360Insights Privacy Policy and Miele Privacy...


Citation preview

360Insights Privacy Policy


Miele Privacy Policy

360insights Privacy Policy

1. Who We Are

We are 360incentives.com Canada Inc. as well as our family of affiliated companies, including 360incentives.com USA, Inc., and 360incentives.com UK Limited (collectively referred to herein as “360insights,” “we,” “us,” or “our”).

2. Purpose of This Privacy Policy

We provide rebate, SPIFF, volume incentive, MDF/Co-Op, sell through processing

services, and channel analytics (the “Services”) for our manufacturing and

distributorship clients (“Partners”). This Privacy Policy explains how we handle your

Personal Information, including how we collect it, use it, and share it with others, in

the course or fulfilling our obligations to our Partners. Having reviewed this Privacy

Policy, or having been given the opportunity to do so, and by clicking on the “Continue” icon of the pop-up that opens when you enter this site (the “Site”), you

expressly consent to the terms and conditions of this Privacy Policy and to the Terms

and Conditions governing use of the Site. If you have questions, comments or

concerns about our Privacy Policy or the Terms and Conditions, please contact us at


3. If You Elect Not to Provide Personal Information

You may choose not to provide us with your Personal Information. However, if you choose not to provide your Personal Information, you will not be able to create an account on this Site, and hence you will be unable to apply for and receive any form of rebate or incentive from our Partners. In some cases, a rebate or incentive may be available by obtaining a mail in form from one of our Partners.

4. What Is Personal Information?

Personal Information includes: your name, address, telephone number, email address,

credit card information, postal/zip code, town or city, and gender; click through

activity, product preferences or instructions; information about your computer and

about your visits to and use of this website, such as your IP address, geographical location, browser type, operating system, referral source, length of visit and number of

page views; information that you provide to us for the purpose of registering with us

(including your name, email address, telephone number, postal address, and company

details); information relating to any transactions carried out between you and us or the

manufacturers and distributors whom we represent including information relating to

any purchases you make; information that you provide to us for the purpose of

obtaining the Services, health and financial information, email notifications and/or newsletters; and, any other information that you choose to send to us.

5. Anonymized Data

We may create de-identified or anonymized data from Personal Information by

excluding data components (such as your name, email address or linkable tracking ID) that makes the data personally identifiable to you, through pseudonymization, or through other means. Use of anonymized and de-identified data is not subject to this

Privacy Policy.

6. Why We Collect Personal Information

We collect Personal Information in order to facilitate the Services that are offered through the Site, including administration of rebates to customers and sales incentives to employees and agents of the manufacturers and distributors whom we

represent, and the proper registration of product warranties. We may also put Personal Information to other uses, which may include communicating information and offers to you; to better understand, analyze, and respond to your needs and preferences; and to subsequently develop, enhance, and/or provide products and

services to meet those needs and preferences.

We also keep track of your product preferences and instructions and analyze that

information. In addition to providing the Services to you, we may use Personal Information to enter you into a contest, speed-up the process of registering a

subsequent purchase, or to respond by email to an inquiry that you posted online.

Your Personal Information may also be used by us to contact you regarding other

products or services which may be of interest to you (including those that our

manufacturers or distributors may offer), and for our manufacturers or distributors customer appreciation programs. You may also be provided with an option to provide

Personal Information to permit one of our Partners to fulfil warranty obligations, or to

notify you of a safety recall relative to a particular product. Your Personal

Information may be combined with other Personal Information collected by us to

provide aggregate statistical information about customers’ service usage preferences.

Your Personal Information may be passed on to a third party in the event of a transfer of

ownership or assets, or a bankruptcy, of 360insights or any of its affiliates or

distributors. 360insights or any of its affiliates or distributors may also disclose your

Personal Information to one or more of their respective subsidiary and parent companies

and businesses, and other affiliated legal entities and businesses who are under common

corporate control. However, all of the parent, subsidiary and affiliated legal entities and

businesses of 360insights that receive your Personal Information will comply with the

terms of this Privacy Policy with respect to their use and disclosure of such Personal

Information. 360insights itself assumes no responsibility or liability for the privacy

practices of our manufacturers or distributors in their handling of your Personal

Information they collect from you online or offline.

7. How We Collect Personal Information

(a) When you register for an account or interact with our Services.

We collect Personal Information when you access a Site or seek to access the Services, including when you register with us. We use this Personal Information to create your account, enable your activity within our Services, and to provide the

Services generally, including to develop, enhance, and improve our Services and your experience. We also use this data for internal purposes related to certain research, analytics, innovation, testing, monitoring, customer communication, risk

management, and administrative purposes.

(b) When you communicate with us or sign up for promotional materials

We collect Personal Information when you communicate with us or sign up to receive promotional materials or information via email, push notifications, or text messages - including email address, mobile number, WeChat ID, etc.

If you consent to such messages, we may use your Personal Information and other

information to communicate with you about the products of our Partners; provide you with promotional messages and personalized advertising; to notify you of other products; to notify you of contests, challenges, sweepstakes, and other promotions; to

notify you of Services we think may be of interest to you; and, for other marketing purposes.

Please note that regardless of your email settings, we may send you notifications pertaining to the performance of our Services, such as revision of our Terms or this Privacy Policy or other formal communications relating to the processing of your rebate claim.

