Free shipping on orders over €100.

Privacy Policy

Our Privacy Policy and its content

Our Privacy Policy and its content

Key definitions of our Privacy Policy

Key definitions of our Privacy Policy

Consent to our Privacy Policy

Consent to our Privacy Policy

Principles for processing Personal data

Principles for processing Personal data

What Personal data is collected and for what purposes?

What Personal data is collected and for what purposes?

What Happens in Case of International Data Transfers Outside Switzerland?

What happens in case of International data transfers outside Switzerland?

What happens in case of International data transfers outside Switzerland?

Where Is Your Personal Data Hosted and Stored?

Where is your Personal data hosted and stored?

Where is your Personal data hosted and stored?

Personal Data Retention Period

Personal data retention period

Personal data retention period

Personal Data Security

Personal data security

Your Rights Regarding Personal Data

Your rights regarding Personal data

Data Protection by Design and by Default (Art. 7 FADP)

Data protection by Design and by Default (Art. 7 FADP)

Complaints and Supervisory Authority

Complaints and Supervisory authority

Links to Third-Party Sites

Links to third-party sites

Amendments to This Privacy Policy

Amendments to this Privacy Policy

Applicable Law and Jurisdiction

Applicable law and Jurisdiction

Contact and Legal Notices

Our Privacy Policy and its content

The protection of Personal Data is a priority for MTHV Sàrl, Route du Bout du Monde 7a, 1206 Geneva, Switzerland (UID: CHE-333.107.586) (the "Company", "We", "Our", "Us").

In operating Our Website, We may collect Personal Data.

This Privacy Policy describes the conditions under which We collect, hold, use, and retain your information, as well as the choices you have made regarding the use and Disclosure of your Personal Data when browsing www.droohair.com (the "Site").

Key definitions of our Privacy Policy

Term

Consent

Consent

Any freely given, specific, and informed indication of will by which a Data Subject accepts the processing of Personal Data relating to them.

Data Controller

The natural or legal person who, alone or jointly with others, determines the purposes and means of the processing of Personal Data and is responsible for such processing.

Personal Data

Any information relating to an identified or identifiable natural person.

Data Subject

Any natural person whose Personal Data is subject to processing (You, the customer, or the user of the Site).

Processing

Any operation or set of operations, whether or not by automated means, applied to Personal Data, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, erasure, or destruction.

Disclosure

Making Personal Data accessible, for example by permitting consultation, transmission, or publication.

Principles for processing Personal data

When We collect Personal data, We strive to respect the following principles:

  • Fairness and Lawfulness: During the Processing of Personal Data, individual rights must be protected. Personal Data must be collected and Processed lawfully, fairly, and in good faith, and processing must be proportionate to the intended purpose.

  • Purpose Limitation: Personal Data processed by the Company must be adequate and relevant to the purposes for which it is collected and processed. This involves ensuring that collected data categories are not excessive. Any subsequent modification of these purposes is permitted only to a limited extent and must be justified.

  • Transparency: The Data Subject must be informed of how their Personal Data is processed, including the existence of this Privacy Policy, the identity of the Data Controller, the purpose of Processing, and third parties to whom data may be communicated.

  • Consent of the Data Subject: Personal Data must be collected directly from the Data Subject, and their Consent may be required prior to Processing. Consent must be explicit and verifiable (for example, via an unchecked box or form validation). Consent is valid only if freely given. If Consent is not obtained before Processing for any reason, it must be documented as soon as possible after Processing begins. Personal Data may be processed without Consent if necessary to pursue a legitimate interest of the Company (legal or financial) or if required/authorized by law.

  • Data Accuracy: Personal Data held in records must be accurate and updated when necessary. Inaccurate or incomplete data must not be retained and must be erased.

What Personal data is collected and for what purposes?

This Privacy Policy applies to all information received during your visit to Our Site. We collect Personal Data only when We have a legal basis to do so.

