Privacy Notice/Your Privacy Rights

Last Updated: 18th May 2018

This Privacy Notice applies to information that each of Michael Kors (UK) Limited, Michael Kors (USA), Inc., and their parents, subsidiaries and affiliate entities worldwide (individually and collectively referred to herein as “Michael Kors”, “we,” “us” or “our”) collects from and about you:

(i) on or in connection with your visits to one of our stores or otherwise offline in the UK;

(ii) through purchases you make from our catalog and have delivered to a UK address; or

(iii) in connection with your visits to michaelkors.co.uk (or any subdomain thereof), or one of our other websites, applications or other services from which you are accessing this Privacy Notice (each referred to herein as a “Site,” and collectively, the “Sites”). (Note: Information collected through our Careers Page is subject to a separate privacy notice, located here.)

This Privacy Notice describes how and what information we collect, how we use it and to whom and under what circumstances we may disclose it. The personal information we collect under this Privacy Notice is controlled by Michael Kors (UK) Limited, 33 Kingsway, London, WC2B 6UF, United Kingdom. The “personal information” we collect and process under this Privacy Notice means any information from which you can be identified and includes your name, postal address, zip or postal code, email address, telephone number, date of birth, payment information, demographic information, transaction details, IP address, site usage information and other information we may collect, depending on the circumstances.

Below is a Table of Contents for this Privacy Notice. Please select to skip directly to the different sections of this Privacy Notice to understand our practices and your rights with respect to your information:

HOW WE COLLECT INFORMATION

Information You Provide to Us

We (and our service providers) collect personal information from and when you:

  • purchase products or services from us, whether on a Site, through a catalog or in one of our stores, including after sales care services;
  • create an account with us, or otherwise sign up for a service or feature;
  • opt in to receive marketing from us, including through one of our third party partners acting on our behalf;
  • complete a survey;
  • participate in a sweepstake, contest or other promotion run or sponsored by Michael Kors;
  • contact our customer services team;
  • communicate with us via third-party social media sites;
  • submit a rating or review via our site; or
  • contact us, or otherwise provide information to us.

In some cases, you may provide personal information to us about another person, such as when you purchase a gift for someone and request that we ship it to that person, or when you share Site content with another person. In such cases, you confirm that you have the authorization of such person to provide us with such information.

When you are a creating an account for the first time on michaelkors.co.uk with an email address that you have previously provided to us in another circumstance (e.g., in one of our stores, when signing up for our emails, or by entering one of our sweepstakes or other promotions), we may recognize that email address and, once you have completed the online account set-up process, you may be able to see some of your personal information already included in your new online account. This is happening because we have recognized your email address and, for your convenience, have added your information to your online account. You can always change this information by signing into your online account.

Third-Party Sources & Publicly Available Sources

We also work closely with third parties (such as business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, address update providers, data append providers, co-promotion partners and credit reference agencies), and may lawfully receive demographic and other personal information about you from those third parties, which we may combine with the information you have provided to us. For example, we may lawfully collect information about you from content on social media platforms (e.g., when you choose to log in to our Site through a third-party social media platform (e.g., Facebook), subject to your actions and settings on those platforms). We do this to better tailor our products, services, Sites and communications, and to ensure we are providing our customers and visitors with the best shopping and browsing experiences. We process all data we obtain from such other sources in accordance with this Privacy Notice.

Note that content and information that you submit on or through Facebook, Twitter, Instagram, Tumblr and other third-party platforms may appear on our Sites through feeds or interfaces that we have with those platforms. We are not responsible for the information, content and/or privacy practices of any such third-party platforms or content pulled through them.

Site Usage Information & Other Information Collected Automatically

As part of the standard operation of the Sites, certain information is collected automatically about your visits to the Sites or your device accessing a Site. Our servers may automatically gather some of this “Site usage information” (such as your IP address, and information about your browsers, your device, your location, and your shopping, browsing and other usage activities). Additionally, if we have your consent, then we (and our service providers) may use cookies and other similar technologies to collect and track such information (see our Cookies/Ad Choices Policy for more details).

