PRIVACY NOTICE

Data privacy is of high importance for H&M and we want to be open and transparent with our processing of your personal data.

We therefore have a policy setting out how your personal data will be processed and protected.

Who is the controller of your personal data?
The Thai company, HThai (Thailand) Co., Ltd (“H&M”), is the controller of the personal data you submit to us and responsible for your personal data under applicable data protection law.

HThai (Thailand) Co., Ltd
4, 4/1-4/2, 4/4 Central World Plaza,
1st Floor, Unit No. F110-116,
Rajdamri Road, Pathumwan Bangkok 10330 Thailand

Companies register: Thailand Companies Registration Office
Company registration number: 0105554157458
Authorized representative: Mr. Philippe LASSAUX
VAT registration number: VAT NO. 0105554157458

The website is operated for Hthai (Thailand) Co. Ltd jointly by Hthai (Thailand) Co. Ltd and Gill Capital (S) Pte. Ltd

Where do we store your data?
The data that we collect from you is stored within Thailand but may also be transferred to and processed in countries outside of Thailand, such as countries of the European Economic Area (“EEA”). Any such transfer of your personal data will be carried out in compliance with applicable laws.

For transfers of your personal data, H&M will use Standard Contractual Clauses and Shields as safeguards for countries without adequacy decisions from the European Commission.

Who can access your data?
Your data may be shared within the H&M group and within the Gill Capital group (for details on the H&M group, please refer to H&M group annual report which may be found at about.hm.com; for details on the Gill Capital group, please refer to www.gillcapital.sg.com). We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group and outside the Gill Capital group.

Data that is forwarded to third parties, is only used to provide you with our services. You will find categories of third parties under every specific process below.

What is the legal ground for processing?
For every specific process of personal data we collect from you, we will inform you whether the provision of personal data is statutory or required to enter a contract and whether it is an obligation to provide the personal data and possible consequences if you choose not to.

What are your rights?
Right to access:
You have the right to request information about the personal data we hold on you at any time. You can contact us and we will provide you with your personal data via e-mail.

Right to portability:
Whenever we process your personal data, by automated means based on your consent or based on an agreement, you have the right to get a copy of your data transferred to you or to another party. This only includes the personal data you have submitted to us.

Right to rectification:
You have the right to request rectification of your personal data if the information is incorrect, including the right to have incomplete personal data completed. If you have an H&M account or Club membership you can edit your personal data under your account and membership pages.

Right to erasure:
You have the right to erase any personal data processed by us at any time except for the following situations:


*You have an ongoing matter with Customer Service;
*You have an open order which has not yet been shipped or partially shipped;
*You have an unsettled debt with H&M or us, regardless of the payment method;
*If you are suspected or have misused our services within the last four years;
*Your debt has been sold to a third party within the last three years or one year for deceased customers;
*Your credit application has been rejected within the last three months;
*If you have made any purchase, we will keep your personal data in connection to your transaction for book-keeping purposes.

Your right to object to processing based on legitimate interest:
You have the right to object to processing of your personal data that is based on H&M's legitimate interest. H&M will not continue to process the personal data unless we can demonstrate legitimate grounds for the process which overrides your interest and rights or due to legal claims.

Your right to object to direct marketing:
You have the right to object to direct marketing, including profiling analysis made for direct marketing purposes.

You can opt out from direct marketing by the following means:

*Following the instruction in each marketing emails;
*By editing the settings of your H&M account.

Right to restriction:
You have the right to request that we restrict the process of your personal data under the following circumstances:

*If you object to a processing based H&M’s legitimate interest, we shall restrict all processing of such data pending the verification of the legitimate interest;
*If you have claim that your personal data is incorrect, we must restrict all processing of such data pending the verification of the accuracy of the personal data;
*If the processing is unlawful you can oppose the erasure of personal data and instead request the restriction of the use of your personal data instead;
*If we no longer need the personal data but it is required by you to defend legal claims.

How can you exercise your rights?
We take data protection very seriously and therefore we have dedicated customer service personnel to handle your requests in relation to your rights stated above. You can always reach them at dataprotection@hthai.co.th.

Data Protection Officer:
We have appointed a Data Protection Officer to ensure that we continuously process your personal data in an open, accurate and legal manner. You can contact our Data Protection Officer at dataprotection@hthai.co.th and write DPO as subject matter.

