PRIVACY NOTICE EXTERNAL PARTNERS

Data privacy is of high importance for H&M group and we want to be open and transparent with our processing of your personal data.
We therefore have a policy setting out how your personal data will be processed and protected.


Who is the controller of your personal data?
The Swedish company, H & M Hennes & Mauritz GBC AB (“the H&M group”), is the controller and responsible for your personal data under applicable data protection law.


Where do we store your data?
The data that we collect from you is stored within the European Economic Area (“EEA”) but may also be transferred to and processed in a country outside of the EEA. Any such transfer of your personal data will be carried out in compliance with applicable laws.

For transfers outside the EEA, H&M group will use Standard Contractual Clauses and Privacy Shield as safeguards for countries without adequacy decision from the European Commission.


Who has access to your personal data?
Your personal data may be shared within the H&M group (for details on the companies within the H&M group, please refer to our annual report which may be found at about.hm.com). We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group.

The H&M group company will only act as the personal data processor and processes the personal data on behalf of the Swedish company.

Personal data that is forwarded to third parties, is only used to provide you with our services. You will find what categories of third parties there are under each specific process below.


What is the legal ground for processing?
For every specific processing of personal data we collect from you we will inform you whether the provision of personal data is statutory or required to enter a contract and whether it is an obligation to provide the personal data and possible consequences if you choose not to.


WHAT ARE YOUR RIGHTS?

Right to access:
You have the right to request information about the personal data we hold on you at any time. You can contact H&M group that will provide you with your personal data via e-mail.


Right to portability:
Whenever H&M group process your personal data by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.


Right to rectification:
You have the right to request rectification of your personal data if they are incorrect, including the right to have incomplete personal data completed


Right to erasure:
You have the right to erase any personal data processed by H&M group at any time except for the following situations

  • for exercising the right of freedom of expression and information
  • to comply with a legal obligation
  • for the establishment, exercise or defence of legal claims


Your right to object to processing based on legitimate interest: 
You have the right to object to processing of your personal data that is based on H&M group's legitimate interest. H&M group will not continue to process the personal data unless we can demonstrate a legitimate ground for the process which overrides your interest and rights or due to legal claims.


Your right to object to direct marketing:
You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes. You can opt out from direct marketing by following the instruction in each marketing mail.


Right to restriction:
You have the right to request that H&M group restricts the process of your personal data under the following circumstances:

  • if you object to a processing based on H&M group's legitimate interest, H&M group shall restrict all processing of such data pending the verification of the legitimate interest.
  • if you have claim that your personal data is incorrect, H&M group must restrict all processing of such data pending the verification of the accuracy of the personal data.
  • if the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data.
  • if H&M group no longer needs the personal data but it is required for you to make or defend legal claims.


How can you exercise your rights? We take data protection very seriously and therefore we have dedicated personnel to handle your requests in relation to your rights stated above. You can contact us at  dataprotection.externalpartners@hm.com. and write External Partner request as subject matter.


Data Protection Officer
We have appointed a Data Protection Officer to ensure that we continuously process your personal data in an open, accurate and legal manner. You can contact our Data Protection Officer at  dataprotection.externalpartners@hm.com and write DPO as subject matter.

Right to complain with a supervisory authority: 
If you consider the H&M group to process your personal data in an incorrect way you can contact us. You also have the right to turn in a complaint to a supervisory authority.


Updates to our Privacy Notice:
We may need to update our Privacy Notice. The latest version of the Privacy Notice is always available on our website. We will communicate any material changes to the Privacy Notice, for example the purpose of why we use your personal data, the identity of the Controller or your rights.


BUSINESS RELATIONS

Why do we use your personal data?
We will use your personal data to evaluate potential business partners and manage existing business relations including communication, procurement, contract signing and financial transactions.

We will process your personal data in order to achieve the purpose of the contract.
We will also use personal data to provide business partners with access to H&M group´s systems.
We will use personal data to manage legal requirements for financial trading information.
We will process your personal data in case of legal issues and disputes.


What types of personal data do we process?
We will process following categories of personal data:

  • contact details such as name, e-mail address and telephone number
  • date of birth
  • social security ID
  • user name´s
  • gender
  • bank account
  • nationality
  • work related information, such as company, department and work role
  • photo and images


Who has access to your personal data?
Your personal data that is forwarded to third parties is only used for the purposes mentioned above.
We share your personal data with external advisors, IT service providers and other external service providers.