HOW WE USE PERSONAL INFORMATION

We use the personal information we collect from and about you for a variety of purposes and based on one or more legal justifications, as set out below:

PURPOSE

WHAT WE USE

JUSTIFICATION

To improve your experience in our stores and on the Sites including to track your activities on the Sites; to track clicks, purchases and conversion; to recognize your computer or device so that you are able to save your preferences and stay logged in to the Site without having to re-enter your online account credentials; to preserve the contents of your shopping cart and remind you if you have left items in it, or to remind you if you left the Sites without adding items to your cart; and to otherwise enhance, monitor and analyze Site usage.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, preferences, site usage information

Our legitimate business interests in providing the best shopping and browsing experiences to our customers and visitors, and to continuously improve and protect our company, property and customers against fraud (referred to as “our legitimate interest”)

To process and fulfill your requests for products and services, and to keep you informed about your requests

Name, email address, postal address (including postcode), telephone number, payment information

Performance of our contract obligations; our legitimate interest

To better understand you (including through profiling activities), in order to provide relevant, more tailored offers and messaging on and in connection with our Sites, services and products, and personalize your experience on the Sites as permitted by relevant law

Name, email address, postal address (including postcode), telephone number, date of birth, order history, IP address, preferences, site usage information

Our legitimate interest; consent

To contact you (via postal mail, email, and/or any other method you have elected) with promotional materials about Michael Kors and select partners from time to time

Name, email address, postal address (including postcode), telephone number, preferences, site usage information

Our legitimate interest; consent

To contact you when necessary or appropriate in connection with your relationship with us (such as via email in regards to your rating or review submissions)

Name, email address, postal address (including postcode), telephone number, preferences, site usage information

Performance of our contract obligations; our legitimate interest

For market research and to review and improve our advertising and emails, merchandise selections, content, services, customer service, business planning, online and offline operations and overall shopping experience

Name, email address, postal address (including postcode), telephone number, date of birth, order history, IP address, site usage information

Performance of our contract obligations; our legitimate interest

To enforce our terms and conditions, and to protect the security or integrity of the Sites, our customers and our business in general (such as protecting against illegal or fraudulent activity, or misuse including cyber attacks)

Name, email address, postal address (including postcode), telephone number, date of birth, payment information, order history, IP address, site usage information

Our legitimate interest

To set up and manage your online account (including, for example, to send password reminders or notifications to changes to your account details) and to process your communication and privacy preferences

Name, email address, postal address (including postcode), telephone number, date of birth, payment information, order history, preferences, site usage information

Performance of our contract obligations; our legitimate interest

To process product returns, replacements, repairs and alterations; to resolve product issues (e.g., sending replacement products); and other customer service related issues

Name, email address, postal address (including postcode), telephone number, payment information, order history

Performance of our contract obligations; our legitimate interest

To comply with legal requirements to which Michael Kors may be subject (e.g., tax or financial reporting requirements and court orders)

Name, email address, postal address (including postcode), telephone number, date of birth, payment information

Legal obligation

We use CCTV in our stores. Please ask in store if you would like more details about how we use CCTV recordings.

WITH WHOM DO WE SHARE PERSONAL INFORMATION

We may disclose personal information we process for the following purposes and in the following ways, to the extent permitted by law and depending on such purpose(s) or way(s):

RECIPIENT/PURPOSE

WHAT WE SHARE

JUSTIFICATION

To Michael Kors (USA), Inc., 11 West 42nd St., New York, New York, 10036, USA and Michael Kors (Switzerland) GmbH, for all the same purposes described in the How We Use Information section above.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Performance of our contract obligations, our legitimate interest and/or consent depending on the purpose as described in the How We Use Information section above

To our service providers and suppliers who act as data processors for us and process such information on our behalf, for all the same purposes described in the How We Use Information section above.*

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Performance of our contract obligations, our legitimate interest and/or consent depending on the purpose as described in the How We Use Information section above

To provide information to and as required by local law enforcement agencies, other local government authorities, or otherwise required by law or to protect the rights and safety of our property, company and customers.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information

Our legitimate interest, legal obligation

On a case by case basis, in the event that Michael Kors or substantially all of its assets are acquired by one or more third parties as a result of an acquisition, merger, sale, consolidation, bankruptcy, liquidation or other similar corporate reorganization, where your information may be one of the transferred assets.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Our legitimate interest, legal obligation

If you have consented to our sharing of your personal information with third parties to use for their own marketing purposes, as permitted by law.

Name, email address, postal address (including postcode), telephone number, date of birth, demographic information, order history, IP address, payment information, preferences, site usage information

Consent

*These third-party partners act on our behalf and help us to operate the Sites and provide functionality, content, communications and other services, including the provision of the following services to and for us: website hosting; database hosting; address list hosting and management; email deployment and management; analytics; content and product distribution; payment processing; fulfillment; inventory management; security; and fraud detection and prevention. Current service providers include Aptos, Cheetah Digital, Spark::red, Adobe, Metapack, Epsilon/Abacus, CallCredit, Sixpay, CyberSource and arvato. If you would like to know more information about the third-party companies currently charged with such data processing, please contact us with your request at EUprivacy@michaelkors.com.