Processing Activity

Data Category

Source

Purpose of Processing

Legal Basis

Data Controller

Recipients

Contact via phone, email, or mail

Data generated by your inquiries

Information provided by You

(i) Relationship management

(ii)
Managing rights requests

(iii)
Service improvement

(i) & (ii) Contract performance (iii) Legitimate interest

MTHV Sàrl

Customer relationship management providers

Browsing the Site

Automatically collected technical data (IP, cookies, location)

Automatically collected

(i)
Secure site navigation

(ii) Personalize experience based on location/preferences

(i)
Legitimate interest

(ii)
Consent for personalization/cookies

MTHV Sàrl

Site management providers and hosting partners: Framer (Host: AWS – USA)

Interaction with third-party partners

Socio-demographic, contact, and profile data

Transmitted by third-party partners

Commercial prospecting and targeted advertising

Consent granted directly to third-party partners

MTHV Sàrl

Site management providers and marketing partners

Newsletter Subscription

Email address provided

Information provided by You

Delivering the newsletter

Consent to receive marketing

MTHV Sàrl

Newsletter delivery provider: Klaviyo

E-commerce Order

Name, address, payment details

Information provided by You

Fulfilling the sales order (Terms & Conditions)

Performance of contract (Terms & Conditions)

MTHV Sàrl

Hosting (Framer/AWS), secure payment providers (Stripe, PayPal), logisticians/carriers (Swiss Post, DHL), accounting software, transactional email systems (Klaviyo)

What happens in case of International data transfers outside Switzerland?

In operating the Site and our services (hosting, order processing, email marketing), your Personal Data may be communicated to our processors and partners located in the following countries:

  • Switzerland

  • Member States of the European Union (EU) / European Economic Area (EEA)

  • United States (specifically for hosting and emailing service providers: Framer, Amazon Web Services, Klaviyo)

Where your data is transferred to a country that does not provide an adequate level of data protection recognized by the Swiss Federal Council or the European Commission (notably the United States), the Company guarantees that the transfer is strictly safeguarded by one of the following mechanisms:

  1. The recipient’s certification under the Swiss-U.S. and EU-U.S. Data Privacy Framework;

  1. The execution of Standard Contractual Clauses (SCCs) approved by the Swiss Federal Data Protection and Information Commissioner (FDPIC / PFPDT) and the European Commission;

  1. In the absence thereof, an exceptional transfer based on your explicit consent or the strict necessity to perform your order (performance of a contract).

Where is your Personal data hosted and stored?

Your Personal Data is hosted and stored within highly secure IT infrastructures provided by our specialized processors:

  • Website Management Platform: The Site is designed and deployed via the Framer platform (Framer B.V. / Framer Inc.). Framer B.V. (Rozengracht 207B, 1016 LZ Amsterdam, Pays-Bas) 

  • Cloud Infrastructure and Data Centers: Actual hosting of databases and site content is provided by Amazon Web Services (AWS) (AWS EMEA SARL / Amazon.com, Inc.). Data is stored primarily in secure data centers located within the European Union (notably the AWS Frankfurt/Germany region) and/or the United States.

To ensure data confidentiality and integrity, our hosting providers implement state-of-the-art technical and organizational measures:

  • In-Transit Encryption: All data transferred between your browser and the Site is encrypted using secure SSL / TLS (HTTPS) protocols.

  • At-Rest Encryption: Hosted databases and files are encrypted on servers using AES-256 bit encryption.

  • Security Certifications: AWS data centers comply with international security certifications (ISO/IEC 27001, SOC 1 / SOC 2 / SOC 3, and PCI-DSS for payment processing).

  • Backups and Redundancy: Automated regular backups are conducted to prevent accidental data loss or alteration.

Framer and Amazon Web Services (AWS) act strictly as data processors on behalf of MTHV Sàrl. They are bound by strict contractual obligations prohibiting any independent use, resale, or communication of your Personal Data to third parties without Our prior instructions.

Personal data retention period

In accordance with the Swiss FADP (Art. 6 para. 4), the Company retains your Personal Data only for as long as strictly necessary to fulfill the purposes for which it was collected, or to comply with statutory requirements.

Applied retention periods vary by data type:

  • Order and Invoicing Data (Name, address, transactions): Retained throughout the commercial relationship, then archived for 10 years from the close of the fiscal year. This corresponds to the Swiss statutory obligation to retain accounting records (Art. 958f of the Swiss Code of Obligations - CO).

  • Marketing and Newsletter Data (Email address): Retained until you withdraw consent (via the unsubscribe link in each email) or for a maximum of 3 years from your last active contact (e.g., email click or purchase).

  • Customer Service Data (Inquiries, support emails): Retained for the duration of request handling, then archived for 1 to 3 years following ticket resolution for dispute management.

