Privacy Policy and Cookies

Latest version:

Data protection information

Who is the data controller for the processing of your data?

The Data Controller for personal information collected and processed on our platforms ("platforms" refers to use of the MANGO website, app or the devices in our physical stores, as well as those derived from your relationship with MANGO) is PUNTO FA, S.L.(“MANGO”), with Corporate Tax ID no.B-59.088.948. You can contact MANGO via the following means:

  • Postal address:Customer Services, C/ Mercaders 9-11 (Polígono Industrial Riera Caldes), 08184 Palau-Solità i Plegamans (Barcelona).
  • E-mail:personaldata@mango.com

MANGO has appointed a Data Protection Officer who you may contact and/or raise any issue relating to the processing of your personal information by sending an e-mail to <u>dpo@mango.com</u> or by sending your query to the following postal address:DPO Office, Carrer dels Mercaders 9-11 (Polígono Industrial Riera Caldes), 08184 Palau-Solità i Plegamans (Barcelona), Spain.

What type of personal information does Mango collect and process?

MANGO may collect from your relationship and use of our services, the following data and/or data categories:i) identification and contact data; ii) personal information; iii) financial data, such as credit card data (PAN+CVV2), in compliance with PCI DSS standards, which will be used for payment processing whenever you purchase any of our items or, in the case of returns for transfers, the account number for which we need to process the refund of your purchase; iv) data observed in the purchasing of our products and consumer habits and preferences of our customers; v) user data of MANGO’s platforms.

For what purpose do we process your personal information and what is the lawful basis?

At MANGO we may process your personal information for the following purposes:

A) CREATION OF A USER ACCOUNT

  • Manage your registration, which will involve the creation of a MANGO user account. This account will allow you to centralise any issue relating to your user status, and give you access to certain functions available and reserved for those with said status. For example, having a user account will allow you to store certain information that may be used in future purchases and/or interactions with MANGO.

Furthermore, the creation of a user account will allow you to participate in the MANGO Likes You loyalty programme, in countries where it is available. Registration on this programme may result in discounts and/or benefits in the services of third-party collaborators, as well as discounts on your future purchases at MANGO. In this regard, we inform you that countries that dispose of the MANGO Likes You loyalty programme will publish this on their respective websites.

  • The lawful basis that legitimises the processing of your data for this purpose is the execution of a contract, understood as such the accepted Terms & Conditions.
  • At the time of account creation. The processing of your data is necessary to ensure compliance with the obligations and rights provided for in the Terms & Conditions.

B) PURCHASE OF MANGO PRODUCTS

Process the purchase of items via the different purchasing channels enabled by MANGO. This procedure consists of taking all the appropriate steps in order to manage your purchase and, wherever applicable, guarantee the correct delivery of your order, in addition to undertaking any procedure related to the sale of the item such as, for example, the management and issue of proof purchase documents such as the simplified electronic invoice, the sales or Tax Free invoice and, wherever applicable, managing the return of the items.

To do this, we may send you information about the status of the purchase by e-mail, SMS and/or any other channel available at any moment.

  • The lawful basis for the processing of your data for this purpose is the execution of a contract understanding as such the Conditions of Sale accepted at the moment of purchasing the items. The processing of your data is necessary to guarantee the fulfilment of the rights and obligations contained in the Conditions of Sale.

Management of the Mango Gift Card

  • The lawful basis for the processing of your data for this purpose is the execution of a contract understanding as such the Conditions of Use accepted at the time of purchasing the card. The processing of your data is necessary to guarantee the fulfilment of the rights and obligations contained in the Conditions of Use.

With regard to the processing of online purchases, MANGO, as data controller, will carry out the corresponding actions for the prevention, detection and control of abuse and fraud in the use of our services , which may result in the existence of automated decision making.

Said automated decisions shall consist of the analysis of behaviour in the payment process which, in general terms, will use data relating to the purchasing process and the purchase history, in order to determine whether the transaction may be considered fraudulent. This information will allow us to detect and try to prevent fraudulent practices in payment transactions, allowing us to reject purchases and consequently protect both you, as a data subject (in the case of identity theft), and MANGO as a service provider and data controller.

