necessary

Dufry

Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website

Persistent

HTML

section_data_ids

Preferences

Dufry

Used in a context with the shopping cart functionality. Remembers any wish-list products and visitor credentials when checking out

1 day

HTTP

store

Preferences

Dufry

Determines the preferred language of the visitor. Allows the website to set the preferred language upon the visitor´s re-entry

1  year

HTTP

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_gid

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

collect

 

Performance

Google Analytics

Used to send data to Google Analytics about the visitor´s device and behavior. Tracks the visitor across devices and marketing channels

Session

Pixel

product_data_storage

 

Performance

Dufry

Determines which products the user has viewed, allowing the website to promote related products

1 day

HTTP

recently_compared_product_previous

 

Performance

Dufry

Necessary for the compare-products function on the website

1 day

HTTP

recently_viewed_product

 

Performance

Dufry

Determines which products the user has viewed, allowing the website to promote related products

1 day

HTTP

recently_viewed_product_previous

Performance

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

1 day

HTTP

_boomr_akamaiXhrRetry

Marketing

Dufry

Collects information on user preferences and/or interaction with web-campaign content. This is used on CRM campaign platform used by the website owners for promoting events or products

Persistent

HTML

_fbp

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

_gcl_au

Marketing

Google AdSense

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services

3 months

HTTP

AA003

Marketing

atdmt.com

Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website

3 months

HTTP

ads/ga-audiences

Marketing

Google

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor´s online behaviors across websites

Session

Pixel

all

Marketing

Dufry

Tracks the user´s interaction with the website´s search-bar-function. This data can be used to present the user with relevant products or services

Persistent

HTML

ATN

Marketing

atdmt.com

Targets ads based on behavioral profiling and geographical location

2 years

HTTP

_bkrmk

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect session information

24 hours

 

_bkrmku

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect user information

10 years

 

_bkrmkt

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect information related to event tracking

24 hours

 

eng_mt

Marketing

Dufry

Tracks the conversion rate between the user and the advertisement banners on the website. This serves to optimize the relevance of the advertisements on the website

Persistent

HTML

fr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

https://cx.atdmt.com/

Marketing

atdmt.com

Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers

Session

Pixel

MUID

Marketing

Microsoft/Bing.com

Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronizing the ID across many Microsoft domains

1 year

HTTP

pixel

Marketing

outbrain.com

Unclassified

Session

Pixel

recently_compared_product

Marketing

Dufry

This cookie is used to determine which products the visitor has viewed. This information is used to promote related products and optimize ad-efficiency

Persistent

HTML

Recently_compared_product_previous

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

recently_viewed_product

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

recently_viewed_product-previous

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

tr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

Session

Pixel

trctestcookie

Marketing

Dufry

Detects whether partner data synchronization is functioning and currently running. This function sends user data between third party advertisement companies for the purpose of targeted advertisements

Session

HTTP

used

Marketing

Dufry

Tracks the user´s interaction with the website’s search bar function. This data can be used to present the user with relevant products or services

Persistent

HTML

_uetsid

Unclassified

Dufry

Unclassified

1 day

HTTP

_uetsid

Unclassified

Dufry

Unclassified

Persistent

HTML

_uetsid_exp

Unclassified

Dufry

Unclassified

Persistent

HTML

 

Privacy Notice

 

1. Introduction

This Privacy Notice describes the way we treat all the personal data you provide or that we have obtained through our Dufry Websites and Applications and in our Stores.

  Summary of provisions:

                                                                                                      

2. Controller of Personal Data, Sources of Personal Data and What Personal Information about Customers do Dufry Websites and Applications collect?

  • Controller and Processors of Personal Data

Dufry International AG and the local Dufry entity which owns the local Store that you are visiting or from whom you are purchasing goods are joint controllers of the personal data that you (as data subject) provide us or we received in our Stores and Dufry Websites and Applications.

  • Types of Personal Data collected and Sources of Personal Data

We collect personal data directly from our customers through Dufry Websites and Applications and our Stores.

We collect the following types of personal data about you from the following sources:

Information that you provide to us: We receive and store any information you enter on Dufry Websites and Applications and Stores or give us in any other way such as during registration, accessing your account or profile, submitting queries or as part of a survey or competition or utilising gift coupons or customer support or communicate with us or purchasing in Stores or using our products or services.

Due to such actions, you may supply us with your (i) name, postal address, email address, phone numbers, (ii) data necessary to process your payment (including the credit card/payment instrument  information and personal security code associated with your credit card) for Store purchases or  on line purchase of gift vouchers, to reserve purchases (under the Dufry Reserve & Collect Websites), to apply for a refund,  or to communicate with customer services regarding a refund to the credit card/payment instrument, (iii) flight departure/destination, flight date and delivery address for the subscriber and airport location to collect any pre ordered reserve & collect products or make purchases of our products and services in Stores.  Demographical data such as your age, gender, country, nationality, preferred language, passport number and citizenship, date of birth, country of residence, country of registration to Dufry Websites and Applications, purchases history and  other travel information including travel date, preferred departure airport and airline loyalty membership details are also collected. You must hold a valid flight ticket to be able to make duty free or duty paid purchases from Dufry. Such information is collected to meet our contractual obligations with airport authorities and legal obligations towards customs and other regulatory authorities.

When you register for membership, subscribe for services or the newsletter or other marketing communications including blogs or customer comments or use the Dufry Websites and Applications or purchase in our Stores, we collect log in details, passwords, any password questions and hints, similar security information used for authentication and account access is also collected for the access into your personal account and profile and to utilise the Reserve and Collect elements  or the RED customer loyalty elements of  Dufry Websites and Applications or  in our Stores.

You can choose not to provide certain information, but then you might not be able to utilise many of the features of the Dufry Websites and Applications. See What Are Your Choices section below.

