Privacy Policy for KRONE Vinduer A/S

All companies within the DOVISTA Group respect and protect your privacy. This DOVISTA privacy policy (‘privacy policy’) is intended to help you understand why we collect personal data about you, what types of personal data we collect, how we collect it, how long we retain it, who we share it with, and your rights. We also explain how we safeguard your information.

This DOVISTA Privacy Policy complies with the EU General Data Protection Regulation 2016/679 (‘GDPR’) and the Data Protection Act.
The data controller responsible for your personal data is:

KRONE VINDUER A/S

Ålborgvej 576

9760 Vrå

CVR no.: 28979967

Hereinafter referred to as ‘KRONE’.

Our parent company is DOVISTA A/S, which is registered in Denmark under CVR no. 21147583 with its registered head office at Bygholm Søpark 21D, 8700 Horsens, Denmark.

Why we process personal data and the legal basis for collecting information

The main reason we collect, use and store your information is to enable us to provide our services to you. “Service”, “our service” and similar terms refer to conducting business with you or your organisation and assisting you with enquiries, sales processes and complaints.

We also process information about your use of the services for business development purposes, to inform you about our business operations, products and services through marketing, and to improve our services based on any feedback you provide us with. We may also process your personal data for contractual and recruitment purposes and to comply with legal obligations.

We process personal data on various legal grounds as set out below.

Performance of a contract, including a purchase – GDPR, Article 6(1)(b):

  • When we process personal data in relation to a contract, our legal basis is ‘performance of a contract’, including a purchase.
  • When we send out a newsletter about our products, we do so on the basis of your consent. Where the legal basis for processing is consent, you have the right to withdraw your consent at any time.
  • If we share your personal data with law enforcement or other public authorities, we do so because we are legally obliged to do so.
  • Act as your first point of contact.
  • Fulfil the information obligations set out in Articles 13 and 14 of the GDPR.
  • Exercise your rights under Articles 15–22 of the GDPR.
  • Handle notifications regarding privacy breaches and complaints concerning data security.

Consent – GDPR, Article 6(1)(a):

Legal obligation – GDPR, Article 6(1)(c):

Legitimate interest – GDPR, Article 6(1)(f):

  • We have a legitimate business interest in processing your data, for example when we assist you with enquiries.

Special categories – GDPR, Article 9(2)(a) and GDPR, Article 9(2)(f):

  • When we process special categories of data, we do so to comply with legal requirements relating to compliance matters.
  • Until you unsubscribe from our newsletter, which you can do at any time.
  • We retain photographs and customer testimonials for as long as necessary and as agreed.
  • To comply with, for example, anti-corruption regulations, we retain information in accordance with the legislation we are obliged to comply with.

  • There is an adequate level of protection in the country in question, as determined by the European Commission, or

The types of personal data we process

The following are the main types of personal data collected by KRONE, along with the main purpose and the legal basis for collecting the personal data:

Activity

Types of personal data we collect

(for illustrative purposes)

Purpose

Legal basis

General business operations

Name, contact details and other information necessary to conduct business with you or your organisation.

As part of KRONE’s normal business operations, we collect personal data about individuals, customers, suppliers (including third-party service providers) and other stakeholders.

GDPR – Article 6(1)(b)

GDPR – Article 6(1)(f)

Assisting with enquiries




Name, email address, telephone numbers, conversations, other contact details, photographs, floor plans of your house, where you provide such information to KRONE.

You may choose to provide personal data, such as contact details, when you contact us by telephone, email, post or via our available digital platforms.

This personal data enables us to respond to enquiries regarding, for example, KRONE products; to arrange an appointment and provide a quote for the installation of KRONE products; to arrange servicing of a window; or to process claims covered by the KRONE warranty.

The information may be disclosed to DOVISTA A/S or other DOVISTA A/S sales companies within the group, relevant independent tradespeople or dealers in order to enable us to assist our customers with their enquiries, provide services or provide a quotation.

GDPR – Article 6(1)(b)

GDPR – Article 6(1)(f)

Sales and order fulfilment

Name, contact details, credit information and credit checks, etc.

We may collect personal data about customers and potential customers in order to do business with you or your organisation.

We may pass on this information to dealers, independent tradespeople or logistics partners in order to process a customer’s order, including arranging delivery of KRONE products to the customer or assisting with enquiries, such as arranging consultations between you and our product advisers. We also share your information with third parties for the purpose of credit checks.

GDPR – Article 6(1)(b)

GDPR – Article 6(1)(f)

Complaints or paid services

Name, contact details, etc.

To facilitate the servicing of KRONE products in accordance with the KRONE warranty or through paid services, i.e. we handle enquiries via telephone, email and site visits. In this context, we may share your personal data with KRONE partners to assist you with a service.

GDPR – Article 6(1)(c)

GDPR – Article 6(1)(b)

GDPR – Article 6(1)(f)

Marketing

Contact details, such as name, address, email, telephone number, purchase history, etc.

Please note that this list is not exhaustive, as we may process any personal data collected in connection with your interactions with our parent company, DOVISTA A/S, our website, products and services.

Based on your consent or our legitimate interests, where relevant, we process your personal data for the purpose of informing you about KRONE’s business operations, products and services.

For the above purposes, we produce marketing material in the form of a newsletter, provided you have subscribed to it.


If you do not wish to receive further information, you can unsubscribe from our marketing communications at any time by using the link at the bottom of the email. You can also contact us by email or post to unsubscribe.

For some marketing activities, we act as a joint data controller with other DOVISTA companies and have entered into joint data processing agreements that allocate roles and responsibilities amongst the DOVISTA companies.