  • The lawful basis for the processing of your data to fulfil this goal is the legitimate interest of MANGO to analyse all the operations that occur in the payment process of the products it sells to ensure that no economic fraud will occur that impact negatively on itself or its customers. In this regard, we consider that there is a general interest for the processing to help generate, improve and maintain public confidence in the financial relationships developed through the payment methods made available by MANGO in its online commerce, in order to prevent public mistrust resulting from fraud or fraudulent activity in the same.
  • We inform you that, in this case, MANGO has compelling and legitimate grounds to enable the processing of your data for this purpose, for which your right to opposition in accordance with the provisions of article 21.1 of the General Data Protection Regulation shall not apply.
  • You can obtain more information about said evaluation by making a direct request to our Data Protection Officer.

In cases where you are registered as a user and purchase one of our items via our platforms, we may carry out the following data processing:

  • Save your credit card details for use in future purchases.

The lawful basis for the processing of your data is the express consent given by you for us to save this information for use in future purchases, without prejudice to the legitimate use of your credit card data in the execution of a contract, in line with what is indicated in the previous section. This consent may be withdrawn at any time without said withdrawal affecting the lawfulness of the processing based on your consent prior to withdrawal.

C) CONFIGURE YOUR RELATIONSHIP WITH MANGO AS A BRAND

Newsletter: management and sending of commercial information on exclusive promotions and new products adapted to your profile, sending audiences via digital platforms, and notifications relative to pending garments and accessories in your shopping bag via e-mail, SMS, WhatsApp, notifications from the Mango App or any other communication channel and/or digital platform. This includes promotional actions such as, for example, the management of competitions and prize draws organised by MANGO. In cases where you agree to receive commercial notifications via different channels, certain personal information may be used to personalise notifications via online means.

  • The lawful basis for the processing of your data is the express consent given by you, which you may withdraw it at any time without said withdrawal affecting the lawfulness of the processing based on your consent prior to withdrawal.

Management of the alerts service to notify the availability of garments and accessories via our Mango App, e-mail, SMS, WhatsApp or any other communication channel and/or digital platform.

  • The lawful basis for the processing of your data for this purpose is the express consent given by you, which you may withdraw it at any time without said withdrawal affecting the lawfulness of the processing based on your consent prior to withdrawal.

Garment search service in Mango stores (localisation). Mango will process your personal data in order to indicate the availability of the selected garment in the stores closest to the location provided by your device. We will not subsequently retain this data on our systems.

  • The lawful basis for the processing of your data for this purpose is the consent given by you to access the location of your device.

This consent may be withdrawn at any time without said withdrawal affecting the lawfulness of the processing based on your consent prior to withdrawal.

Respond to the exercise of the rights recognised in the data protection legislation.

  • The lawful basis for the processing of your data is the fulfilment of a legal obligation with regard to managing the exercise of rights, in accordance with the obligation contained in the General Data Protection Regulation.

Attend to queries, requests and possible complaints that you make via Customer Service channels, such as postal mail, telephone, e-mail, WhatsApp, Social Media, forms in the Mango App/Web, virtual assistant in the App/Web with AI capabilities and any other channel enabled for this purpose. Depending on the reason you are contacting MANGO, the lawful basis for the processing of your data may vary. In this regard:

  • We consider that MANGO has a legitimate interest to correctly resolve and respond to the suggestions, queries or requests that you make via Customer Service channels, on the understanding that, under no circumstances, will your rights and/or freedoms be affected or prejudiced by the fact that we are responding to a request initiated by you.
  • In cases where this relates to an order that needs to be attended to formalise the purchase, the lawful basis for the processing of your data is the <strong>execution of a contract understanding as such the Conditions of Sale.
  • In cases where your data is processed to attend to a complaint sent via the Customer Services channel, the lawful basis for the processing of your data is the fulfilment of a legal obligation</strong> contained in the General Law for the Defence of Consumers and Users.

After providing any of our services, send you quality surveys aimed at finding out your opinion and degree of satisfaction with your dealings with MANGO. The information collected as a result of the survey will allow us to create and improve our services and procedures, said experience being of considerable interest to us.

  • The lawful basis for the processing of your data is the legitimate interest.Our legitimate interest consists of being able to guarantee that our platforms remain secure, as well as to help MANGO understand the needs, expectations and your degree of satisfaction with the brand and, therefore, improve our services at all times. All these actions are carried out in order to improve your degree of satisfaction and ensure a unique browsing and purchasing experience, via aggregated analysis.

