Loading...

loading

Privacy & Personal Data Protection and Cookie Policy

A. Privacy and Personal Data Protection Policy

1. Introduction
2. Who We Are and How to Contact Us?
3. What Personal Data Do We Collect & When We Collect It?
4. For What Purposes and Based on Which Legal Grounds Do We Use Your Personal Data?
5. To Whom Do We Disclose Your Personal Data?
6.  Processing of Personal Data in Third Countries
7. Where Do We Store and For How Long Do We Keep Your Personal Data?
8. What Are Your Rights as Data Subject?
9. How Can You Exercise Your Rights As Data Subject And Our Data Subject Request Procedure?
10. Automated Decision-Making and Profiling
11. Confidentiality & Security
12. Other Provisions
B. Cookies

 

A. Privacy and Data Protection Policy

1. Introduction

LC Waikiki (the “Company”, “we”, “us”, “our”) respects your privacy and is committed to protect and process your personal data fairly and transparently, in accordance with the provisions of Law of Georgia on Personal Data Protection. All your personal details and information belong to you and we acknowledge and respect that.
Since visiting www.lcw.com/en-GE,  www.lcw.com/ge-GE (“Website”, “Online Store”) and accessing our online store services (registration, orders) implies collection and processing of your personal data, we have developed and hereby make available to you our Privacy & Personal Data Protection and Cookies Policy (“Privacy Policy”) in order for you to fully understand what data do we collect and when, how and why we use it, to whom do we disclose personal data and how we keep it secure alongside other relevant information. Within this Privacy Policy you can also find information on your rights as data subject and how can you exercise them.
Before accessing, browsing or otherwise using this Website, please read carefully this Privacy Policy alongside our Terms & Conditions.
Our Website may contain links to third party websites and services. Please remember that when you use a link to go from our Website to another website or when you request a service from a third party, this Privacy Policy no longer applies, and you shall be subject to the third party’s privacy policy.
If anything is unclear to you or should you require more information on any section of this Privacy Policy, please feel free to contact us using the details below.
In order for you to browse this Privacy Policy more easily, please find below a glossary of the relevant legal terms/notions and their definitions/explanations:
Legal term/notion Definition/Explanation
   
Personal Data Protection Law The Law of Georgian on Personal Data Protection
Personal data any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
Special categories of personal data data connected to a natural person’s racial or ethnic origin, political views, religious or philosophical beliefs, membership of professional organizations, state of health, sexual life, criminal history, administrative detention, putting a person under restraint, plea bargains, abatement, recognition as a victim of crime or as a person affected, also biometric and genetic data that allow to identify a natural person by the above features.
Data subject any natural person whose personal data is processed.
Processing any operation performed in relation to the data by automated, semi-automatic or non-automatic means, in particular collection, recording, photographing, audio recording, video recording, organisation, storage, alteration, restoration, request for access to, use or disclosure by way of data transmission, dissemination or otherwise making them available, grouping or combination, locking, deletion, or destruction.
Controller the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data and who, directly or through a data processor, processes personal data.
Joint controllers two or more controllers that jointly determine the purposes and means of processing and who, directly or through a data processor, processes personal data.
Processor a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
Recipient a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, except for a Personal Data Protection Service.
Consent Freely given, specific, informed and unambiguous indication of the data subject's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
Online identifiers internet protocol addresses, cookie identifiers or other identifiers such as radio frequency identification tags provided by data subject devices, applications, tools and protocols. These may leave traces which, in particular when combined with unique identifiers and other information received by the servers, may be used to create profiles of natural persons and identify them.
Profiling any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person, in particular to analyze or predict aspects concerning that natural person’s performance at work, economic situation, health, personal preferences, interests, reliability, behavior, location or movements.

2. Who We Are and How to Contact Us

This Website, all the available online services (e.g. personal shopping etc.) and thus all related data processing activities are jointly operated and carried out by the following entities from the LC Waikiki Group of companies as joint controllers:
  1. Mainly by LC WAIKIKI MAĞAZACILIK HIZMETLERI TIC. A.Ş., mother company and sole shareholder of LC WAIKIKI GE LLC, registered and functioning under Turkish laws, with headquarters in Turkey, 15 Temmuz Mahallesi Gülbahar Cad. No:41 Bağcılar, 34212 İstanbul, Turkey for marketing and profiling purposes;
  2. In subsidiary by LC WAIKIKI GE LLC, company registered and functioning under Georgian laws, with headquarters in Georgia, Tbilisi, 5a Dolidze Street, floor 6, duly registered with the National Agency of Public Registry under ID No 404916114.
If you have any questions about this Privacy Policy or want to exercise any of your rights set out in this Privacy Policy, please contact us by one of the following means:

