Data Protection Policy
Thank you for your interest in our website. The protection of your privacy is very important to us. Therefore, we will process your data carefully, for a specific purpose and on the basis of your consent, and only in accordance with the legal requirements for data protection.
In this data protection policy we inform you about the aspects of data processing within our website.
The responsible body within the meaning of the data protection laws is:
Villeroy & Boch
AG Saaruferstraße
66693 Mettlach
Tel. +49 (0) 68 64 / 81 0
E-mail information(at)villeroy-boch.com
(hereinafter “Villeroy & Boch”)
I. When and for what purpose does Villeroy & Boch collect personal data?
It is generally possible to use our websites without submitting personal data.
If you use one of our services (e.g. our newsletter, the Bathroom Planner, our online shop or our contact form), you enter your data voluntarily. We use this data (such as name, address, e-mail address, telephone and fax number) exclusively for the purpose for which you provide it (e.g. for processing contact requests, processing orders and payments, delivery of goods and provision of services such as, in particular, the dispatch of newsletters or bathroom planning) and only for the execution of our own business purposes. Information we receive from you helps us process your order as smoothly as possible, improve our service for you and prevent misuse and fraud.
When you access our website, information of a general nature is automatically recorded. This information (server log files) includes, for example, the type of web browser, the operating system used, the domain name of your internet service provider and such like. This is only information that does not allow conclusions to be drawn about you. This information is technically necessary in order to correctly deliver the contents of websites requested by you and is mandatory when using the internet. Anonymous information of this kind is statistically evaluated by us, in order to optimise our internet appearance and the technology behind it.
We do not sell your data, nor do we use it for unspecified purposes.
Your personal data will only be used within the Villeroy &Boch Group and by our business partners who may be commissioned to fulfil your wishes.
Below we inform you in detail about the handling of your data.
II. General information about our services
If you use our services, we will ask you for personal data (at the time of collection, we will explain which information is required and which you may voluntarily provide).
To protect the security of your data during transmission, we use state-of-the-art encryption techniques (such as SSL) over HTTPS.
For users who have signed up for one or more of the following services, it is possible to change or delete the information provided at registration at any time. Of course, we will also provide you with information about the personal data we hold about you at any time. We are happy to correct or delete this at your request, as long as no statutory retention requirements prevent this. To contact us in this context and to revoke your consent, please use the contact details provided at the end of this data protection policy.
III. Our services in detail
In the following, we would like to explain our services to you in detail, and in particular the legal basis for and purpose of the data processing.
1. Shopping in our online shop
Our website also offers the possibility of convenient online shopping. We use the data provided by you without your separate consent exclusively for the fulfilment and processing of your order. With complete processing of the contract and full payment of the purchase price, your data will be blocked for further use and deleted after expiry of the tax and commercial regulations, unless you have expressly consented to its further use.
Purpose of data processing: Implementation and processing of the purchase process initiated by you as well as compliance with legal requirements such as, in particular, customs provisions.
Legal basis: Article 6 (1) (b) GDPR (required to fulfil the contract) and Article 6 (1) (c) GDPR (fulfilment of a legal obligation)
For shopping in the online shop, provision of the data is required by you. Without this data no contract can be concluded. Failure to provide the data would result in your being unable to shop on our website.
1.1 With a customer account
A free and password-protected customer account gives you the opportunity to take full advantage of our website. When you register to use personalised services via a customer account, some of your personal information is collected, such as your name, address, contact and communications data (e.g. telephone number and e-mail address). If you are registered with us, you can access content and services that we only offer to registered users.
1.2 Without a customer account
Of course, you can also use the online shop without a customer account. In this case, you will need to enter the information required to process your order into the ‘Personal Data’ order form integrated on the website. You complete each entry by clicking the ‘Next’ button, which takes you to the payment screen. In order to avoid typing errors and to ensure that you have entered the correct address, the completeness and correctness of your address will be checked during entry.