Information collected automatically through interaction with usOnly if you agree, we receive and store information  where you interact with us through using our products and services, including online technologies (ie. Cookies) and receiving error reports or usage data from software applications on your devices online or via Wi-Fi communications in Stores.

 

We collect and analyse device, connectivity and configuration data including the Internet protocol (IP) address used to connect your computer or device to the internet as described in the Online Technology and Cookies section below.

We may operate CCTV in our Stores and collect video footage and images of you and others when you visit our Stores (including your/their location and physical appearance). For more information please contact the Store staff.

 

Mobile or Dufry Applications: When you choose to use or download Dufry Websites and Applications or allow connectivity via WiFi connections to your device, we receive information about your location and mobile device, including a unique identifier for your personalised device, your GPS data or wireless networks data (WLAN). Location data is neither stored nor transmitted to third parties.  If you agree with the localisation function, we can provide you with location-based services including advertising, search results and personalised content. When you are near one of our Stores, then we can use push email communications to you if you have provided your consent to receive such communications and advertising.

Most mobile devices allow you to turn off location services. For more information, see What are Your Choices section below.

E-Mail Communications: To provide more personalised and interesting email communications, we receive a confirmation when you open email from Dufry Websites and Applications or your device is near one of our Stores, if your computer or device supports this capability and if you have agreed with the localisation function though your device. If you choose not to receive any emails or other mail from us, please adjust your customer communication preferences in your account profile.

Information from other Sources: We receive information about you from other sources and add it to our account information. The third party sources include:

  • Updated delivery and contact address data from third parties which are used to update our records and deliver your next purchase more easily;
  • Social networks when you grant permission to Dufry Websites and Applications to access your data on one or more networks;
  • Service providers that help us determine a location based on your IP address to allow customisation of certain products to your location;
  • Our partners which we offer co-branded services or conduct joint marketing activities;
  • Publicly-available sources from open government databases or other data in the public domain;
  • Information (including CCTV footage and images, as the case shall be) from third parties including the police, tribunals, courts, regulators, airports or other authorities in connection with security incidents or actual or suspected unlawful acts, which may include information relating to actual, alleged or suspected criminal offences.
  • Your employment status with your current employer, which is used to either activate or deactivate your employee discount.

 

3.  Lawful basis and purposes for processing and using your personal data

Lawful purposes

Your personal data is processed by the Group on the basis of a lawful “justification” for such processing, to the extent required by law. In the majority of cases, the processing of your personal data will be justified on one of the following bases:

  • It is provided for in your contract of providing products and services requested by you to be provided by us;
  • It is necessary for us to comply with a legal obligation;
  • It is with your freely provided unequivocal and informed consent for specified processing purposes;
  • It is necessary to protect your or someone else’s life; or
  • It is in our legitimate interests as a business and as your supplier of contractually requested goods, and our interests are not overridden by your interests, fundamental rights or freedoms including legitimate interests as set out below.

The processing of personal data relating to actual, alleged or suspected criminal offences and convictions will be justified by one of the above bases and normally one of the following special conditions:

  • It is necessary for the purposes of preventing or detecting crime or other unlawful acts;
  • It is necessary to protect the public against dishonesty; or
  • We have obtained consent from the relevant individuals involved for the processing.

 

Purposes of processing personal data

We obtain, use, disclose and otherwise process personal data about customers, based on the execution of a contract to:

  • process transactions they request, including e-commerce Reserve and Collect selection and mobile transactions;
  • process information from the RED loyalty programme to verify the identity of the cardholder is the owner of the RED loyalty card and to ensure that the collection or redemption of RED points and confirm the status of a customer to allow for the correct discount to be applied to the sales of goods purchased in Stores or goods reserved for collection under the Reserve & Collect application and purchased in person in Stores;

 This information will enable us to provide access to all areas of the loyalty programme including the employee discount, the Reserve and Collect and Red by Dufry applications contained in Dufry Websites and Applications.

  • review and collect data from the boarding pass, nationality, destination and holder of the valid boarding pass to ensure that the passenger is part of the travelling public to allow Dufry or the Group to provide duty free goods under the terms of the contractual agreement with our landlords or airport authorities;
  • provide payment services including credit cards for online purchases and in Stores purchases;
  • provide goods and services to the customers that they have requested (ie provided an email address to allow the regularly newsletter to be provided to the customer);
  • protect the log in details of the subscribers and system integrity of the Dufry Websites and Applications;
  • communicate with you and personalize our communications with you. i.e. respond to your queries or accommodate your preferences and registration for program membership. We communicate with you by email or phone or SMS to inform you about our services, how to keep your subscription or account active, to communicate regarding a refund or customer inquiry or assisting with web site or Dufry Websites and Applications access or technical queries;
  • to carry out your contractual transactions with us and to provide our products (including the reserving of and pre-selection of duty free products listed in the Reserve and Collect website for collection at the requested Store) to you as requested by you. This includes using your personal information to register or subscribe to any services provided thorough Dufry Websites and Applications; fulfil our legal obligations;  

We also collect personal data to comply with legal obligations, especially the following:

  • passenger name, boarding card to ensure that the consumer reserving the products is a valid traveller to meet our contractual obligations to our landlord and long term concession agreement as well to allow the calculation of the VAT or similar tax allowances to be calculated for the customs authorities; comply with legal obligations, policies and procedures and for internal administrative and analytics purposes; process information or claims in connection with incidents at Stores;
  • protect the rights or property or safety of Dufry Websites and Applications or Stores, including our customers and visitors; and
  • assist third parties including the police, tribunals, courts, regulators, airports or other authorities with their investigations or requests or to report security incidents or suspected or actual unlawful acts. This assistance is provided for the purposes of preventing or detecting unlawful acts, the apprehension or prosecution of offenders, protecting the safety of our customers or visitors or in connection with other lawful requests to disclose personal data that we received from or make to third parties (for example missing persons investigations).