GDPR – Article 6(1)(a)

GDPR – Article 6(1)(f)

Customer surveys

Customers as part of surveys

In order to improve the products and services we offer, we may collect personal data from customers in connection with surveys.

We will contact you with a survey and process personal data as part of our legitimate interest.

GDPR – Article 6(1)(f)

Compliance, including anti-corruption, whistleblower hotline and sanctions screening

All types of personal data.

We may collect personal data to comply with legislation, a court or regulatory authority decision and/or to disclose information to relevant public authorities as required or permitted by law.



GDPR – Article 6(1)(c)

GDPR – Article 6(1)(f)

GDPR – Article 9(2)(a)

GDPR – Article 9(2)(f)

How we collect your personal data

Directly from you

In most cases, personal data is collected directly from you or generated as part of your use of our services, products and channels. We collect the personal data you provide to us when you request products, services or information from us, register with us, participate in public forums, use a chatbot or take part in other activities on our digital platforms and apps, respond to customer surveys or otherwise interact with us. We collect information via various technologies, such as cookies. For information on cookies, please refer to our cookie policy notice.

From our business partners

In some cases, we may collect your personal data from our business partners when they require our assistance to provide you with the best possible service.

From your public website

In some cases, we collect your personal data from your company’s websites when we wish to offer you our services.

Links to other websites

This website contains links to other websites (such as Facebook and Instagram), to which KRONE’s data protection notice does not apply. Please note that we do not endorse other websites or their content. We encourage you to read the privacy policies on each individual website you visit.

How long do we retain your personal data?

We only retain your personal data for as long as is necessary for the purposes described in this Privacy Policy. This means that retention periods will vary depending on the type of data and the reason we hold it.

Examples of retention periods:

Who do we share your personal data with?

Our company is part of the DOVISTA Group, which operates globally. We share your personal data within the DOVISTA Group, but only if it is necessary to fulfil the purpose for which we process your personal data. All entities within the DOVISTA Group have entered into a joint data processing agreement and/or acceded to an agreement whereby all follow the same procedures when processing personal data, ensuring that the same level of security is maintained throughout the Group and allocating roles and responsibilities amongst DOVISTA companies. If two or more companies act as joint data controllers, each of the joint data controllers is obliged to independently:

We may also share your personal data with selected third parties, including:

  • Business partners, suppliers and subcontractors with whom we collaborate to offer you the best possible service during the support and sales process, including, for example, logistics providers and outsourced customer service.
  • Technology providers who help us improve and optimise our platforms, as well as companies that provide website support and hosting for us.
  • Advertisers and advertising networks that use data to select and display relevant adverts to you and others, provided you have given your consent.
  • Social networking sites such as LinkedIn, Instagram and Google, where required, for data processing for marketing purposes and based on your consent.
  • With other parties to ensure the security of our customers, to protect our rights and property, to comply with legal processes, or in other cases where we believe in good faith that sharing is required by law.

When we work with external service providers, we enter into a data processing agreement where relevant. These service providers are prohibited from using your personal data for purposes other than those we have requested or as required by law.

Transfer to third countries

In some cases, we may also transfer personal data to companies in so-called ‘third countries’, which are countries outside the European Economic Area. If we do so, we ensure that the data is protected and only transfer it if one of the following conditions applies:

    • we use standard contractual clauses (EU model clauses) approved by the European Commission, as well as additional supplementary measures to regulate the data transfer.
 
Data security

The security, integrity and confidentiality of your personal data are important to us. We have therefore implemented technical, administrative and physical security measures designed to protect your personal data against unauthorised access, disclosure and alteration. From time to time, we review our security procedures to take account of relevant new technologies and methods. Please be aware that, despite our very best efforts, no security measures are perfect or impenetrable.

Your data protection rights

Under the GDPR, as a data subject, you have the following rights in relation to the personal data we hold about you:

Your rights

Legal basis

Further details

Access to your data

GDPR, Article 15

You have the right to request information as to whether KRONE is processing personal data relating to you, and if so, you have the right to request a copy of the personal data we have processed.

Request for rectification

GDPR, Article 16

You have the right at any time to request the rectification of any inaccurate or incomplete personal data we may be processing about you.

Request erasure

GDPR, Article 17

You have the right to request the erasure of your personal data, depending on the processing activity and in certain circumstances, before we would normally be obliged to cease processing.

Request restriction of processing

GDPR, Article 18

You have the right to request restriction of processing, which means that you may request that KRONE restrict the use of your personal data in certain circumstances.

Data portability

GDPR, Article 20

Under certain conditions, you have the right to receive the personal data you have provided to us in a machine-readable format.

Right to object

GDPR, Article 21

If you are not satisfied with how we process personal data at KRONE, you can send your objections toprivacy@dovista.com . If a complaint is lodged, the complainant’s name and contact details must be provided to KRONE.

If you have any questions regarding the specific personal data we process or hold about you, or if you wish to exercise your rights, please contactprivacy@dovista.com .

We will respond to your request to exercise your rights within one month, but we reserve the right to extend this period by two months. If we extend the response time, we will notify you within one month of your request.

If you feel that we have not dealt with your complaint satisfactorily, you may lodge a complaint with the Danish Data Protection Agency, Carl Jacobsens Vej 35, 2500 Valby, tel. 33 19 32 00, dt@datatilsynet.dk.

Changes to this privacy notice from KRONE

From time to time, we may amend this privacy notice to reflect the latest technologies, industry practices, legal requirements or for other reasons. We will always publish the latest version on our website. We therefore recommend that you review the privacy notice regularly.


This privacy notice was last updated in December 2023.