Privacy Policy
Our Privacy Policy and its content
The protection of Personal Data is a priority for MTHV Sàrl, Route du Bout du Monde 7a, 1206 Geneva, Switzerland (UID: CHE-333.107.586) (the "Company", "We", "Our", "Us").
In operating Our Website, We may collect Personal Data.
This Privacy Policy describes the conditions under which We collect, hold, use, and retain your information, as well as the choices you have made regarding the use and Disclosure of your Personal Data when browsing www.droohair.com (the "Site").
Key definitions of our Privacy Policy
Consent to our Privacy Policy
By accessing the Site, you acknowledge that you have read and understood this Privacy Policy.
The collection and Processing of your Personal Data are based on strictly defined legal grounds (notably the performance of your orders, compliance with our legal obligations, or Our legitimate interest).
Where required by law — particularly for commercial marketing sent by email (Newsletter) or the placement of advertising and tracking cookies —, Your free, specific, and informed consent will be explicitly requested (for example, via an unchecked opt-in box or the cookie management banner).
You may withdraw your Consent at any time for these specific processing activities by contacting Us or using the unsubscribe links provided to you.
Principles for processing Personal data
When We collect Personal data, We strive to respect the following principles:
- Fairness and Lawfulness: During the Processing of Personal Data, individual rights must be protected. Personal Data must be collected and Processed lawfully, fairly, and in good faith, and processing must be proportionate to the intended purpose.
- Purpose Limitation: Personal Data processed by the Company must be adequate and relevant to the purposes for which it is collected and processed. This involves ensuring that collected data categories are not excessive. Any subsequent modification of these purposes is permitted only to a limited extent and must be justified.
- Transparency: The Data Subject must be informed of how their Personal Data is processed, including the existence of this Privacy Policy, the identity of the Data Controller, the purpose of Processing, and third parties to whom data may be communicated.
- Consent of the Data Subject: Personal Data must be collected directly from the Data Subject, and their Consent may be required prior to Processing. Consent must be explicit and verifiable (for example, via an unchecked box or form validation). Consent is valid only if freely given. If Consent is not obtained before Processing for any reason, it must be documented as soon as possible after Processing begins. Personal Data may be processed without Consent if necessary to pursue a legitimate interest of the Company (legal or financial) or if required/authorized by law.
- Data Accuracy: Personal Data held in records must be accurate and updated when necessary. Inaccurate or incomplete data must not be retained and must be erased.
What Personal data is collected and for what purposes?
This Privacy Policy applies to all information received during your visit to Our Site. We collect Personal Data only when We have a legal basis to do so.
What happens in case of International data transfers outside Switzerland?
In operating the Site and our services (hosting, order processing, email marketing), your Personal Data may be communicated to our processors and partners located in the following countries:
- Switzerland
- Member States of the European Union (EU) / European Economic Area (EEA)
- United States (specifically for hosting and emailing service providers: Framer, Amazon Web Services, Klaviyo)
Where your data is transferred to a country that does not provide an adequate level of data protection recognized by the Swiss Federal Council or the European Commission (notably the United States), the Company guarantees that the transfer is strictly safeguarded by one of the following mechanisms:
- The recipient’s certification under the Swiss-U.S. and EU-U.S. Data Privacy Framework;
- The execution of Standard Contractual Clauses (SCCs) approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC / PFPDT) and the European Commission;
- In the absence thereof, an exceptional transfer based on your explicit consent or the strict necessity to perform your order (performance of a contract).
Where is your Personal data hosted and stored?
Your Personal Data is hosted and stored within highly secure IT infrastructures provided by our specialized processors:
- Website Management Platform: The Site is designed and deployed via the Framer platform (Framer B.V. / Framer Inc.). Framer B.V. (Rozengracht 207B, 1016 LZ Amsterdam, Pays-Bas)
- Cloud Infrastructure and Data Centers: Actual hosting of databases and site content is provided by Amazon Web Services (AWS) (AWS EMEA SARL / Amazon.com, Inc.). Data is stored primarily in secure data centers located within the European Union (notably the AWS Frankfurt/Germany region) and/or the United States.
To ensure data confidentiality and integrity, our hosting providers implement state-of-the-art technical and organizational measures:
- In-Transit Encryption: All data transferred between your browser and the Site is encrypted using secure SSL / TLS (HTTPS) protocols.
- At-Rest Encryption: Hosted databases and files are encrypted on servers using AES-256 bit encryption.
- Security Certifications: AWS data centers comply with international security certifications (ISO/IEC 27001, SOC 1 / SOC 2 / SOC 3, and PCI-DSS for payment processing).
- Backups and Redundancy: Automated regular backups are conducted to prevent accidental data loss or alteration.
Framer and Amazon Web Services (AWS) act strictly as data processors on behalf of MTHV Sàrl. They are bound by strict contractual obligations prohibiting any independent use, resale, or communication of your Personal Data to third parties without Our prior instructions.
Personal data retention period
In accordance with the Swiss FADP (Art. 6 para. 4), the Company retains your Personal Data only for as long as strictly necessary to fulfill the purposes for which it was collected, or to comply with statutory requirements.
Applied retention periods vary by data type:
- Order and Invoicing Data (Name, address, transactions): Retained throughout the commercial relationship, then archived for 10 years from the close of the fiscal year. This corresponds to the Swiss statutory obligation to retain accounting records (Art. 958f of the Swiss Code of Obligations - CO).
