Privacy policy

1. General Information

At HERZ Boutique, we respect the privacy of our customers and users and are committed to protecting their personal data in accordance with applicable data protection regulations.

This Privacy Policy explains what personal data we collect, for what purposes we use it, the legal basis for processing it, how long we keep it, with whom we may share it, and what rights you have as a user.

2. Data Controller

The data controller responsible for the personal data collected through this website is:

Owner: KIM-YVA HERZ
Trade name: HERZ Boutique
NIF/CIF: Y0070572E
Registered address: CAMINO LAS CABRAS 18, 38400 PUERTO DE LA CRUZ, TENERIFE, SPAIN
Contact email: herz.santelmo@gmail.com
Website: HERZBOUTIQUE.COM

3. Personal Data We May Collect

We may collect and process the following personal data:

  • Full name.

  • Email address.

  • Phone number.

  • Billing address.

  • Shipping address.

  • Data related to orders, purchases, returns, exchanges and refunds.

  • Information necessary to manage payments, invoicing and customer service.

  • Browsing data, IP address, device type, browser, language, approximate location and behaviour within the website.

  • Information voluntarily provided through forms, emails, messages or communications with customer service.

  • Marketing preferences, when the user has agreed to receive commercial communications.

HERZ Boutique does not store full bank card details. Payments are processed through secure payment gateways managed by third parties.

4. Purposes of Processing

We process your personal data for the following purposes:

4.1. Order Management

We use your data to process purchases, confirm orders, prepare shipments, manage deliveries, issue invoices, process exchanges, returns or refunds, and resolve issues related to your purchase.

4.2. Customer Service

We may process your data to respond to enquiries, requests, complaints, product questions, shipping issues or any communication related to our services.

4.3. Payment and Invoicing Management

We process the information necessary to manage payments, verify transactions, issue invoices and comply with our tax and accounting obligations.

4.4. Commercial Communications

If you give us your consent, we may send you commercial communications, promotions, discounts, product launches or information related to HERZ Boutique.

We may also send you commercial communications when there is a prior commercial relationship and such communications are related to products or services similar to those you have purchased.

You may unsubscribe at any time by following the instructions included in each communication or by writing to:

herz.santelmo@gmail.com

4.5. Website Improvement and User Experience

We may use browsing data to analyse the operation of the website, improve the user experience, detect errors, optimise the online store, measure campaign performance and improve our products and services.

4.6. Advertising and Measurement

We may use analytics, measurement and advertising tools to understand user behaviour, measure ad performance and display personalised content or advertising, always in accordance with applicable regulations and, where necessary, with the user’s consent.

4.7. Security and Fraud Prevention

We may process certain data to protect the online store, detect suspicious transactions, prevent fraud, avoid unauthorised access and ensure the security of the website and our operations.

4.8. Compliance with Legal Obligations

We may process and retain data when necessary to comply with legal, tax, accounting, administrative, consumer protection or any other obligations required by applicable regulations.

5. Legal Basis for Processing

The processing of your personal data is based on the following legal grounds:

  • Performance of a contract: when we use your data to manage a purchase, prepare a shipment, process a return, manage a payment or provide customer support related to an order.

  • Consent: when you subscribe to commercial communications, accept non-essential cookies or voluntarily provide us with data for a specific purpose.

  • Legal obligation: when we must retain or disclose information for tax, accounting, administrative, legal or consumer protection reasons.

  • Legitimate interest: when we process data to improve our services, prevent fraud, ensure website security, respond to enquiries related to our products or manage communications with existing customers, always respecting the user’s rights.

6. Data Retention

We will keep your personal data only for as long as necessary to fulfil the purpose for which it was collected.

In general:

  • Data related to orders will be kept for as long as necessary to manage the purchase, shipment, return, warranty, after-sales service and any possible legal responsibilities.

  • Tax and accounting data will be kept for the periods required by applicable regulations.

  • Data used for commercial communications will be kept until you withdraw your consent or request to unsubscribe.

  • Data related to enquiries or customer service will be kept for as long as necessary to manage the request and any possible related responsibilities.

  • Data obtained through cookies will be kept in accordance with our Cookie Policy.

When the data is no longer necessary, it will be securely deleted, blocked or anonymised, unless there is a legal obligation to retain it.