3. What Personal Data Do We Collect & When We Collect It ?

3.1. Personal data that LC Waikiki collects. Depending upon your interaction with our Website and on the services, you choose to use, we can collect the following personal data about you:
(i) Personal Data we obtain directly from you:
• Name and Surname;
• ID number;
• Billing and Delivery Address(es);
• Email Address(es) (personal or professional);
• Phone Number(s) (personal or professional);
• Shopping and Purchase information (order number, purchased items, related messages and communications, delivery and return status, order history);
• Payment details (payment status, preferred payment method);
• Account Password and Login details, account ID;
• Date of Birth;
• Shopping preferences or details (category of products you are interested in e.g. ladies wear, style of interest etc.);
• Your interactions with our Customer Relationship Management (any online of phone requests, return requests, complaints etc.);
(ii) Data that we may collect automatically when you interact with this Website and our services, depending on your browser settings:
• Online identifiers and other data such as:
  • IP Address - When visiting our Website we can collect an automatically populated IP address assigned to your device. An IP address is a unique number which allows a computer, group of computers or another internet connected device (such as your mobile phone or tablet) to browse the internet;
  • Device information (device type, operating system, software versions, configuration settings, internet connection details), including location data;
  • Website usage, browsing history, shopping basket content - We can also record the time and date of your visit, the pages that were requested, the referring website (if provided) and your internet browser version;
  • Interaction with our e-mail newsletters through beacons/links that allow us to know if you have read the newsletter and can track you on our Website if you are logged in; 
  • Cookie information (please see our Cookie Policy for details).
(iii) Information we may obtain from third parties:
• Social Media - Depending on your settings or the privacy policies for social media and messaging service like Facebook, you may be requested to give us permission to access information from those accounts or services such as (public profile information, your account ID, other information you have agreed to share).
3.2. We Do Not Purposely Collect:
(i) Credit or debit card information
Should you decide to pay for your order online, kindly be informed that your card data is collected and processed directly by the online payment processor and no such data is disclosed to us. 
(ii) Personal Data of Children
LC Waikiki does not knowingly solicit personal data from children or send them requests for personal data. Although this Website can be accessed by visitors of all ages, we do not intentionally collect personal data from persons under the age of 18. As per our Terms & Conditions customers under the age of 18 are not allowed to create a user account or register for our e-mail newsletter. If you are under the age of 18, please do not try to use any of our services that implies collection of personal data.
In case a person under the age of 18 has registered a user account on our Website by using false information, we shall cancel the child's account and delete the child's personal data from our records, upon request from a parent or a legal guardian.
(iii) Special categories of data
LC Waikiki does not request you to provide information on your health, racial or ethnic origin, personal beliefs or sexual orientation or any other special categories of data defined under the Personal Data Protection Law. However, in case you may deliberately provide us with such details while communicating with us, soliciting our assistance or while submitting a complaint, we shall process such special category data in order to reply, assist you or otherwise settle your complaint.
3.3. When does LC Waikiki collect personal data?
In general, we collect your data when you decide to interact with us. This could include visiting our Website, purchasing our products online, registering a user account, registering for our newsletter etc.
We collect personal data when you:
  • Visit, access or navigate through our Website;
  • Register a customer account through our Single Sign On (“SSO”) system that has been designed for your satisfaction. The SSO enables you to register with the same ID and password through multiple LC Waikiki e-commerce platforms all over the countries where we carry e-commerce activities. In other words, one customer account will enable you to shop on any platform and send products to any location where LC Waikiki delivers, to track all orders you submitted on various platforms and prevents you from opening multiple accounts and remembering different passwords;
  • Update or modify your profile within your customer account;
  • Submit an order for purchasing our products;
  • Register to receive our e-mail newsletter and interact with our e-mail newsletters;
  • Contact us by telephone, email or online through our “Contact us” Section for any reason (order queries, complaints, website issues);
  • Choose to complete any surveys that we send to you for research purposes (although you are under no obligation to complete these);
  • From time to time, we may also get data about you from third parties, such as, when you engage with us via social media. This could include other partners that we have run partnerships, competitions and events with.

4. For what purpose and based on which legal ground do we use your personal data?

We use your personal data in several ways and for different purposes, including providing services that you have requested, offering you a personalized experience, processing your orders and requests and informing you about our products.
For a comprehensive, but easy to follow presentation of our purposes and legal grounds, please go through the tables below:
Personal
Data
Purpose Legal Ground
Your name and contact details (billing and delivery address, telephone number, e-mail address) To process, confirm and fulfil your order, including, confirming payment, updating you on the status of your order and shipping the order to you. Data processing is necessary to deal with the application of a data subject (to provide services to him/her), as per Article 5(j) of the Personal Data Protection Law. Additionally, data processing is necessary to enter into a contract at the request of the data subject, as per Article 5(b) of the Personal Data Protection Law.
Your name, ID number and billing address Billing and accountancy record keeping. To comply with our legal obligations, as per Article 5(d) of the Personal Data Protection Law.
 
