Privacy policy
Privacy Policy
Last updated: 16 September 2025
This Privacy Policy explains how IIC BV / Gillio (“we,” “us,” or “our”) collects, uses, and protects your personal data when you visit our website or purchase our products.
We are based in Belgium and are therefore subject to the General Data Protection Regulation (GDPR). This means that all customers within the European Union (EU) benefit from GDPR rights and protections. For customers outside the EU, we apply similar principles of privacy and transparency, even if local laws differ.
- Data We Collect
We may collect and process the following categories of personal data:
- Identification and contact details: name, address, email address, phone number.
- Order details: items purchased, purchase dates, payment and delivery details.
- Preferences and communications: subscriptions to restock notifications, newsletters, or promotional updates.
- Technical data: IP address, browser type, device information, and website usage (through cookies or similar technologies, subject to consent where required).
- How We Use Your Data
Your personal data will only be used for legitimate purposes, including:
- Processing and fulfilling your orders worldwide.
- Providing customer support and responding to inquiries.
- Sending you restock notifications, newsletters, or promotional communications (only if you have opted in).
- Improving our website, products, and services.
- Meeting legal, accounting, or reporting obligations in Belgium and the EU.
We do not sell or rent your personal data to third parties.
- Legal Basis for Processing
For customers in the EU, processing is based on GDPR legal grounds:
- Contractual necessity: to fulfill your order or provide a requested service.
- Consent: for marketing communications or restock notifications.
- Legal obligation: to comply with EU and Belgian law.
- Legitimate interest: to improve our services, prevent fraud, or ensure the security of our website.
For customers outside the EU, we process your data under similar principles (contractual necessity, consent, and legitimate interest) but without the direct application of GDPR rights, unless required by local law.
- Data Sharing
- Your data may be shared with trusted third-party service providers (e.g., payment processors, shipping companies, IT service providers) strictly for the purpose of carrying out our business activities.
- For EU customers, your data is not transferred outside the European Union unless adequate safeguards (such as Standard Contractual Clauses) are in place.
- For non-EU customers, your data may be transferred internationally in order to complete your order (e.g., shipping to your country). We ensure that any such transfers are handled securely and only to the extent necessary.
- Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy:
- Customer and order data: up to 10 years, to comply with legal and tax requirements in Belgium.
- Marketing data: until you withdraw your consent or unsubscribe.
After these periods, your data will be securely deleted or anonymized.
- Your Rights
- For EU customers: You are fully covered by GDPR and have the following rights: access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
- For non-EU customers: While GDPR does not legally apply, we extend similar options where reasonably possible, such as unsubscribing from marketing and requesting correction or deletion of your data.
To exercise any of these rights, please contact us (see Section 8).
- Security Measures
We take appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These include encryption, access controls, and secure storage systems.
- Contact Information
If you have any questions, requests, or complaints regarding this Privacy Policy or how we process your personal data, please contact us:
IIC BV / Gillio
Breedveld 2, Unit 7
1651 Lot (Beersel)
Belgium
???? +32 (0)2 380 63 19
✉️ helpdesk@gillio.eu
- EU residents may also lodge a complaint with their national Data Protection Authority (DPA).
- Non-EU residents should contact their local supervisory authority, if applicable.