Where we process your personal data on the basis of our legitimate interests, those will be our interests in:

  • Providing and improving the products we offer and perform essential business operations. This includes operating the products, maintaining and improving the performance of the products, developing new features, conducting research and providing customer support;
  • Protecting the security and safety of our products and our customers, to detect and prevent unlawful acts including fraud and to confirm the validity of the subscriber logging into Dufry Websites and Applications;
  • Using personal data for statistical and analytical purposes. Whenever reasonably possible we will anonymize such information before using it for statistical or analytical purposes. Such information is processed in the legitimate interests of Dufry International AG to maintain the efficiency, relevancy and availability of the Dufry Websites and Applications;
  • Effective management and operation of Dufry and the Group companies;
  • to maintain our business relationship, where you are a user or subscriber of our Dufry Websites and Applications;
  • improve Dufry Websites and Applications, Stores, quality of service and customers shopping experience;
  • Advertising : Sending you communications regarding our products, services, campaigns, special offers promotions, contests and customer surveys, newsletters related to Dufry Websites and Applications and Stores and  to provide invitations to attend events;
  • to commence, protect or defend Dufry in actual or threatened legal proceedings.

 

Finally, if you have provided your consent via the Dufry Websites or Applications , we will process your personal data on the basis of consent to:

  • Provide you with targeted advertising based on your purchase history (including items purchased, abandoned baskets, day and store of purchase), and profile (date of birth, gender, country of residence, country of registration, nationality, RED status);
  • Provide you with targeted advertising based on the travel information you provide us (and including travel date, preferred departure airport, airline loyalty membership details), by answering the customers surveys you may receive from us from time to time;
  • sending or making promotional offers on behalf of other companies that offer travel related servicesbut if we do this, then we do not give that business your personal data.

 

4. Sharing  your Personal Data

We will not transfer or disclose your personal information, other than as set out below:

  • Effective management and operation of Dufry and the Group companies, and only when certain services are centralized;
  • to third party service providers (companies or individuals) that we employ to perform functions on our behalf such as fulfilling orders, delivering to retail locations or Stores, sending postal mail and email, removing repetitive information from customer lists, analysing data, providing marketing assistance, providing search results and links, processing credit card payments and providing customer service. These providers have access to personal information needed to perform their functions, but may not use it for other purposes and include the following categories of data recipients:

(i) advertising and media consultants,

(ii) market research consultants;

(iii) providers of technical services;

(iv) website designers and developers;

(v) cloud computing service providers;

(vi) electronic storage providers;

(vii) customer services; and

(viii) with your current employer, as part of our ongoing checks to verify that you still remain eligible for the employee discount.

  • in releasing account and other personal data to comply with the law, undertaking litigation or other proceedings or to enforce or comply with or apply our terms of use and other agreements, or protect the rights, property or safety of Dufry Websites and Applications or Stores. This includes exchanging information with other companies for fraud prevention and credit risk reduction;
  • to comply with legal or regulatory requirements or obligations in accordance with applicable law, a court order or a subpoena;
  • with regulatory authorities, airport authorities, Dufry International AG and Group landlords and concession partners and customs and tax authorities to show the calculation of such tax exemptions;
  • to data analytical firms, Google Analytics Inc.;
  • in an emergency, such as to safeguard the life, health, or property of an individual; or
  • to third parties including the police, tribunals, courts, regulators, airports or other authorities to assist them with their investigations or requests or for us to report security incidents or suspected or actual unlawful acts. This includes allowing such third parties to access and take copies of CCTV images or other video footage where CCTV cameras are in place and  these relate to such incidents and acts;

 

5. Storing  your Personal Data

Your personal information you have provided to the controller will be located in a Dufry  AG cloud based customer management database software tool located within data centres maintained in the territories of the EEA, the purpose of which is to manage the business relationship with you, in accordance with the provisions of the data protection laws.

Dufry International AG will manage the customer relationship with you and any marketing materials can be provided, by Dufry as Controller.

 

6. Security of personal data

Your personal data will be secured by taking security measures that are commensurate with the sensitivity of the personal data processed. To this end, Dufry and all Group entities maintain appropriate physical, technical, and administrative security measures with a view to protecting personal data against theft; accidental loss; unauthorised alteration; unauthorised or accidental access, processing, erasure, use, disclosure or copying; and/or accidental or unlawful destruction.

When we have provided (or you have chosen) a password allowing access to certain benefits of the Dufry Websites and Applications, you are responsible for safeguarding it and keeping it confidential and you undertake not  to allow it to be used by third parties. Unfortunately, the transmission of information thorough the internet is not completely secure. Although we will take all reasonable commercial measures to protect your personal data, we cannot guarantee the security of any personal information or data you disclose on line. You accept the inherent security implications of using the internet and to the extent permitted by law, we will not be responsible for any breach of security, unless we have been acting with gross negligence and only within the limitations as set out in the terms and conditions of use for Dufry Websites and Applications.  

 

7. Transfers of Data Outside of Your Country

Your personal data (as described above) may be transferred to other Group entities or to third parties described  above, only to the extent required for Dufry International AG and group companies to perform their obligations to you, or for you to access your Dufry Websites and Applications, or for the purposes described above in this Notice, provided such purposes are in accordance with applicable laws.  In particular:

 

  • Your profile and contact information contained in systems such as corporate communications systems, customer relationship management databases or directories will be accessible to all marketing, sales and customer support or customer care employees of Group companies worldwide.

 

  • Your personal data may be transferred to or accessed by Group employees located inside or outside your country, and/or a person or company that is not part of the Group located in or outside your country, on a need-to-know basis. Transfers outside the UK and EU may be made pursuant to the European Commission's Standard Contractual Clauses ("SCC") or other legally acceptable mechanisms which ensure an adequate level of protection. As permitted by law, you may be entitled, upon request to the Global Data Protection Co-Ordinator, to be informed about the appropriate safeguards that have been taken to protect your Personal Data for transfer outside the UK and EU.