What is the legal ground to process your personal data?
The processing of your personal data for the following purposes are based on H&M group’s legitimate interest:

  • to manage business relations
  • to provide business partners access to our systems
  • to manage legal requirements for financial trading
  • to manage legal issues and disputes

The processing of your personal data to achieve the purpose of the contract are necessary for fulfillment of contract.

The processing of your personal data for financial trading information is based on legal obligations.


How long do we save your data?
We will keep your data for follow up and to evaluate procurement and business partners, for the length of the agreement and time to preclude legal issues.

For legal disputes we will keep the data during the ongoing dispute and for a period of time after the dispute when the information is still relevant.

We will keep the data for financial trading information for 5 years in accordance to legal requirements.


MEDIA AND COMMUNICATION

Why do we use your personal data?
When we create media content such as articles, interviews, videos and pods for all our channels we will process your personal data if you appear in such content. We also use personal data to prepare, facilitate, follow up on interviews and media coverage.

When we archive media material such as press clips, images and photos, campaigns, press releases, videos and recordings to preserve the company's history your personal data will be processed if you appear in the material.

To manage different types of events, including meetings and press conferences, we will process personal data of the invited persons. Certain events may be recorded and transcribed.

We will use your personal data to send out financial reporting and other company information to recipients based on legitimate interest or if you have signed up to receive such information.

We will use your personal data to manage use of press samples.

If you contact us for information requests we will process your personal data.


What types of personal data do we process?
We will process following categories of personal data:

  • contact details such as name, e-mail address and telephone number
  • date of birth
  • user name
  • gender
  • nationality
  • work related information, such as company, country of employment and work role
  • size information
  • photo and images
  • video footage
  • audio recording

What is the legal ground to process your personal data?
The processing of your personal data for the following purposes are based on H&M group’s legitimate interest:

  • managing content, including produce, administrate, archive and distribute media content
  • manage press conferences and meetings
  • to analyze media coverage, including social media
  • manage press samples
  • to manage requests
  • to manage events

The processing of your personal data for teleconference is based on your consent. If you have signed up to receive company information the processing of your personal data is based on your consent.


How long do we keep your data?
We save your data if needed to fulfil the purpose for which it was collected to pursue our legitimate interests or until there is no longer any legal requirements or right for us to keep the data.
For the processing of personal data for the purposes based on consent we will keep the data untill you withdraw your consent.


Your right to object to processing based on legitimate interest
You have the right to object to the processing of your personal data that is based on H&M's legitimate interest. H&M group will not continue to process the personal data unless we can demonstrate a legitimate ground for the process which overrides your interest and rights or due to legal claims.


Your right to withdraw your consent
You have the right to withdraw your consent from the processing of your personal data at any time. When you do so we might not be able to provide you with the service based on the consent.


ANNUAL GENERAL MEETING

Why do we use your personal data?
We will use your personal data to manage H&M group's Annual General Meeting, including sending out invitations, managing registration of participants record and transcript of the Annual General Meeting. We will also use personal data to manage power of attorneys and corporate registration certificates for attendance to the annual general meeting.


What types of personal data do we process?
We will process following categories of personal data

  • contact details such as name and e-mail address
  • date of birth
  • social security ID
  • company
  • photo and images
  • financial information, such as amount of shares


Who has access to your personal data?
Your personal data that is forwarded to third parties, is only used to provide you with the services mentioned above.

We will share personal data with mail distribution companies for our annual report, e-mail service companies to distribute invitations, with central securities depository to manage shareholders and power of attorneys.
We share your data with production agencies for the production of the annual report.


What is the legal ground to process your personal data?
The processing of personal data to register for the meeting, to record and transcribe the meeting is based on H&M group's legitimate interest.
The processing of personal data to register shareholders' presence at the meeting is based on a legal obligation.


How long do we save your data?
We will keep your data for registration and for attendance to the meeting and list of legal representatives for 39 months.


IT & SECURITY

Why do we use your personal data?
We will process personal data to manage, register and resolve IT and information security incidents. We will also use personal data to handle incidents and accidents.

