Privacy Policy
Presentation
Our Privacy Policy and its content
Key definitions of our Privacy Policy
Consent to our Privacy Policy
Principles for processing Personal data
What Personal data is collected and for what purposes?
What happens in case of International data transfers outside Switzerland?
Where is your Personal data hosted and stored?
Personal data retention period
Personal data security
Your rights regarding Personal data
Data protection by Design and by Default (Art. 7 FADP)
Complaints and Supervisory authority
Links to third-party sites
Amendments to this Privacy Policy
Applicable law and Jurisdiction
Contact and Legal Notices
Our Privacy Policy and its content
Our Privacy Policy and its content
Key definitions of our Privacy Policy
Key definitions of our Privacy Policy
Consent to our Privacy Policy
Consent to our Privacy Policy
Principles for processing Personal data
Principles for processing Personal data
What Personal data is collected and for what purposes?
What Personal data is collected and for what purposes?
What Happens in Case of International Data Transfers Outside Switzerland?
What happens in case of International data transfers outside Switzerland?
What happens in case of International data transfers outside Switzerland?
Where Is Your Personal Data Hosted and Stored?
Where is your Personal data hosted and stored?
Where is your Personal data hosted and stored?
Personal Data Retention Period
Personal data retention period
Personal data retention period
Personal Data Security
Personal data security
Your Rights Regarding Personal Data
Your rights regarding Personal data
Data Protection by Design and by Default (Art. 7 FADP)
Data protection by Design and by Default (Art. 7 FADP)
Complaints and Supervisory Authority
Complaints and Supervisory authority
Links to Third-Party Sites
Links to third-party sites
Amendments to This Privacy Policy
Amendments to this Privacy Policy
Applicable Law and Jurisdiction
Applicable law and Jurisdiction
Contact and Legal Notices
Our Privacy Policy and its content
The protection of Personal Data is a priority for MTHV Sàrl, Route du Bout du Monde 7a, 1206 Geneva, Switzerland (UID: CHE-333.107.586) (the "Company", "We", "Our", "Us").
In operating Our Website, We may collect Personal Data.
This Privacy Policy describes the conditions under which We collect, hold, use, and retain your information, as well as the choices you have made regarding the use and Disclosure of your Personal Data when browsing www.droohair.com (the "Site").
Key definitions of our Privacy Policy
Term
Consent
Consent
Any freely given, specific, and informed indication of will by which a Data Subject accepts the processing of Personal Data relating to them.
Data Controller
The natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of Personal Data and is responsible for such processing.
Personal Data
Any information relating to an identified or identifiable natural person.
Data Subject
Any natural person whose Personal Data is subject to processing (You, the customer, or the user of the Site).
Processing
Any operation or set of operations, whether or not by automated means, applied to Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, erasure, or destruction.
Disclosure
Making Personal Data accessible, for example by permitting consultation, transmission, or publication.
Consent to our Privacy Policy
By accessing the Site, you acknowledge that you have read and understood this Privacy Policy.
The collection and Processing of your Personal Data are based on strictly defined legal grounds (notably the performance of your orders, compliance with our legal obligations, or Our legitimate interest).
Where required by law — particularly for commercial marketing sent by email (Newsletter) or the placement of advertising and tracking cookies —, Your free, specific, and informed consent will be explicitly requested (for example, via an unchecked opt-in box or the cookie management banner).
You may withdraw your Consent at any time for these specific processing activities by contacting Us or using the unsubscribe links provided to you.
Principles for processing Personal data
When We collect Personal data, We strive to respect the following principles:
Fairness and Lawfulness: During the Processing of Personal Data, individual rights must be protected. Personal Data must be collected and Processed lawfully, fairly, and in good faith, and processing must be proportionate to the intended purpose.
Purpose Limitation: Personal Data processed by the Company must be adequate and relevant to the purposes for which it is collected and processed. This involves ensuring that collected data categories are not excessive. Any subsequent modification of these purposes is permitted only to a limited extent and must be justified.
Transparency: The Data Subject must be informed of how their Personal Data is processed, including the existence of this Privacy Policy, the identity of the Data Controller, the purpose of Processing, and third parties to whom data may be communicated.
Consent of the Data Subject: Personal Data must be collected directly from the Data Subject, and their Consent may be required prior to Processing. Consent must be explicit and verifiable (for example, via an unchecked box or form validation). Consent is valid only if freely given. If Consent is not obtained before Processing for any reason, it must be documented as soon as possible after Processing begins. Personal Data may be processed without Consent if necessary to pursue a legitimate interest of the Company (legal or financial) or if required/authorized by law.
Data Accuracy: Personal Data held in records must be accurate and updated when necessary. Inaccurate or incomplete data must not be retained and must be erased.
What Personal data is collected and for what purposes?
