(a) Valuing your privacy and safeguarding your personal data.
At Dufry, we respect your privacy and adhere to applicable data protection and privacy laws and relevant e-commerce laws globally. We strive to consistently exceed our clients’ expectations regarding the products and services that we offer to our travel retail customers. We create experiences that our customers value by responsibly using information with which you entrusted us.
This Privacy Notice describes the way we treat all the personal data you provide or that we have obtained through our Dufry Websites and Applications and in our retail stores.
(b) Applicability and links to other third party applications and/or websites
This Privacy Notice applies to all visitors and anyone who accesses or uses our products and services of the retail store locations (“Stores”) and the global Dufry.com websites and any local country Dufry websites or our mobile applications currently called Red by Dufry application, Forum By Dufry,Dufry Red Loyalty Program or Reserve and Collect customer program mobile applications (as amended from time to time) of Dufry AG, its subsidiaries, affiliated companies and such other companies where Dufry AG has effective management control over such entities (collectively called “Dufry”, “us” ,”we” and such websites and applications collectively called “Dufry Websites and Applications”). “Personal data” means any information relating to an individual who is identified or identifiable, such as name, address, email, phone number and information relating thereto.
Dufry Websites and Applications may contain links to and from the applications and/or websites of our partner networks, advertisers, third parties and affiliates. They are merely for informational purposes. If you follow a link to any of these applications and/or websites, please bear in mind that they have their own privacy policies and that we assume no responsibility or liability arising whatsoever nor endorse any practices from their policies.
BY ACCESSING DUFRY WEBSITES AND APPLICATIONS AND ACCEPTING THE STATEMENT WITH THE LINK OK, I AGREE AND CONTINUING TO ACCESS THE DUFRY WEBSITES AND APPLICATION OR YOU ENTER AND PURCHASE PRODUCTS IN OUR STORES, YOU ACCEPT THE TERMS AND THE PROCESSING OF PERSONAL DATA DESCRIBED IN THE PRIVACY NOTICE. IF YOU DO NOT AGREE, PLEASE REFRAIN FROM ACCESSING DUFRY WEBSITES AND APPLICATIONS OR OUR STORES.
YOU MAY WITHDRAW YOUR CONSENT AT ANY TIME. WE WILL THEN REFRAIN FROM FURTHER PROCESSING YOUR PERSONAL DATA, EXCEPT TO THE EXTENT THE PROCESSING OF YOUR PERSONAL DATA IS LAWFUL FOR OTHER REASONS EVEN WITHOUT YOUR CONSENT, SUCH AS LAWFUL PURPOSES AS FULFILLING THE CONTRACTUAL OBLIGATIONS OR COMPLIANCE WITH LAW OR TO PROTECT OUR OR THIRD PARTIES LEGITIMATE INTERESTS (SUCH AS THE UNINTERRUPTED AVAILABILITY OF OUR WEBSITE OR ENFORCEMENT OF VIOLATIONS OF LAW).
(c ) Summary of provisions:
(a) Controller and Processors of Personal Data
Dufry AG and the owner of the local website (as set out in the terms) which you are currently visiting or the local Dufry entity which owns the local Store that you are visiting or from whom you are purchasing goods are joint controllers of the personal data that you (as data subject) provide us or we received in our Stores and Dufry Websites and Applications.
(b) Types of Personal Data collected and Sources of Personal Data
We collect personal data directly from our customers through Dufry Websites and Applications and our Stores.
We obtain, use, disclose and otherwise process personal data about customers to (i) process transactions they request, including e-commerce Reserve and Collect selection and mobile transactions, (ii) improve Dufry Websites and Applications, Stores, quality of service and customers shopping experience, (iii) send communications about our products, services, campaigns, promotions, competitions, sweepstakes and customer satisfaction surveys, (iv) prevent and detect fraud and abuse, (v) process information or claims in connection with incidents at Stores, (vi) enable service providers to perform certain activities on Dufry’s behalf, (vii) protect the log in details of the subscribers and system integrity of the Dufry Websites and Applications, (viii) comply with legal obligations, policies and procedures and for internal administrative and analytics purposes,(ix) allow valid RED loyalty members to access their accounts and accumulate and redeem points under their RED loyalty card and receive the relevant discount on their purchases in Stores according to their status as a RED loyalty card member and (x) to commence, protect or defend Dufry in actual or threatened legal proceedings.