We may use your Personal Information to respond to your requests for technical support, online services, information regarding your claim, or to any other

communication you initiate. This includes accessing your account to address technical support requests. We may also use your Personal Information to address your requests, enquiries, and complaints.

(c) When you engage with our online communities or advertising.

We may collect your Personal Information when you engage with our online communities. This includes when you click on advertisements, interact with our social media pages, submit content, leave reviews, or otherwise enter information into comment fields, blogs, message boards, events, and other community forums sponsored by or affiliated with 360insights.

(d) When you connect with us through social media.

You may choose to enable, log into, or sign on to the Services through various social

media or social networking services, such as Facebook, WeChat, or Twitter ("Social

Media"). When you connect using your Social Media accounts, we may collect Personal Information that you have provided to that Social Media. For example, when

you log in with your Facebook credentials, with your consent, we may collect

Personal Information from your Facebook profile that is permitted under Facebook's

Terms of Use - such as your email address, profile picture, and friend list. We use this

data to provide, enhance, and personalize the Services (e.g., to help connect you with

or suggest friends within our Services). If you do not want to provide us with this data, you need to adjust the privacy settings on your Social Media account.

(e) When we leverage and/or collect cookies, device IDs, Location, data from the environment, and other tracking technologies.

We may collect certain Personal Information using cookies and other technologies such as web beacons, device IDs, and IP addresses. We specifically use browser cookies for different purposes, including cookies that are strictly necessary for

functionality and cookies that are used for personalization, performance/analytics, and advertising. Our Cookie and Device Identifiers section contains more information and options to control or opt-out of certain data collection or uses.

8. Sharing of Personal Information

Your Personal Information has been collected by us in connection with purchases made by you of the products or services of the manufacturers or distributors for whom we provide our rebate and salesperson incentive programs, and for the other

uses described in the Why We Collect Personal Information section above. By providing your Personal Information to us, you are consenting to our sharing that information with the manufacturer or distributor from whom you purchased a product or service. That manufacturer or distributor may use your personal information for the

same purposes as we do.

We will not otherwise share your Personal Information, except: to third parties

performing functions on our behalf (such as analyzing data, providing marketing

assistance, providing search results and links, processing credit card and other

payments, and providing customer service); where we are required by law to disclose Personal Information; in connection with any legal proceedings or prospective legal

proceedings; in order to establish, exercise or defend our legal rights (including

providing information to others for the purposes of fraud prevention and reducing

credit risk); and, to the purchaser (or prospective purchaser) of any business or asset

which we are (or are contemplating) selling, we will require any person or entity to

whom we provide your Personal Information to agree to comply with our then current Privacy Policy. We will take reasonable commercial efforts to ensure that

they comply with our Privacy Policy, however we will have no liability to you if any

such person or entity fails to do so.

9. International Data Transfers

360insights is a global organization and provides Service in a variety of

jurisdictions. Sharing data cross-border is essential to the Services so that you receive the same high-quality service wherever you are in the world. As a result, we

will, subject to law, transfer Personal Information collected in connection with the

Services, to entities in countries where data protection standards may differ from

those in the country where you reside. By accessing the Site and utilizing the

Services, you understand and consent to our transfer of your Personal Information

globally. In certain circumstances, courts, law enforcement agencies, regulatory agencies or security authorities in those other countries will be entitled to access

your Personal Information.

10. Consent

We try to ensure that you understand how we use your Personal Information. One of

the ways this is done is by obtaining your consent. Consent may be either express or implied. Express consent is given when we specifically ask you if it is acceptable to

you that we gather certain information and you explicitly agree that it is. Implied

consent occurs when you provide information that may be Personal Information

without objection. As we obtain only the information necessary to assist you with

the transaction you require, we operate under the understanding that you have agreed

to provide us with this Personal Information voluntarily and with knowledge of this Policy whenever you do so.

11. Withdrawal of Consent

Except as required by law, we will not use or disclose your Personal Information for any purpose for which you refuse us consent or later withdraw your consent. You may at any time withdraw your consent with future effect and without affecting the

lawfulness of processing of your Personal Information based on the consent you

provided before you withdrew it. If you withdraw consent, you agree that in spite of this withdrawal we may continue to use the Personal Information previously provided

to us to the extent that we are contractually obligated to do so and to the extent

necessary to enforce any contractual obligations you may have to 360insights. You

also understand that although you can use our site for some purposes without

providing us with any Personal Information, we need Personal Information about you

for some Services, including those that require payment or involve an ongoing relationship with 360insights or our Partners. If you refuse to provide us with the

Personal Information we require or later withdraw your consent to use and disclose

this information, we may no longer be able to provide you with the Services.

12. Cookies and Device Identifiers

This Site uses “cookies” and device identifiers to help personalise your online

experience with us. A cookie is a small text file that is stored on your computer to help us make your visit to our site more “user-friendly”. Cookies provide us with

information about your use of the Site that can help us improve the Site and your

experience with it. Any Personal Information collected about you through cookies will

be treated in accordance with this Privacy Policy. If you have set your browser to

warn you before accepting cookies, you should receive a warning message with each

cookie. You may refuse cookies by turning them off in your browser, however you should be aware that our site like most other popular sites may not work well with

“cookies disabled.” A device identifier is a unique label can be used to identify a

mobile device. Device identifiers may be used to track, analyze and improve the

performance of the Site and the Services.