This Privacy Policy applies to all information received during your visit to Our Site. We collect Personal Data only when We have a legal basis to do so.
Processing Activity
Data Category
Source
Purpose of Processing
Legal Basis
Data Controller
Recipients
Contact via phone, email, or mail
Data generated by your inquiries
Information provided by You
(i) Relationship management
(ii)
Managing rights requests
(iii)
Service improvement
(i) & (ii) Contract performance (iii) Legitimate interest
MTHV Sàrl
Customer relationship management providers
Browsing the Site
Automatically collected technical data (IP, cookies, location)
Automatically collected
(i)
Secure site navigation
(ii) Personalize experience based on location/preferences
(i)
Legitimate interest
(ii)
Consent for personalization/cookies
MTHV Sàrl
Site management providers and hosting partners: Framer (Host: AWS – USA)
Interaction with third-party partners
Socio-demographic, contact, and profile data
Transmitted by third-party partners
Commercial prospecting and targeted advertising
Consent granted directly to third-party partners
MTHV Sàrl
Site management providers and marketing partners
Newsletter Subscription
Email address provided
Information provided by You
Delivering the newsletter
Consent to receive marketing
MTHV Sàrl
Newsletter delivery provider: Klaviyo
E-commerce Order
Name, address, payment details
Information provided by You
Fulfilling the sales order (Terms & Conditions)
Performance of contract (Terms & Conditions)
MTHV Sàrl
Hosting (Framer/AWS), secure payment providers (Stripe, PayPal), logisticians/carriers (Swiss Post, DHL), accounting software, transactional email systems (Klaviyo)
What happens in case of International data transfers outside Switzerland?
In operating the Site and our services (hosting, order processing, email marketing), your Personal Data may be communicated to our processors and partners located in the following countries:
Switzerland
Member States of the European Union (EU) / European Economic Area (EEA)
United States (specifically for hosting and emailing service providers: Framer, Amazon Web Services, Klaviyo)
Where your data is transferred to a country that does not provide an adequate level of data protection recognized by the Swiss Federal Council or the European Commission (notably the United States), the Company guarantees that the transfer is strictly safeguarded by one of the following mechanisms:
The recipient’s certification under the Swiss-U.S. and EU-U.S. Data Privacy Framework;
The execution of Standard Contractual Clauses (SCCs) approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC / PFPDT) and the European Commission;
In the absence thereof, an exceptional transfer based on your explicit consent or the strict necessity to perform your order (performance of a contract).
Where is your Personal data hosted and stored?
Your Personal Data is hosted and stored within highly secure IT infrastructures provided by our specialized processors:
Website Management Platform: The Site is designed and deployed via the Framer platform (Framer B.V. / Framer Inc.). Framer B.V. (Rozengracht 207B, 1016 LZ Amsterdam, Pays-Bas)
Cloud Infrastructure and Data Centers: Actual hosting of databases and site content is provided by Amazon Web Services (AWS) (AWS EMEA SARL / Amazon.com, Inc.). Data is stored primarily in secure data centers located within the European Union (notably the AWS Frankfurt/Germany region) and/or the United States.
To ensure data confidentiality and integrity, our hosting providers implement state-of-the-art technical and organizational measures:
In-Transit Encryption: All data transferred between your browser and the Site is encrypted using secure SSL / TLS (HTTPS) protocols.
At-Rest Encryption: Hosted databases and files are encrypted on servers using AES-256 bit encryption.
Security Certifications: AWS data centers comply with international security certifications (ISO/IEC 27001, SOC 1 / SOC 2 / SOC 3, and PCI-DSS for payment processing).
Backups and Redundancy: Automated regular backups are conducted to prevent accidental data loss or alteration.
Framer and Amazon Web Services (AWS) act strictly as data processors on behalf of MTHV Sàrl. They are bound by strict contractual obligations prohibiting any independent use, resale, or communication of your Personal Data to third parties without Our prior instructions.
Personal data retention period
In accordance with the Swiss FADP (Art. 6 para. 4), the Company retains your Personal Data only for as long as strictly necessary to fulfill the purposes for which it was collected, or to comply with statutory requirements.
Applied retention periods vary by data type:
Order and Invoicing Data (Name, address, transactions): Retained throughout the commercial relationship, then archived for 10 years from the close of the fiscal year. This corresponds to the Swiss statutory obligation to retain accounting records (Art. 958f of the Swiss Code of Obligations - CO).
Marketing and Newsletter Data (Email address): Retained until you withdraw consent (via the unsubscribe link in each email) or for a maximum of 3 years from your last active contact (e.g., email click or purchase).
Customer Service Data (Inquiries, support emails): Retained for the duration of request handling, then archived for 1 to 3 years following ticket resolution for dispute management.