We collect the following types of personal data about you from the following sources:
Information that you provide to us: We receive and store any information you enter on Dufry Websites and Applications and Stores or give us in any other way such as during registration, accessing your account or profile, submitting queries or as part of a survey or competition or utilising gift coupons or customer support or communicate with us or purchasing in Stores or using our products or services.
Due to such actions, you supply us with your (i) name, postal address, email address, phone numbers, (ii) data necessary to process your payment (including the credit card/payment instrument information and personal security code associated with your credit card) for Store purchases or on line purchase of gift vouchers, to reserve purchases (under the Dufry Reserve & Collect Application), to apply for a refund, or to communicate with customer services regarding a refund to the credit card/payment instrument, (iii) flight destination, flight date and delivery address for the subscriber and airport location to collect any pre ordered reserve & collect products or make purchases of our products and services in Stores. Demographical data such as your age, gender, country, preferred language, passport number and citizenship, date of birth and country of residence are also collected. You must hold a valid flight ticket to be able to make duty free or duty paid purchases from Dufry. Such information is collected to meet our contractual obligations to our landlord and airport authorities and legal obligations towards customs and other regulatory authorities.
When you register for membership, subscribe for services or the newsletter or other marketing communications including blogs or customer comments or use the Dufry Websites and Applications or purchase in our Stores, we collect log in details, passwords, any password questions and hints, similar security information used for authentication and account access is also collected for the access into your personal account and profile and to utilise the Reserve and Collect elements or the RED customer loyalty elements of Dufry Websites and Applications or in our Stores.
You can choose not to provide certain information, but then you might not be able to utilise many of the features of the Dufry Websites and Applications. See What Are My Choices section below. (https://sso.dufry.com/profile)
Information collected automatically through interaction with us: We receive and store information where you interact with us through using our products and services, including online technologies (ie Cookies) and receiving error reports or usage data from software applications on your devices online or via WiFi communications in Stores.
We collect and analyse device, connectivity and configuration data including the Internet protocol (IP) address used to connect your computer or device to the internet, computer and connection information such as browser type, version, time zone and other computer software installed on the device, browser plug in types and versions, operating system, shopping preferences, wish list, purchase history, the features you use and pages accessed and web sites visited.
We also collect the Uniform Resource Locator (URL) clickstream to and from our Dufry Websites and Applications, including date and time, cookie number, products viewed and searched for and the phone number used to contact our customer support teams. We collect technical information to help us identify your device for fraud prevention and diagnostic purposes such as any problems to the product and settings, error reports including data as to the type and severity of the problem, details of software and hardware related to an error, contents of files you were using when an error occurred and data about other software on the device.
We collect browser data including persistent and session cookies and other online technologies as set out below in the Online Technologies section below. We utilise Google Analytics to assist with software tools to measure and collect the performance data on Dufry Websites and Applications including download error or performance issues caused. Further information can be found under (Google Analytics Terms of Service & Privacy).
Most browsers allow you to opt out of cookies or turn on do not track. For more information, see What are My Choices section below [https://sso.dufry.com/profile].
Mobile or Dufry Applications: When you choose to use or download Dufry Websites and Applications or allow connectivity via WiFi connections to your device, we receive information about your location and mobile device, including a unique identifier for your personalised device, your GPS data or wireless networks data (WLAN). Location data is neither stored nor transmitted to third parties If you agree with the localisation function, we can provide you with location-based services including advertising, search results and personalised content. Once you are near one of our Stores, then we can use push email communications to you if you have provided your preference to receive such communications and advertising.
Most mobile devices allow you to turn off location services. For more information, see What are My Choices section below [https://sso.dufry.com/profile].
E-Mail Communications: To provide more personalised and interesting email communications, we receive a confirmation when you open email from Dufry Websites and Applications or your device is near one of our Stores, if your computer or device supports this capability. Additionally, we compare our customer list to lists received from other companies, in an effort to reduce repetitive or unnecessary messages or spam being sent to our customers.
If you choose not to receive any Emails or other mail from us, please adjust your customer communication preferences in your account profile.
Information from other Sources: We receive information about you from other sources and add it to our account information. The third party sources include:
(a) Lawful purposes
Your personal data is processed by the Group on the basis of a lawful “justification” for such processing, to the extent required by or permissible under applicable law. The processing of special categories of personal data (including data relating to health, sexual preferences racial or ethnic origin, religious beliefs) is always justified on an additional basis as set out below.