 

  • Dufry International AG may process your personal data as a controller in order to administer and provide you with products and services that you requested, to administer global sales and customer programs, promotional and marketing activities and surveys, competitions and coupon and gift promotions, communications with customers, advertising campaigns with us, to manage sales and customer relationships and to prepare sales and customer relationship management and customer support reporting, consistent with the terms of this Notice. Dufry International AG is located in Switzerland, a country that benefits from an adequacy decision of the European Commission and the UK that has found Swiss law to afford adequate protection to personal data.
  • Transfers may be made to respond to law enforcement requests or discovery procedures, or where required or permitted by applicable laws, court orders, government regulations, or government authorities (including tax and employment). Such transfers may entail access by courts or governmental authorities outside your country, after having ensured that only your minimal necessary data is disclosed and transferred, or that such data is de-identified or that, where possible, appropriate stipulative court orders have been issued.

 

A list of the countries located outside the EU to which your Personal Data may be transferred, and an indication of whether they have been determined by the European Commission to grant adequate protection to Personal Data, can be found at https://ec.europa.eu/info/strategy/justice-and-fundamental-rights/data-protection/data-transfers-outside-eu_en. For the UK, you can find up to date information on countries that have been granted adequate protection to personal data by visiting the ICO website (www.ico.org.uk).

Transfers of Personal Data in accordance with this Section 7 are based on the same legal bases as applicable for the respective purposes of processing as set out  above.

 

8. Retention of personal data

Dufry data retention policy requires that personal data be retained for no longer than required to fulfil the purposes for which it was collected. In general, personal data, or records containing personal data, will be retained for periods of time required in accordance with applicable legal, tax, or accounting obligations. In specific circumstances, and in accordance with applicable law, Dufry may retain your personal data for longer periods of time (such as for the duration of the relevant statute of limitation) so that we have an accurate record of our dealings with you or to protect the legitimate interests of Dufry International AG or local Dufry entity name, who owns this Dufry Website or Application.  In all cases, where your information is no longer required, Dufry will ensure it is disposed of in a secure manner.

 

9. Minors

Dufry Websites and Applications do not provide products and services to children. Whilst we may sell toys and confectionary which may appeal to children, any reservation for our products and services can only be provided to adults over the age of 18 years old. We do not knowingly collect personal information from children under the age of 18 years, without the consent of the child’s parent or guardian. Accordingly, the parent will need to complete and submit a fully completed and signed Parental Personal Data Consent Form along with evidence of the person’s identity, to the email address: privacy@dufry.com.

 

10.  Online Technologies including Cookies

  • Cookies

This website uses cookies and/or similar technologies that store and retrieve information when you browse. A “cookie” is a small text file that identifies your mobile device and/or computer on our server. 

In general, these technologies can serve many different purposes, such as, for example, recognizing you as a user, obtaining information about your browsing habits, or customizing the way content is displayed. The specific uses we make of these technologies are described below.

If you want more information about how it works, we recommend you visit www.allaboutcookies.org and www.youronlinechoices.eu

  • Authorization for the use of cookies

To use cookies on Dufry Websites and Applications, we request your express consent to accept cookies on the Dufry Websites and Applications by clicking "ACCEPT ALL" in the notice at the bottom of the Dufry Websites and Applications, so that they may be downloaded to your mobile device and/or computer hard drive.

Once you have provided your consent to the use of cookies, the file is added, and the cookie helps analyse web traffic and allows us to know when you visit a particular website. Cookies allow applications to respond in a personalized way. The web application can tailor its operation to your needs, collecting your likes and dislikes and remembering information about your preferences. We use traffic log cookies that identify which applications and/or pages are being used. This helps us analyze data about web traffic and improve our Dufry Web Sites and applications in order to tailor them to customer needs.

Overall, cookies help us deliver improved Dufry Web sites and applications, allowing us to monitor which pages you find useful and which you do not. A cookie in no way gives us access to any information on your mobile device or computer or any other information about you, other than the data you choose to share with us. You can choose to accept, configure and/or customize your selection through the "CMP”.

Most web browsers automatically accept cookies, but you can change your browser's settings to reject cookies, if you wish. Cookies, including those already established, can be deleted from your hard drive, following the instructions that are described below.

  • Types of cookies used and their purpose

To access the complete list of cookies we use on this Website, please refer to the last section “Cookies Inventory” of this policy.

The cookies are then classified according to a series of categories. However, it is important to note that the same cookie may be included in more than one category.

Depending on the entity that manages the equipment or domain from which the cookies are sent and how the data obtained is processed, we can distinguish:

  • First-party cookies: Are those that are sent to the user's terminal equipment from a computer or domain managed by the editor itself and from which the service requested by the user is provided.
  • Third-party cookies: These are those that are sent to the user's terminal equipment from a computer or domain that is not managed by the editor, but by another entity that processes the data obtained through cookies.

Depending on the time they remain activated in the terminal equipment, we can distinguish:

  • Session cookies: These are types of cookies designed to collect and store data while the user accesses a website. They are often used to store information that is only of interest to be retained for the provision of the service requested by the user on a single occasion (e.g. a list of products purchased).
  • Persistent cookies: These are a type of cookie in which the data is still stored on the terminal and can be accessed and processed for a period defined by the person responsible for the cookie, and which can range from a few minutes to several years.

