Menu

Privacy Policy

Last Updated: 01/06/2024

Kozy Reno ("us", "we", or "our") operates the website [https://www.kozyreno.com] (the "Service").

At Kozy Reno, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, disclose, and safeguard your data when you use our website or services. By accessing or using our platform, you agree to the terms outlined in this Privacy Policy.

Information Collection and Use

We collect various types of information to provide and improve our services. This includes:

  • Personal Information: such as your name, email address, phone number, and mailing address.

  • Payment Information: when you make a purchase or payment through our platform.

  • Usage Data: including information about your interactions with our website and services.

  • Cookies and Tracking Technologies: to enhance your experience and analyze usage patterns.

We use the information we collect for various purposes, including to:

  • Provide and maintain our services.

  • Process transactions and fulfill orders.

  • Improve and personalize user experience.

  • Communicate with you about promotions, updates, and news.

  • Analyze usage patterns and trends to enhance our platform.

Information Sharing and Disclosure

We may share your information with third-party service providers and partners to facilitate our services and operations. This includes payment processors, shipping companies, and marketing service providers. We do not sell or rent your personal information to third parties for marketing purposes. Your data may also be disclosed as required by law or to protect our rights and interests.

Data Security

We take measures to safeguard your information from unauthorized access, disclosure, alteration, or destruction. This includes implementing technical, administrative, and physical security measures to protect your data. However, no method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security.

Your Rights

You have the right to access, correct, or delete your personal information and to opt-out of certain communications. You may also request information about the data we have collected and how it is being used. To exercise these rights or for any questions regarding your privacy, please contact us using the details provided below.

Children's Privacy

Our Service does not address anyone under the age of 18 ("Children"). We do not knowingly collect personal identifiable information from anyone under the age of 18. If you are a parent or guardian and you are concerned that your child has provided us with personal information without your consent, please contact us immediately. We will make every effort to promptly remove such information from our records.

Data Protection Officer

Kozy Reno appoints a Data Protection Officer (DPO) to oversee compliance with this Privacy Policy and data protection laws. The DPO can be contacted at [email address] for any inquiries regarding your personal information or privacy concerns.

International Data Transfers

If you are accessing our Service from outside of the United Kingdom, please be aware that your information may be transferred to, stored, and processed in the United Kingdom. By using our Service, you consent to the transfer of your information to the United Kingdom and acknowledge that data protection laws may differ from those in your country.

Third-Party Links

Our Service may contain links to third-party websites or services that are not operated by us. We have no control over, and assume no responsibility for, the content, privacy policies, or practices of any third-party sites or services. We recommend reviewing the privacy policies of these websites before providing any personal information.

User Responsibilities

While we take measures to protect your personal information, you are responsible for maintaining the security of your account credentials and for any actions taken on your account. Please notify us immediately if you become aware of any unauthorized use or security breaches related to your account.

Legal Basis for Processing Personal Information

We rely on various legal bases to collect, use, and process your personal information, including:

  • Consent: When you provide consent for specific processing activities.

  • Contractual Obligations: To fulfill our contractual obligations with you.

  • Legitimate Interests: Pursuing our legitimate business interests, provided they do not override your rights and freedoms.

  • Legal Obligations: Complying with legal obligations, such as regulatory requirements or court orders.

UK Privacy Rights

If you are a resident of the United Kingdom, you may have additional rights under the UK Data Protection Act and the General Data Protection Regulation (GDPR). These rights may include the right to know what personal information is being collected about you, the right to request deletion of your personal information, and the right to object to the processing of your personal information. To exercise these rights, please contact us using the information provided below.

Retention of Personal Information

We retain your personal information for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law. The criteria used to determine the retention period include the length of time we have an ongoing relationship with you, our legal obligations, and whether retention is advisable in light of our legal position (such as in regard to applicable statutes of limitations, litigation, or regulatory investigations).

Data Subject Rights

As a data subject, you have certain rights regarding your personal information. These rights may include:

  • Right to Access: You have the right to request access to the personal information we hold about you and receive a copy of that information.

  • Right to Rectification: You have the right to request that we correct any inaccuracies in your personal information.