Browsing Data and Cookies: Technical connection logs (IP addresses) are retained for up to 12 months. Cookie consent preferences are stored for 6 months.
Upon expiry of retention periods, Personal Data is permanently erased or irreversibly anonymized.
Personal data security
In accordance with Article 8 FADP and the Swiss Data Protection Ordinance (DPO), the Company implements appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk.
1. Technical Security Measures
In-Transit Encryption: All communication between your browser and the Site is secured via SSL / TLS (HTTPS) encryption.
At-Rest Encryption: Databases containing customer information are encrypted on hosting servers using AES-256 bit standards.
Payment Security: Banking details are never stored on our servers and are processed directly by PCI-DSS compliant payment processors.
Access Control: Access to data within our company is strictly restricted to authorized personnel (least privilege principle) using multi-factor authentication (2FA).
2. Organizational and Contractual Measures
Processor Selection: Pursuant to Article 9 FADP, we ensure all processors (hosts, carriers, marketing tools) provide sufficient security guarantees via Data Processing Agreements (DPAs).
Backups and Continuity: Automated backups ensure rapid data recovery in case of technical incidents.
3. Breach Notification (Art. 24 FADP)
In the event of a security incident leading to a personal data breach posing a high risk to your personality or fundamental rights, We undertake to notify the Federal Data Protection and Information Commissioner (FDPIC / PFPDT) as soon as possible, as well as the affected individuals when required by law.
Your rights regarding Personal data
In accordance with the Swiss Federal Act on Data Protection (FADP), you have the following rights:
Right of Access (Art. 25 FADP): Obtain confirmation as to whether your Personal Data is being processed and receive a full copy.
Right to Rectification (Art. 32 FADP): Request immediate correction of inaccurate, incomplete, or outdated data.
Right to Erasure (Art. 32 FADP): Demand deletion of your data, unless statutory retention obligations (e.g., 10-year accounting requirement) or legitimate grounds apply.
Right to Withdraw Consent: Revoke consent at any time for consent-based processing (newsletters, non-essential cookies) with future effect.
Right to Data Portability (Art. 28 FADP): Receive your data in a structured, commonly used, machine-readable format or request transfer to a third party.
Right to Object (Art. 30 FADP): Object at any time to data processing, particularly for direct marketing.
How to Exercise Your Rights:
Contact us by email at hello@droohair.com. Requests are processed free of charge within 30 days (Art. 18 DPO). We reserve the right to request proof of identity in cases of reasonable doubt.
Data protection by Design and by Default (Art. 7 FADP)
In accordance with Article 7 FADP, the Company integrates Data Protection by Design and Data Protection by Default into all systems.
1. Protection by Design
When building services, developing the Site, or choosing vendors, We ensure systems limit collection to what is strictly necessary (data minimization) and embed technical safeguards like encryption from inception.
2. Protection by Default
We guarantee that, by default, processing is restricted to what is strictly necessary:
Cookies & Trackers: Non-essential cookies are blocked by default until active consent is given.
Marketing: Marketing opt-in boxes are never pre-checked.
Restricted Access: Personal data is not accessible to unnecessary third parties by default.
Complaints and Supervisory authority
If you believe your Personal Data has been processed in violation of the FADP, please contact us at hello@droohair.com to find a swift resolution.
You also have the right to lodge a complaint or report an infringement directly to the competent Swiss supervisory authority:
Federal Data Protection and Information Commissioner (FDPIC / PFPDT)
Feldeggweg 1, CH-3003 Bern
Website: www.edoeb.admin.ch
(EU residents may also lodge a complaint with their local EU data protection authority).
Links to third-party sites
The Site may contain hyperlinks to third-party websites. The Company has no control over these sites and disclaims all liability for their privacy practices. We encourage you to review their respective Privacy Policies.
Amendments to this Privacy Policy
The Company reserves the right to update this Privacy Policy at any time to comply with legal, regulatory, or technical changes. The latest version will always be available on the Site with its revision date.
Applicable law and Jurisdiction
This Privacy Policy is governed exclusively by substantive Swiss law, excluding its conflict of laws rules.
In the event of any dispute regarding the interpretation or validity of this Notice, exclusive jurisdiction is granted to the ordinary courts of the Canton of Geneva, subject to appeal to the Swiss Federal Supreme Court.
Contact and Legal Notices
For any questions regarding data processing or to exercise your rights, you can contact us:
Data Controller (Switzerland):
MTHV Sàrl – DROO Hair
Route du Bout du Monde 7a, 1206 Geneva, Switzerland
IDE: CHE-333.107.586
Email: hello@droohair.com | Phone: +41 79 524 64 06
Website: [www.droohair.com](https://www.droohair.com)EU Representative (Art. 27 GDPR):EU Representative (Art. 27 GDPR):
Please refer to the Legal Notice for our complete contact details.