Depending on the purpose for which the data obtained through cookies are processed, we can distinguish between:

  1. a) Strictly necessary cookies: are those that, managed by us or by third parties, allow you to browse through the Website, platform or application and the use of the different options or services that exist therein, as well as, for example, controlling traffic and data communication, to identify the session, access restricted access parts, to remember the elements that make up your order, to manage the payment, control fraud linked to service security, apply for enrolment or participation in an event, enable dynamic content or share content through social networks.
  2. b) Preference cookies: the cookies that allow us to remember your information so that you can access the service with certain characteristics that may differentiate your experience from that of other users, such as, for example, the language, the number of results to display when you perform a search, the appearance or content of the service depending on the type of browser through which you access the service or the region from which you access the service, etc.
  3. c) Performance cookies: those that, processed by us or by third parties, allow us to quantify the number of users and thus perform the statistical measurement and analysis of the use made by the users of the service offered. To do this, we analyse your browsing on our website in order to improve the offer of products or services we offer.

We use Google Analytics cookies to collect statistical data on users' activity on the Website and thus be able to improve the services provided to users.

The information generated by Google cookies about your use of Dufry websites and applications, including the IP address, may be transmitted and stored by Google on servers located in the United States. Google may use this information to evaluate how you use the website, to compile website application activity reports for us and to offer other services concerning website activity and internet use. Google may transfer this information to third parties when required to do so by law, or when said third parties process information on behalf of Google. Google will not associate your IP address with any other data in Google’s possession. The Google website has more information about Google Analytics, as well as a copy of Google’s privacy policy pages.

  1. d) Marketing cookies: those cookies that, processed by us or by third parties, allow us to analyze your Internet browsing habits so that we can show you advertising related to your browsing profile.

We use Google, GoogleAdWords, Google DoubleClick, bing.com, atdmt.com, demdex.net, taboola.com, outbrain.com, eversttech.com, Blueknow and Facebook cookies, among other, to manage the spaces that Dufry advertising serves and accesses. These cookies allow us to measure the effectiveness of our online campaigns, provide information of interest to you and offer you advertising content of your choice. Information generated by some of these cookies about your use of Dufry Web Sites and applications, including your IP address, may be transmitted to and stored by the third party on servers located in the United States. Through its Privacy Policies you can obtain more information about how cookies work and how they are used.

  1. e) Unclassified cookies: these are cookies that are in the process of being classified.

 

(d) Browser settings

  1. a) If you wish, you can change your browser settings and choose the storage options or access to cookies, as well as activate, disable or delete them. These options must be applied following the instructions in your browser:
  • Google Chrome: https://support.google.com/chrome/answer/95647?hl=es
  • Internet Explorer: https://support.microsoft.com/es-es/help/17442/windows-internet-explorer-delete-manage-cookies#
  • Mozilla Firefox: https://support.mozilla.org/es/kb/cookies-informacion-que-los-sitios-web-guardan-en-
  • Safari: https://support.apple.com/es-es/guide/safari/sfri11471/mac
  • Android:https://support.google.com/accounts/answer/32050?co=GENIE.Platform%3DAndroid&hl=es
  • Apple (iOS): https://support.apple.com/es-es/HT201265
  1. b) Social media connection and plug-ins:

On some websites in our online catalog we use social media plug-ins www.facebook.com ("Plug-in"), operated by Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (“Facebook”).

Online catalog websites in the Dufry websites and applications may contain a plug-in and will be marked with a clearly visible Facebook logo (i.e., a white "f" in a blue icon) or may also display the "Facebook Plug-in".

If you access a website like this, containing the aforementioned plug-in, your browser will establish a direct connection to Facebook servers, and Facebook will transmit the plug-in content directly to your browser.

If you are registered on Facebook and you have logged in to your Facebook user account, you will receive any information you access on the corresponding website by integrating the plug-in. If you actively use the plug-in, either by clicking the “Like” or “Share” button, or by leaving a comment on the website in question, the corresponding information will be directly sent from your browser to Facebook and used on Dufry websites and applications.

To prevent Facebook from collecting the aforementioned information about you when accessing the website, you must follow the instructions contained in the settings on the Facebook website and/or log out of the Facebook website before visiting the website in question on Dufry websites and applications. You should also delete all Facebook cookies contained in your browser.

The purpose and scope of the data collection and subsequent use of data by Facebook, as well as the rights and setting options you have to protect your Personal Data or private space, can be found in the Facebook Privacy Policy. We assume no responsibility for the content of the aforementioned websites, nor the Facebook Privacy Policy.

On some of our websites, applications and \or mobile solutions, we use social plugins of the social network www.Linkedin.com (“Plug In”), which is operated by Microsoft Corporation, One Microsoft Way, Redmond, 98052 – 6399, USA (“LinkedIn”).

 

The websites and\or mobile solutions in Dufry Websites and Applications can contain a plug in are marked with a clearly visible LinkedIn logo or the addition of “LinkedIn Social Plugin”.

If you access a website and\or mobile solutions like this containing such a plugin, your browser will establish a direct connection with the LinkedIn servers and LinkedIn will transmit the content of the plugin directly to your browser.

If you are registered with LinkedIn and are logged into your LinkedIn user account, LinkedIn will receive the information that you accessed the respective website and\or mobile solutions by the integration of the plugin. If you use the plugin actively by activating the “share” button or placing a commentary on the respective website, the corresponding information will be transmitted from your browser directly to LinkedIn and used there in Dufry Websites and Applications.

In order to avoid LinkedIn collecting the above information about you when you access such a website, please following the instructions in settings on the LinkedIn website and/or log out of the LinkedIn website, before visiting the respective website and\or mobile solutions in Dufry Websites and Applications. Additionally, you should delete any LinkedIn cookies present from your browser.

The purpose and extent of data collection and further use and usage of data by LinkedIn as well as your rights and setting options in this regard for the protection of your Personal Data or private space can be found in the LinkedIn Privacy Policy.  We assume no responsibility for the contents of the websites and\or mobile solutions and the LinkedIn Privacy Policy.

 On some of our websites, applications and\or mobile solutions, we use social plugins of the social network youtube.com or other networks found at www.google.com (“Plug In”), which is operated by Google. Inc.,1600 Amphitheatre Parkway, Mountain View, CA 940439 United States.