  • Right to Erasure: You have the right to request that we erase your personal information under certain circumstances, such as when the information is no longer necessary for the purposes for which it was collected.

  • Right to Restrict Processing: You have the right to request that we restrict the processing of your personal information under certain circumstances, such as when you contest the accuracy of the information or when the processing is unlawful.

  • Right to Data Portability: You have the right to receive the personal information you have provided to us in a structured, commonly used, and machine-readable format and to transmit that information to another controller.

To exercise these rights, please contact us using the contact information provided at the end of this Privacy Policy. We will respond to your request in accordance with applicable law.

Data Breach Notification

In the event of a data breach that may compromise the security of your personal information, we will promptly notify you and the relevant authorities in accordance with applicable laws and regulations. Our notification will include information about the nature of the breach, the types of information affected, and the steps we are taking to mitigate the situation.

Data Protection Officer

Kozy Reno has appointed a Data Protection Officer (DPO) to oversee data protection and privacy matters. The DPO is responsible for ensuring compliance with data protection laws and handling inquiries related to personal information. You can contact the DPO at [email address].

Supervisory Authority

If you are located in the European Economic Area (EEA) or the United Kingdom (UK), you have the right to lodge a complaint with a supervisory authority if you believe that our processing of your personal information violates applicable data protection laws. For contact information for your local supervisory authority, please refer to their website.

Third-Party Service Providers

We may engage third-party companies and individuals to facilitate our Service ("Service Providers"), provide the Service on our behalf, perform Service-related services, or assist us in analyzing how our Service is used. These third parties have access to your personal information only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

Business Transfers

If Kozy Reno is involved in a merger, acquisition, or sale of assets, your personal information may be transferred. We will provide notice before your personal information is transferred and becomes subject to a different Privacy Policy.

Aggregated Data

We may aggregate and anonymize data collected through our Service and use it for any purpose, including but not limited to analyzing usage patterns, improving our Service, and developing new features and functionalities. This aggregated data is not personally identifiable and does not reveal your identity.

User Contributions

You may choose to submit content, such as reviews or comments, through our Service. Please be aware that any information you voluntarily disclose in these areas becomes public information and may be viewed and used by others. We encourage you to exercise caution when sharing personal information in public areas of the Service.

Governing Law

This Privacy Policy is governed by and construed in accordance with the laws of the United Kingdom, without regard to its conflict of law principles. Any dispute arising from or relating to this Privacy Policy shall be subject to the exclusive jurisdiction of the courts of England and Wales.

Data Subject Requests

If you are a resident of the European Economic Area (EEA) or the United Kingdom (UK), you have certain rights under data protection laws, including the General Data Protection Regulation (GDPR). These rights may include the right to access, rectify, restrict, or delete your personal information, as well as the right to data portability and the right to object to processing. You can exercise these rights by contacting us using the contact information provided below.

Automated Decision-Making

We do not use automated decision-making processes, including profiling, that produce legal effects concerning you or significantly affect you without human intervention. Any automated processing we conduct is solely for the purpose of improving our services and does not have legal or similarly significant effects on you.

Changes to This Privacy Policy

We reserve the right to update or modify this Privacy Policy at any time, in our sole discretion. If we make material changes to this Privacy Policy, we will notify you by posting a notice on our website or by sending you a direct communication. Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.

Severability

If any provision of this Privacy Policy is found to be invalid, unlawful, or unenforceable, the remaining provisions will remain in full force and effect to the fullest extent permitted by law. The invalid provision will be replaced by a valid, lawful, and enforceable provision that comes closest to the original intention of the invalid provision.

Data Protection Principles

We adhere to the following data protection principles:

  • Lawfulness, fairness, and transparency: We process personal information lawfully, fairly, and in a transparent manner.

  • Purpose limitation: We collect personal information for specified, explicit, and legitimate purposes and do not process it in a manner that is incompatible with those purposes.

  • Data minimization: We collect only the minimum amount of personal information necessary for the purposes for which it is processed.

  • Accuracy: We take reasonable steps to ensure that personal information is accurate, complete, and up-to-date.