Your name and contact details, order information, payment details Refunds and returns. Performance of the distance sales contract we have concluded with you, as per Articles 5(b) and 5(j) of the Personal Data Protection Law.
We may also have to comply with our legal obligations in record keeping, as per Article 5(d) of the Data Protection Law.
Your name, contact details, account ID, order information and status, payment details (for registered customers) Customer support and general assistance (answering any questions or complaints) Performance of the distance sales contract we have concluded with you, as per Articles 5(b) and 5(j) of the Personal Data Protection Law.
In case you have not submitted an order or registered an account, it is our legitimate interest to assist you in any matter regarding our products, Website and services, as per Article 5(i) of the Personal Data Protection Law.
Your name and contact details (for unregistered customers)
Your name and contact details In the detection and prevention of fraud or other crimes. It is our legitimate interest to protect LC Waikiki against fraud and it is also our legal duty to report crimes, as per Articles 5(i) and 5(d) of the Personal Data Protection Law.
Your name and contact details To invite you to complete a survey where you have purchased goods on this Website and/or to measure your satisfaction with our call center and/or other services we provide. We may use third parties to send you these surveys and compile responses. It is our legitimate interest to monitor and further improve the quality of our products and services, as per Article 5(i) of the Personal Data Protection Law.
Password and login information To verify your identity when you access your account or to contact you to perform security checks. It is our legitimate interest, as per Article 5(i) of the Personal Data Protection Law, to verify your identity and to ensure that services are provided to the correct person.
Your payment details For purposes of fulfilling your order, confirm and receipt your payment, updating the order and payment status of your order and shipping the order to you. We've got to do this to perform our distance sales contract with you and our contracts with partners and suppliers who work with us to provide a service to you, as per Articles 5(b), 5(i) and 5(j) of the Personal Data Protection Law.
Date of birth To verify your age and the fact that you are not a person under the age of 18. It is our legitimate interest to verify that you have the capacity to conclude a contract with us, as per Article 5(i) of the Personal Data Protection Law.
Sex To show you products or the section of the Website dedicated to your gender. It is our legitimate interest to showcase you LC Waikiki products that could be more relevant to you, as per Article 5(i) of the Personal Data Protection Law.
Your name and e-mail and/or telephone number, your saved preferences in language and country for registered customers as enabled by SSO system For marketing purposes such as to send you email and SMS about promotions, campaigns, discounts and new product offers for LC Waikiki goods, as per your preferences. Your consent, when choosing to subscribe to our newsletter, as per Article 5(a) of the Personal Data Protection Law. You are free to unsubscribe from receiving these marketing communications at any time.
We collect your contact details in the process of a sale of our product. Based on your consent, we shall send you e-mails to market only LC Waikiki products. You shall be able to opt-out from receiving these emails when we first collect your contact details, and you shall be able to unsubscribe in every subsequent communication from us in the same form in which the direct marketing is carried out.
Your activity on the Website To monitor and improve the services and the Website, by observing browsing activity and session replays.
Analytical purposes, for understanding and improving our Website performances.
It is our legitimate interest, as per Article 5(i) of the Personal Data Protection Law to monitor and improve our services and Website performances. Your consent to cookies, as per Article 5(a) of the Personal Data Protection Law. Please see our section on Cookies and our Cookie Policy for more details. You can withdraw your consent and manage your cookie settings at any time.
Your device information, preferences and cookies provided when you browse our website To tailor your experience online and show you personalized Website pages (in combination with other information you have provided us or our third parties) so that we can offer you goods, services, promotions and offers that we think you will be interested in. Your consent to cookies, as per Article 5(a) of the Personal Data Protection Law. Please see our section on Cookies and our Cookie Policy for more details. You can withdraw your consent and manage your cookie settings at any time.
Data gathered by Advertising Cookies, advertising technologies and other online identifiers, search history, accessed content on our Website. To target our advertising banners, more precisely to show you LC Waikiki advertising on Social Media platforms or on other websites you use.
We use for such purpose several digital marketing networks, ad exchanges and advertising technologies such as advertising cookies, web beacons, pixels, online identifiers, ad tags, including specific services offered by sites and Social Media, such as, Facebook’s Custom Audience service.
The LC Waikiki banners and ads you may see will be based on your activity on our Website (search history and accessed content) or on LC Waikiki banners and ads that you have clicked/accessed before.
We will do this only if you have consented, as per Article 5(a) of the Personal Data Protection Law, to the use of advertising cookies on our Website. Please see our Cookie Policy for more details. You can withdraw your consent and manage your cookie settings at any time.
Your name, gender, Website activity, shopping habits and preferences as resulted from cookies and online identifiers, social media accounts information Profiling purposes,
to combine the information that we collect directly from you, with any information that we obtain from third parties to whom you have given your consent to pass that data onto us, (such as the Social Media platforms) in order to create a profile of shopping behavior and to classify our customers into segments, using shopping habits information regarding your personal or professional interests, demographics, experiences with our products and contact preferences.
In principal, this is based on your consent to cookies, as per Article 5(a) of the Personal Data Protection Law. Please see our Cookie Policy for more details. You can withdraw your consent and manage your cookie settings at any time.
Secondary it is also our legitimate interest to understand our customers and what will interest them for the best customer experience, as per Article 5(i) of the Personal Data Protection Law. These segments help us to understand our customers better. To the extent we receive data from third parties, this will be based on the permission you have given that third party to share your data with us.
Your contact details, order information, purchase history Profiling purposes, in order to create a profile of offline shopping behavior and to send you email and SMS about promotions, campaigns, discounts and a new product offers for LC Waikiki goods, as per your preferences. Your consent as per Article 5(a) of the Personal Data Protection Law. You are free to unsubscribe from receiving these marketing communications at any time.
Your name, contact details, order information, payment details, purchase history Defending or fulfilling our rights in court (including the recovery of due amounts) It is our legitimate interest to seek fulfillment of our rights and do defend ourselves in court against any complaints, as per Article 5(i) of the Personal Data Protection Law.
Your name, contact details and all other requested information Providing the competent authorities and public institutions with the necessary information during official investigations/procedures. Fulfilling our legal obligations, as per Article 5(d) of the Personal Data Protection Law,
 