1.3 Purchase on account / installment purchase
In order to be able to offer you the payment methods of Klarna, we pass on your personal contact and order data to Klarna during the ordering process. On this basis, Klarna evaluates and provides the available payment methods. Your transmitted personal data will be processed in accordance with the following provisions Klarna data protection notice. https://www.klarna.com/de/datenschutz/
1.4 Security
Your payment details are protected during transmission to our servers through the use of SSL security procedures. You can check the security of the connection using the information in your browser's URL display. If the beginning of the address line changes from ‘http’ to ‘https’, there is a secure connection. In addition, all service providers used for payment processing are certified and comply with the highest safety regulations of e-commerce industry standards.
1.5 Compliance with customs legislation
Due to several EU regulations (2580/2001/EC, 881/2002/EC and 753/2011/EC) as well as other legal requirements, we as a company are required to check our customers' data against publicly available foreign trade and embargo lists before concluding a sales contract. We carry out this comparison to fulfil legal requirements. We carry out the comparison only when you order a product in our online shop and are liable to pay. Only the following stock data is compared: First name, surname and address.
2. Personal newsletter
If you have specifically subscribed to our newsletter, we will use your information to periodically send you personalised information about new products, promotions, competitions and our many customer services.
For a successful registration we need a valid e-mail address. In order to verify that an application is actually made by the owner of an e-mail address, we use the ‘double opt-in’ procedure. For this purpose we record the order of the newsletter, the dispatch of a confirmation e- mail and the receipt of the requested answer. The data will be used exclusively for the newsletter and will not be shared with third parties.
Your consent to the storage of your personal data and its use for newsletter distribution can be revoked at any time. Each newsletter has a corresponding link for this purpose. In addition, you can unsubscribe at any time via the contact options indicated at the end of this data protection notice.
By unsubscribing, we consider your consent to the creation of your personalised user profile and the receipt of newsletters based on it to be revoked.
Purpose of data processing: Regular dispatch of newsletters by e-mail to the e-mail address provided by you.
Legal basis: Article 6 (1) (a) GDPR (consent)
Profiling: We evaluate your use of the sent newsletters and the subsequent visits to our website in order to further improve the newsletter and our website and to optimise those according to your actual interests.
In order to always provide you with a personally tailored offer and to anticipate which products of ours you may be interested in, we will create a customer profile for you based on the information we have about you. We use existing information, such as your shopping history, preferences and interests that you actively share with us via your customer account or that we derive from your recorded interactions with our newsletter. Standard technologies such as cookies or tracking pixels are used in our newsletter. The messages we send you will be personalised and customised according to your individual preferences and interests.
3. My Club
As a member of My Club you have chosen to participate in the Villeroy & Boch customer loyalty programme. For this purpose, a corresponding registration is required, stating the requested personal data. We store your password for your My Club account and the purchases you make in addition to the personal data you provide when registering. Your membership gives you many benefits, which you can read about in detail in the My Club’s conditions of participation. In addition, every two months you will receive information about exclusive Privilege Club promotions and events via a special newsletter.
Purpose of data processing: Sending special offers and information about Villeroy & Boch AG products.
Legal basis: Article 6 (1) (a) GDPR (consent)
4. Bathroom Planner and Bathroom Inspirator
You can create a plan of your personalised bathroom using the Bathroom Planner area of our website. This plan will then be sent to you by e-mail. In addition, Villeroy & Boch or a retailer of your choice may contact you by telephone or e-mail for the purpose of consulting you on the bathroom you have chosen.You can create a plan of your personalised bathroom using the Bathroom Planner area of our website. This plan will be sent to you by e-mail. You can also have the plan forwarded to the retailer of your choice, who can then consult with you on the bathroom you’ve chosen via e-mail or by phone.
Purpose of data processing: Sending a bathroom plan that you have created, to be contacted by Villeroy & Boch for the purpose of bathroom consulting and sharing your contact information with the retailer of your choice for the purpose of bathroom consulting. Contact can be made by telephone or e-mail.Sending a bathroom plan you’ve created and sharing your contact information with the retailer of your choice for the purpose of bathroom consulting with them via e-mail/phone.
Legal basis: Article 6 (1) (a) GDPR (consent)
5. After-sales service
If your porcelain should ever be discontinued, you can have our after-sales service notify you ahead of time — up to 12 months before the series is phased out. This leaves plenty of time to buy replacements or complete the set. You will only receive a message if the decor you’ve registered is expiring.
Purpose of data processing: Information about product cycles and the availability of certain products on the market.
