Privacy policy
PRIVACY POLICY
Last updated on 2025-08-21
Please read this Privacy Policy (hereinafter referred to as the “Policy”) carefully as it contains important information regarding how, when, and why ROCOCO CO. LTD collects, uses, and stores your personal data, with whom it may share it, as well as to inform you about your rights as a data subject and the measures taken to protect your personal data, in connection with ROCOCO CO. LTD’s processing over its website, products and services.
Accessing and/or using ROCOCO CO. LTD website, products, and services by any person imposes the obligation to comply with the provisions set forth in the Terms and Conditions.
The website https://haku-clothing.live/ (hereinafter referred to as the “Website”) is owned and managed by ROCOCO CO. LTD, a company incorporated by Japan laws, headquartered at 1-8-8 Bakuromachi, Chuo-ku, Osaka-shi, Osaka, Japan.
1. APPLICABILITY
This Policy regarding the processing of personal data only applies to the processing activities performed by ROCOCO CO. LTD and shall be complemented with the Terms and Conditions and the Cookie Policy.
The Website may contain information about or links to other websites that are outside ROCOCO CO. LTD custody and/or control. Carefully read and review the privacy policies of each of those websites when you browse on them to get an understanding of how your personal data is being used and shared by those third-party websites.
2. DEFINITIONS
The terms used within this Policy have the same meaning as those mentioned in Terms and Conditions, unless otherwise mentioned in this Policy.
-
“Haku Clothing”, "we”, “us” or “our” means ROCOCO CO. LTD and any of its affiliates that are providing the Website, products and services.
-
“Users” means any natural person or any customer’s employees, representatives, consultants, contractors, or agents who are using the Services for customer’s benefit.
-
“You” or “your” means current or potential customer of Haku Clothing, as a User of the Website, products and services provided by Haku Clothing.
-
“Services” means all of our web-based websites (including this website), applications, tools and platforms that you have subscribed to or that we otherwise make available to you, and are developed, operated, and maintained by us, accessible via the Website or another designated URL,
-
“Personal data” means any information relating to an identified or identifiable natural person;
-
“Processing” means any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
-
“Processing activity(ies)” means one or more operations that relate to one of the different stages that the processing of personal data may involve.
-
“Controller” means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data. For the purposes of this Policy, Haku Clothing acts as Controller.
-
“Data subject” means an identified or identifiable natural person. An identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
-
“Consent” of the data subject means any freely given, specific, informed and unambiguous indication of the user's wishes by which he or she, by a statement or by a clear affirmative action, signifies agreement to the processing of personal data relating to him or her.
3. COLLECTING PERSONAL DATA
In general, the personal data we process is collected directly from you, as a data subject. However, there may be situations where your personal data is collected indirectly from social media, from the website of the company you represent, from your employer as a contact person, from a third party who recommended you or from various public platforms (for example ad platforms).
When we, as the Controller, do not receive the personal data directly from you, we will inform you within the legal term about our processing of your personal data.
If you provide us with personal data belonging to other individuals (for example, colleagues), you have the responsibility to make sure you have obtained prior approval from those persons for sharing their data with us.
4. CHILDREN AND SPECIAL DATA
Our Website and Services are not directed at children. We do not knowingly or intentionally collect personal data from children who have not reached the level of maturity in their country and who are not able to assume obligations in accordance with the applicable legislation.
If you are the holder of parental responsibility of a child who has not reached the level of maturity in the country of residence and you believe your child has provided us with personal data, please contact us to request the erasure of their personal data and we will act upon your request in accordance with the legal requirements.
We do not collect nor is our intention to collect personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation, or personal data relating to criminal convictions and offences or related security measures, excepting the situations expressively regulated by the law.
5. PRICESSED PERSONAL DATA, PURPOSES, LEGAL GROUNDS AND RETENTION PERIODS
Below you will find information about the purposes for which we process your personal data, the categories of personal data we collect for those purposes, the legal grounds on which we carry out the processing activities and the periods of time we store the personal data in relation to the purposes of the processing.
We will inform you and, where the lawful basis is your consent, we will ask for you freely-given consent if we intend to process your personal data for a new purpose that is materially different from that for which the personal data was initially collected.
Where the lawful basis for the processing is your consent, you may withdraw it at any time without constraint and without affecting the lawfulness of the processing prior to its withdrawal.
