Privacy Policy
GIGA
PRIVACY POLICY
THE GIGA COMPANY
Effective 18 May 2026
1. Identity of the data controller
THE GIGA COMPANY, publisher of the GIGA brand, is responsible for the processing of personal data collected via the brand's website (hereinafter « the Site »).
|
Company |
THE GIGA COMPANY |
|
Address |
Avenue Louise 231, 1050 Ixelles, Belgium, Belgium |
|
CBE number |
BE1025.040.075 |
|
Personal data contact |
contact@thegigacompany.com |
|
Website |
www.thegigacompany.com |
2. Data collected
2.1. Data collected directly
The Company collects the following data in the context of the commercial relationship:
Identification data: surname, first name;
Contact details: email address, postal address, telephone number;
Order data: products purchased, amount, date, frequency, history;
Marketing communication data: email address, first name, communication preferences, history of opened/clicked emails (subject to consent);
Promotional operations participation data: surname, first name, email address, social media username, content submitted in the context of contests or co-creation operations, date and time of participation.
Feedback and review data: rating given, free comment, photos or videos submitted voluntarily, username or display name chosen by the user.
Location data: country, region, delivery city;
Account data: login credentials (email + hashed password);
Payment data: card type, last 4 digits (complete banking data is processed by the PCI-DSS certified payment provider - the Company does not have access to it);
Communications: messages exchanged with customer service.
2.2. Data collected automatically
When browsing the Site, data is collected automatically:
Technical data: IP address (anonymized), browser, operating system, screen resolution;
Browsing data: pages visited, visit duration, navigation path, traffic source (UTM);
Behavioral data: clicks, scroll, cart abandonment, interactions;
Conversion data: conversion rate, cart value, products viewed vs purchased.
3. Purposes and legal bases of the processing
In accordance with Article 13 of the GDPR, the Company informs data subjects of the purposes and legal bases of its processing operations:
|
Purpose of processing |
Legal basis (GDPR) |
Data concerned |
Retention period |
|
Order processing and customer relationship management |
Performance of the contract (art. 6.1.b) |
Identification, orders, delivery, payment |
Duration of commercial relationship + 5 years |
|
Sending of transactional emails (confirmation, tracking, reminder) |
Performance of the contract (art. 6.1.b) |
Email, first name, order content |
Duration of the commercial relationship |
|
Direct email marketing (newsletters, offers) |
Consent (art. 6.1.a) or legitimate interest if existing customer (art. 6.1.f) |
Email, first name, purchase history |
Until withdrawal of consent or 3 years of inactivity |
|
Behavioral analysis and browsing statistics |
Cookie consent (art. 6.1.a) |
Browsing data, anonymized IP |
13 months (cookies) + 26 months (analytics) |
|
Analysis of purchase data for commercial management |
Legitimate interest (art. 6.1.f) |
Purchase history, location, frequency |
3 years after last purchase |
|
Collection and publication of product reviews and feedback |
Consent (art. 6.1.a) |
Username/name, rating, comment, photo/video |
Until withdrawal or deletion upon request |
|
Management of contests and promotional operations (selection of participants, prize draw, awarding of prizes) |
Performance of the contract (art. 6.1.b) |
Social media username, comment, winner's contact details only |
Duration of the operation + 1 year (proof of participation) |
|
Reuse of submitted content in GIGA communications |
GIGA communications Consent (art. 6.1.a) |
Submitted content, username |
Until withdrawal |
|
Aggregation and anonymized statistical analysis |
Legitimate interest / anonymized data (outside the scope of the GDPR if anonymous) |
Aggregated data not attributable to a person |
Unlimited (anonymized data) |
|
Handling of complaints and product recalls |
Legal obligation (art. 6.1.c) |
Identification, orders, products concerned |
5 years from closure |
|
Fraud prevention |
Legitimate interest (art. 6.1.f) |
IP, order data, payment |
13 months |
|
Accounting and tax obligations |
Legal obligation (art. 6.1.c) |
Billing data |
7 years (Belgian accounting obligation) |
4. Aggregated and anonymized statistical data
4.1. Principle of aggregation and anonymization
The Company may aggregate customer data to produce commercial statistics (purchase volumes by region, consumer profiles, seasonality, price elasticity, etc.). These statistical data, once genuinely anonymized and non-re-identifiable, fall outside the scope of the GDPR.
The Company undertakes that the data shared with third parties for statistical purposes shall be:
Genuinely anonymized and non-re-identifiable, in accordance with the standards of Opinion 05/2014 of the WP29 on anonymization techniques and the subsequent guidelines of the European Data Protection Board (EDPB);
Aggregated at a sufficient level of granularity to prevent any individual re-identification;
Devoid of any direct or indirect identifier.