13. Site Usage Information

Like most websites, this Site gathers traffic patterns, site usage information and other

aggregated data in order to evaluate our visitors’ preferences and the effectiveness of our Site. This aggregate usage data does not identify you individually. We may share anonymous, aggregated statistics about visitors to our Site with others outside our company, or we may allow third-parties to collect aggregate data through our Site.

14. Access

We will advise you on request about what Personal Information about you that we have

collected, as well as how it has or will be used. If you provide a written request for this

information, we will provide it to you within a reasonable time following confirmation

of your identity and may, if you are not a European Economic Area resident, charge a

reasonable cost (e.g. photocopying and mail charges) to the

individual making the request. We will inform you whether or not we hold Personal

Information about you and, when possible, the source of the Personal Information, its use, and any parties to whom it may have been disclosed. You may be required to

provide sufficient proof of your identity at this time to ensure the safety and security

of the Personal Information we hold and that it is provided to individuals in

accordance with this Policy. We reserve the right to decline to provide access to

Personal Information where the information requested: would disclose Personal

Information of another individual or of a deceased individual; is subject to legal privilege; is personal health information that was not provided to us directly by the

individual requesting access; is not readily retrievable and the burden or cost of

providing would be disproportionate to the nature or value of the information; does

not exist, is not held, or cannot be found by us; could reasonably result in serious

emotional harm to the individual or another individual, or serious bodily harm to

another individual; or, may harm or interfere with law enforcement activities and other investigative or regulatory functions of a body authorized by statute to perform

such functions. We will not respond to repetitious or vexatious requests for access.

15. Updating or Correcting Your Information

You may in most cases correct or update your Personal Information by accessing your Account directly, or by instructing us to do so on your behalf.

16. Security and Retention

We operate secure data networks protected by industry standard firewall and password protected systems, and maintain physical, encryption, electronic and procedural safeguards to guard the integrity and privacy of these servers and of your

Personal Information. Although we cannot guarantee that there will never be a security problem, we and our agents that have access to your information carefully guard against the loss, misuse or alteration of the information we collect on our Site.

We will retain your Personal Information for as long as your account is active or as needed to provide Services to you. We will retain and use your Personal Information as necessary to comply with our legal obligations, resolve disputes, and enforce our agreements.

17. Delete Account / Withdraw Processing Consent

You are free to withdraw your account consent for 360insights to process your Personal Information by sending an email to privacy@360insights.com or by writing to us at 360insights, 300 King St., Whitby ON L1N 4Z4, Attention: Chief Privacy Officer

18. Residents of the European Economic Area

In order to comply with the requirements of the European General Data Protection Regulation (GDPR) for our European consumers and users, this Privacy Policy outlines the legal basis on which we process your Personal Information and provides other information required by the GDPR.

In addition to the common rights granted to all users of the Site who provide us with Personal Information, the GDPR provides the following additional rights to residents of the European Economic Area:

Right to erasure (Art. 17 GDPR): You have the right to ask us to delete your Personal Information, as permitted by law.

Right to restriction of processing (Art. 18 GDPR): You have the right to request the limiting of our processing under limited circumstances.

Right to data portability (Art. 20 GDPR): You have the right to receive the Personal

Information that you have provided to us, in a structured, commonly used and machine-

readable format, and you have the right to transmit that information to another controller,

including to have it transmitted directly, where technically feasible.

Right to object (Art. 21 GDPR): You have the right to object to our processing of your Personal Information, as permitted by law.

Right to lodge a complaint before the Data Protection Authority (Art.77 GDPR): We encourage you to contact us directly and allow us to work with you to address your concerns. Nevertheless, you have the right to lodge a complaint with a competent

data protection supervisory authority, in particular in the EU Member State where you reside, work or the place of the alleged infringement. You have the right to do so if you consider that the processing of Personal Information relating to you infringes applicable data protection laws.

19. Privacy Shield Statements

360incentives.com USA, Inc. is self-certified under the EU-U.S. Privacy Shield Framework ("Privacy Shield") regarding the collection, use, and retention of Personal Information from European Union member states.

For EU Personal Information received in the United States under the Privacy Shield, we

certify that it adheres to the Privacy Shield Principles of Notice, Choice, Accountability

for Onward Transfer, Security, Data Integrity and Purpose Limitation,

Access, and Recourse, Enforcement and Liability. If there is any conflict between the standards of this Privacy Policy and the Privacy Shield Principles, the Privacy Shield Principles govern. To learn more about the Privacy Shield program, please visit the US Department of Commerce Privacy Shield website.

Under the Onward Transfer Principle, we may remain liable for the processing of European Personal Information that we transfer to our third party agents or service providers. In some instances, we may also be required to disclose Personal

Information to comply with valid requests from public authorities, including for national security or law enforcement purposes.

In compliance with the Privacy Shield, we commit to resolve your complaints

concerning data privacy and our collection or use of your Personal Information. We welcome you to bring any concerns directly to us. Eligible unresolved privacy complaints related to violations of the Privacy Shield Principles can be reported to the JAMS Mediation, Arbitration and ADR Services (“JAMS”), an alternative

dispute resolution provider located in the United States. If you do not receive timely acknowledgment of your complaint, or if your complaint is not satisfactorily addressed by us, please visit https://www.jamsadr.com/eu-us-privacy-shield for

information on how to file a complaint with JAMS.