5. To Whom Do We Disclose Your Data?

In order to provide our products and services to you, we share your data with the relevant LC Waikiki employees and if required, may share with several partners as well, as categorized below:
• LC Waikiki employees bound by duty of confidentiality from several departments (Online Sales, Marketing, IT).
• Partners that help us confirm your order by providing e-mail delivery services.
• Partners that help us get your orders to you by providing fulfillment services (warehouse, order packing and operating return) and shipment/delivery services.
• Partners that help us provide our Website and deliver our marketing and advertising to you, such as IT providers, marketing agencies, advertising partners and website hosts.
• To the extent required by law, search warrant or court order, to public authorities and institutions, judicial research bodies, judicial courts, if we are under a duty to disclose your personal data in order to comply with any legal obligation or if we are seeking defense or fulfillment of our rights in court.
• Companies approved by you, such as social media sites (if you choose to link your accounts to us), and payment service providers, if you choose to perform the payment through their payment service.
• In case we shall sell assets or transfer an area of the business to a new provider, it might be necessary for us to disclose your personal data to the prospective buyers or any third party who acquires our assets or to whom the business is transferred to.
We shall disclose to such partners only the data necessary for them to provide their services.
All our partners have undertaken to ensure and to protect the confidentiality of your data. We always conclude written contracts and data processing agreements with our Partners which provide assurances in relation to their adherence to Georgian data security standards and to the implementation of adequate technical and organizational measures designed to protect your personal data. We do not, and shall not, sell any of your personal data to any third party.

6. Processing of the personal data in a third country

We are an international business; therefore, your personal data may be processed or received outside the territory of Georgia. Please take into consideration, that the main data controller is LC WAIKIKI MAĞAZACILIK HIZMETLERI TIC. A.Ş, a company with its headquarters in Turkey. Even though your data physically are not stored in Turkey, the employees of the main controller will have a constant access to your data, and they will process these data for e-commerce activities with you.
We hereby inform you that the Personal Data Protection Service has yet to decide that Turkey ensures an adequate level of personal data protection. Accordingly, Turkey is not named by the Personal Data Protection Service in the “whitelist” of countries with proper security guarantees for personal data protection.
Please however note that LC Waikiki Group of companies operate on an international level, including in the European Union, and all companies within the group ensure that personal data is processed in full compliance with General Data Protection Regulation (GDPR) in accordance with the consistent data processing standards applicable within the group by taking adequate legal, organizational, technical and security measures. We hereby guarantee that, your personal data collected under this policy, will be processed in full compliance with Personal Data Protection Law and General Data Protection Regulation (GDPR).
You, as the data subject, hereby give an explicit consent to the data controller, LC WAIKIKI MAĞAZACILIK HIZMETLERI TIC. A.Ş., a company with its headquarters in Turkey, for the processing and/or reception of the personal data in accordance with this policy. In case you do not agree to the processing and/or reception of your personal data by LC WAIKIKI MAĞAZACILIK HIZMETLERI TIC. A.Ş., a company with its headquarters in Turkey, please do not use our website.
When justified or necessary, we will transfer your personal data to partners/entities established or owning servers in third countries in a manner consistent with legal requirements.
In all cases, any transfer of your personal data will be compliant with applicable data protection laws and standards.