In the majority of cases, the processing of your personal data will be justified on one of the following bases:
The processing of special categories of personal data will be justified by one of the above conditions and normally by one of the following special conditions:
(b) Purposes of processing personal data
We obtain, use, disclose and otherwise process personal data about customers to:
We use personal data to carry out your contractual transactions with us and to provide our products (including the reserving of and pre-selection of duty free products listed in the Reserve and Collect application for collection at the requested Store) to you as requested by you. This includes using your personal information to register or subscribe to any services provided thorough Dufry Websites and Applications.
We collect personal data especially the collection of the passenger name, boarding card to ensure that the consumer reserving the products is a valid traveller to meet our contractual obligations to our landlord and long term concession agreement as well to allow the calculation of the VAT or similar tax allowances to be calculated for the customs authorities.
Where we process your personal data on the basis of our legitimate interests, those will be our interests in :
We will not transfer or disclose your personal information outside our corporate group of Dufry AG, other than as set out below:
Nevertheless, within our corporate group of Dufry AG, certain services are centralised to provide one or more affiliates for the entire group or a part of it.
Your personal information you have provided to either or both joint controllers be located in a Dufry AG cloud based customer management database software tool located within data centres maintained in the territories of the EEA, unless the local data protection laws require that the local Dufry entity will be included in a file owned by the local Dufry Entity, the purpose of which is to manage the business relationship with you, in accordance with the provisions of the local data protection laws. However, the customer relationship and the personal data if any is held with the local Dufry entity who owns this Website or Applications can be accessed or communicated to group or affiliated companies of Dufry AG.
Dufry AG and local Dufry AG entity will manage the customer relationship with you and any marketing materials can be provided, in accordance with your preferences, by Dufry as Controller or by the local Dufry entity as a joint controller or processed on behalf of Dufry AG.
Your personal data will be secured by taking security measures that are commensurate with the sensitivity of the personal data processed. To this end, Dufry and all Group entities maintain appropriate physical, technical, and administrative security measures with a view to protecting personal data against theft; accidental loss; unauthorised alteration; unauthorised or accidental access, processing, erasure, use, disclosure or copying; and/or accidental or unlawful destruction.
When we have provided (or you have chosen) a password allowing access to certain benefits of the Dufry Websites and Applications, you are responsible for safeguarding it and keeping it confidential and you undertake not to allow it to be used by third parties. Unfortunately, the transmission of information thorough the internet is not completely secure. Although we will take all reasonable commercial measures to protect your personal data, we cannot guarantee the security of any personal information or data you disclose on line. You accept the inherent security implications of using the internet and to the extent permitted by law, we will not be responsible for any breach of security, unless we have been acting with gross negligence and only within the limitations as set out in the terms and conditions of use for Dufry Websites and Applications.
Your personal data (as described above) may be transferred to other Group entities or to third parties described above, only to the extent required for Dufry AG and group companies to perform their obligations to you, or for you to access your Dufry Websites and Applications, or for the purposes described above in this Notice, provided such purposes are in accordance with applicable laws. In particular:
A list of the countries located outside the EU to which your Personal Data may be transferred, and an indication of whether they have been determined by the European Commission to grant adequate protection to Personal Data, can be found at https://ec.europa.eu/info/strategy/justice-and-fundamental-rights/data-protection/data-transfers-outside-eu_en
Transfers of Personal Data in accordance with this Section 7 are based on the same legal bases as applicable for the respective purposes of processing as set out above.
Dufry data retention policy requires that personal data be retained for no longer than required to fulfil the purposes for which it was collected. Dufry AG can provide a copy of the Group Data Retention Policy upon request to the email address: email@example.com. In general, personal data, or records containing personal data, will be retained for periods of time required in accordance with applicable legal, tax, or accounting obligations. In specific circumstances, and in accordance with applicable law, Dufry may retain your personal data for longer periods of time (such as for the duration of the relevant statute of limitation) so that we have an accurate record of our dealings with you or to protect the legitimate interests of Dufry AG or local Dufry entity name, who owns this Dufry Website or Application. In all cases, where your information is no longer required, Dufry will ensure it is disposed of in a secure manner.
Dufry Websites and Applications do not provide products and services to children. Whilst we may sell toys and confectionary which may appeal to children, any reservation for our products and services can only be provided to adults over the age of 18 years old. We do not knowingly collect personal information from children under the age of 18 years, without the consent of the child’s parent or guardian. Accordingly, the parent will need to complete and submit a fully completed and signed Parental Personal Data Consent Form along with evidence of the person’s identity, to the email address: firstname.lastname@example.org.