Note that if your complaint is not resolved through either a direct interaction with us, or JAMS, under limited circumstances, a binding arbitration option may be available before a Privacy Shield Panel.

For the purposes of enforcing compliance with the Privacy Shield, 360incentives.com USA, Inc. is subject to the investigatory and enforcement powers of the United States Federal Trade Commission.

20. Marketing communications

Where we are legally required to do so, we ask you for your prior consent before providing you with promotional materials or information (referred to as “Commercial

Electronic Messages, or “CEM”s). You may revoke your consent to the receipt of CEMs at any time. This will not affect the processing of your Personal Information in relation to any rebate or incentive claim submitted to us on behalf of any of our

manufacturer or distributor clients.

21. Changes to this Privacy Policy

In order to enhance our Services, it might be necessary to change this Privacy Policy

from time to time. We therefore reserve the right to modify this Privacy Policy in

accordance with the applicable data protection laws. Please visit our Website from time to time for information on updates to this Privacy Policy.

22. Governing Law

360insights controls and operates this Site in Canada. Our online privacy practices are governed by the laws of Canada and Ontario, which may differ from privacy laws in your province, state or home country. By submitting your Personal Information to this

Site or to a 360insights manufacturer or distributor, you consent to the transfer of your Personal Information to any country and its use and disclosure in accordance with Canadian federal and Ontario provincial law and with this Privacy Policy.

23. For More Information or Assistance

If you have any questions regarding this Privacy Policy or the privacy practices of 360insights or its affiliates, or if you require assistance to withdraw your consent to our processing of your Personal Information or wish to request that your Personal Information be deleted, please contact us by sending an email

to privacy@360insights.com or writing to us at 360insights, 300 King St., Whitby ON L1N 4Z4, Attention: Chief Privacy Officer.

Miele Privacy Policy This Privacy Notice aims to inform you about the data processing in connection with our website and related services. The processing of personal data takes place exclusively within the framework of the respective valid legal data protection regulations, in particular the General Data Protection Regulation (hereinafter referred to as "GDPR"). 1. General information 1.1 Personal data In accordance with Art. 4 (1) GDPR, “personal data” means any information relating to an identified or identifiable natural person (hereinafter referred to as the “data subject”; a natural person is considered as being identifiable, directly or indirectly, in particular by means of an identifier such as a name, an identification number, location data, an online identifier or one or more special characteristics expressing the physical, physiological, genetic, mental, economic, cultural or social identity of this natural person. 1.2 Controller The controller within the meaning of Art. 4 (7) GDPR is Miele Co Ltd, Fairacres, Marcham Road, Abingdon, Oxfordshire, OX14 1TW Tel: 0330 160 6600 E-mail: info@miele.co.uk 1.3 Data Protection Officer You can contact our Data Protection Officer at the postal address listed under 1.2 or by sending an e-mail to: dpo@miele.co.uk 2. Collection and processing related to our website 2.1 Automatically processed data when visiting Each time you access our website, your browser automatically transmits data that are stored in the log files of the server. This includes the following data (hereinafter referred to as the "Log file data"): Information about browser type and browser version; operating system of the user; Internet service provider and IP address of the user; and

date and time of the access. The Log file data is anonymised and then evaluated on a continuous basis in order to improve the website, to adapt the website to the interests of our users and to be able to remedy errors quickly. For these purposes, the legal basis for the processing of data is our legitimate interest pursuant to Art. 6 (1)(f) GDPR. In a non-anonymised form, Log file data are used solely to detect malfunctions and to ensure system security, including detection and tracking of improper access attempts and fraud and abuse attempts. The data are stored for 7 to 14 days and then deleted. On occasions, we require the further storage of Log file data for evidence purposes so this will not be deleted until final clarification of the respective incident has been obtained and may in individual cases be forwarded to the investigating authorities. 2.2 Processed data when using the online shop If you actively submit data to us, for example by registering with our online shop or placing an order, we will process the data transmitted by you. When registering for our online shop or when using the online shop, we collect and process the following information from you: title; name; address; telephone number; password; as well as date of birth (voluntary); and order history. When ordering, we also process the following information: items ordered; delivery address, if different; and invoice and payment data. We process the above data in order to update your registration and to process your orders. The legal basis for processing this data is performance of a contract pursuant to Art. 6 (1)(b) GDPR. We store the data collected for the purposes of performing the contract until the expiry of the statutory or any contractual warranty and guarantee claims. Thereafter, we store the information required by commercial and tax law for the statutory periods of time for the sole purposes of making it available to the tax authorities in the event of an audit being. Your payment data will be forwarded to the respective payment service provider for payment processing. If you pay via PayPal, you will be redirected to PayPal's website via a link. With regard to payment processing, the data processed relate to your name, your address, your e-mail address, any telephone numbers and account or credit card information. If you have a query regarding the use of your personal data by PayPal please refer to the