7. Where Do We Store and For How Long Do We Keep Your Personal Data?

Your personal data is stored by LC Waikiki on servers located in Netherlands..
We process and retain personal data only for as long as is necessary to fulfill our purposes, contractual obligations and other legal obligations of storage / archiving, as the case may be.
We shall retain the data only for as long as is necessary and / or prescribed by law for that purpose. For example:
  • Data processed for concluding and performing the distances sales contract will be kept for the entire contractual period plus a maximum period of 3 years during which related rights should reach prescription/statute of limitation.
  • Data processed for user account purposes will be kept for as long as your account is valid. Your account shall be disabled and closed after a period of inactivity of 10 years calculated since the last log-in in that account. This means that personal data that is not subject to archiving or does not refer to an order (distance sales contract) shall be deleted after such period of inactivity. You will be able to register a new customer if your old one has been disabled.
  • Data processed for billing purposes and supporting accounting documents will be kept for a period of 6 years, as the case may be, according to the Georgian accounting laws.
  • Data processed under your consent will be processed during the validity period of your consent or until you choose to withdraw your consent, or the data is no longer necessary. We reserve the right to ask you periodically to renew your consent.
  • Data processed under our legitimate interest will be processed for a maximum period of 5 years, after which it will be anonymized and processed for statistical purposes.
In some circumstances, such as to meet our legal or regulatory obligations, resolve disputes, prevent fraud and abuse, or enforce our terms and conditions, we may hold on to your personal data after we’ve finished providing services to you, or for longer than our general retention policy.

8. What Are Your Rights as Data Subject?

You have the following rights in relation to the personal data we hold about you:    

·Your right to be informed about how your personal data is being used

You have the right to be provided with sufficient information, in a concise, transparent and easily understandable form, in order for you to gain insight and understanding of our processing activities and thus to ensure transparency of personal data use. For such informational purposes we have designed and made available to you this Privacy Policy.
This Privacy Policy will keep you informed about how we will use your personal data. All necessary details have been provided hereto, so please read it carefully.

·Your right of access

In brief
If you submit an access request to us, we shall confirm whether we are processing your personal data and, if so, provide you with a copy of that personal data (along with certain other details).
In detail
Upon your request, we will confirm that we process your personal data and, if so, we will provide you with a copy of your personal data that is subject to our processing and the following information:
a)   the purposes of the processing;
b)   the categories of personal data concerned;
c)   to whom his/her personal data were disclosed, and the grounds and purpose of the disclosure;
d) the legal grounds for data processing;
e) the ways in which the data were collected;
The data subject shall be provided with the above-mentioned information not later than 10 working days after the request as per Article 14.2 of the Personal Data Protection Law.
The first copy of your personal data is provided free of charge. For additional specimens of the same personal data, we may charge a reasonable additional charge, taking into account the related administrative costs.

·Your right to correct, update and add personal data

If the personal data that we hold about you is inaccurate or incomplete, you are entitled to have it corrected and/or updated. You can personally do so by updating you user account information. If you do not want to personally update or you do not have a user account, you can submit a request and we shall perform the necessary changes.
If we’ve shared your personal data with others, we’ll let them know about the changes where possible. If you ask us, where possible and lawful to do so, we’ll also tell you who we’ve shared your personal data with so that you can contact them directly.
In order to keep personal data accurate, we may request you to reconfirm/renew your personal data from time to time.
We will correct, update and/or add personal data or inform you about the grounds for refusal within 10 working days after your request.