Profiling based on behavioral and consumption data collected through your browsing, your interactions with the brand and those derived from your purchase history in order to show you priority recommendations or content on our platform, in accordance with your preferences, as well as sending you commercial notifications adapted to your profile, provided you have given us your consent for this purpose.

  • Taking into account the characteristics of the profiling and after balancing your interests as the data subject, and those of MANGO as the data controller, it has been determined that the lawful basis for the processing of your data is the legitimate interest deeming that it is in the interest of all parties involved that such priority items may be of interest to the consumer. Consequently, by showing items that may reflect the priorities of the user in question as a matter of priority, MANGO will be able to offer you a better quality service and a more positive user experience, while At the same time, the fact that users have a positive experience, while giving MANGO a reputational benefit based on the fact that users will have a positive browsing and shopping experience on our platforms.
  • Taking into account the characteristics of the profiling and after balancing your interests as the data subject, and those of MANGO as the data controller, it has been determined that the lawful basis for the processing of your data for consumer profiling, in order to send you commercial notifications adapted to the interests, tastes and preferences of consumers, is the legitimate interest deeming that it is in the interest of all parties involved to send personalised commercial notifications. Consequently, being able to adapt commercial notifications to your user profile will allow MANGO to offer you a better quality service since you will only receive notifications whose content may be of interest to you, thus avoiding the sending of generic notifications which may be excessive or of little interest to the data subjects. This will increase your degree of satisfaction and, in turn, benefit MANGO, since it will be able to send more effective commercial notifications that favour the capture of new customers and gain the loyalty of existing ones, while also improving its commercial image.
  • The profiling algorithm does not formulate recommendations on actions to take (neither in terms of segment nor on an individual basis) and does not apply automated decision-making either, but merely analyses the consumer behaviour of customers and potential customers in order to know their interests, tastes and preferences by predicting the future consumer behaviour of the data subject. Based on this information, a Marketing manager will decide what it the best strategy for said segment, customer or potential customer.
  • You can obtain more information on the evaluation of legitimate interest by making a request directly to our Data Protection Officer.

How long do we keep your personal information?

In order to guarantee that the personal information are appropriate, pertinent and limited to what is necessary for the purposes for which they are processed, MANGO will keep your personal information only for a period that is reasonably necessary to fulfil the purpose for which they were collected, given the requirements to respond to issues that are raised or to resolve problems, make improvements, activate services and fulfil the requirements of the applicable legislation. This means that we may keep your personal information for a reasonable time, including after you have stopped using the services of MANGO and/or have stopped using its platforms.After this period, your personal information will be blocked in all MANGO systems for the sole purpose of making them available to the competent authorities in order to attend to any potential administrative or legal responsibilities and the exercise or defence of complaints. Once the blocking period for personal information has passed, they will be permanently deleted.

Who do we share your personal information with?

Your personal information may be shared with MANGO Group companies for internal administrative purposes based on legitimate interest.

Your personal information will be communicated to third parties in order to comply with any legal obligations that may apply in each case, for example, to Public Authorities and/or Bodies whenever required by the applicable tax, employment or Social Security legislation, or any other that may apply.

In cases where you make a purchase on our platforms, your data may be communicated, wherever applicable, to financial institutions and payment service providers, fraud detection and prevention organisations, for example Signifyd, and logistics, transport and goods delivery suppliers.Such communications are strictly necessary in order to guarantee the delivery of your order.

You are also informed that MANGO may contract third parties that will have access to your data as the result of a service provision we have entered into.Such third parties may provide technology, customer service, marketing and advertising services, among others, and in all cases will process your data in accordance with the instructions of MANGO and never for their own aims.

MANGO shall not, under any circumstances, sell your personal information to third parties.

International transfers

International data transfers may occur in cases where the companies that MANGO shares your data with are located outside the European Economic Area. These are lawful, since appropriate guarantees to protect personal information have been established.In cases where the destination country is not covered by an adequacy decision, MANGO will regulate the relationship with the third-party destination country shall by subscribing to the Standard Contractual Clauses adapted by the European Commission, whose contents may be consulted via the following link https://ec.europa.eu/info/law/law-topic/data-protection/international-dimension-data-protection/standard-contractual-clauses-scc_en

In all cases, third parties sharing certain personal information will have previously accredited the adoption of suitable technical and organisational measures for the correct protection of the same.