General Terms and Conditions, Terms of Use and Privacy Notice of PayPal (Europe) S.à rl et Cie, SCA, 22-24 Boulevard Royal, L-2449 Luxembourg on the website: www.paypal.com. Orders for Miele calendars are processed via external service providers, to whom any payments are also to be made. These service providers act on our behalf and following our instructions. The delivery address will be forwarded to the delivery partner appointed by us. So that the delivery partner can contact you to coordinate the delivery date or in the case of delivery problems, we will provide the delivery partner with your e-mail address and, if applicable, telephone number. The respective data are transmitted solely for the respective purposes and are deleted after delivery. Some of our delivery partners offer track-and-trace services. We will transfer your e-mail address to the delivery partner in order to enable our partner to provide its track-and-trace services to you. The legal basis for the processing of the data is the consent pursuant to Art. 6(1)(a) GDPR. 2.3 Collection service In the event that you are in default of payment despite repeated reminders, we reserve the right to forward the data required for the execution of a collection to a debt collection agency for the purpose of fiduciary collection or to sell the outstanding claims to a collection service provider. In the event of a sale, the collection service provider becomes the holder of the claim and asserts the claims in its own name. The legal basis for the transfer of data in connection with the fiduciary collection is performance of contract pursuant to Art. 6 (1)(b) GDPR and for the transmission of data in the context of the sale of a claim our legitimate interest pursuant to Art. 6 (1)(f) GDPR. 2.4 Credit check Our company regularly checks your credit status for contracts and –in cases where we have a legitimate interest – even for existing customers. For this purpose, we work together with a service partner from which we receive the necessary data. In order to perform the above, we will transmit your name and contact details to our service partner. The legal basis for the data processing is our legitimate interest pursuant to Art. 6 (1)(f) GDPR. 2.5 Miele Club If you register for the Miele customer program Miele Club, we will collect the following customer data as part of the registration: title; name; address; telephone number;

password; and date of birth (voluntary). We process these customer data for the purpose of providing our customer programme. The legal basis is performance of contract pursuant to Art. 6 (1)(b) GDPR. We store the customer data during your membership in our Miele customer program Miele Club. Thereafter, we store the customer data only and insofar as we are obliged to store it for reasons based on commercial and tax law. 2.6 Commercial communication If and insofar as you have given us your consent for advertising purposes, e.g. you have signed up to the e-mail newsletter, the data processing required in the context of establishing contact with you takes place on the legal basis of consent pursuant to Art. 6 (1)(a) GDPR (hereinafter referred to as "Consent"). You may revoke your consent to us at any time with effect for the future (e.g. by using the unsubscribe link included in the e-mail). It might be possible that commercial communication will be provided through our external service providers. 3. Contact and customer service

3.1 Contacting us Our website lists different ways that you can contact us. Furthermore, you can contact us through our social media presences (e.g. on Facebook or Instagram). If you use these and contact us e.g. by e-mail, we will process the data you provided to us in order to answer your request. We have a legitimate interest in answering your enquiries. The legal basis for the data processing is therefore our legitimate interest pursuant to Art. (6)(1)(f) GDPR. If the purpose of your request is to conclude a contract, the legal basis is performance of contract pursuant to Art. 6 (1)(b) GDPR. When contacting us, data transmitted to us will be deleted after completion of your request, provided and insofar as we are not obliged to store it for reasons based on commercial and tax law. 3.2 Miele Customer Service You can contact Miele Customer Service in various ways, e.g. by telephone or online. In this case, we will process the data you submit to us as part of your request. Insofar as is necessary for the provision of customer service, for example, to collect the device from you, to carry out repair work or to process warranty or guarantee claims, your data will be forwarded to our service partners. The legal basis for the processing of your data in the context of customer service is performance of contract pursuant to Article 6 (1) (b) GDPR.

With regard to customer service, data transmitted to us will be deleted upon expiry of the corresponding warranty or guarantee periods, provided and insofar as we are not obliged to store them for a longer period for reasons based on commercial and tax law. 4. Cookies We also use cookies or similar technologies on our website, such as pixels (hereinafter referred to as "Cookies"). Cookies are small text files stored by your browser on your device, or image files, such as pixels. The next time you visit our website with the same device, the information stored in cookies will either be returned to our website (hereinafter referred to as "First Party Cookies") or to another website (hereinafter referred to as "Third Party Cookies"). The information stored in the cookies tells the website that you have already visited it. This allows us to display the website in the best possible way in accordance with your preferences. Only the Cookie itself is identified on your terminal. In addition, personal data will be processed only after your explicit consent or if absolutely necessary in order to be able to use the service offered and requested by you accordingly. You can disable certain Cookies on our Cookie settings page. Furthermore, you can generally prevent the storage of Cookies by setting your browser software accordingly; in that case, you may not be able to use all features of our website to their fullest extent. We inform you about the use of cookies in advance with a corresponding note on a banner. 5. Analysis and targeting tools 5.1 Google services On our website, we use various services provided by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland (hereinafter referred to as "Google"). For more information about Google services please visit http://www.google.com/privacy/ads/. 5.1.1 Google Analytics Our website uses Google Analytics for the needs-oriented design and improvement of the website. Google Analytics uses so-called cookies that are stored on your terminal and that allow an analysis of the use of the website by you. The information generated by the cookie is usually transmitted to a Google server in the US and stored there. We use the extension of IP anonymisation (referred to as IP masking) on this website, i.e. your IP address is shortened by Google within Member States of the European Union or in the other States that are party to the Agreement on the European Economic

