Privacy policy
Last updated: 18 September 2026
This Privacy Policy explains how [[TO BE COMPLETED BY OWNER: store name]] (we, us, our) handles personal data when you visit our webshop for MYKONOS perfumes, place an order or contact us. We process personal data in accordance with the General Data Protection Regulation (Regulation (EU) 2016/679, GDPR) and the Dutch GDPR Implementation Act (UAVG).
1. Who is responsible for your data
The controller within the meaning of Article 4(7) GDPR is:
- Trade name: FragranceGems VOF
- Legal form: Vennootschap onder firma (VOF)
- Registered business address: IJsselstroom 33, 2721 AW Zoetermeer, The Netherlands
- Chamber of Commerce (KVK) number: 42151014
- Privacy contact: [[TO BE COMPLETED BY OWNER: privacy contact e-mail address]]
You can use the privacy contact above for every question or request about your personal data.
2. Personal data we process
Depending on how you use our webshop, we process the following categories of personal data:
- Identity and contact data: name, delivery address, billing address, e-mail address and, if you provide it, phone number.
- Order data: products ordered, order number, order and return history, invoice data, chosen payment method and payment status. Payment details such as card numbers are processed by the payment service provider; we do not have access to full card numbers.
- Account data: if you create a customer account: login e-mail address, saved addresses and preferences.
- Communication data: messages you send us by e-mail or through a contact form, including withdrawal notices and complaints.
- Technical and usage data: IP address, device and browser type, language settings, pages viewed, date and time of your visit and cookie identifiers. Part of this data is only collected if you have given consent through the cookie preferences.
- Marketing preferences: whether you subscribed to our newsletter and the record of your consent.
We receive most data directly from you. We also receive data automatically when you use the webshop, from payment service providers (payment status and fraud signals) and from carriers (delivery status). We do not ask for special categories of personal data, and we ask you not to send them to us.
The data marked as required in the checkout is necessary to conclude and perform the purchase contract. Without this data we cannot process your order.
3. Purposes and legal bases
We only process personal data for the purposes below, each based on a legal basis from Article 6(1) GDPR.
| Purpose | Data used | Legal basis |
|---|---|---|
| Accepting, processing and delivering your order, handling your payment and sending order and dispatch messages | Identity and contact data, order data | Article 6(1)(b) GDPR - performance of the contract with you |
| Handling withdrawals, returns, refunds and legal guarantee claims | Identity and contact data, order data, communication data | Article 6(1)(b) GDPR - performance of the contract, and Article 6(1)(c) GDPR - our obligations under consumer law |
| Creating and managing your customer account | Account data | Article 6(1)(b) GDPR - performance of the contract |
| Answering your questions and complaints | Identity and contact data, communication data, order data | Article 6(1)(b) GDPR where your message relates to an order; otherwise Article 6(1)(f) GDPR - our legitimate interest in providing good customer service |
| Keeping accounting and tax records | Order data and invoice data | Article 6(1)(c) GDPR - legal obligation, including the Dutch fiscal retention obligation |
| Responding to requests from data subjects and from competent authorities | The data relevant to the request | Article 6(1)(c) GDPR - legal obligation |
| Securing the webshop and preventing and investigating fraud and abuse | Technical and usage data, order data, payment status | Article 6(1)(f) GDPR - our legitimate interest in a secure webshop and in protecting our customers and ourselves against fraud |
| Establishing, exercising or defending legal claims | The data relevant to the claim | Article 6(1)(f) GDPR - our legitimate interest in protecting our legal position |
| Strictly necessary cookies (shopping cart, checkout, country and language selection, remembering your cookie choice) | Technical data | Article 6(1)(f) GDPR - our legitimate interest in a working webshop; these cookies are exempt from the consent requirement |
| Analytics and measuring how the webshop is used | Technical and usage data | Article 6(1)(a) GDPR - your consent, given through the cookie preferences |
| Marketing cookies and personalised advertising | Technical and usage data | Article 6(1)(a) GDPR - your consent, given through the cookie preferences |
| Newsletters and other marketing e-mails | E-mail address, name, marketing preferences | Article 6(1)(a) GDPR - your consent; you can unsubscribe through the link in every marketing e-mail |
Where we rely on a legitimate interest (Article 6(1)(f) GDPR), we have weighed that interest against your interests and rights. You can object to this processing at any time; see section 7.
4. Who receives your data
We share personal data only where this is necessary for the purposes above, with the following categories of recipients:
- Webshop platform and hosting: our webshop, checkout and customer accounts are hosted by Shopify (Shopify International Limited, Ireland, and its affiliates). Shopify processes personal data on our behalf as a processor under a data processing agreement. For some of its own services, for example Shop Pay or a Shop account if you choose to use them, Shopify acts as an independent controller under its own privacy policy, which you can read at shopify.com/legal/privacy.
- Payment service providers: they receive the data needed to carry out and secure your payment. Payment service providers are generally independent controllers and process your data under their own privacy policies.
- Carriers and logistics providers: they receive your name and delivery address and, where needed for delivery notifications, your e-mail address or phone number.
- E-mail and customer service tools: used to send order-related messages and to handle your enquiries. Marketing e-mails are only sent if you have given consent.
- Analytics and advertising providers: only if and to the extent that you have given consent through the cookie preferences.
- Accountants and professional advisers: under a duty of confidentiality, where needed for our administration or legal position.
- Public authorities: where we are legally required to provide data, for example to tax authorities.