·Your right to delete and to destruct personal data

In brief
Also known as the "right to be forgotten", this right enables you to request deletion, destruction of your personal data in some circumstances, such as, where we no longer need it or if you withdraw your consent (where applicable). We shall comply with your request unless we have a reason for keeping your personal data.
If we’ve shared your personal data with others, we shall let them know about the erasure where possible. If you ask us, where it is possible and lawful for us to do so, we shall also inform you who we’ve shared your personal data with so that you can contact them directly.
In detail
You may ask us to delete or destruct your personal data and we will respond to your request without undue delay, if one of the following circumstances:
a)   Data is no longer required for the purposes for which it was collected or processed;
b)   You withdraw consent to the processing of your data when your data processing is based on your consent and there is no other legal basis on which to process your personal data;
c)   You oppose the processing of your data on our legitimate interest, including the creation of profiles based on this ground, or you oppose data processing for direct marketing purposes, including the creation of profiles for direct marketing purposes;
d)   Your data has been processed unlawfully;
e)   Personal data should be deleted to comply with a legal obligation under the Georgian legislation;
f)   Personal data have been collected in connection with the provision of information services to children and the basis of processing is consent;
g) In other cases, defined under the Personal Data Protection Law.
Unless this proves impossible or involves disproportionate efforts, we shall notify each recipient to whom your personal data has been disclosed for erasure purpose. Upon your request, we shall inform you of those recipients.
We reserve the right to refuse deletion of your data when processing is required:
a)   For the exercise of the right to free expression and information;
b)   In order to comply with a legal obligation that applies to us as a personal data controller;
c)   For purposes of archiving in the public interest, scientific or historical research or for statistical purposes, insofar as the deletion of the data is likely to render impossible or seriously impair the achievement of the objectives of the processing;
d)   To establish, exercise or defend a right in court;
e) In other cases, defined under the Personal Data Protection Law.
We will delete and/or destruct your personal data or inform you about the grounds for refusal within 10 working days after your request.

·Your right to restrict us from using your data

In brief
In certain circumstances (including where we use legitimate interests as set out below) you can ask us to stop processing your personal data or ask for us to limit the ways in which we process this data. However, we can refuse a request in some cases - we shall provide you with information explaining why we have refused your request if we do this.
In detail
You may ask us to block and restrict the processing of your personal data in one of the following circumstances:
a)   Contest the accuracy of the data - in this case, at your request, we will restrict the processing for the period we perform the necessary checks on the accuracy of your data;
b)   Data processing is illegal, and you do not want to delete your data;
c)   We no longer need your data for processing, but processed data about you is necessary to establish, exercise or defend a right in court;
d)   You opposed the processing of your data under our legitimate interest, including the creation of profiles based on this basis - in this case, at your request, we will restrict the processing for the period in which we verify that our legitimate rights do not prevail over your rights.
e) In other cases defined under the Personal Data Protection Law.
We will block and restrict your personal data or inform you about the grounds for refusal immediately but not later than within 3 working days after your request.
If your data processing has been restricted, we shall only be able to store your data. Any other way of processing out of storage will be done only:
  • after obtaining your consent;
  • for finding, exercising or defending a right in court;
  • to protect the rights of data controller or of another natural or legal person;
  • for reasons of public interest.
We will inform you before lifting any processing restriction as set out above.
Unless this proves impossible or involves disproportionate efforts, we will communicate to each recipient to whom your data has been disclosed restricting the processing of such data. At your request, we will inform you of those recipients.

·Your right to object

You may request us not to further process your personal data for reasons relating to your particular circumstances and if the processing of your data is based on our legitimate interest. We will cease processing of your data unless we demonstrate that we have legitimate and compelling reasons that justify processing and those reasons prevail over your interests, rights and freedoms, or whether the purpose of the processing is to establish, exercise or defend a right in court.
 
If we’ve shared your personal data with others, we shall let them know about your objection where possible. If you ask us, where it is possible and lawful for us to do so, we shall also inform you who we’ve shared your personal data with so that you can contact them directly.
We will cease processing of your personal data or inform you about the grounds for refusal within 10 working days after your request.

·Your right to data portability

You have the right to receive the data that concerns you and that you have provided us with in order to transmit such data to another controller, in the following circumstances:
  • Your data processing is based on your consent or on a contract between us and you; and
  • Your data is processed by automatic means.
We will provide your personal data in a structured, commonly used, and machine-readable format.
If technically feasible, you can request that your personal data be transmitted directly to the controller indicated by you.

·Your rights in relation to automated decision-making and profiling

You have the right not to be subject to a decision when it is based on automatic processing, including not being profiled, if the automatic decision or profiling has legal effects or significantly affects you, except in the following cases:
  • the automatic decision is based on your express consent.
  • the automatic decision is required to conclude or execute a contract between you and us;
  • the automatic decision is authorized by the law.
 

·Your right to withdraw consent

If we rely on your consent as our legal ground for processing your personal data, you are entitled to withdraw that consent at any time. Withdrawal of consent does not affect the lawfulness of the processing of your personal data on the basis of your consent prior to its withdrawal.
We will destruct and/or cease processing of your personal data within 10 working days after your request.

·Your right to stop direct marketing

You are entitled to stop us from using your personal data for direct marketing purposes. You can do this by accessing the unsubscribe link at the bottom of our emails or by sending us a request.
We will stop processing your data for direct marketing purposes within 7 working days after your request.