Area. Only in exceptional cases will the full IP address be sent to a Google server in the US and shortened there. On behalf of the operator of this website, Google will use this information to evaluate your use of the website, to compile reports on website activity and to provide other services related to website activity and Internet usage to the website operator. The legal basis for the data processing is legitimate interest pursuant to Art. (6)(1)(f) GDPR. Google's services also include reporting on the effectiveness of our advertising efforts (including across devices), the demographics and interests of our users, and cross-device delivery features of online advertising when you have a Google Account and personalised advertising (hereinafter referred to as "personalised ads"). In this case, the legal basis of data processing is the consent you granted to Google (Art. 6 (1)(a) GDPR). You may object to the collection or analysis of your data by Google Analytics by downloading and installing the browser plug-in available under the following link: https://tools.google.com/dlpage/gaoptout. The data sent by us and linked to cookies, user identifiers (e.g. user ID) or advertising IDs will be automatically deleted after 14 months. For more information about the Google Analytics terms and conditions, visit http://www.google.com/analytics/terms/. 5.1.2 Google Remarketing Features Google's remarketing feature allows us to show our users advertisements based on their interests on our other websites within the Google Ads Network (so-called "Google ads" or ads on other websites). For this purpose, the interaction of the users on our website is analysed in order to be able to show users targeted advertising even after visiting our website on other sites. Google stores a number in the browsers of users who visit certain Google services or websites on the Google Display Network. This number records the visits of these users. The legal basis for the data processing is legitimate interest pursuant to Art. (6)(1)(f) GDPR. You may disable the use of cookies by Google by installing the plug-in provided at the following link: www.google.com/settings/ads/plugin 5.1.3 Google Conversion Tracking We also use Google's Conversion Tracking in this context. When you click on an ad served by Google, a 30-day conversion tracking cookie will be placed on your device. These cookies are not for personal identification. The information gathered using the conversion cookie is used to generate conversion statistics for Google Ads advertisers. The legal basis for this data processing is legitimate interest pursuant to Art. (6)(1)(f) GDPR.

You can disable Google interest-based ads on your browser by turning off http://www.google.com/settings/ads or opting out of http://www.aboutads.info/choices/. 5.1.4 Further Services of the Google Marketing Platform In addition, our website uses further services of the Google Marketing Platform (formerly “Google doubleclick”). These services use cookies to serve ads that are relevant to users, to improve campaign performance reports or to prevent a user from receiving ads multiple times. Google uses a cookie ID to record which ads are played in which browser and thus prevents them from being displayed multiple times. In addition, Google can use cookie IDs to track what are known as conversions, i.e. whether a user sees an advertisement and later goes to the advertiser's website and buys something there. According to Google, such cookies do not contain person information. Your browser automatically establishes a direct connection to the Google server. We have no influence on the extent and further use of the data collected through the use of this tool by Google. According to Google, through the involvement of this services, Google receives the information that you have accessed the relevant part of our website or clicked on an ad from us. If you are registered with a service of Google, Google can assign the visit to your user account. Even if you are not registered with Google or have not logged in, there is a chance that the provider will find out and store your IP address. In addition, the Google cookies allow us to understand whether you are performing certain actions on our website after you have viewed or clicked on one of our ads on Google or on another platform (Conversion Tracking) (“Floodlight”). Google uses this cookie to understand the content with which you have interacted on our web sites so that it can later send you targeted advertising. You can prevent the tracking process by setting your browser software accordingly (e.g. third party cookies disabled), deactivate the cookies for conversion tracking by blocking cookies from the domain www.googleadservices.com in your browser settings, at www.google.com/settings/ads, for interest-based ads of the providers that are part of the About Ads self-regulatory campaign, via the link http://www.aboutads.info/choices or the link http://www.google.com/settings/ads/. We point out that in this case you may not be able to use all the features of this offer in full. For more information about the Google Marketing Platform please visit https://marketingplatform.google.com/. You can also find more information from the Network Advertising Initiative (NAI) at http://www.networkadvertising.org/. The legal basis for the data processing is your consent pursuant to Art. (6)(1)(a) GDPR. 5.2 Facebook Custom Audiences

Our website uses the "Custom Audiences" remarketing feature of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (hereinafter referred to as "Facebook"). This allows users of the website to be shown interest-based advertisements ("Facebook Ads") as part of their visit to the social network Facebook or other websites that also use the process. We are interested in showing you advertisements that are of interest to you in order to make our online offers more interesting to you. The legal basis for the processing of your data is legitimate interest pursuant to Art. 6(1(1)(f) GDPR. The use of Custom Audience means your browser automatically establishes a direct connection to the Facebook server. We have no influence on the extent and further use of the data collected through the use of this tool by Facebook and therefore inform you that according to our knowledge: By integrating Facebook Custom Audiences, Facebook receives the information that you have accessed our website or have clicked on an ad from us. If you are registered with a service of Facebook, Facebook can assign the visit to your Facebook account. Even if you are not registered with Facebook or have not logged in, there is a chance that the provider will process your IP address and other identifying features. Disabling the "Facebook Custom Audiences" feature is available to logged-in users at https://www.facebook.com/settings/?tab=ads#. For more information about data processing through Facebook, please see: https://www.facebook.com/about/privacy. 5.3 Amazon Conversion Pixel and Amazon Remarketing Pixel Our website uses Amazon Conversion Pixel and Amazon Remarketing Pixel web analytics services from Amazon.com, Inc., 410 Terry Ave. North Seattle, WA, United States. The Amazon Conversion Pixel and the Amazon Remarketing Pixel use cookies that are stored on your computer that allow us to analyse the use of the Website by you, as well as personalised advertising. You can prevent the storage of cookies by using a corresponding setting on your browser software; however, please note that if you do this, you may not be able to use all the features of this website to the fullest extent possible. You may also prevent Amazon from collecting the data generated by the cookie and related to your use of the website, as well as the processing of such data by Amazon, by clicking on this link and selecting the setting "Do not personalise Ads by Amazon for this Internet Browser": https://www.amazon.de/adprefs. Alternatively, you can select the appropriate settings at http://www.youronlinechoices.com/en. An opt-out cookie will then be set in your browser, which prevents the future collection of your data by the Amazon Pixels when visiting our website. This opposition is valid as long as you do not delete the opt-out cookie. The legal basis for this is legitimate interest pursuant to Art. 6 (1)(f) GDPR, whereby the improvement in comfort and quality of our services justifies our legitimate interest.