A "cookie" is a small text file that identifies your mobile device and/or equipment on our server. None of the Cookies we use collect your personal information and they cannot be used to identify you, only the mobile device and/or equipment used. Unless stipulated otherwise, we will not pass personally identifiable data to third parties.
We use 'persistent' cookies. 'Persistent' cookies usually have a long shelf life because they are "collected" and "updated" every time a user visits an application and/or page where the same or a similar cookie is being used.
Information obtained through cookies is used by us and by third parties that we have hired in order to show you advertising related to your preferences. For a full list of the cookies that we use, please click here
Cookies generally help us provide better Dufry Websites and Applications, which allows us to monitor which pages you find useful and those which are not. A cookie does not allow us to access any other data on your mobile device, equipment or to any information about you, other than the data you choose to share with us. You can choose to accept or decline cookies. Most web browsers automatically accept cookies, but you can modify your browser setting to decline cookies if you prefer. Cookies, including those which have already been set, can be deleted from your hard drive.
(b) Google Analytics
Google Analytics are used to help us understand how to make the best use of our content and find out how we can improve it. These cookies allow us to track your progress through our Dufry Websites and Applications, collect personal data at their origin, which applications and/or pages you visit, and the time you spend on the site. This data is then stored by Google in order to create reports.
(c) Interest based advertising tools including Google Inc “similar audiences” function, conversion tracking and Adserver Systems for distribution of advertising material and campaign analysis
We also work with vendors and strategic marketing partners to help deliver advertisements and personalised content that we believe will be of interest to you. These vendors and other partners include advertisers, advertising agencies, advertising networks, audience segment providers, data exchanges, analytics providers and other similar providers.
We may also engage one of these vendors to deliver our advertisements to consumers whose online behaviours on sites other than Dufry Websites and Applications indicate that they be interested in Dufry products and services. In other instances, we engage in special arrangements with certain advertisers in which we think our website visitors and subscribers would have an interest. We allow these advertisers to deliver co-branded messages (Dufry and advertiser) directly to consumers who have visited or subscribed to Dufry Websites and Applications.
You can use the following link to deactivate Adserver system cookies: http://site.adform.com/privacy-policy
(c) Social media log in and plug ins
On some websites of our on line catalogue, we use social plugins of the social network www.facebook.com , which is operated by Facebook Inc., 1601 S.California Ave, Palo Alto, CA 94304, USA (“Facebook”).
The websites of our online catalogue in Dufry Websites and Applications can contain a plug in are marked with a clearly visible Facebook logo (ie white “f” on a blue icon) or the addition of “Facebook Social Plugin”).
If you access a website like this containing such a plugin, your browser will establish a direct connection with the Facebook servers and Facebook will transmit the content of the plugin directly to your browser.
If you are registered with Facebook and are logged into your Facebook user account, Facebook will receive the information that you accessed the respective website by the integration of the plugin. If you use the plugin actively by activating the “like” button or the “share” button or placing a commentary on the respective website, the corresponding information will be transmitted from your browser directly to Facebook and used there in Dufry Websites and Applications.
In order to avoid Facebook collecting the above information about you when you access such a website, please following the instructions in settings on the Facebook website and/or log out of the Facebook website, before visiting the respective website in Dufry Websites and Applications. Additionally, you should delete any Facebook cookies present from your browser.
You have the right under applicable law to access, obtain a copy and correct personal data concerning you, subject to limited exceptions that may be prescribed by applicable laws. Where justified and mandated by applicable law, you may also require that your personal data be deleted or blocked, or you may be entitled to obtain information about the processing of your data, or object to further processing of your data.
In the event your personal data is processed on the basis of your consent, you have the right to withdraw consent at any time, without affecting the lawfulness of processing based on consent before its withdrawal. You can do this by (i) in some cases deleting the relevant Personal Data from the relevant IT system (although note that in this case it may remain in back-ups and linked systems until it is deleted in accordance with our data retention policy) or (ii) contacting your Global Data Protection Co-Ordinator.
As permitted by law, you also have the following additional rights:
Where your personal data is subject to restriction in this way we will only process it with your consent or for the establishment, exercise or defense of legal claims.
Please contact us by submitting a Data Subject Access Request Form (available upon request) in writing or by email to either of the addressees listed below.