·Your right to lodge a complaint with the supervisory authority

You have the right to contact the Personal Data Protection Service if you believe the processing of your data is not in compliance with the applicable law.
More information about the Personal Data Protection Service can be obtained by visiting https://www.personaldata.ge/ka

·Your right to seek judicial remedy

Without prejudice to any other administrative or non-judicial remedy, you have the right to pursue an effective judicial remedy against:
(i) a controller/processor that infringed the rights granted to you by the Personal Data Protection Law;
(ii) a legally binding decision of the Personal Data Protection Service or any other supervisory authority.
To the extent that you have suffered a moral or material damage as a result of the Personal Data Protection Law infringement, you have the right to obtain compensation.

 

9. How You Can Exercise Your Rights as Data Subject and Our Data Subject Requests Procedure ?

Submitting a request.  For the exercise of any rights above, please submit your request in writing or by phone, using the contact details indicated above.
Identification of the applicant. In order to be able to properly address and manage your request, we urge you to identify yourself as completely as possible. In case we have reasonable doubts as to the identity of the applicant, we will ask for further information to confirm the alleged identity.
Providing our answer. We will provide you with our response and any requested information in electronic format, unless you request them to be provided in another format.
In case of refusal. In so far as we refuse to meet your request, we will inform you of the reasons which led to this decision and of the possibility to submit a complaint to the Personal Data Protection Service or to the Georgian courts and to apply for a judicial remedy.
Taxes. Exercising your rights as a data subject is free. However, to the extent that your claims are manifestly unfounded or excessive, especially by taking into account their repetitive character, we reserve the right to refuse the fulfillment of such requests.

10. Automated decision-making & Profiling

In order to provide you with speedy and customized services and to communicate with you efficiently, we might make some decisions about you in an automated way, without our staff intervention. Automated decision-making happens, for example, when we automatically registered your user account after you have inserted the required personal data, when we send you an order receipt confirmation or when we use your personal data for profiling.
As regards profiling, we use it in order to customize adverts for you based on your previous interactions with our Website, purchase behaviors, the way you access our services and where you access our services from. In this way we can achieve sending you adverts that will correspond to your likes and interests. Also, most likely you will not be sent adverts of products that are not available in your area. You can choose to stop being profiled by opting-out of marketing cookies or by updating your cookie preferences if you have previously consented.

11. Confidentiality & Security

We are committed to keeping the personal data you provide to us secure and we will take adequate measures to protect your personal data from loss, misuse or alteration. We do not sell your personal data for any purpose.
We have implemented personal data security policies, rules and technical measures to protect the personal data that we have under our control from any potential threat such as:
  • unauthorized access;
  • improper use or disclosure;
  • unauthorized modification; and
  • unlawful destruction or accidental loss.
All of our employees and data processors (i.e. those who process your personal data on our behalf,), who have access to, and are associated with the processing of personal data, are obliged to respect the confidentiality of your personal data.   
The security of our data processing activities is ensured by the implementation of adequate technical safeguards such as pseudonymization and encryption of personal data and regularly monitoring our servers and IT systems for possible vulnerabilities and attacks.

12. Other provisions

This Privacy Policy and the Cookies Policy have been last updated as off 24.07.2024 and are to be governed by the Georgian laws.
This Privacy Policy and the Cookies Policy represents the formalization of the LC Waikiki compliance with Georgian laws.
To ensure that we keep you updated on how we use your personal data and that we comply with all relevant and applicable data protection legislation and recommendations/opinions issued by competent authorities in the data protection field, we will update this Privacy Policy from time to time to reflect any changes we undertake. In case of significant changes, we shall notify you by e-mail (if such data is available to us).
However, we recommend you to review this Privacy Policy including our Cookies Policy periodically.

B. Cookie Policy

We believe that cookies and tracking technologies such as pixels and beacons (“Cookies”) make your experience on our Website more personal and enjoyable. This Cookie Policy will explain to you exactly what they are, what cookies do we use and for what purposes.

1. What are cookies?

In short, cookies are small encrypted text files or pieces of software code that often include an unique identifier. They are stored on your device by a website such as ours. They gather various information about how you are using our Website.
Cookies can be split into the following main categories:
  • after their issuer:
  • First-party cookies - these are issued by the website you have accessed. Their main purpose is to enable the website your visit to memorize your preferences.
  • Third-party cookies - these are cookies that are set by a website other than the one you are on. If you visit a website and a separate operator sets a cookie through that website this would be a third-party cookie.
  • after their persistency
  • Session cookies – these cookies are used during a browser session and will expire after you close it. They are used for purposes such as remembering what you have put in your shopping basket as you browse around a website.
  • Persistent cookies – these cookies are stored on a device in between browser sessions. This allows your preferences or actions across a website (or in some cases across different websites) to be remembered. They serve multiple purposes including remembering users' preferences and choices when using a site or to target advertising.