5.4 Smartlook Our website uses the Smartlook analysis service of Smartsupp.com s.r.o., Milady Horakove 13, 602 00 Brno, Czech Republic. Smartlook captures movements on the viewed websites in so-called heatmaps. This allows us to see where users are clicking and how far they are scrolling. This allows us to make our website better and more customer friendly. This includes information about the website and the referencing URL, the date and time of the visit to the website and technical information in the form of screen resolution, operating system, browser type and device type, as well as the country and town from which the website was accessed. The users' IP address or form information will not be used for this purpose. You can disable Smartlook using the following opt out switch: Disable Smartlook. The Smartlook privacy policy can be found here: https://www.smartlook.com/en/privacy. The legal basis for the use of Smartlook is legitimate interest pursuant to Art. 6 (1)(f) GDPR, whereby the improvement in comfort and quality of our website justifies our legitimate interest. 6. Social media plugins Our website uses the Facebook social media plug-in of Facebook Inc., 1601 S. California Ave, Palo Alto, CA 94304, USA (hereinafter referred to as "Facebook"). An overview of Facebook plug-ins can be found here: http://developers.facebook.com/docs/plugins; You can find further information on Facebook's Privacy Policy at the following link: www.facebook.com/policy.php Facebook may receive the information that you have accessed the corresponding website of our online service and possibly interacted with the plug-in. By activating the plug-in, your personal data will be saved and sent to Facebook in the USA. We have no influence on the collected data and data processing operations, nor are we aware of the full extent of data collection, the purpose of the processing, or the retention periods. We also have no information on how to delete the data collected by Facebook. As far as we know Facebook stores the data collected about you as usage profiles and uses them for purposes of advertising, market research and/or tailor-made website design. Such an evaluation is carried out in particular (also for non-logged-in users) for the presentation of needs-based advertising and to inform other users of the social network about your activities on our website. You have a right to object to the formation of these user profiles, whereby you must exercise this right to Facebook. Through the plug-ins we offer you the opportunity to interact with the social networks and other users, so that we can improve our offer and make it more interesting for you

as a user. The legal basis for the use of the plug-ins is legitimate interest pursuant to Art. 6(1)(f) GDPR. You can completely prevent the plug-ins from being loaded using add-ons for your browser, so-called script blockers. 7. Social media presence 7.1 Note regarding the Facebook Fanpage Accessing https://www.facebook.com/MieleGreatBritain/ will take you to our fanpage on the Facebook.com social network of Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland (hereinafter referred to as "Facebook"). If you visit our fanpage, Facebook collects data and processes it in the US, if necessary. This also happens if you yourself are not a registered user of Facebook or simply have not logged in to your Facebook account. According to information provided by Facebook, the data collected includes, among other things, the IP address, operating system information, hardware versions and browser type, data collected from Facebook cookies about your user behaviour, and other technical data. Please refer to the Facebook Privacy Policy, which you can access here: https://www.facebook.com/privacy/explanation. You can also find information from Facebook about cookies on https://www.facebook.com/policies/cookies. 7.2 Note regarding Twitter We operate the Twitter account https://twitter.com/miele_gb?lang=en or MieleGreatBritain (@Miele_GB) on the short message service, Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, (hereinafter referred to as "Twitter"). The body responsible for the data processing of persons living outside of the United States is Twitter International Company, One Cumberland Place, Fenian Street, Dublin 2 D02 AX07, Ireland. When you use Twitter, your personal data are collected, transmitted, stored, disclosed and used by Twitter, transmitted, stored and used wherever you reside in the United States, Ireland and any other country in which Twitter operates. We have no influence on the processing of the collected data, as it is performed solely by Twitter. Information about which data are processed by Twitter and used for which purposes can be found in the Twitter Privacy Policy: https://twitter.com/privacy 7.3 Note regarding Instagram We run the Instagram account https://www.instagram.com/miele_gb/?hl=en or Miele Great Britain (@miele_gb) on the social network Instagram, which is part of Facebook Ireland Ltd, 4 Grand Canal Square, Grand Canal Harbour, Dublin 2 Ireland (hereinafter referred to as "Instagram"). If you visit our account, data will be collected