The websites and\or mobile solutions in Dufry Websites and Applications can contain a plug in are marked with a clearly visible Google logo) or the addition of  “Google Social Plugin”).

If you access a website like this containing such a plugin, your browser will establish a direct connection with the Google servers and Google will transmit the content of the plugin directly to your browser.

If you are registered with Google and are logged into your Google or gmail user account, Google will receive the information that you accessed the respective website and\or mobile solutions by the integration of the plugin. If you use the plugin actively by activating the “share” button or placing a commentary on the respective website and\or mobile solutions, the corresponding information will be transmitted from your browser directly to Google and used there in Dufry Websites and Applications.

In order to avoid Google collecting the above information about you when you access such a website and\or mobile solutions, please following the instructions in settings on the Google websites and/or log out of the Google website, before visiting the respective website and\or mobile solutions in Dufry Websites and Applications. Additionally, you should delete any Google cookies present from your browser.

The purpose and extent of data collection and further use and usage of data by Google Analyticals)  as well as your rights and setting options in this regard for the protection of your Personal Data or private space can be found in the Google Privacy Policy.  We assume no responsibility for the contents of the websites and\or the mobile solutions and the Google Privacy Policy.

(e) Opposing to the installation of cookies from third party providers

The user may, at any time, reject the installation of a certain type of cookies, such as advertising and third-party cookies. Some of our providers have a direct system to oppose the installation of their Cookies.

Below you will find a list of providers and links (you will easily find the “opt-out” button to object):

- Youtube and Google Analytics (“opt-out”): https://tools.google.com/dlpage/gaoptout?hl=None

- ADOBE Analytics and Marketing & Audience Manager (“opt-out”): http://www.adobe.com/es/privacy/opt-out.html

Keep in mind that if at any time you delete the cookies from your browser, your opt-out preferences from the previous providers may be deleted, so you will have to oppose their installation again.

(f) Warning about the deletion of cookies

You may delete and block all cookies from this site, but part of the site will not work or the quality of the website may be affected.

If you have any questions about our cookies policy, you can contact this page through our Contact channels.

(g) Revision

These lists will be updated as quickly as possible as the website services offered on the website change or evolve. However, occasionally during this update, the list may no longer include a cookie, although it will always refer to cookies for purposes identical to those recorded in these lists.

As a visitor, subscriber or continuing to access the Dufry Websites and Applications or via the WiFi network or location services in Stores, you consent to use of cookies and other online technologies as detailed in this Section and in accordance with this privacy statement. Dufry and its third party marketing partners may use cookies, invisible pixels and web beacons to obtain information about you while visiting the Dufry Websites and Applications and our Stores.

 

11.  What are your rights?

You have the right under applicable law to access, obtain a copy and correct personal data concerning you, subject to limited exceptions that may be prescribed by applicable laws.  Where justified and mandated by applicable law, you may also require that your personal data be deleted or blocked, or you may be entitled to obtain information about the processing of your data, or object to further processing of your data. 

 

In the event your personal data is processed on the basis of your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You can do this by (i) in some cases deleting the relevant Personal Data from the relevant IT system (although note that in this case it may remain in back-ups and linked systems until it is deleted in accordance with our data retention policy) or (ii) contacting your Global Data Protection Co-Ordinator.

You also have the right to be informed about how your personal data is handled and from whom we receive your data.

 

As permitted by law, you also have the following additional rights:

  • Data portability - where we are relying upon your consent or the fact that the processing is necessary for the performance of a contract to which you are party as the legal basis for processing, and that personal data is processed by automatic means, you have the right to receive all such personal data which you have provided to Dufry or the Group in a structured, commonly used and machine-readable format, and also to require us to transmit it to another controller where this is technically feasible.
  • Right to restriction of processing - you have the right to restrict our processing of your personal data where:
    • you contest the accuracy of the personal data until we have taken sufficient steps to correct or verify its accuracy;
    • where the processing is unlawful but you do not want us to erase the personal data;
    • where we no longer need your personal data for the purposes of the processing, but you require such personal data for the establishment, exercise or defence of legal claims; or
    • where you have objected to processing based on legitimate interest from Dufry  (see below) and pending verification as to whether Dufry or the Group has compelling legitimate grounds to continue processing.

 

Where your personal data is subject to restriction in this way we will only process it with your consent or for the establishment, exercise or defense of legal claims.

  • Right to object to processing justified on legitimate interest grounds - where we are relying upon legitimate interest to process personal data, then you have the right to object to that processing. If you object, we must stop that processing unless we can either demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms or where we need to process the personal data for the establishment, exercise or defence of legal claims. Where we rely upon legitimate interest as a basis for processing we believe that we can demonstrate such compelling legitimate grounds, but we will consider each case on an individual basis.

 

  • Right to object to processing for marketing purposes – you have the right to object to any  processing of your data for marketing purposes (including profiling). Additionally, see What are Your Choices?

 

Please contact us by submitting a Data Subject Access Request Form (available upon request) in writing or by email to either of the addressees listed below.

Some of these rights may not apply in certain circumstances. For example, you may not be entitled to know we have shared your personal data with the police or to receive a copy of your personal information if it relates to a police investigation and we have been informed by the police that notifying you or providing you with a copy will prejudice their investigations.

 

Dufry has appointed a Global Data Protection Co-Ordinator who may be contacted securely and confidentially at the following E – Mail address : privacy@dufry.com.  Alternatively, you can send your  Data Subject Access Request Form, written comments, questions or concerns to

 

Dufry International AG

Brunngässlein 12

Basel, 4052

Switzerland

Attention : Global Data Protection Co-Ordinator

 

12.  What are Your Choices ?

Dufry Websites and Applications provide you with access to a range of information about your account and your interactions with us. To ensure that your personal data is accurate and up to date, we encourage you to regularly review and update your information as appropriate, if or your contact details or address has changed. If you have subscribed to Dufry Websites and Applications, especially the Red by Dufry application or the Reserve and Collect  websites, then you can either access your account and make the changes or request the changes are made by sending an email request along with evidence of your identity to privacy@dufry.com.