Data not collected directly from the data subject

In certain services offered via our platforms, such as Gift Cards, the user may provide personal information to the recipient of the same. In this case, MANGO will also comply with its obligations in accordance with the provisions contained in the data protection legislation, processing them solely for the purpose for which they have been provided to us.

How does Mango protect your personal information?

Our platforms use data security technologies such as network and application firewalls, anti-automated threat systems, access control procedures and cryptographic mechanisms to prevent any unauthorised access to data and guarantee data confidentiality. Periodic security audits and frequent controls are also carried out to make risk assessments. In order to achieve said aims, users accept that MANGO will obtain data for the purpose of authenticating access controls.

Furthermore, all transactions via our platforms will be made via secure payment systems. Confidential payment details are transmitted directly in encrypted format to the corresponding entity.

MANGO declares that it has adopted all the technical and organisational measures necessary to guarantee the security and integrity of the personal information it processes, and to prevent the loss, alteration and/or unauthorised use of the same by third parties.

What are your privacy rights in relation to your personal information?

Your rights are set out below.You may exercise them via the e-mail address personaldata@mango.comIn order to process your request to exercise your rights, we may ask you to provide proof of your identity.

Right of access

You have the right to obtain confirmation whether at MANGO processing personal information that concern you, or otherwise, and to access the personal information MANGO possesses about you.

Right to rectification

You have the right to request that MANGO rectifies personal information when they are incorrect or for them to be completed when they are incomplete. In cases where you have a user account, you should correct your data directly by accessing the “My data” section of your profile.

Right of erasure

You can request that your personal information is erased when, among other reasons, the data is no longer necessary for the purposes for which they were collected.

Right to restrict processing

You have the right to request the restriction of the processing of your data, in which case we will only keep them for the exercise or defence of legal claims.

Right to data portability

You have the right to receive personal information in a structured, commonly used and machine-readable format, and to transmit them to another controller when the treatment is based on consent or the execution of a contract, provided they are transmitted by automated means.

Right to object

You can object to the processing of your personal details based on the public or legitimate interest pursued by MANGO, including the profiling of data. In this case, MANGO will stop processing the data, except for compelling legal grounds or when necessary for the exercise or defence of possible legal claims. You also have the right to object to the processing of data for direct marketing purposes.

Automated individual decisions

Wherever this applies, you have the right not to be subject to a decision based solely on automated processing, including data profiling, which has a legal or similarly significant effect on you. However, it will not be possible to exercise said right in cases where the decision is necessary for the formalisation or execution of a contract between you and MANGO; it is authorised by the law applicable to MANGO whenever it establishes the appropriate measures to safeguard your rights, freedoms and legitimate interests; or where it is based on your explicit consent.

Right to submit a complaint

You have the right to lodge a complaint before the competent local Supervisory Authority, which in Spain is the Spanish Data Protection Agency (www.aepd.es).

Modifications to the privacy policy

This privacy policy will be available at all times. However, in cases where we modify the content of the same in a substantial and significant way, we shall notify you via our platforms or to your e-mail address, in order to comply with the duty of information contained in the GDPR. Consequently, if you wish, you may exercise your rights as a data subject.

Cookies Policy

What are cookies and how are they used?

Cookies are files installed on the user's computer, phone, tablet or any other device, with the purpose of recording the user's activities during their browsing time on this website and/or the MANGO mobile application ("Web/App"). Through the use of cookies, it is possible for the server where the Web/App is located to recognize the browser used by the user, allowing, for example, the registered user to access areas and services without having to register on each visit and remember their language, country preferences, etc. on future visits. Cookies are also used to measure audience and traffic parameters, control progress and number of entries.

In relation to the concept of "Cookie", we also refer to other technologies similar to cookies that, in a similar way, allow storing or retrieving certain information from a device such as, for example, flash cookies, web beacons or bugs, pixels, HTML5 (local storage), and SDK technology for App formats, as well as the use of fingerprinting techniques to identify the device of the interested party.

What does Mango use cookies for?

