Skip to content

Cart

Your cart is empty

Privacy Policy

GIGA

PRIVACY POLICY

THE GIGA COMPANY

Effective 18 May 2026

 

1. Identity of the data controller

THE GIGA COMPANY, publisher of the GIGA brand, is responsible for the processing of personal data collected via the brand's website (hereinafter « the Site »).

Company

THE GIGA COMPANY

Address

Avenue Louise 231, 1050 Ixelles, Belgium, Belgium

CBE number

BE1025.040.075

Personal data contact

contact@thegigacompany.com

Website

www.thegigacompany.com

2. Data collected

2.1. Data collected directly

The Company collects the following data in the context of the commercial relationship:

Identification data: surname, first name;

 

Contact details: email address, postal address, telephone number;

 

Order data: products purchased, amount, date, frequency, history;

 

Marketing communication data: email address, first name, communication preferences, history of opened/clicked emails (subject to consent);

 

Promotional operations participation data: surname, first name, email address, social media username, content submitted in the context of contests or co-creation operations, date and time of participation.

 

Feedback and review data: rating given, free comment, photos or videos submitted voluntarily, username or display name chosen by the user.

 

Location data: country, region, delivery city;

 

Account data: login credentials (email + hashed password);

 

Payment data: card type, last 4 digits (complete banking data is processed by the PCI-DSS certified payment provider - the Company does not have access to it);

 

Communications: messages exchanged with customer service.

 

2.2. Data collected automatically

When browsing the Site, data is collected automatically:

Technical data: IP address (anonymized), browser, operating system, screen resolution;

 

Browsing data: pages visited, visit duration, navigation path, traffic source (UTM);

 

Behavioral data: clicks, scroll, cart abandonment, interactions;

 

Conversion data: conversion rate, cart value, products viewed vs purchased.

3. Purposes and legal bases of the processing

In accordance with Article 13 of the GDPR, the Company informs data subjects of the purposes and legal bases of its processing operations:

Purpose of processing

Legal basis (GDPR)

Data concerned

Retention period

Order processing and customer relationship management

Performance of the contract (art. 6.1.b)

Identification, orders, delivery, payment

Duration of commercial relationship + 5 years

Sending of transactional emails (confirmation, tracking, reminder)

Performance of the contract (art. 6.1.b)

Email, first name, order content

Duration of the commercial relationship

Direct email marketing (newsletters, offers)

Consent (art. 6.1.a) or legitimate interest if existing customer (art. 6.1.f)

Email, first name, purchase history

Until withdrawal of consent or 3 years of inactivity

Behavioral analysis and browsing statistics

Cookie consent (art. 6.1.a)

Browsing data, anonymized IP

13 months (cookies) + 26 months (analytics)

Analysis of purchase data for commercial management

Legitimate interest (art. 6.1.f)

Purchase history, location, frequency

3 years after last purchase

Collection and publication of product reviews and feedback

Consent (art. 6.1.a)

Username/name, rating, comment, photo/video

Until withdrawal or deletion upon request

Management of contests and promotional operations (selection of participants, prize draw, awarding of prizes)

Performance of the contract (art. 6.1.b)

Social media username, comment, winner's contact details only

Duration of the operation + 1 year (proof of participation)

Reuse of submitted content in GIGA communications

GIGA communications Consent (art. 6.1.a)

Submitted content, username

Until withdrawal

Aggregation and anonymized statistical analysis

Legitimate interest / anonymized data (outside the scope of the GDPR if anonymous)

Aggregated data not attributable to a person

Unlimited (anonymized data)

Handling of complaints and product recalls

Legal obligation (art. 6.1.c)

Identification, orders, products concerned

5 years from closure

Fraud prevention

Legitimate interest (art. 6.1.f)

IP, order data, payment

13 months

Accounting and tax obligations

Legal obligation (art. 6.1.c)

Billing data

7 years (Belgian accounting obligation)

4. Aggregated and anonymized statistical data

4.1. Principle of aggregation and anonymization

The Company may aggregate customer data to produce commercial statistics (purchase volumes by region, consumer profiles, seasonality, price elasticity, etc.). These statistical data, once genuinely anonymized and non-re-identifiable, fall outside the scope of the GDPR.

The Company undertakes that the data shared with third parties for statistical purposes shall be:

Genuinely anonymized and non-re-identifiable, in accordance with the standards of Opinion 05/2014 of the WP29 on anonymization techniques and the subsequent guidelines of the European Data Protection Board (EDPB);

 

Aggregated at a sufficient level of granularity to prevent any individual re-identification;

 

Devoid of any direct or indirect identifier.