We like to inform you about our products and services and those of our partners and to also send you surveys, promotional materials and invitations to events, to participate in competitions or receive coupons or gift certificates as well as communications on your birthday or other special events. If you choose not to receive such communications or modify what method of communications such as SMS, email, letter or phone  we use to contact you or you choose not to agree to the use of cookies or other on line technologies, then you to opt out of such activities by submitting the opt out provision which is the unsubscribe link to the website to allow the customer to unsubscribe (if an electronic communication), or for all other  non-electronic communications,  by submitting  an objection email or letter to specify your preferences to privacy@dufry.com. You can change your preferences or choices at any time or provide a new consent to such activities by providing  a signed consent form consenting to the use of cookies, advertising materials or preferred method of communication to privacy@dufry.com.

 

13.  Changes to our Privacy Notice

Changes and amendment to the terms of this Privacy Notice can be made at any time and shall apply as soon as they are published on any Dufry Websites and Applications. Should you not agree to any changes or amendments, then you should refrain from continuing to use our services or products or access Dufry Websites and Applications or our Stores.

 

14.  Where to make a Data Protection complaint?

You have the right to lodge complaints pertaining to the processing of your personal data with the relevant data protection supervisory authority.


Cookies Inventory

DUFRY Website (www.dufry.com)

Name

Category

Provider

Purpose

Expiry

Type

ak_bmsc

Strictly necessary

tools.investis.com

This cookie is used to distinguish between humans and bots. This is beneficial for the website, in order to make valid reports on the use of the their website

1 day

HTTP

AWSELB

Strictly necessary

irs.tools.investis.com

Used to distribute traffic to the website on several servers in order to optimize response times

Session

HTTP

AWSELBCORS

 

Strictly necessary

irs.tools.investis.com

Registers which server-cluster is serving the visitor. This is used in context with load balancing. In order to optimize user experience

Session

HTTP

bm_sv

 

Strictly necessary

tools.investis.com

Used in the context with the website’s BotManager. The BotManager detects, categorizes and compiles reports on potential bots trying to access the website

1 day

HTTP

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate  statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_gid

 

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

collect

 

Performance

Google Analytics

Used to send data to Google Analytics about the visitor´s device and behavior. Tracks the visitor across devices and marketing channels

Session

Pixel

r/collect

 

Performance

Doubleclick.net

This cookie is used to send data to Google Analytics about the visitor´s deice and behavior. It tracks the visitor across devices and marketing channel.

Session

Pixel

 

RED BY DUFRY

Name

Category

Provider

Purpose

Expiry

Type

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate  statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_git

 

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

pagevisit

 

Performance

r1.trackedweb.net

Registers statistical data on users ‘behavior on the website. Used for internal analytics by the website operator

Session

Pixel

_fbd

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

_gcl_au

Marketing

Google AdSense

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services

3 months

HTTP

AA003

 

Marketing

atdmt.com

Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website

3 months

HTTP

ads/ga-audiences

Marketing

Google

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor´s online behavior across websites

Session

Pixel

ATN

 

Marketing

atdmt.com

Targets ads based on behavioral profiling and geographical location

2 years

HTTP

dmSessionID

Marketing

Dufry

 

Collects information on what products the visitor has viewed and the content of the shopping-cart. This is used to increase the website conversion rate through targeted advertisement and product promotions through emails

1 day

HTTP

fr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

https://cx.atdmt.com/

Marketing

atdmt.com

Sets a unique ID for the visitor that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitate real-time bidding for advertisers

Session

Pixel

IDE

 

Marketing

Google/ Doubleclick.net

Used by Google DoubleClick to register and report the website user´s actions after viewing or clicking one of the advertiser´s ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user

1 year

HTTP

pagead/1p-user-list/#

Marketing

Google

Unclassified

Session

Pixel

r/collect

Marketing

Google/ Doubleclick.net

The cookie is used to send data to Google Analytics about the visitor´s device and behavior. It tracks the visitor across devices and marketing channels

Session

Pixel

recordID

Marketing

Dufry

Collects information on what products the visitor has viewed and the content of the shopping-cart. This is used to increase the website´s conversion rate through targeted advertisement and product promotions through emails

1 year

HTTP

test_cookie

Marketing

Google/ Doubleclick.net

Used to check if the user´s browser supports cookies

1 day

HTTP

tr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

Session

Pixel

_rollupGA

Unclassified

Dufry

(Google Tag Manager)

Unclassified

2 years

HTTP

_rollupGA_gid

Unclassified

Dufry

(Google Tag Manager)

Unclassified

1 day

HTTP

identity

Unclassified

r1.trackedweb.net

Unclassified

Session

Pixel

 

RESERVE & COLLECT (www.shopdutyfree.com)

 

Name

Category

Provider

Purpose

Expiry

Type

AKA_A2 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

1 day

HTTP

form_key

Strictly necessary

Dufry

Ensures visitor browsing-security by preventing cross-site request forgery. This cookie is essential for the security of the website and visitor

Session

HTTP

mage-banners-cache-storage

 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

1 day

HTTP

mage-banners-cache-storage

 

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-banners-cache-timeout

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-cache-sessid

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage

 

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage

 

Strictly necessary y

Dufry

Used to optimize the loading speed on the website. This is done by pre-loading some procedures in the visitor´s browser

Persistent

HTML

mage-cache-storage-section-invalidation

Strictly necessary

Dufry

This cookie is used in context with load balancing. This optimizes the response rate between the visitor and the site, by distributing the traffic load on multiple network links or servers