We may also use third party web analytics services, currently Google Analytics and Adobe services, to help us track and analyze the use of our Site and to measure the effectiveness of our advertising, Site content and communications. These service providers are acting on our behalf and use tools such as cookies, tags and web beacons, to help us gain this understanding. (See our Cookies/Ad Choices Policy for more details on cookies, web beacons and other tags.)

If you choose to contribute to a social, community or other publicly available area or feature of our Site, the information you submit may be made available to the general public depending on your settings (which is why we recommend that you do not submit or post any personal information to such forums, such as your full name, home address, phone number and/or other information that would enable others to contact or locate you).

YOUR CHOICES/YOUR PRIVACY RIGHTS

You have various rights in connection with our processing of your personal information, each of which is explained below. If you wish to exercise one or more of the above rights, please contact us with your request at EUDataSubjectRequests@michaelkors.com, and include your name, email and postal address, as well as your specific request and any other information we may need in order to provide or otherwise process your request.

  • Access. You have the right to request a copy of the personal information we are processing about you, which we will provide back to you in electronic form. For your own privacy and security, in our discretion we may require you to prove your identity before providing the requested information.
  • Rectification. You have the right to have incomplete or inaccurate personal information that we process about you rectified. Note that you can always make certain adjustments to certain personal information directly through your online account.
  • Deletion. You have the right to request that we delete personal information that we process about you, except we are not obligated to do so if we need to retain such data in order to comply with a legal obligation or to establish, exercise or defend legal claims.
  • Restriction. You have the right to restrict our processing of your personal information where you believe such data to be inaccurate, our processing is unlawful or that we no longer need to process such data for a particular purpose, but where we are not able to delete the data due to a legal or other obligation or because you do not wish for us to delete it. In such case, we would mark stored personal information with the aim of limiting particular processing for particular purposes in accordance with your request, or otherwise restrict its processing.
  • Portability. You have the right to obtain personal information we hold about you, in a structured, electronic format, and to transmit such data to another data controller, where this is (a) personal information which you have provided to us, and (b) if we are processing that data on the basis of your consent (such as for direct marketing communications) or to perform a contract with you (such as to manage your online account).
  • Objection. Where the legal justification for our processing of your personal information is our legitimate interest, you have the right to object to such processing on grounds relating to your particular situation. We will abide by your request unless we have compelling legitimate grounds for the processing which override your interests and rights, or if we need to continue to process the data for the establishment, exercise or defence of a legal claim.
  • Withdrawing Consent. If you have consented to our processing of your personal information, you have the right to withdraw your consent at any time, free of charge. If you would like to withdraw consent, including if you would like to opt out of receiving marketing correspondence from us, or if you wish us to stop sharing your personal information with third party marketers, please contact us at europe.customerservice@michaelkors.com or for marketing follow the unsubscribe instructions located in the email (as relevant). (Note that we never share your payment information with other marketers.)
    • Please understand that if you opt out of receiving promotional correspondence from us, we may still contact you in connection with your online account, relationship, activities, transactions and communications with us. Additionally, if you do request that we stop sharing your personal information with third parties for their direct marketing purposes, it is also prudent for you to opt out from or contact that third party directly.
  • Make a Complaint. You have the right to lodge a complaint with the local data protection authority if you believe that we have not complied with applicable data protection laws.

    If you are based in, or the issue relates to, the UK, the UK Authority can be contacted as follows:

                The Information Commissioner’s Office
                Telephone: +44 0303 123 1113 / +44 1625 545 700
                Email: casework@ico.org.uk
                Website: www.ico.org.uk
                Web-form: www.ico.org.uk/concerns
                Address: Water Lane, Wycliffe House, Wilmslow, Cheshire, SK9 5AF

    If you are based or the issue you would like to complain about took place elsewhere in the European Economic Area (EEA), please click here for a list of local data protection authorities in the countries within the EEA in which we operate.

Note that the rights outlined above do not extend to non-personal information.

HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION

Your personal information is stored by us and/or our service providers for as long as necessary to fulfill the specific purposes described herein and to the extent permitted by applicable laws. When we no longer have a legitimate business purpose for your personal information, or when you request that we delete your personal information (except where we need to retain it in order to comply with a legal obligation or to establish, exercise or defend legal claims), we will remove such information from our systems and records, which includes taking steps to anonymise it so that you can no longer be identified from it.