2. What cookies do we use and for what purposes?

When you first access our Website, you will be asked to consent to our use of Cookies as described below:
1. Functionality cookies – these cookies make our Website usable by providing functionality that will allow you to shop (page navigation, adding products to your basket etc.). Our site could not function properly without them, therefore this is the only type of cookies for which we do not require your consent.
2. Statystics/Analytical cookies – these cookies help us to understand how visitors interact with our Website. The information collected by these cookies is usually anonymous.
3. Advertising (marketing) cookies – these cookies allow us to personalize our adverts for you by showing you advertising that is relevant to your interest and shopping history. They can also track you through different websites and allow us to show you LC Waikiki advertising banners on third party websites.
You can find below a detailed list of the cookies we use and what is their purpose:
Category Name Value Description Expiry
Functionality acceleratorSecureGUID .lcw.com Hybris core cookie Does not expire.
JSESSIONID .lcw.com The general purpose of this cookie is that it is used by pages written in JSP. In general, it is used for creation an anonymous user and a session by server. Does not expire.
_ga .lcw.com This cookie is used for creation randomly a unique customer identifier and helps distinguish customers. 2 years
_gat_UA-21191506-3 .lcw.com It is a variation of "_gat" cookie and limits the saved data amount in high traffic rated web sites. 1 month
cb-enabled .lcw.com It is used for saving rejected notifications in order to avoid sending new notifications when customer comes back. 1 year
countryCode .lcw.com It is a representation of domain of customer's country. Does not expire.
visitorID .lcw.com It is a representation of visitors. Does not expire.
ADRUM .lcw.com This cookie is used for improving user experience and gathering information about the technical problems customers faced. Does not expire.
lcwstorefrontRememberMe .lcw.com Cookie for "remember me" function 1 month
CV_registerDate .lcw.com It is representation of customer registered date. Does not expire.
CV_userId .lcw.com It is a representation of current visitors on the web site. Does not expire.
ADRUM_BTa akcdn4.lcw.com This cookie is used for improving user experience and gathering information about the technical problems customers faced. 1 month
ADRUM_BTa akcdn1.lcw.com This cookie is used for improving user experience and gathering information about the technical problems customers faced. 1 month
lcw-ro-cart .lcw.com It stores the items on the customer's cart. 10 years
lcw-uk-cart .lcw.com It stores the items on the customer's cart. 10 years
Third Party Analytics IDE .doubleclick.net It calculates the count of Google maps users and their beheviour such as preferred zoom level. Google Inc. defines it and there is no control on it. 2 years
_gid .lcw.com It is used for distinguishing customers by Google Analytics. 1 month
Third Party Advertising fr .facebook.com It is used for advertising by Facebook. 3 months

3. Other tracking technologies

-  Facebook Pixel Code
A piece of code that lets us measure, optimize and build audiences for our advertising campaigns. The Facebook pixel collects five types of data:
  • Http headers - Anything present in HTTP headers. HTTP headers are a standard web protocol sent between any browser request and any server on the Internet. HTTP headers include IP addresses, information about the web browser, page location, document, referrer and person using the website.
  • Pixel-specific data - This includes the pixel ID and Facebook cookie.
  • Button click data - This includes any buttons clicked by site visitors, the labels of those buttons and any pages visited as a result of the button clicks.
  • Optional values - Developers and marketers can optionally choose to send additional information about the visit through custom data events. Example custom data events are conversion value, page type and more.
  • Form Field Names - This includes website field names such as "email", "address" and "quantity" when a person purchases a product or service. The pixel does not capture field values unless an advertiser includes them as part of advanced matching or optional values.
- Criteo Code
This is used to track you through various selected website and provide you with personalized adverts when you visit such other websites. Banner advertising appears on selected websites with which we are affiliated, and we use the information we have learned from cookies to tailor this advertising to things we think you will like, based, for example, on your browsing history.
- Google AdWords (double click)
A tool used to perform paid search marketing activities like retargeting and conversion tracking via the Google browser.
- E-mail beacons
Tiny graphics files that contain a unique identifier that enable us to recognize when someone has opened an e-mail that we have sent them.

4. How can you manage or opt-out of cookies?

You can withdraw your consent and manage your cookie settings at any time by accessing the Manage Cookies section of our Website. Last but not least, please be aware you can set your browser to reject cookies or you can delete them yourself if you wish.
We hope that this Cookie Policy was comprehensive. Should you require further information, please do not hesitate to contact us using the contact details above.