7. Recipients of the Data

In order to manage our online store and provide our services, your personal data may be shared with third-party providers necessary for the operation of the business, including:

  • E-commerce platform.

  • Payment gateways.

  • Shipping and logistics companies.

  • Web hosting and technology service providers.

  • Email marketing and commercial communication tools, if you have agreed to receive them.

  • Web analytics, measurement and advertising tools, where applicable.

  • Customer service providers.

  • Tax, accounting or legal advisors.

  • Banks and financial institutions, when necessary to manage payments or refunds.

  • Public authorities, official bodies, courts or tribunals when there is a legal obligation.

These third parties will only have access to the data necessary to provide their services and must process it in accordance with applicable data protection regulations.

8. International Data Transfers

Some technology providers used by HERZ Boutique may be located outside the European Economic Area or may process data from third countries.

When this occurs, we will endeavour to ensure that such transfers are carried out with appropriate safeguards in accordance with applicable regulations, such as adequacy decisions, standard contractual clauses or other legally valid mechanisms.

9. User Rights

As a user, you may exercise the following rights in relation to your personal data:

  • Right of access: to know what personal data we process about you.

  • Right of rectification: to request the correction of inaccurate or incomplete data.

  • Right of erasure: to request the deletion of your data where applicable.

  • Right to object: to object to the processing of your data in certain cases.

  • Right to restriction of processing: to request that we limit the use of your data in certain circumstances.

  • Right to data portability: to receive your data in a structured format and transmit it to another controller where applicable.

  • Right to withdraw consent: to withdraw at any time the consent given for processing based on that consent.

  • Right not to be subject to automated decisions: to request not to be subject to decisions based solely on automated processing when they produce legal effects or significantly affect you in a similar way.

To exercise your rights, you can write to us at:

herz.santelmo@gmail.com

You must clearly indicate which right you wish to exercise and provide the information necessary to verify your identity if required.

You also have the right to lodge a complaint with the Spanish Data Protection Agency if you believe that the processing of your personal data does not comply with applicable regulations.

10. Commercial Communications

HERZ Boutique may send you commercial communications only where there is a legal basis for doing so, such as your consent or a prior commercial relationship permitted by applicable regulations.

Each commercial communication will include the option to unsubscribe or stop receiving such messages.

You can also request to unsubscribe directly by writing to:

herz.santelmo@gmail.com

11. Cookies and Similar Technologies

This website may use cookies and similar technologies to ensure its operation, analyse browsing, personalise the user experience, measure advertising campaigns and, where applicable, display personalised advertising.

Cookies that are necessary for the operation of the website may be used without prior consent when they are essential to provide the requested service.

Analytics, advertising, personalisation or any other non-essential cookies will require the user’s prior consent where required by applicable regulations.

For more information about which cookies we use, for what purpose, for how long and how you can configure or reject them, please see our Cookie Policy.

12. Data Security

HERZ Boutique applies reasonable technical and organisational measures to protect personal data against loss, misuse, unauthorised access, disclosure, alteration or destruction.

However, no system for transmitting or storing information over the Internet can guarantee absolute security.

13. Minors

This website is not intended for children under the age of 14.

We do not knowingly collect personal data from children under the age of 14. If we detect that we have collected personal data from a minor without the corresponding authorisation, we will delete it as soon as possible.

14. Accuracy of Data

The user guarantees that the personal data provided is truthful, complete, accurate and up to date.

The user will be responsible for any damage, loss or issue caused by providing incorrect, false, incomplete or outdated data.

15. Automated Decisions

HERZ Boutique does not make decisions based solely on automated processing that produce legal effects concerning the user or similarly significantly affect them.

However, some external payment, security, fraud prevention, analytics or advertising tools may use automated processes in accordance with their own policies and applicable regulations.

16. Changes to the Privacy Policy

HERZ Boutique reserves the right to modify this Privacy Policy to adapt it to legal, technical, commercial or website operation changes.

The current version will always be the one published on this page.

17. Contact

For any questions related to this Privacy Policy or the processing of your personal data, you can contact us at:

herz.santelmo@gmail.com

18. Last Updated

This Privacy Policy was last updated on 01/06/2026.