Dufry has appointed a Global Data Protection Co-Ordinator who may be contacted securely and confidentially at the following E – Mail address : email@example.com. Alternatively, you can send your Data Subject Access Request Form, written comments, questions or concerns to
Attention : Global Data Protection Co-Ordinator
Dufry Websites and Applications provide you with access to a range of information about your account and your interactions with us. To ensure that your personal data is accurate and up to date, we encourage you to regularly review and update your information as appropriate, if your communication preferences change or your contact details or address has changed. If you have subscribed to Dufry Websites and Applications, especially the Red by Dufry application or the Reserve and Collect Application, then you can either access your account and make the changes or request the changes are made by sending an email request along with evidence of your identity to firstname.lastname@example.org.
Changes and amendment to the terms of this Privacy Notice can be made at any time and shall apply as soon as they are published on any Dufry Websites and Applications. Should you not agree to any changes or amendments, then you should refrain from continuing to use our services or products or access Dufry Websites and Applications or our Stores.
You have the right to lodge complaints pertaining to the processing of your personal data with the relevant data protection supervisory authority.
|Category||Name||Used by||Purpose(s)||Expiration Date||Personal Data||Information disclosed|
|Functional||Remember me||Dufry||Used to automatically login the user between sessions. If the user does not explicitly click on logout, then SSO will use this cookie to automatically login the user next time he will access the SSO||1 year||no||no|
|Functional||JSESSIONID||Dufry||Used to track the current session||End of each user session||no||no|
|Analytical||-ga||Dufry||Website analytics||2 years||no||no|
|Analytical||-gid||Dufry||Website analytics||24 hours||no||no|
|Analytical||AWSELB||Dufry/ Amazaon||Used to track the current session||End of each user session||no||no|
|Analytical||-utma||Dufry /Google Analytics||Website analytical to track visitors including first and last visit (returning visits)||Persistent cookie remains on computer until it expires or the cookie cache is cleared.||yes||Cookie updates when information sent to Google Analytics|
|Analytical||-utmc||Dufry /Google Analytics||Website analytical to determine the end of browser sessions. Used to determine whether the user was in a new session/visit||Cookie created in conjunction with the –umtb cookie.||no||Cookie updates when information sent to Google Analytics|
|Analytical||-umtv||Dufry/ Google Analytics||Website Analytical persistent cookie for segmentation, data experimentation and operates with the –umtz cookie to improve cookie targeting capabilities.||Persistent cookie remains on computer until it expires or the cookie cache is cleared||no||Cookie updates when information sent to Google Analytics|
Cookies within the Dufry Reserve & Collect Application
|Category||Name||Used by||Purpose(s)||Expiration Date||Personal Data||Information disclosed|
|Cart||Dufry||The association with your shopping cart.||Persistent||yes||no|
|Category - info||Dufry||Stores the category information on the website page, that allows to display pages more quickly.||Persistent||yes||no|
|Compare||Dufry||Items that you have in the Compare Products list||Persistent||yes||no|
|Currency||Dufry||Your preferred currency||Persistent||yes||no|
|Customer||Dufry||An encrypted version of your customer id with the store.||Persistent||yes||no|
|Customer_ Auth||Dufry||An indicator if you are currently logged into the store||Persistent||yes||no|
|Customer_Info||Dufry||An encrypted version of the customer group you belong to .||Persistent||yes||no|
|Customer_Segment_IDS||Dufry||Stores the Customer Customer Segment ID||Persistent||No||no|
|External_No_Cache||Dufry||A flag, which indicates whether caching is disabled or not.||Persistent||No||no|
|Frontend||Dufry||Your session ID on the server.||Persistent||No||No|
|Guest_View||Dufry||Allows guests to edit their orders||Persistent||No||No|
|Last_Category||Dufry||The last category you visited.||Persistent||No||No|
|Last_ Product||Dufry||The most recent product you have viewed||Persistent||No||No|
|Newmessage||Dufry||Indicates whether a new message has been received||Persisent||No||No|
|Store||Dufry||The store view or language you have selected||Persistent||No||No|
|Viewed_Product_IDS||Dufry||The products that you have recently viewed||Persistent||No||No|
|Wishlist||Dufry||An encrypted list of products added to your Wishlist||Persistent||No||No|
|Wishlist_CNT||Dufry||The number of items in your Wishlist||Persistent||No||No|