4.2. Sharing of statistical data with commercial partners

As part of its B2B commercial strategy, the Company may share aggregated and anonymized statistical data such as: sales volumes by geographic area, aggregated socio-demographic profiles, purchase frequency and average cart value, repeat purchase rate. This information does not constitute a « sharing of personal data » within the meaning of the GDPR, provided that it is genuinely anonymized.

4.3. What the Company does not do

The Company expressly undertakes not to:Sell identifiable personal data to third parties;

Share personal data with advertisers for third-party advertising targeting purposes, except with explicit consent;

 

Cross-reference personal data with third-party databases without an appropriate legal basis.

5. Management of cookies and consent

The Site uses cookies and trackers for technical, analytical and, subject to consent, advertising purposes.

The details of the cookies used, their purposes, their retention periods and the ways to exercise your choices are set out in the Cookie Policy available on the Site at: https://thegigacompany.com › pages › cookie-policy.

Consent for non-essential cookies is collected via a consent banner compliant with the recommendations of the Belgian Data Protection Authority (DPA). It can be withdrawn at any time via the preference manager accessible from the footer of the Site.

6. Data transfers outside the EU/EEA

Some providers may transfer data outside the European Union. The Company ensures that these transfers are governed by appropriate safeguards: 

Standard Contractual Clauses (SCC) approved by the European Commission;

 

Adequacy decision (e.g. EU-US Data Privacy Framework for transfers to the United States);

 

Binding Corporate Rules (BCR) where applicable.

7. Data recipients and processors

The personal data collected in the context of operating the Site is hosted within the European Economic Area (EEA) or transferred to providers located outside the EEA under the conditions described in Section 6. In the context of its activity, the Company may share personal data with the following categories of recipients, strictly limited to what is necessary for each purpose:

Category of recipient

Examples

Data concerned

E-commerce platform

Shopify Inc. (USA

All order and account data

Payment provider

Shopify Payments

Transaction data, billing details

Logistics provider / carrier

Bpost and Mondial Relay

Name, delivery address, order number

Emailing tool and CRM

Klaviyo

Email, first name, purchase history, email behavior

Analytics tools

Google Analytics 4 (USA)

Anonymized browsing data

Social media and advertising

Meta Platforms (USA), Google Ads (USA)

Behavioral data (subject to consent)

Competent authorities

DPA, FASFC, judicial authorities

Data required by law

Providers acting as processors within the meaning of Article 28 of the GDPR are bound to the Company by a Data Processing Agreement (DPA) guaranteeing an adequate level of protection.

The complete list of processors can be provided upon request sent to contact@thegigacompany.com.

NB: the payment provider acts as an independent data controller for banking data. The Company does not store any complete banking data and only has access to the 4 last digits of the card and the card type. The processing of payment data is governed by the privacy policy of the relevant provider.

8. Rights of data subjects

In accordance with Articles 15 to 22 of the GDPR, every data subject has the following rights:

Right of access (art. 15): obtain confirmation of processing and a copy of the data;

 

Right to rectification (art. 16): correct inaccurate or incomplete data;

 

Right to erasure (art. 17): delete the data (« right to be forgotten »), subject to legal retention obligations;

 

Right to restriction of processing (art. 18): temporarily freeze the processing;

 

Right to portability (art. 20): receive your data in a structured format;

 

Right to object (art. 21): object to processing based on legitimate interest or for direct marketing purposes;

 

Right to withdraw consent (art. 7.3): withdraw your consent at any time, without retroactive effect;

 

Right not to be subject to an automated decision (art. 22).

 

These rights can be exercised by email at contact@thegigacompany.com or by post to the registered office, with a copy of proof of identity. The Company responds within one month (extendable by two months in case of complexity).

In the event of an unsatisfactory response, the data subject may lodge a complaint with the Belgian Data Protection Authority (DPA): www.autoriteprotectiondonnees.be.

9. Data security

The Company implements appropriate technical and organizational measures to protect personal data:

Encryption of data in transit (SSL/TLS) and at rest;

 

Data access restricted according to the principle of least privilege;

 

Strengthened password policy;

 

Logging of access to sensitive data;

 

Regular review of access rights;

 

Notification procedure in case of a data breach: 72h to the DPA (art. 33 GDPR), notification to data subjects if high risk (art. 34 GDPR).

10. Updates to this policy

This Privacy Policy may be modified at any time to reflect changes in the Company's practices or legal requirements. Substantial changes will be notified to users by email or by a notice visible on the Site. The update date is indicated in the header of the document.