Right to complain with a supervisory authority:
If you consider H&M to process your personal data in an incorrect way you can contact us. You also have the right to raise a complaint to a supervisory authority.

Updates to our Privacy Notice:
We may need to update our Privacy Notice. The latest version of the Privacy Notice is always available on our website. We will communicate any material changes to the Privacy Notice, for example the purpose of why we use your personal data, the identity of the Controller or your rights.

ONLINE PURCHASE

Why do we use your personal data?

We will use your personal data to manage your purchase online at H&M by processing your orders and returns via our online services and send you notifications of delivery status or in the event of any problems with the delivery of your items.

We will use your personal data to manage your payments.

We will also use your data in order to handle complaints and warranty matters for products.

Your personal data is being used to identify you and to validate your legal age for shopping online and to confirm your address with external partners.

We want to offer you different payment alternatives and will carry out analysis in order to find out what payment alternatives are available to you, including your payment history and credit checks.

What types of personal data do we process?

We will process following categories of personal data:

* Contact information such as name, address, e-mail address and telephone number;
* Payment information and payment history;
* Credit information;

Order information.
* If you have an H&M account or are an H&M Club member we will also process your personal data submitted in relation to the account or membership such as:
* Account or membership ID;
* Shopping history.

Who has access to your personal data?

Your personal data that is forwarded to third parties, is only used to provide you with the services mentioned above, companies to validate your address, communication agencies to send you order confirmation, warehouse and distribution suppliers in connection with the delivery of your order. Payment service providers for your payment. Credit reference agencies for identity and credit checks and debt collection agencies.

Please be aware that many of these recipient companies have an independent right or obligation to process your personal data.

What is the legal ground to process your personal data?

The processing of your personal data is necessary for Hus to fulfil the service of managing and delivering the order to you.

How long do we save your data?

We will keep your data as long as you are an active customer as well for documentary as may be required by Law and Regulation.

Automated decision making:

When you apply for credit as a method of payment we will perform an automated decision-making process regarding your credit application. You have the right to express your point of view and to contest the decision with a member of staff.

DIRECT MARKETING

Why do we use your personal data?

We will use your personal data to send you marketing offers, information surveys and invitations through e-mails, text messages, phone calls and postal mail.

In order to optimize your experience of H&M we will provide you with relevant information, recommended products, send you reminders of products left in your shopping bag and send you personalized offers. All these great services are based on your previous purchases, what you have clicked on and information you have submitted to us.

What types of personal data do we process?

We will process following categories of personal data:
* Contact information such as e-mail address, telephone number and postal code
* If you want updates for kids (if you choose to provide that to us)
* Gender (if you choose to provide that to us)
* What products and offers you have clicked on

If you have a H&M account or are a H&M Club member we will also process your personal data submitted in relation to the account and membership such as:

* Name
* Address
* Age
* Shopping history
* How you navigated and clicked on the site

Who has access to your personal data?

Data that is forwarded to third parties is only used to provide you with the service mentioned above, to media agencies and technical suppliers for distribution of physical and digital direct marketing.

We never pass on, sell or swap your data for marketing purposes to third parties outside the H&M group or Gill Capital group.

What is the legal ground to process your personal data?

The processing of your personal data is based on your consent when you agree to direct marketing. Except for postal marketing, including catalogues, that will be sent to you based on our legitimate interest.

Your right to withdraw your consent:

You have the right to withdraw your consent for the processing of your personal data at any time and also object to direct marketing.

When you do so, we won’t be able to send you any further direct marketing offers or information based on your consent

You can opt out from direct marketing by the following means:

* Following the instruction in each marketing post
* By editing the settings of your H&M account

How long do we save your data?

We will keep your data for direct marketing until you withdraw your consent. For e-mail marketing we will consider you an inactive customer if you haven't opened an e-mail within the last year. After this time period your personal data will be deleted.

H&M Account

Why do we use your personal data?

We will use your personal data to create and manage your personal account in order to give you a personalized and relevant experience at H&M.

We will provide you with your order history, details around your orders and enable you to handle your account settings (including marketing preferences). We will also provide you with easy ways to maintain accurate and updated information such as contact details and payment information.

Furthermore, we will enable you to save items in your shopping bag, offer you size recommendations and enable you to rate and review the products you've purchased from us. In order to provide you with relevant product recommendations we will process your navigation and browsing on our digital platforms (including website and app), your shopping history and product reviews as well as the data you submitted to us through your account.

Please read our full  Privacy Notice.