1 day

HTTP

mage-cache-storage-section-invalidation

Strictly necessary

Dufry

Used to optimize the loading speed on the website. This is done by pre-loading some procedures in the visitor´s browser

Persistent

HTML

mage-cache-timeout

Strictly necessary

Dufry

This cookie is necessary for the cache function. A cache is used by the website to optimize the response time between the visitor and the website. The cache is usually stored on the visitor´s browser

Persistent

HTML

mage-messages

Strictly necessary

Dufry

Necessary for the functionality of the website´s chat-box function

1 day

HTTP

mage-translation-file-version

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Session

HTTP

mage-translation-file-version

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Persistent

HTML

mage-translation-storage

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Session

HTTP

mage-translation-storage

 

Strictly necessary

Dufry

Used in context with the language setting on the website. Facilitates the translation into the preferred language of the visitor

Persistent

HTML

PHPSESSID

Strictly necessary

Dufry

Preserves user session state across page requests

1 day

HTTP

product_data_storage

Strictly necessary

Dufry

Necessary for the compare-products function on the website

Persistent

HTML

recently_compared_product

Strictly necessary

Dufry

Necessary for the compare-products function on the website

1 day

HTTP

RT

Strictly necessary

LinkedIn

This cookie is used to identify the visitor through an application. This allows the visitor to login to a website through their LinkedIn application for example

6 days

HTTP

test

Strictly necessary

Dufry

Used to detect if the visitor has accepted the marketing category in the cookie banner. This cookie is necessary for GDPR-compliance of the website

Persistent

HTML

section_data_ids

Preferences

Dufry

Used in a context with the shopping cart functionality. Remembers any wish-list products and visitor credentials when checking out

1 day

HTTP

store

Preferences

Dufry

Determines the preferred language of the visitor. Allows the website to set the preferred language upon the visitor´s re-entry

1  year

HTTP

_ga

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

2 years

HTTP

_gat

Performance

Dufry

(Google Analytics)

 

Used by Google Analytics to throttle request rate

1 day

HTTP

_gid

Performance

Dufry

(Google Analytics)

Registers a unique ID that is used to generate statistical data on how the visitor uses the website

1 day

HTTP

collect

 

Performance

Google Analytics

Used to send data to Google Analytics about the visitor´s device and behavior. Tracks the visitor across devices and marketing channels

Session

Pixel

product_data_storage

 

Performance

Dufry

Determines which products the user has viewed, allowing the website to promote related products

1 day

HTTP

recently_compared_product_previous

 

Performance

Dufry

Necessary for the compare-products function on the website

1 day

HTTP

recently_viewed_product

 

Performance

Dufry

Determines which products the user has viewed, allowing the website to promote related products

1 day

HTTP

recently_viewed_product_previous

Performance

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

1 day

HTTP

_boomr_akamaiXhrRetry

Marketing

Dufry

Collects information on user preferences and/or interaction with web-campaign content. This is used on CRM campaign platform used by the website owners for promoting events or products

Persistent

HTML

_fbp

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

_gcl_au

Marketing

Google AdSense

Used by Google AdSense for experimenting with advertisement efficiency across websites using their services

3 months

HTTP

AA003

Marketing

atdmt.com

Collects information on user behavior on multiple websites. This information is used in order to optimize the relevance of advertisement on the website

3 months

HTTP

ads/ga-audiences

Marketing

Google

Used by Google AdWords to re-engage visitors that are likely to convert to customers based on the visitor´s online behaviors across websites

Session

Pixel

all

Marketing

Dufry

Tracks the user´s interaction with the website´s search-bar-function. This data can be used to present the user with relevant products or services

Persistent

HTML

ATN

Marketing

atdmt.com

Targets ads based on behavioral profiling and geographical location

2 years

HTTP

_bkrmk

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect session information

24 hours

 

_bkrmku

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect user information

10 years

 

_bkrmkt

Marketing

Blueknow.com

Abandoned cart recovery solution. Collect information related to event tracking

24 hours

 

eng_mt

Marketing

Dufry

Tracks the conversion rate between the user and the advertisement banners on the website. This serves to optimize the relevance of the advertisements on the website

Persistent

HTML

fr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

3 months

HTTP

https://cx.atdmt.com/

Marketing

atdmt.com

Sets a unique ID for the visitor, that allows third party advertisers to target the visitor with relevant advertisement. This pairing service is provided by third party advertisement hubs, which facilitates real-time bidding for advertisers

Session

Pixel

MUID

Marketing

Microsoft/Bing.com

Used widely by Microsoft as a unique user ID. The cookie enables user tracking by synchronizing the ID across many Microsoft domains

1 year

HTTP

pixel

Marketing

outbrain.com

Unclassified

Session

Pixel

recently_compared_product

Marketing

Dufry

This cookie is used to determine which products the visitor has viewed. This information is used to promote related products and optimize ad-efficiency

Persistent

HTML

Recently_compared_product_previous

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

recently_viewed_product

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

recently_viewed_product-previous

Marketing

Dufry

Collects information on which products have been viewed by the visitor. This is used for optimizing the specific visitor´s navigation on the website

Persistent

HTML

tr

Marketing

Facebook

Used by Facebook to deliver a series of advertisement products such as real time bidding from third party advertisers

Session

Pixel

trctestcookie

Marketing

Dufry

Detects whether partner data synchronization is functioning and currently running. This function sends user data between third party advertisement companies for the purpose of targeted advertisements

Session

HTTP

used

Marketing

Dufry

Tracks the user´s interaction with the website’s search bar function. This data can be used to present the user with relevant products or services

Persistent

HTML

_uetsid

Unclassified

Dufry

Unclassified

1 day

HTTP

_uetsid

Unclassified

Dufry

Unclassified

Persistent

HTML

_uetsid_exp

Unclassified

Dufry

Unclassified

Persistent

HTML

 

.