COS BY YOU PRIVACY NOTICE

Data privacy is of high importance for COS and we want to be open and transparent with our processing of your personal data.

We therefore have a policy setting out how your personal data will be processed and protected.

Who is the controller of your personal data?

The Swedish company, H & M Hennes & Mauritz GBC AB (“COS”), is the controller of the personal data you submit to us and responsible for your personal data under applicable data protection law.

H & M Hennes & Mauritz GBC AB
Mäster Samuelsgatan 46
106 38 Stockholm
Sweden

Companies register: Bolagsverket/Swedish Companies Registration Office
Company registration number: 556070-1715
Authorised representative: Karl-Johan Persson
VAT registration number: VAT NO. SE556070171501

Why do we use your personal data?

We want to share and inspire the ways of wearing COS pieces. We will use your personal data to share user generated content by uploading the pictures you submit to us on all our platforms.

What types of personal data do we process?

We will process following categories of personal data

*Instagram account name
*photo
*video

Who has access to your personal data?

Data that is forwarded to third parties is only used to provide you with the service mentioned above, to media agencies and technical suppliers to upload your pictures you submit to us.

We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group.

What is the legal ground to process your personal data?

The processing of your personal data is necessary to fulfill the service of COS by you.

Collecting your personal data when uploading your pictures to COS by you is required to fulfill our commitments according to the terms and conditions for COS by you.

If you don't submit your personal data we won't be able to upload your pictures on COS by you.

How long do we save your data?

We will keep your personal data for 24 months or until the agreement with COS is terminated.

Where do we store your data?

The data that we collect from you is stored within the European Economic Area (“EEA”) but may also be transferred to and processed in a location outside of the EEA. Any such transfer of your personal data will be carried out in compliance with applicable laws.

For transfers outside the EEA, COS will use Standard Contractual Clauses and Shields as safeguards for countries without adequacy decisions from the European Commission.

Who can access your data?

Your data may be shared within the H&M group (for details on the companies within the H&M group, please refer to our annual report which may be found at about.hm.com). We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group.

The local COS company will only act as the personal data processor and processes the personal data on behalf of the Swedish company.

Data that is forwarded to third parties, is only used to provide you with our services. You will find categories of third parties under every specific process below.

What is the legal ground for processing?

For every specific process of personal data we collect from you, we will inform you whether the provision of personal data is statutory or required to enter a contract and whether it is an obligation to provide the personal data and possible consequences if you choose not to.

What are your rights?

Right to access:

You have the right to request information about the personal data we hold on you at any time. You can contact COS and we will provide you with your personal data via e-mail.

Right to portability:

Whenever COS processes your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.

Right to rectification:

You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed. If you have a COS account you can edit your personal data under your account and membership pages.

Right to erasure:

You have the right to erase any personal data processed by COS at any time except for the following situations:

*you have an ongoing matter with Customer Service
*you have an open order which has not yet been shipped or partially shipped
*you have an unsettled debt with COS, regardless of the payment method
*if you are suspected or have misused our services within the last four years
*your debt has been sold to a third party within the last three years or one year for deceased customers
*your credit application has been rejected within the last three months
*if you have made any purchase, we will keep your personal data in connection to your transaction for book-keeping purposes.

Your right to object to processing based on legitimate interest:

You have the right to object to processing of your personal data that is based on COS’ legitimate interest. COS will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.

Your right to object to direct marketing:

You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes.
You can opt out from direct marketing by the following means:
* following the instruction in each marketing email
* by editing the settings of your COS account

Right to restriction:

You have the right to request that COS restricts the process of your personal data under the following circumstances:
* if you object to a processing based COS’ legitimate interest, COS shall restrict all processing of such data pending the verification of the legitimate interest
* if you have claim that your personal data is incorrect, COS must restrict all processing of such data pending the verification of the accuracy of the personal data
* if the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data instead
* if COS no longer needs the personal data but it is required by you to defend legal claims

How can you exercise your rights?

We take data protection very seriously and therefore we have dedicated customer service personnel to handle your requests in relation to your rights stated above. You can always reach them at customerservice.us@cos.com.

Data Protection Officer:

We have appointed a Data Protection Officer to ensure that we continuously process your personal data in an open, accurate and legal manner. You can contact our Data Protection Officer at customerservice.us@cos.com and write DPO as subject matter.

Right to complain with a supervisory authority:

If you consider H&M to process your personal data in an incorrect way you can contact us. You also have the right to raise a complaint to a supervisory authority.

Updates to our Privacy Notice:

We may need to update our Privacy Notice. The latest version of the Privacy Notice is always available on our website. We will communicate any material changes to the Privacy Notice, for example the purpose of why we use your personal data, the identity of the Controller or your rights.

To remove Photos or Moving Content please contact customerservice@cosstores.com.