Legal basis: Article 6 (1) (a) GDPR (consent)
6. Sweepstakes and competitions
Every so often you will have the opportunity to participate in sweepstakes and competitions on our website.Personal data (e-mail address, name, address and other information as needed) may likewise be collected and stored during these campaigns for the purpose of implementation, depending on the respective terms and conditions of participation that apply. The personal information we collect from you during these campaigns will only be used to run the campaign (e.g. determining the winner of sweepstakes, notifying the winner and sending the prize) and will be deleted after it is finished.
If you have given your express consent as part of the campaign, we will send you our newsletter as described under III. 2. If you choose to revoke your consent later, this will not negatively impact your chances of winning or your participation in sweepstakes.
Purpose of data processing: Implementing and executing the sweepstakes/contest.
Legal basis: Article 6 (1) (a) GDPR (consent)
7. Gift list
You have the option to transfer the products available in our online shop to a gift list and manage them there. A customer account must be created in order to do this. You can then send the gift list you created to the people you specify.
Purpose of data processing: Sending a selection of products from Villeroy & Boch AG to a group of recipients defined by you, with your e-mail address as the sender.
Legal basis: Article 6 (1) (a) GDPR (consent)
8. Contact form
If you contact us via e-mail or our contact form, the information you provide will be stored for the purposes of processing the request as well as for any follow-up questions and sending you any requested information, if applicable.
Purpose of data processing: Responding to your request.
Legal basis: Article 6(1)(b) of the GDPR (required for implementing pre-contractual measures that are made at the request of the person in question)
Revocation of consent:
Consents given by you are always voluntary and can be revoked at any time with effect for the future without giving reasons. For this purpose, you can contact the above address of Villeroy & Boch.
9. CRM system
A central CRM database helps us manage our relationships with customers, interested parties and partners to deliver the best possible customer communication. This allows us to have a closer relationship with you and to quickly respond to your queries.
Purpose of data processing: Customer communication management and faster processing in Sales, Service and Marketing.
Legal basis: Article 6 (1) (f) GDPR (legitimate interest)
Legitimate interests:
• Fast and efficient handling of queries from customers, interested parties and partners
• Support of our Service, Sales and Marketing processes by an experienced and reliable partner as well as reducing our efforts in maintaining the IT infrastructure
Recipient of the data: CRM provider
The technical service provider of the CRM system is located in a third country. The data processing is secured via an order processing contract and the EU standard contractual clauses agreed with the service provider.
10. Click & Meet
You also have the opportunity to shop locally at our local stores during the Corona pandemic. The prerequisite for this is that you reserve a corresponding shopping appointment with us. The data you provide when reserving an appointment will be used exclusively for the administration of the visit appointments and to contact you by telephone should you not be on site at the reserved time and other customers are prevented from visiting our store due to their existing reservation.
Purpose of data processing: management and booking of the appointment reservation you have made.
Legal basis: Article 6(1)(b) GDPR (Necessary for the performance of pre-contractual measures, which are carried out at the request of the data subject).
11. Product notifications / wish list alerts
If you have explicitly registered for our product notifications and wish list alerts, we will use your data to send you messages about changes in your wish list (prices and availability) and periodic reminders about your wish list.
For an effective registration we need a valid email address. To verify that a registration is actually made by the owner of an e-mail address, we use the "double-opt-in" procedure. For this purpose, we log the order of the alert, the sending of a confirmation e-mail and the receipt of the response requested herewith. The data is used exclusively for sending product notifications and wish list alerts and is not passed on to third parties.
You can revoke your consent to the storage of your personal data and its use for sending product information at any time. In each product notification and alert you will find a corresponding link. In addition, you can unsubscribe at any time using the contact option provided at the end of this privacy notice.
By unsubscribing, we consider your consent to the creation of your personalized usage profile and the receipt of product information based on it as revoked.
Purpose of data processing: sending product notifications and alerts by e-mail to the e-mail address you have provided.
Legal basis: Article 6(1)(a) GDPR (consent)
12. Right of withdrawal regarding your consent
Where you use any of the above services on the basis of consent, the following applies to such consents:
Revocation of consent: Consents given by you are always voluntary and can be revoked at any time with effect for the future without giving reasons. To do so, you can contact Villeroy & Boch at the above address.