TRANSFER AND PROCESSING OF INFORMATION IN THE U.S. AND OTHER COUNTRIES

Your personal and other information may be transferred to and stored and processed in the United States, Switzerland and in other countries by our affiliates and our service providers pursuant to the laws of the United States or such other jurisdictions. We will ensure that such data is processed and transferred in accordance with this Privacy Notice and applicable laws.

Such countries may provide lesser privacy protections than the EEA countries, and you acknowledge that your information may thus be subject to U.S. and foreign laws and accessible to U.S. and foreign governments, courts, law enforcement and regulatory agencies. Where your personal information is transferred to our affiliates in Switzerland, the European Commission has decided that Switzerland provides adequate protection to personal information. Michael Kors is taking additional measures to protect personal information that is transferred from the EU to other countries through contracts with importing entities incorporating standard clauses approved by the European Commission (available here: https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/model-contracts-transfer-personal-data-third-countries_en).

SECURITY

We have implemented technical and organizational security measures in an effort to safeguard the personal information in our custody and control. Such measures we have implemented include, for example, limiting access to personal information only to employees and authorized service providers who need to know such information for the purposes described in this Privacy Notice, as well as other administrative, technical and physical safeguards. Additionally, our service providers are not authorized to use or disclose your personal information for any purpose other than providing the services to us or on our behalf, or as otherwise may be required by applicable law. While we endeavor to always protect our systems, Sites, operations and information against unauthorized access, use, modification and disclosure, due to the inherent nature of the Internet as an open global communications vehicle and other risk factors, we cannot guarantee that any information, during transmission or while stored on our systems, will be absolutely safe from intrusion by others, such as hackers.

To provide you with increased security, certain personal information stored in your online account is only accessible via your username and password. You are responsible for maintaining the confidentiality of your online account credentials, and we strongly recommend that you do not disclose your online account username or password to anyone. We will never ask you for your password in any unsolicited communication. Please notify us immediately (see Contact Us section below) of any unauthorized use of your online account credentials or any other suspected breach of security.

CHILDREN'S PRIVACY

The Sites are not directed to children under the age of sixteen (16), and we do not knowingly collect any personal information from children under sixteen on any Site. If you are under sixteen, do not provide your personal information on, through or to any Site. Individuals who are below the age of eighteen (18) (or the age of majority in the applicable jurisdiction) should not use the Sites or our Services without authorization from a parent or legal guardian.

THIRD-PARTY WEBSITES

The Sites may contain links (which may take the form of hyperlinks, widgets, clickable logos, plug-ins, images or banners) to websites and services operated by entities other than Michael Kors. This Privacy Notice does not apply to such other websites or services, and we recommend that you review their posted privacy policies so that you understand the relevant information collection, use and disclosure practices of such other websites and services.

PHISHING, SPOOFING & OTHER SCHEMES

It has become increasingly common for hackers, cyber-criminals and other unauthorized individuals to send emails and other communications to consumers purporting to represent a legitimate company, such as a bank or an online retailer, and requesting through those communications that the consumer provide personal, often sensitive, information. Sometimes, the domain name of the sender’s email address, or the domain name of the website requesting such information, may appear to be the domain name of a legitimate, trusted company. If you receive a request to provide information (including your online account password, or any payment information) via email or to a website or individual that does not seem to be affiliated with the Sites or Michael Kors, or that otherwise seems suspicious to you, please do not respond or disclose your information. Michael Kors will never send you an email requesting that you verify any credit card information, financial information or other personal information. Please immediately report any such communication or request to us at europe.customerservice@michaelkors.com.

Additionally, Michael Kors works with customs authorities, law enforcement and legal representatives globally in an effort to prevent the sale of counterfeit Michael Kors products, both online and offline. To avoid the risk of purchasing counterfeit products, it is best to only buy directly from official Michael Kors e-commerce websites, official Michael Kors retail stores, and authorized department stores, specialty retailers and e-tailers that you know to be reputable. To report suspected counterfeit Michael Kors merchandise, please email brandprotection@michaelkors.com.

CHANGES TO THIS PRIVACY NOTICE

We may change this Privacy Notice from time to time and the amended notice will be posted to the Sites. Under certain circumstances (for example, in connection with certain material adverse changes to this Privacy Notice), we may also elect to notify you through additional means, such as posting a notice on the home page(s) of the Sites or contacting you via email.

CONTACT US

If you have any questions about this Privacy Notice and/or about the privacy policies and practices of our service providers, please contact us at EUprivacy@michaelkors.com, or at: Michael Kors, 33 Kingsway, London, WC2B 6UF, Attn: Legal department.