  • Browsing Data and Cookies: Technical connection logs (IP addresses) are retained for up to 12 months. Cookie consent preferences are stored for 6 months.

Upon expiry of retention periods, Personal Data is permanently erased or irreversibly anonymized.

Personal data security

In accordance with Article 8 FADP and the Swiss Data Protection Ordinance (DPO), the Company implements appropriate technical and organizational measures (TOMs) to ensure a level of security appropriate to the risk.

1. Technical Security Measures

  • In-Transit Encryption: All communication between your browser and the Site is secured via SSL / TLS (HTTPS) encryption.

  • At-Rest Encryption: Databases containing customer information are encrypted on hosting servers using AES-256 bit standards.

  • Payment Security: Banking details are never stored on our servers and are processed directly by PCI-DSS compliant payment processors.

  • Access Control: Access to data within our company is strictly restricted to authorized personnel (least privilege principle) using multi-factor authentication (2FA).

2. Organizational and Contractual Measures

  • Processor Selection: Pursuant to Article 9 FADP, we ensure all processors (hosts, carriers, marketing tools) provide sufficient security guarantees via Data Processing Agreements (DPAs).

  • Backups and Continuity: Automated backups ensure rapid data recovery in case of technical incidents.

3. Breach Notification (Art. 24 FADP)

In the event of a security incident leading to a personal data breach posing a high risk to your personality or fundamental rights, We undertake to notify the Federal Data Protection and Information Commissioner (FDPIC / PFPDT) as soon as possible, as well as the affected individuals when required by law.

Your rights regarding Personal data

In accordance with the Swiss Federal Act on Data Protection (FADP), you have the following rights:

  • Right of Access (Art. 25 FADP): Obtain confirmation as to whether your Personal Data is being processed and receive a full copy.

  • Right to Rectification (Art. 32 FADP): Request immediate correction of inaccurate, incomplete, or outdated data.

  • Right to Erasure (Art. 32 FADP): Demand deletion of your data, unless statutory retention obligations (e.g., 10-year accounting requirement) or legitimate grounds apply.

  • Right to Withdraw Consent: Revoke consent at any time for consent-based processing (newsletters, non-essential cookies) with future effect.

  • Right to Data Portability (Art. 28 FADP): Receive your data in a structured, commonly used, machine-readable format or request transfer to a third party.

  • Right to Object (Art. 30 FADP): Object at any time to data processing, particularly for direct marketing.

How to Exercise Your Rights:

Contact us by email at hello@droohair.com. Requests are processed free of charge within 30 days (Art. 18 DPO). We reserve the right to request proof of identity in cases of reasonable doubt.

Data protection by Design and by Default (Art. 7 FADP)

In accordance with Article 7 FADP, the Company integrates Data Protection by Design and Data Protection by Default into all systems.

1. Protection by Design

When building services, developing the Site, or choosing vendors, We ensure systems limit collection to what is strictly necessary (data minimization) and embed technical safeguards like encryption from inception.

2. Protection by Default

We guarantee that, by default, processing is restricted to what is strictly necessary:

  • Cookies & Trackers: Non-essential cookies are blocked by default until active consent is given.

  • Marketing: Marketing opt-in boxes are never pre-checked.

  • Restricted Access: Personal data is not accessible to unnecessary third parties by default.

Complaints and Supervisory authority

If you believe your Personal Data has been processed in violation of the FADP, please contact us at hello@droohair.com to find a swift resolution.

You also have the right to lodge a complaint or report an infringement directly to the competent Swiss supervisory authority:

Federal Data Protection and Information Commissioner (FDPIC / PFPDT)

Feldeggweg 1, CH-3003 Bern

Website: www.edoeb.admin.ch

(EU residents may also lodge a complaint with their local EU data protection authority).

Amendments to this Privacy Policy

The Company reserves the right to update this Privacy Policy at any time to comply with legal, regulatory, or technical changes. The latest version will always be available on the Site with its revision date.

Applicable law and Jurisdiction

This Privacy Policy is governed exclusively by substantive Swiss law, excluding its conflict of laws rules.

In the event of any dispute regarding the interpretation or validity of this Notice, exclusive jurisdiction is granted to the ordinary courts of the Canton of Geneva, subject to appeal to the Swiss Federal Supreme Court.

The Droo Drop.

The Droo Drop

New drops, hair talk, everything Droo and a little more straight to your inbox.