13. Social plugins
We offer you the option of using “social media buttons” on our website. We rely on the “Shariff” solution to protect your data during use of these features. As a result, these buttons are only integrated onto the website as graphics that contain a link to the corresponding website of the button’s provider.
Clicking this graphic will redirect you to the respective provider’s services. Your data will not be sent to the respective provider until then. As long as you do not click the graphic, there will be no exchange of any kind between you and the provider of the social media button. Information about the collection and use of your data in social networks can be found in the relevant provider’s respective terms and conditions of use.
We have integrated social media buttons for the following companies on our website:
Facebook Inc. (1601 S. California Ave - Palo Alto – CA 94304 - USA)
Twitter Inc. (795 Folsom St. - Suite 600 - San Francisco - CA 94107 - USA)
Pinterest (808 Brannan Street, San Francisco, CA 94103, USA)
Instagram (601 Willow Rd - Menlo Park CA 94025 - USA)
14. Villeroy & Boch Fan Pages on social networks/ platforms
We use our fan pages on social networks and platforms for active communication with customers and users. When you visit these fanpages, your data may be collected and stored for market research and advertising purposes in order to create user profiles using pseudonyms. We use these in order to be able to display advertising to you within and outside the platforms, which is based on your presumed interests. For this purpose, cookies are used when visiting our fan pages, which store the usage behavior of the pseudonymous user.
You will find a complete description of the respective processing and the possibilities for objection in the details of the respective providers.
They can also best support you with information requests and the assertion of user rights. Should you require our help in this regard, please do not hesitate to contact us.
Further information on Page Insights can be found here: https://de-de.facebook.com/legal/terms/page_controller_addendum
15. Customer list synchronization – Custom Audiences
We use Custom Audiences with customer list matching.
This function allows us to transmit an encrypted (hashed, as pseudonym) customer list, consisting of the email addresses of our customers whose consent we have received, to third-party companies, which then compare it with information from users of the platforms that has also been hashed. This allows us to determine which of our customers are also users of these third-party companies.
This information is then used to create so-called "custom audiences", i.e. target groups. These target groups are shown adverts specifically tailored to this target audience.
Purpose: Displaying advertising tailored to target groups
Legal basis: Article 6(1)(a) GDPR.
Consent given by you is always voluntary and can be revoked at any time with effect for the future without giving reasons. To do so, you can contact Villeroy & Boch at the above address or use the Preference Centre, which you can access via the "My interests" link in the newsletter.
Villeroy & Boch is responsible for the processing of personal data by uploading the customer list.
Third-party companies with which we use this process are:
- Meta Platforms Ireland Limited
- Google Inc.
- Pinterest Europe Ltd.
- Criteo GmbH
- Amazon
- TikTok Technology Limited (Ireland)
An adequacy decision by the EU Commission, the Data Privacy Framework (DPF), is in place for the USA. Companies not based in the EU are certified in accordance with the
Data Privacy Framework. In addition, data processing is secured by the contracts agreed with the service provider and the EU standard contractual clauses.
IV. Collecting data during your visit to our website
Along with the information that you submit yourself, we collect other data from you during your visit through cookies and tracking. We would like to clarify this in the following.
1. Cookies and other tracking technologies
Some of our websites use “cookies”. This standard technology refers to small text files that are stored on the device you use and allow your visit to a website to be made more convenient or more secure, among other things. Via the cookies, we automatically receive certain data about your computer and your internet connection, such as your IP address, the browser used and operating system,. Cookies may also be used to better tailor the offerings on a website to the visitor’s interests or generally improve the site based on statistical analysis.
Cookies cannot be used to start programs or transmit viruses to a computer. Using the information in the cookies, we can make navigation easier for you and allow our web pages to be displayed correctly.
Third-party technologies such as scripts, pixels and tags that we embed in our websites for advertising purposes also set cookies on your terminal device. In the following sections, we explain what we use these technologies for and how you can adjust the settings to suit your needs.
2. Cookie categories
Depending on the function and purpose, we divide data processing into different categories. The purpose of each category is described in our Consent Management Tool and your consent to these categories can be adjusted here.
You can decide yourself whether the browser you use permits cookies or not. Please note that website features may be restricted or even suspended if cookies are disabled.