from Instagram and processed in the US, if necessary. This also happens if you yourself are not a registered user of Instagram or have not logged in to your Instagram account. We have no influence on the processing of the collected data, as it is performed solely by Instagram. According to information provided by Instagram, the data collected includes, among other things, the IP address, operating system information, hardware versions and browser type, data collected from Instagram cookies about your user behaviour, and other technical data. Please refer to the Instagram Privacy Policy, which you can access here: https://help.instagram.com/519522125107875?helpref=page_content. 7.4 Note regarding YouTube We operate the YouTube Channel https://www.youtube.com/channel/UCfXwDm8rRwCIiU3qU-wNINQ (Miele Great Britain) on the YouTube video platform, which is part of YouTube LLC, 901 Cherry Ave., San Bruno, CA 94066 USA (hereinafter referred to as "YouTube"). If you visit our channel, data will be collected from YouTube and processed in the US, if necessary. This also happens if you yourself are not a registered user of YouTube or have not logged in to your YouTube account. We have no influence on the processing of the collected data, as it is performed solely by YouTube. According to information provided by YouTube, the data collected includes, among other things, the IP address, operating system information, hardware versions and browser type, data collected from YouTube cookies about your user behaviour, and other technical data. Please refer to the YouTube Privacy Policy, which you can access here: https://policies.google.com/privacy. 8. Job applications If you apply via the Miele application portal or form or otherwise for a position with us and send us application documents, we will process the personal data you provide in this context only for the purpose of the application process. Insofar as you have applied for an advertised position, the documents will be automatically deleted six months after completion of the application procedure, provided deletion does not conflict with our legitimate interests. In the case of an application without reference to an advertised position (unsolicited application), the application will be kept for a maximum period of one year in order to contact you, if necessary, with regard to a vacancy that arises during this time. At any time you have the option of requesting the deletion of your application prior to expiry of the scheduled retention periods. In the case of a successful application, the data provided to us will be stored in your employee file in compliance with the legal requirements. If you have applied for an position with another Miele Group company, we will forward your application to the respective company for the purpose of deciding on the establishment of an employment relationship.

As far as we process your data for the decision on the establishment of an employment relationship, the legal basis the performance of our employment contract with you and our legitimate interests of managing our relationship with you (where the processing activities are not strictly speaking necessary for the performance of a contract. In all other cases, the legal basis for storing your application data is your consent in accordance with Art. 6(1) lit. (a) GDPR. 9. Miele trade fair presence If you visit one of our booths, we collect your data if you provide us with such, e.g. by handing over your business card. We process these data to respond to your queries, e.g. contact for further discussions or offers. If this is necessary to respond to your queries (e.g. when requesting a contact abroad), we will forward your data to the responsible person of the respective company of the Miele Group. We have a legitimate interest in answering your enquiries. The legal basis for the data processing is our legitimate interest pursuant to Art. (6)(1)(f) GDPR. If the purpose of your request is to conclude a contract, the legal basis is performance of contract pursuant to Art. 6 (1)(b) GDPR. If you give us your consent for such, the legal basis is Art. 6 (1)(a) GDPR. You may revoke your consent at any time with effect for the future. When contacting us, data transmitted to us will be deleted after dealing with your request, provided and insofar as we are not obliged to store it for reasons based on commercial and tax law. At our booths, we also occasionally take pictures and film recordings for documentation, marketing and press purposes, which are then published via i.a. our social media channels (e.g. Facebook, YouTube or Instagram). In this case, we expressly point this out to you by posting a notice on the stand. You may revoke any consent granted to us regarding the use of an image at any time with effect for the future. 10. Access to your personal data Within the context of the data processing described in this privacy notice, it might be possible that we transfer personal data to the following categories of recipients (in addition to the recipients expressly stated in this privacy notice): authorized agents and other consultants (e.g. attorneys, tax accountants, auditors); service providers; companies of the Miele Group (https://www.miele.com/en/com/subsidiaries-2156.htm); insurance companies; and state agencies and governmental bodies.

We only transfer personal data to third parties insofar it is required to fulfil our contractual obligations, in case we have or the respective third party has a legitimate interest in processing the personal data or if you have given consent to the transfer. Furthermore, we only transfer personal data to third parties if and insofar we are obligated to do so according to applicable law, regulatory action or court order. 11. Your Rights Data subjects have various rights under the GDPR where certain conditions apply. These include in particular: Right to access: According to Art. 15 GDPR, you can request a confirmation as to whether personal data concerning you is being processed by us. If such processing is available, you may also request further information about the processing from us. Right to rectification: In accordance with Art. 16 GDPR, you are entitled to rectification and/or completion if the processed personal data concerning you is incorrect or incomplete. Right to restriction of processing: You may request, pursuant to Art. 18 GDPR, that the processing of your personal data be restricted. Right to erasure: According to Art. 17 GDPR, you also have the right under certain circumstances to demand the deletion of your personal data stored about you. Right to data portability: In accordance with Art. 20 GDPR, you are also entitled to receive the personal data that you have provided in a structured, common and machine-readable format and to transmit it without any obstruction from us to another controller. 12. Right to complaint You have the right to complain about the handling of your personal data to a data protection authority. 13. Right of objection If your personal data are processed on the basis of legitimate interests pursuant to Art. 6(1)(f) GDPR, you have the right to object to the processing of your personal data in accordance with Art. 21 GDPR, provided there are reasons for this arising from your particular situation or if your objection is based on being targeted to marketing purposes. In the latter case, you have a general right of objection, which is implemented by us without any situation being specified.