  • Storage limitation: We retain personal information for no longer than necessary to fulfill the purposes for which it is processed.

  • Integrity and confidentiality: We implement appropriate technical and organizational measures to ensure the security of personal information and protect it from unauthorized or unlawful processing and accidental loss, destruction, or damage.

Third-Party Analytics

We may use third-party analytics services, such as Google Analytics, to analyze the use of our Service and track user behavior. These services may use cookies and other tracking technologies to collect information about your use of the Service and generate reports on website activity. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

Entire Agreement

This Privacy Policy constitutes the entire agreement between you and Kozy Reno regarding the collection, use, and disclosure of your personal information. It supersedes all prior agreements and understandings, whether written or oral, relating to the subject matter herein.

Privacy Policy Acceptance

By using our Service, you acknowledge that you have read and understood this Privacy Policy and agree to abide by its terms and conditions. If you do not agree with any aspect of this Privacy Policy, please do not use our Service.

Data Localization

Your personal information may be stored and processed in any country where we have facilities or in which we engage service providers. By using our Service, you consent to the transfer of your information to countries outside of your country of residence, including the United Kingdom, which may have different data protection laws than your jurisdiction.

User Consent

By providing us with your personal information, you consent to the collection, use, and disclosure of that information in accordance with this Privacy Policy. If you provide personal information about another person, you represent that you have the authority to do so and that you have obtained consent from that person for the collection, use, and disclosure of their information as described in this Privacy Policy.

Updates to Your Information

You have the right to update or correct your personal information at any time by contacting us using the contact information provided below. We will take reasonable steps to ensure that your personal information is accurate, complete, and up-to-date.

Contact Us

If you have any questions or concerns about this Privacy Policy or our practices regarding your personal information, please contact us at [email address].

This Privacy Policy is a comprehensive document designed to inform users about how their personal information is collected, used, and protected by Kozy Reno. It complies with relevant privacy regulations and provides users with clear guidance on their rights and options regarding their data.

1. Data Protection Officer (DPO) Contact Details:

• It's good that a DPO has been appointed. However, make sure to provide an actual email address where the DPO can be contacted. Placeholder text like [email address] should be replaced with specific contact details.

2. International Data Transfers:

• This section mentions the transfer of data to the UK, which is adequate. Still, it should explicitly state compliance with GDPR provisions regarding international data transfers, especially post-Brexit considerations.

3. Third-Party Links and Endorsements:

• The policy mentions that the website may contain links to third-party sites. It's prudent to also advise users to review the privacy practices of these sites, as their data handling practices might differ significantly.

4. Consent and User Rights:

• The policy outlines user consent well. It could be strengthened by including instructions on how users can withdraw their consent at any time, which is a requirement under the GDPR.

5. Children's Privacy:

• The policy states that it does not knowingly collect information from children under 18. It's important to ensure mechanisms are in place to verify ages and to delete data if collected inadvertently.

6. Legal Basis for Processing:

• You've listed the legal bases for processing personal data. Make sure these are specific and justified in the context of the activities performed by Kozy Reno. Overly broad or vague justifications can lead to compliance issues.

7. Updates and Changes to the Privacy Policy:

• The section on changes is good but consider specifying how users will be notified of these changes (e.g., email notifications).

8. Retention of Personal Information:

• The policy should specify the typical retention periods for different types of personal data or the criteria used to determine these periods.

9. Right to Erasure and Data Portability:

• Make these rights more prominent in the policy and ensure there are easy-to-follow instructions for users to request data deletion or portability.

10. Severability:

• The clause is standard and appropriate. However, ensure any amendments maintain the enforceability of the remaining provisions.

11. Data Breach Notification:

• It's good that the policy includes this; however, ensure that the notification procedures are specific about timelines and the types of breaches that will be reported to users and regulators.

Overall, the privacy policy seems comprehensive, but attention should be paid to specific details, especially around data protection rights, international data transfers, and the operationalization of user rights under GDPR. It might be beneficial to have this document reviewed by a legal professional specializing in data protection to ensure all aspects of the GDPR and UK Data Protection Act are thoroughly addressed.

Contact us