During access and navigation on the website or through the use of the mobile app, MANGO may store or record IP addresses, user preferences or the type of device used for the main purposes of (i) compiling statistics related to the number of visits or web traffic; (ii) offering a more personalized browsing experience; and (iii) remembering sign in data, even on different devices, and (iv) displaying advertising, on this page or others, based on browsing habits within our website.

Similarly, we do not store sensitive personal identification information such as your address, your password, etc., in the cookies we use.

MANGO does not sell customer data to third parties in any case.

Who uses the information stored in the cookies?

The information stored in the Web/App cookies is used by Punto Fa, S.L. (“MANGO”), with N.I.F. B-59.088.948:

  • Postal address: C/Mercaders, 9-11 (Polígono Industrial Riera Caldes) 08184 Palau-solità i Plegamans (Barcelona, Spain).
  • Email: personaldata@mango.com

Also, some of the cookies that may be installed are not owned by MANGO but by third parties, you can consult the complete list of cookies used by MANGO in the configuration panel which you will find below.

What type of cookies does Mango use?

Below are the types of cookies used on the MANGO Web/App, based on the type of cookies according to their purpose and the entity that manages them (own and third-party).

Management

Description

Self-managed cookies

These are those that are created or managed by MANGO, as the person responsible for the Web/App.

Third-party cookies

These are those that are managed by service providers unrelated to MANGO. These are identified in the configuration panel which you can access from the "configure cookies" button that you will find below.

Purpose

Description

Strictly necessary cookies

These cookies are necessary for the website to function and cannot be deactivated in our systems. They are usually configured to respond to actions made by you to receive services, such as adjusting your privacy preferences, signing in to your account, or completing forms. You can configure your browser to block or alert the presence of these cookies, but some parts of the website will not work. These cookies do not store any personally identifiable information.

Preference or customization cookies

These are those that allow you to access the service remembering predefined characteristics based on a series of criteria such as, for example, the language, the type of browser through which the service is accessed, the regional configuration from where the service is accessed, etc.

Not accepting these cookies could generate slow performance or poorly adapted recommendations.

Analysis cookies

These are those that, treated by us or by third parties, allow us to quantify the number of users and thus carry out the measurement and statistical analysis of the use that users make of the offered service. For this, your navigation on our website is analyzed in order to improve the offer of products or services that we offer you.

Behavioral advertising cookies

These are those that, treated by us or by third parties, allow us to analyze your browsing habits on the Internet so that we can show you advertising related to your browsing profile.

Social Network Cookies

These are those that are set by a series of social network services, that we have added to the site, to allow you to share our content with your friends and networks.

How to disable cookies in the most commonly-used web browsers

You can allow, block or delete the cookies installed on your computer in the settings options of your web browser.If you block them, certain services that require their use may not be available to you.

Below, we provide some links to information on how to enable your preferences on the most commonly-used web browsers:

Google Chrome

Mozilla Firefox

Internet Explorer

Safari

Opera

If you have accepted the third-party cookies, you can delete them from your web browser options or from the system offered by the third-party itself.

Conservation periods

MANGO will retain the personal data collected only for the specified, provided, and limited period necessary to fulfill the purpose for which they were collected, as well as to comply with the requirements of applicable legislation. Once the intended purpose is fulfilled, your data will be properly blocked for the period during which legal actions may arise and, once the prescription period has passed, they will be properly deleted.

Similarly, the data obtained through the use of cookies accepted by the user will be kept for a period of 13 months and, consequently, once this period has passed, a new consent will be requested when you visit our WEB/APP.

Regarding the third parties identified in the cookie settings panel, you can consult their retention period in their respective privacy policies.

Data transfers to third countries

Generally, data processing is carried out by service providers located within the European Economic Area or in countries that have been declared to have an adequate level of protection.

In the event of international data transfers to countries that do not have a decision of adequacy from the European Commission, MANGO will use the Standard Contractual Clauses adapted by the European Commission as a guarantee for those transfers in compliance with Items 44 to 49 of the 2016/679 Data Protection Regulation. In any case, the third parties with whom personal data is shared will have previously accredited the adoption of adequate technical and organizational measures for the correct protection of the data.

In relation to third parties that manage cookies, you can inform yourself about the transfers to third countries that, where appropriate, they carry out in their corresponding cookie policies.

How to manage your consent preferences

You can configure the categories of optional cookies by clicking on the cookie settings button below: