Launching soon in Australia and New Zealand.
FRAMEO
Legal

Privacy policy

Version: XXX

1. Controller

The controller for the processing of personal data in connection with this website and the FRAMEO services offered through it is:

  • XXX full company name
  • XXX legal form
  • XXX street and number
  • XXX postcode and city
  • XXX country
  • Email: XXX
  • Phone: XXX
  • Company or register number: XXX
  • Australian ABN/ACN, if applicable: XXX
  • New Zealand NZBN, if applicable: XXX

Where another FRAMEO or Blum company is responsible for specific services, this will be communicated with the relevant service or before the data is collected.

2. Privacy contact

For questions about data protection or to exercise your rights, you can reach us at:

  • Email: XXX
  • Postal address: XXX

Data protection officer, if appointed

  • XXX
  • Email: XXX

Privacy Officer for Australia and/or New Zealand

  • XXX
  • Email: XXX

3. Scope

This privacy policy explains how we process personal data when you:

  • visit www.frameokitchens.com;
  • create a FRAMEO user account;
  • use the FRAMEO configurator;
  • create or save a kitchen design;
  • book a consultation or showroom appointment;
  • contact us or send us documents;
  • subscribe to our newsletter;
  • request a quote, place an order or use other FRAMEO services.

We comply with the applicable data protection laws. These may include in particular the European Union General Data Protection Regulation (“GDPR”), the German Telecommunications Digital Services Data Protection Act (“TDDDG”), the Australian Privacy Act 1988 together with the Australian Privacy Principles, and the New Zealand Privacy Act 2020.

4. Data we process

Depending on how you use our services, we may process in particular the following data:

  • name, address and contact details;
  • account, registration and login data;
  • information about your kitchen, building or renovation project;
  • room dimensions, floor plans, photos and uploaded files;
  • designs, configurations, product and material selections;
  • appointment, consultation and communication data;
  • quote, order, delivery, installation and payment data;
  • newsletter and marketing preferences;
  • IP address, browser, device, operating system and access time;
  • usage, analytics, security and error data;
  • cookie and consent information;
  • other information you voluntarily provide to us.

Please do not submit personal data in free-text fields, photos, plans or documents that is not required for the respective enquiry or design.

5. Provision of the website

When you access our website, technically necessary data is processed. This may include your IP address, the time of access, the page requested, browser and device information, the referrer URL as well as technical status and error data.

We use this data to:

  • provide the website and its functions;
  • ensure security and stability;
  • detect attacks, misuse and technical faults;
  • maintain and improve our systems;
  • comply with legal obligations and protect legal claims.

Where the GDPR applies, processing is based on Art. 6(1)(f) GDPR. Our legitimate interest lies in the secure, reliable and efficient operation of our digital services.

  • Hosting provider: XXX
  • Server locations: XXX
  • Retention of technical log data: XXX

6. Contact, consultations and showroom appointments

When you contact us, request a consultation or book a showroom appointment, we process the data you provide in order to handle your enquiry and to prepare, hold and follow up on the appointment.

This may include your name, email address, phone number, location, preferred appointment, message and details about your project.

Where the GDPR applies, processing is based on:

  • Art. 6(1)(b) GDPR where the enquiry serves to prepare or perform a contract;
  • Art. 6(1)(f) GDPR for other business enquiries;
  • Art. 6(1)(a) GDPR where we obtain your consent.
  • Appointment booking provider, if used: XXX
  • Retention period: XXX

7. User account and sign-in

When you create a FRAMEO account, we process your registration, profile and login data to provide the account, authenticate you and store your designs and preferences.

Where the GDPR applies, processing is based on Art. 6(1)(b) GDPR.

If you sign in with Google or Apple, we receive — depending on the provider and your selection — a user identifier, your name, your email address and possibly your profile picture. With “Sign in with Apple”, Apple may provide a relay email address instead of your personal email address.

Providers:

  • Google: XXX;
  • Apple: XXX;
  • other sign-in services: XXX.

Further information on data processing can be found in the privacy notices of the respective provider.

  • Retention of account data: XXX
  • Deletion of inactive accounts: XXX

8. FRAMEO configurator and kitchen planning

When you use the FRAMEO configurator, we process the planning information you enter or upload. This may include room dimensions, floor plans, photos, connections, product and material selections, design versions, comments as well as technical session and usage data.

We use this data to:

  • provide the configurator;
  • create, display and save your design;
  • manage changes and different design versions;
  • share your design at your request with a consultant or selected service partner;
  • prepare quotes, orders, deliveries or installations;
  • detect technical faults;
  • improve the security, usability and performance of the configurator.

Where the GDPR applies, processing is based on Art. 6(1)(b) GDPR. Technical security and improvement measures may additionally be based on Art. 6(1)(f) GDPR.

  • Configurator operator: XXX
  • Hosting provider: XXX
  • Database provider: XXX
  • Server locations: XXX
  • Retention of designs: XXX

If you send a design to a consultant, showroom or service partner, the necessary data may be passed on to the recipient you selected or who is responsible for your area.

9. Quotes, orders, delivery and installation

If you request a quote, place an order or use delivery, installation, assembly or service offerings, we process the data required to perform them.

This includes in particular your contact and address data, design, product selection, quote and contract data, payment information, delivery and installation appointment data as well as information about complaints, warranty or service cases.

We may share the necessary data in particular with the following recipients:

  • responsible FRAMEO and Blum companies;
  • showroom, sales and consulting partners;
  • planners, project partners and specialist companies;
  • delivery, logistics, installation and assembly companies;
  • payment and financial service providers;
  • IT, hosting and support providers;
  • tax advisors, auditors, legal advisors and authorities.

Data is only shared where this is necessary for the respective purpose or permitted by law.

Where the GDPR applies, processing is based on Art. 6(1)(b), Art. 6(1)(c) or Art. 6(1)(f) GDPR.

Contract, order and invoice data is stored in accordance with statutory retention obligations.

10. Newsletter and marketing

If you subscribe to our newsletter or other electronic marketing communications, we process in particular your email address and, where applicable, your name, location, language, interests and marketing preferences.

Where required, we use a double opt-in procedure. In doing so we store the time of registration and confirmation as well as the technical information required to evidence your consent.

Where the GDPR applies, sending is based on your consent under Art. 6(1)(a) GDPR or — for existing customers and where legally permitted — on our legitimate interest under Art. 6(1)(f) GDPR.

You can unsubscribe from marketing communications at any time via the unsubscribe link in the relevant message or by email to XXX. The withdrawal applies for the future.

  • Newsletter service provider: XXX
  • Location and server locations: XXX
  • Retention period: XXX

Opens and clicks are only measured where this is permitted under applicable law and any required consent has been given.

11. Cookies and analytics

We use cookies and similar technologies, for example local storage, pixels or device identifiers.

Technically necessary technologies serve in particular security, sign-in, storing your selections, providing the configurator and managing your consent. Where the GDPR and the TDDDG apply, they are used on the basis of Art. 6(1)(f) GDPR and Sec. 25(2) TDDDG.

We only use optional analytics, functional and marketing technologies if you have consented beforehand. The legal basis is Art. 6(1)(a) GDPR in conjunction with Sec. 25(1) TDDDG.

You can change or withdraw your consent at any time via “Cookie settings” in the website footer.

We may evaluate usage information to understand how our website and the configurator are used, which functions are particularly relevant and where technical problems or drop-offs occur. This may involve pages visited, session duration, interactions, campaign parameters, device data, approximate location and pseudonymised identifiers.

Analytics and consent services used:

  • consent management: XXX;
  • web analytics: XXX;
  • FRAMEO/AIKU usage analytics: XXX;
  • error monitoring: XXX;
  • other services: XXX.

Further details on the cookies, providers and retention periods used are available in the “Cookie settings”.

12. External content and social networks

Our website may contain content or functions from external providers, for example videos, maps, fonts or social media content. Where data is transferred to external providers as soon as such content loads, this only happens if the required consent has been given.

Providers potentially used:

  • Vimeo or YouTube: XXX;
  • Google Maps: XXX;
  • Instagram: XXX;
  • Pinterest: XXX;
  • LinkedIn: XXX;
  • other providers: XXX.

For plain links to external websites or social networks, data is generally only transferred once you click the link. The respective provider is responsible for the subsequent processing.

13. Service providers and international data transfers

We may use carefully selected service providers for hosting, databases, authentication, email delivery, analytics, customer management, support and other technical or business services.

These include in particular:

  • website hosting: XXX;
  • configurator hosting: XXX;
  • database and authentication: XXX;
  • CRM and customer management: XXX;
  • email and newsletter delivery: XXX;
  • analytics and error monitoring: XXX;
  • other service providers: XXX.

Personal data may be processed in countries outside your country of residence. Possible processing countries include in particular the member states of the European Union and the European Economic Area, Australia, New Zealand, the United States of America and XXX.

For transfers from the EU or the EEA we use — where required — adequacy decisions, standard contractual clauses or other legally recognised safeguards.

For transfers from Australia or New Zealand we take reasonable steps to ensure protection of the data in line with the applicable legal requirements.

Further information on international data transfers and the safeguards used can be requested at XXX.

14. Retention

We store personal data only for as long as necessary for the purposes described, to conduct a business relationship, to comply with legal obligations or to establish, exercise or defend legal claims.

The specific retention period depends in particular on:

  • the nature and purpose of the processing;
  • the duration of your account, project or contract;
  • statutory retention periods;
  • warranty, guarantee and limitation periods;
  • security and misuse risks;
  • consent given or withdrawn.

Intended deletion periods:

  • technical log data: XXX;
  • contact and consultation enquiries: XXX;
  • user accounts: XXX;
  • kitchen designs: XXX;
  • newsletter data and consent records: XXX;
  • analytics and cookie data: XXX;
  • contract, order and invoice data: in line with statutory retention periods.

Instead of deletion, data may be blocked or anonymised where further retention is legally required or permitted in anonymised form.

15. Data security

We take appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration and disclosure.

These may include encryption, access restrictions, role and permission concepts, backups, logging, security controls and regular updates.

Despite these measures, no data transmission or storage can be guaranteed to be entirely free of risk.

16. Your privacy rights

Depending on your place of residence and applicable law, you may have the following rights in particular:

  • access to your personal data;
  • rectification of incorrect or incomplete data;
  • erasure of your data;
  • restriction of processing;
  • objection to certain processing activities;
  • portability of the data you provided;
  • withdrawal of consent with effect for the future;
  • complaint to a competent data protection authority.

To exercise your rights, contact us at XXX. We may request information needed to verify your identity and the legitimacy of the request.

Your rights may be subject to legal conditions and exceptions. In particular, statutory retention obligations or overriding legitimate interests may prevent immediate deletion.

17. Complaints

Please direct privacy requests and complaints to us first:

  • Email: XXX
  • Postal address: XXX

We review complaints in accordance with applicable law and may request additional information required to handle them.

European Union and EEA

You have the right to lodge a complaint with a data protection supervisory authority. The authority responsible for us is:

  • XXX authority
  • XXX address
  • XXX website

Australia

You can contact the Office of the Australian Information Commissioner: www.oaic.gov.au

New Zealand

You can contact the Office of the Privacy Commissioner: www.privacy.org.nz

18. Automated decision-making

We currently do not make decisions based solely on automated processing which produce legal effects concerning you or similarly significantly affect you.

Should we use such automated decision-making in the future, we will provide the required information before it is deployed.

19. Changes to this privacy policy

We may adapt this privacy policy if our services, data processing or legal requirements change.

The current version is available at www.frameokitchens.com/XXX. We will provide appropriate notice of material changes.

  • Last updated: XXX