3. Purpose of processing, legal basis and legitimate interests
The following applies to the above items:
Purpose of data processing: Secure operation of the website as well as allowing targeted communication with customers.
Legal basis: Article 6(1)(a) GDPR (consent via our cookie consent), in exceptional cases not requiring consent, we base our processing on our legitimate interest under Article 6(1)(f) GDPR
Legitimate interests:
• Ensuring proper function of our website
• Optimisation of our website
4. Revocation of consent:
Consents given by you are always voluntary and can be revoked at any time with effect for the future without giving reasons.
Your consent to cookies and other technologies can be adjusted here.
5. Browser settings
You can determine yourself whether the browser you use allows cookies or not. Please note that the functionality of websites may be restricted or even suspended if cookies are not allowed.
Here you can find out more about how to set your browser correctly:
Internet Explorer: https://support.microsoft.com/help/17442/windows-internet-explorer-delete-manage-cookies
Mozilla Firefox: http://support.mozilla.com/de-DE/kb/Cookies
Google Chrome: http://www.google.com/support/chrome/bin/answer.py?hl=de&answer=95647
Safari: https://support.apple.com/kb/PH17191?viewlocale=de_DE&locale=de_DE
Opera: http://www.opera.com/browser/tutorials/security/privacy/
Adobe (Flash cookies): http://www.adobe.com/privacy/policies/flash-player.html
Google Chrome App: https://support.google.com/accounts/answer/61416?co=GENIE.Platform%3DAndroid&hl=de
6. Location of processing of information collected via cookies
Information collected via cookies is primarily processed within the European Union (EU). In some cases, cookie information may also be processed by our contracted service providers or by third-party cookie providers in countries outside the EU that do not offer a comparable level of data protection from an EU perspective. In some countries, such as the USA, there is a particular risk that local authorities may obtain access to cookie information processed there for monitoring purposes and that there are no effective legal remedies against such access. We have implemented appropriate additional safeguards, such as contracts based on the EU standard contractual clauses and the implementation of supplementary technical measures to ensure that information collected via cookies is adequately protected. Where you have given your consent to the use of cookies and other tracking technologies, you also consent to the transfer and further processing of information collected via cookies to countries outside the EU.
V. implemented technologies
VI. Joint responsibility
Villeroy & Boch is jointly responsible with third parties for certain processing of personal data of visitors to our website pursuant to Art. 4 No. 7 GDPR and has concluded special agreements for this purpose pursuant to Art. 26 Para. 1 Sentence 2.
Facebook Pixel: https://www.facebook.com/legal/controller_addendum
Pinterest Tag: https://business.pinterest.com/de/pinterest-advertising-services-agreement/united-states-of-america/
Criteo: https://www.criteo.com/wp-content/uploads/2023/02/Criteo-Data-Protection-Agreement-Feb-23_DE.pdf
TikTok Pixel: https://ads.tiktok.com/i18n/official/policy/controller-to-controller
These agreements stipulate in particular that these third parties are primarily responsible for data processing and that Villeroy & Boch has no access to the individual data of visitors (but can only call up aggregated statistics, e.g. regarding gender or age distribution).
Furthermore, they undertake to respect the rights of the data subjects and to respond, for example, to requests for information, objections or deletion.
You can find an overview of the cookies used on our website under V. Technologies used. You can revoke your consent to the processing of your personal data for the purposes stated there at any time in the future by calling up our cookie banner again via the footer of our homepage and adjusting your settings accordingly.
Villeroy & Boch asks visitors to the website to contact the aforementioned third parties directly with regard to the assertion of their data subject rights concerning the processing of their data. Villeroy & Boch could also only forward requests for information, for example.
VII. Recipients/categories of recipients
1. Other companies in the Villeroy & Boch group
Personal data that you provide during registration (your name, e-mail address, password, and date of birth) will be shared with other companies in the Villeroy & Boch group in order to allow the respective company to provide customer service for you.
We can share the data from your profile with other companies in the Villeroy & Boch group if both companies are responsible for your personal data or if the other companies act as our service provider and your personal data is processed according to our instructions or on our behalf.
We share anonymised and aggregated information with other companies in the Villeroy & Boch group to use for trend analysis.