- Marketing and Newsletter Data (Email address): Retained until you withdraw consent (via the unsubscribe link in each email) or for a maximum of 3 years from your last active contact (e.g., email click or purchase).
- Customer Service Data (Inquiries, support emails): Retained for the duration of request handling, then archived for 1 to 3 years following ticket resolution for dispute management.
- Browsing Data and Cookies: Technical connection logs (IP addresses) are retained for up to 12 months. Cookie consent preferences are stored for 6 months.
Upon expiry of retention periods, Personal Data is permanently erased or irreversibly anonymized.
Personal data security
In accordance with Article 8 FADP and the Swiss Data Protection Ordinance (DPO), the Company implements appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk.
1. Technical Security Measures
- In-Transit Encryption: All communication between your browser and the Site is secured via SSL / TLS (HTTPS) encryption.
- At-Rest Encryption: Databases containing customer information are encrypted on hosting servers using AES-256 bit standards.
- Payment Security: Banking details are never stored on our servers and are processed directly by PCI-DSS compliant payment processors.
- Access Control: Access to data within our company is strictly restricted to authorized personnel (least privilege principle) using multi-factor authentication (2FA).
2. Organizational and Contractual Measures
- Processor Selection: Pursuant to Article 9 FADP, we ensure all processors (hosts, carriers, marketing tools) provide sufficient security guarantees via Data Processing Agreements (DPAs).
- Backups and Continuity: Automated backups ensure rapid data recovery in case of technical incidents.
3. Breach Notification (Art. 24 FADP)
In the event of a security incident leading to a personal data breach posing a high risk to your personality or fundamental rights, We undertake to notify the Federal Data Protection and Information Commissioner (FDPIC / PFPDT) as soon as possible, as well as the affected individuals when required by law.
Your rights regarding Personal data
In accordance with the Swiss Federal Act on Data Protection (FADP), you have the following rights:
- Right of Access (Art. 25 FADP): Obtain confirmation as to whether your Personal Data is being processed and receive a full copy.
- Right to Rectification (Art. 32 FADP): Request immediate correction of inaccurate, incomplete, or outdated data.
- Right to Erasure (Art. 32 FADP): Demand deletion of your data, unless statutory retention obligations (e.g., 10-year accounting requirement) or legitimate grounds apply.
- Right to Withdraw Consent: Revoke consent at any time for consent-based processing (newsletters, non-essential cookies) with future effect.
- Right to Data Portability (Art. 28 FADP): Receive your data in a structured, commonly used, machine-readable format or request transfer to a third party.
- Right to Object (Art. 30 FADP): Object at any time to data processing, particularly for direct marketing.
How to Exercise Your Rights:
Contact us by email at hello@droohair.com. Requests are processed free of charge within 30 days (Art. 18 DPO). We reserve the right to request proof of identity in cases of reasonable doubt.
Data protection by Design and by Default (Art. 7 FADP)
In accordance with Article 7 FADP, the Company integrates Data Protection by Design and Data Protection by Default into all systems.
1. Protection by Design
When building services, developing the Site, or choosing vendors, We ensure systems limit collection to what is strictly necessary (data minimization) and embed technical safeguards like encryption from inception.
2. Protection by Default
We guarantee that, by default, processing is restricted to what is strictly necessary:
- Cookies & Trackers: Non-essential cookies are blocked by default until active consent is given.
- Marketing: Marketing opt-in boxes are never pre-checked.
- Restricted Access: Personal data is not accessible to unnecessary third parties by default.
Complaints and Supervisory authority
If you believe your Personal Data has been processed in violation of the FADP, please contact us at hello@droohair.com to find a swift resolution.
You also have the right to lodge a complaint or report an infringement directly to the competent Swiss supervisory authority:
Federal Data Protection and Information Commissioner (FDPIC / PFPDT)
Feldeggweg 1, CH-3003 Bern
Website: www.edoeb.admin.ch
(EU residents may also lodge a complaint with their local EU data protection authority).
Links to third-party sites
The Site may contain hyperlinks to third-party websites. The Company has no control over these sites and disclaims all liability for their privacy practices. We encourage you to review their respective Privacy Policies.
Amendments to this Privacy Policy
The Company reserves the right to update this Privacy Policy at any time to comply with legal, regulatory, or technical changes. The latest version will always be available on the Site with its revision date.
Applicable law and Jurisdiction
This Privacy Policy is governed exclusively by substantive Swiss law, excluding its conflict of laws rules.
In the event of any dispute regarding the interpretation or validity of this Notice, exclusive jurisdiction is granted to the ordinary courts of the Canton of Geneva, subject to appeal to the Swiss Federal Supreme Court.
Contact and Legal Notices
For any questions regarding data processing or to exercise your rights, you can contact us:
- Data Controller (Switzerland):
-
MTHV Sàrl – DROO Hair
Route du Bout du Monde 7a, 1206 Geneva, Switzerland
IDE: CHE-333.107.586
Email: hello@droohair.com | Phone: +41 79 524 64 06
Website: www.droohair.com - EU Representative (Art. 27 GDPR)
Please refer to the Legal Notice for our complete contact details.