With every party that processes personal data on our behalf we conclude a data processing agreement as required by Article 28 GDPR. We do not sell your personal data. If our business is transferred in whole or in part, customer data may be transferred to the successor within the limits of the law.
5. Transfers outside the European Economic Area
Some of our service providers, including Shopify and its sub-processors, may process personal data in countries outside the European Economic Area (EEA), such as Canada and the United States. We only allow such transfers if:
- the European Commission has decided that the country or the recipient offers an adequate level of protection (Article 45 GDPR); or
- the transfer is covered by the Standard Contractual Clauses (SCCs) adopted by the European Commission (Article 46(2)(c) GDPR), supplemented with additional safeguards where necessary.
You can contact us for more information about these safeguards or to request a copy of them.
6. How long we keep your data
We do not keep personal data longer than necessary for the purpose for which it was collected, unless the law requires a longer period.
| Data | Retention period |
|---|---|
| Order, invoice and payment records | 7 years after the end of the financial year, based on the Dutch fiscal retention obligation (Article 52 of the General State Taxes Act) |
| Customer account | Until you delete your account or ask us to delete it; order records linked to the account are kept for the fiscal retention period |
| Withdrawal, return and guarantee files | For as long as the matter is being handled and afterwards for as long as legal claims can be brought, or 7 years where the file is part of our financial records |
| Customer service correspondence | [[TO BE COMPLETED BY OWNER: retention period for customer service correspondence]] |
| Newsletter and marketing e-mail data | Until you unsubscribe or withdraw your consent; afterwards we only keep what is needed to respect your opt-out and to demonstrate that consent was given |
| Cookie and usage data | For the lifetime of the cookie concerned, as shown in the cookie preferences; consent-based cookies are no longer used after you withdraw consent |
After the retention period we delete the data or make it anonymous.
7. Your rights
Under the GDPR you have the following rights:
- Access (Article 15): to know whether we process your personal data and to receive a copy.
- Rectification (Article 16): to have inaccurate or incomplete data corrected.
- Erasure (Article 17): to have your data deleted, unless we are required or entitled to keep it.
- Restriction (Article 18): to have the processing of your data temporarily limited.
- Data portability (Article 20): to receive the data you provided to us in a structured, commonly used and machine-readable format, or to have it transmitted to another controller.
- Objection (Article 21): to object to processing based on our legitimate interests. You can always object to the use of your data for direct marketing, and we will then stop that use.
- Withdrawal of consent (Article 7(3)): where processing is based on consent, you can withdraw it at any time. This does not affect the lawfulness of processing before the withdrawal.
To exercise your rights, contact us using the details in section 1. We respond within one month of receiving your request. For complex or numerous requests this period can be extended by two further months, in which case we will inform you within the first month. Exercising your rights is free of charge. We may ask for additional information to verify your identity, so that your data is not disclosed to someone else.
Automated decision-making
We do not take decisions based solely on automated processing, including profiling, that produce legal effects for you or similarly significantly affect you (Article 22 GDPR). Our platform and payment providers may run automated fraud risk checks on orders. If such a check affects your order, you can contact us and ask for a review by a person.
8. Complaints to a supervisory authority
If you believe we do not handle your personal data correctly, please contact us first so that we can look for a solution. You also have the right to lodge a complaint with a supervisory authority (Article 77 GDPR). In the Netherlands this is the Autoriteit Persoonsgegevens (Dutch Data Protection Authority), autoriteitpersoonsgegevens.nl. You may also contact the supervisory authority of the EU Member State where you live, where you work or where the alleged infringement took place. An overview of all authorities is available from the European Data Protection Board.
9. Cookies and similar technologies
Our webshop uses cookies and similar technologies. We distinguish between:
- Strictly necessary cookies: required for the shopping cart, the checkout, the country and language selection and for remembering your cookie choice. These are placed without consent.
- Preference cookies: remember choices that make the webshop easier to use.
- Analytics cookies: help us understand how the webshop is used.
- Marketing cookies: used to show and measure advertising.
Cookies that are not strictly necessary are only placed after you have given consent through the cookie banner. You can change or withdraw your choice at any time through the Cookie preferences link on our website. You can also delete or block cookies in your browser settings; parts of the webshop may then not work properly.
10. Security
We take appropriate technical and organisational measures to protect personal data against loss and unlawful processing. The connection to our webshop is encrypted, access to customer data is limited to those who need it, and our processors are contractually bound to confidentiality and security. No system can be guaranteed to be completely secure. If a personal data breach occurs that is likely to result in a high risk for you, we will inform you and the supervisory authority as required by Articles 33 and 34 GDPR.
11. Children
Our webshop is not directed at children under the age of 16. We do not knowingly collect personal data from children under 16 without the consent of a parent or legal guardian. If you believe that a child under 16 has provided personal data to us without that consent, please contact us and we will delete the data.
12. Links to other websites
Our webshop may contain links to websites of third parties. This Privacy Policy does not apply to those websites. Please read the privacy policy of the website concerned.
13. Changes to this Privacy Policy
We may update this Privacy Policy, for example when our services or the law change. The most recent version is always available on this page, with the date of the last update at the top. If a change is significant for you, we will draw your attention to it in an appropriate way.
14. Contact
Questions or requests about this Privacy Policy or about your personal data can be sent to:
- FragranceGems VOF
- IJsselstroom 33, 2721 AW Zoetermeer, The Netherlands
- Privacy contact: [[TO BE COMPLETED BY OWNER: privacy contact e-mail address]]