2. V&B Fliesen GmbH
We have incorporated the product range of V&B Fliesen GmbH on our website under the heading “Tiles.” https://www.villeroy-boch.de/produkte/fliesen.html
You likewise have the option of making a contact request there. All contact requests that concern tiles will be promptly forwarded to V&B Fliesen GmbH, who will then get in touch with you. We will delete these requests from our systems after forwarding them.
3. Other third parties
We will only share the data you provide for the purposes of contract fulfilment, such as with shipping companies or payment service providers, or in cases where we are legally obliged to do so. Examples of these recipients include
• Authorities and courts (legal duty of disclosure)
• Lawyers (assertion of claims)
• Credit institutes (processing payment transactions)
• Credit agencies (for checking credit history)
• Auditors and income tax auditors/accountants (legal audit assignment)
• Insurance companies, insurance agents
• Tax consultants
• Expert/appraiser
• Health insurance providers/pension funds (social insurance carriers)
4. Data transmission to third countries
If we process data in third countries (meaning countries outside the European Union (EU) or the European Economic Area (EEA)) or this occurs in the process of utilising the services of third parties or transmitting data to third parties, this will only be done for the purpose of fulfilling our contractual obligations, on the basis of your consent, due to a legal obligation or based on our legitimate interests.
In doing so, we ensure that your personal data is processed in compliance with the European level of data protection, based on special guarantees or due to corresponding contractual obligation including adequate technical and organisational measures.
VIII. Information about children
We do not knowingly collect any personal data about children under 13 years old as a matter of principle. If we become aware that we have unintentionally collected personal data about children under 13 years old, we will take steps to delete this information as quickly as possible insofar as we are not obliged to retain it under the applicable law.
IX. Obligation to provide data, automatic decision making, profiling
1. Do I have an obligation to provide data?
In the context of the contractual relationship, you must provide the personal data that is necessary for acceptance, implementation and completion of the contractual relationship and for fulfilment of the duties related to the contract, or that we are obliged by law to collect. Without this data, we will generally not be able to conclude or implement the contract with you.
2. To what extent is there automated decision making/profiling?
Within the framework of the procedure for sending newsletters described under III. 2, we use profiling to the extent described there.
X. Deleting or locking data
We abide by the principles of data reduction and data economy.
We therefore only store your personal data as long as necessary to achieve the purposes described here or for the retention period stipulated by the legislator. Once the respective purpose has ceased to exist or this period has lapsed, the relevant data is routinely locked deleted in accordance with legal regulations. If processing is based on consent, the respective purpose generally is considered to cease to exist when the consent becomes invalid due to revocation or passage of time. If processing is necessary for fulfilment of the contract, this will generally occur when the contract has been completed in full and after the retention period expires, as required in particular under the German Commercial Code (HGB) and the German Fiscal Code (Abgabenordnung).
XI. What data protection rights do you have?
You have the right to information under Article 15 of the GDPR, the right to correction under Article 16 of the GDPR, the right to erasure under Article 17 of the GDPR, the right to restriction of processing under Article 18 of the GDPR, the right to objection under Article 21 of the GDPR, and the right to data portability under Article 20 of the GDPR.
You can contact our data protection commissioner to exercise these rights.
You also have the right to file a complaint with a competent data protection supervisory authority (Article 77 of the GDPR in conjunction with Section 19 of the German Federal Data Protection Act, BDSG). A list of supervisory authorities (for the non-public sector) with addresses can be found here:
https://www.bfdi.bund.de/DE/Infothek/Anschriften_Links/anschriften_links-node.html
XII. Our data protection officer
If you have questions about this statement or about data protection at Villeroy & Boch, you can contact our data protection officer directly:
Contact details for our data protection officer:
Villeroy & Boch AG
Datenschutzbeauftragter Saaruferstraße
66693 Mettlach
Tel. +49 (0) 68 64 / 8 13835
service.datenschutz(at)villeroy-boch.com
XIII. Changes to our data protection provisions
We reserve the right to adjust this data privacy notice occasionally to ensure it always meets the current legal requirements or to reflect changes to our services in the data privacy notice, e.g. when introducing new services. In this case, the new data privacy notice will apply to your next visit to our website.
Updated: 03.04.2023