4.2. Sharing of statistical data with commercial partners
As part of its B2B commercial strategy, the Company may share aggregated and anonymized statistical data such as: sales volumes by geographic area, aggregated socio-demographic profiles, purchase frequency and average cart value, repeat purchase rate. This information does not constitute a « sharing of personal data » within the meaning of the GDPR, provided that it is genuinely anonymized.
4.3. What the Company does not do
The Company expressly undertakes not to:Sell identifiable personal data to third parties;
Share personal data with advertisers for third-party advertising targeting purposes, except with explicit consent;
Cross-reference personal data with third-party databases without an appropriate legal basis.
5. Management of cookies and consent
The Site uses cookies and trackers for technical, analytical and, subject to consent, advertising purposes.
The details of the cookies used, their purposes, their retention periods and the ways to exercise your choices are set out in the Cookie Policy available on the Site at: https://thegigacompany.com › pages › cookie-policy.
Consent for non-essential cookies is collected via a consent banner compliant with the recommendations of the Belgian Data Protection Authority (DPA). It can be withdrawn at any time via the preference manager accessible from the footer of the Site.
6. Data transfers outside the EU/EEA
Some providers may transfer data outside the European Union. The Company ensures that these transfers are governed by appropriate safeguards:
Standard Contractual Clauses (SCC) approved by the European Commission;
Adequacy decision (e.g. EU-US Data Privacy Framework for transfers to the United States);
Binding Corporate Rules (BCR) where applicable.
7. Data recipients and processors
The personal data collected in the context of operating the Site is hosted within the European Economic Area (EEA) or transferred to providers located outside the EEA under the conditions described in Section 6. In the context of its activity, the Company may share personal data with the following categories of recipients, strictly limited to what is necessary for each purpose:
|
Category of recipient |
Examples |
Data concerned |
|
E-commerce platform |
Shopify Inc. (USA |
All order and account data |
|
Payment provider |
Shopify Payments |
Transaction data, billing details |
|
Logistics provider / carrier |
Bpost and Mondial Relay |
Name, delivery address, order number |
|
Emailing tool and CRM |
Klaviyo |
Email, first name, purchase history, email behavior |
|
Analytics tools |
Google Analytics 4 (USA) |
Anonymized browsing data |
|
Social media and advertising |
Meta Platforms (USA), Google Ads (USA) |
Behavioral data (subject to consent) |
|
Competent authorities |
DPA, FASFC, judicial authorities |
Data required by law |
Providers acting as processors within the meaning of Article 28 of the GDPR are bound to the Company by a Data Processing Agreement (DPA) guaranteeing an adequate level of protection.
The complete list of processors can be provided upon request sent to contact@thegigacompany.com.
NB: the payment provider acts as an independent data controller for banking data. The Company does not store any complete banking data and only has access to the 4 last digits of the card and the card type. The processing of payment data is governed by the privacy policy of the relevant provider.
8. Rights of data subjects
In accordance with Articles 15 to 22 of the GDPR, every data subject has the following rights:
Right of access (art. 15): obtain confirmation of processing and a copy of the data;
Right to rectification (art. 16): correct inaccurate or incomplete data;
Right to erasure (art. 17): delete the data (« right to be forgotten »), subject to legal retention obligations;
Right to restriction of processing (art. 18): temporarily freeze the processing;
Right to portability (art. 20): receive your data in a structured format;
Right to object (art. 21): object to processing based on legitimate interest or for direct marketing purposes;
Right to withdraw consent (art. 7.3): withdraw your consent at any time, without retroactive effect;
Right not to be subject to an automated decision (art. 22).
These rights can be exercised by email at contact@thegigacompany.com or by post to the registered office, with a copy of proof of identity. The Company responds within one month (extendable by two months in case of complexity).
In the event of an unsatisfactory response, the data subject may lodge a complaint with the Belgian Data Protection Authority (DPA): www.autoriteprotectiondonnees.be.
9. Data security
The Company implements appropriate technical and organizational measures to protect personal data:
Encryption of data in transit (SSL/TLS) and at rest;
Data access restricted according to the principle of least privilege;
Strengthened password policy;
Logging of access to sensitive data;
Regular review of access rights;
Notification procedure in case of a data breach: 72h to the DPA (art. 33 GDPR), notification to data subjects if high risk (art. 34 GDPR).
10. Updates to this policy
This Privacy Policy may be modified at any time to reflect changes in the Company's practices or legal requirements. Substantial changes will be notified to users by email or by a notice visible on the Site. The update date is indicated in the header of the document.