We will also process your data to investigate a breach or non-compliance with regulations or H&M group's policies and requirements.

We will use your personal data for camera monitoring in our facilities such as stores, offices and warehouses for security reasons and for follow up on incidents and accidents.

In order to be compliant with payment card industry regulations, your personal data will be processed through visitor logs and audit reports for audit reasons.
We will also process your personal data related to your key card and the use of it, including follow ups on incidents and accidents.

In the event of investigation of non-compliance with our policies and in whistleblowing related matters we process personal data.


What type of data do we process?
We will process the following categories:

  • contact information such as name, home address, e-mail address and telephone number
  • date of birth
  • work information such as company name and work role
  • logs such as for key cards
  • employment information such as user ID number
  • IP number
  • video surveillance footage
  • photo
  • other necessary information for investigations


Who has access to your personal data?
Data that is forwarded to third parties is only used to perform the services mentioned above. We will share your personal data with security companies, auditors and legal advisors to handle security issues and administration. We will also share your personal data with video surveillance companies for video footage.


What is the legal ground to process your personal data?
The processing of your personal data is based on H&M group our legitimate interest in order for us to manage incidents and security breaches.


How long do we save your data?
We will keep your data for the time we need to prevent and/or report potential fraud and other offenses.

Video footage will be saved in compliance with local legislation but maximum for 30 days.


SPECIFIC INFORMATION FOR ABOUT.HM.COM

Cookies
A cookie is a small text file that is saved to, and during subsequent visits on about.hm.com retrieved from, your computer. H&M uses cookies to enhance and simplify your visit on about.hm.com. We do not use cookies to store personal information, or to disclose information to third parties.

There are two types of cookies; permanent and temporary (session cookies). Permanent cookies are stored as a file on your computer for some time. Session cookies are stored temporarily in your computer's memory and disappear when you close your browser.

We use persistent cookies to store your language choice. The cookie is called hmgroup-lang.

We also use cookies to keep track of that you have accepted the terms of download an which currency you have selected. These cookies are called hmgroup-gallery-terms and hmgroup-curr are stored on your computer for 7 days.

We use Google Analytics Advertising features for demographics and interest reporting, to better understand our visitors. The report shows age, gender and interests. No personally identifiable information will be kept or shown and we cannot connect the information to specific users.


Third-Party Cookies
We use third-party cookies to collect statistics in aggregate form in analysis tools such as Google Analytics. We also use Google Analytics Advertising Features. The cookies used are both permanent and temporary cookies (session cookies). 

You can easily erase cookies from your computer or mobile device using your browser. For instructions on how to handle and delete cookies please look under "Help" in your browser. Using your browser can choose to disable cookies, or to receive a notification each time a new cookie is sent to your computer.

 

Read more about how you can opt out here: https://tools.google.com/dlpage/gaoptout/.

We also use Hotjar cookies to collect information to better understand our visitors. Neither Hotjar or the H&M group sell the collected data or information to other parties. The collected information will be anonymized wherever possible, all information collected is non-personal information and not traceable.

Hotjar can provide information to third parties if they are required by law, or if third parties process the information on behalf of Hotjar.

Read more about how you can opt out cookies from Hotjar here: https://www.hotjar.com/opt-out

Please note that if you choose to disable cookies, you will not be able to take advantage of all features on the site.


Links
about.hm.com may contain links to other websites beyond our control. We cannot be held liable for breaches of integrity or content on these websites - we simply provide the links to make it easier for people visiting our site to find more information within specific areas.


Copyright
The content on this site are copyrighted and belong to H & M Hennes & Mauritz AB.


Colours
We cannot guarantee that the shown on the website exactly reproduce the of the actual garments. This partly depends on the reproduction on your computer.

 

H & M Hennes & Mauritz AB
Mäster Samuelsgatan 46A
106 38 Stockholm
Sweden

Telephone: +46 (0)8 796 55 00
Fax: +46 (0)8 24 80 78
E-mail: info@hm.com

Companies register: Bolagsverket/Swedish Companies Registration Office
Company registration number: 556042-7220
Authorised representative: Karl-Johan Persson
VAT registration number: VAT NO. SE556042722001