You may refuse to provide part or all of your personal data. Certain personal data are essential to fulfill the purposes below and your refusal to provide necessary information may result in our impossibility to deliver the products and services requested.
Depending on the nature of our relationship or interaction, we will process your personal data for the following purposes:
5.1. Purpose: Create an account on our website to improve your shopping and browsing experience with us.
Personal data categories: First name, last name, e-mail address.
Legal basis: The processing of your personal data is based on the performance of the contract represented by the Terms of Use accepted by you when signing up to create an account.
Retention period: We generally store your personal data for as long as you are a registered user of our website.
5.2. Purpose: Facilitate post purchase communication through your account and allow you to easily find information that you chose to save or about your past purchases to ensure a good customer experience and increase sales.
Personal data categories: First name, last name, e-mail address, order status, location, expected delivery time, delivery method, order reference number, order history.
Legal basis: The processing of your personal data is based on the performance of the contract represented by the Terms of Use accepted by you when signing up to create an account.
Retention period: We generally store your personal data for as long as you are a registered user of our website.
5.3. Purpose: Provide you rewards for shopping with us to increase revenue and brand loyalty.
Personal data categories: First name, last name, e-mail address, order history, point history, delivery address, membership rank, available points, number of orders for rank calculation, points to be granted.
Legal basis: The processing of your personal data is based on the performance of the contract represented by the Terms of Use accepted by you when signing up to create an account.
Retention period: We generally store your personal data for as long as you are a registered user of our website.
5.4. Purpose: Analyze your purchase patterns to identify buying preferences, peak shopping times, and repeat purchase rates to increase sales.
Personal data categories: E-mail address, order history, device identification, device’s network location data (such as country), data related to your interaction with the website.
Legal basis: The processing of your personal data is based on your freely expressed consent.
Retention period: Personal data will be processed until you withdraw your consent, after which the data will be deleted where there is no other legal ground for the processing. You can withdraw your consent to the processing at any time, by opt-out of cookies, without affecting the legality of the processing based on the consent before withdrawal.
5.5. Purpose: Use existing customer data to create lookalike audiences to reach new customers who are likely to be interested in our products and services.
Personal data categories: E-mail address.
Legal basis: The processing of your personal data is based on your freely expressed consent.
Retention period: Personal data will be processed until you withdraw your consent, after which the data will be deleted where there is no other legal ground for the processing. You can withdraw your consent to the processing at any time, by opt-out of sharing data with social media platforms, without affecting the legality of the processing based on the consent before withdrawal.
5.6. Purpose: Inform you electronically about promotions, offers, or similar promotional activities, and any other information related to our products and services that we think you may be interested in (e.g., new blog posts) to increase sales.
Personal data categories: E-mail address, birthday.
Legal basis: The processing of your personal data is based on your freely expressed consent or our legitimate interest if the case, to send you direct marketing and information that we think you may be interested in.
Retention period: Personal data will be processed until you withdraw your consent or object to the processing, after which the data will be deleted where there is no other legal ground for the processing. You can withdraw your consent or object to the processing at any time, by clicking Unsubscribe/Opt-out at the bottom of any of our emails, without affecting the legality of the processing based on the consent or our legitimate interest before withdrawal or objection.
5.7. Purpose: Answer requests and provide assistance and support related to our products and services to stimulate customer satisfaction.
Personal data categories: Name, e-mail address, and any other personal data that you choose to include in the message.
Legal basis: The processing of your personal data is performed considering our legitimate interest to communicate with you and provide our support in solving your requests that arise from using/accessing our products and services, and to maintain and promote your satisfaction.
Retention period: Personal data will be stored for a period of seven years from your request.
5.8. Purpose: Accepting, managing and fulfilling customer orders to ensure that the requested products and services are delivered accurately and on time.
Personal data categories: First name, last name, e-mail address, address, postal code, city, county, country, phone, payment method, discount code (if the case), number of loyalty points. Payment details you provide will be encrypted using secure sockets layer (SSL) technology before they are submitted to us over the internet, order reference number, product name. We do not retain or store your credit card information. Your credit card details are passed to our third-party payment providers from time to time. You will be providing credit or debit card information directly to such payment provider which acts as an autonomous data controller and operates a secure server to process payment details, encrypting your credit/debit card information and authorizing payment.
Legal basis: The processing of your personal data is based on the performance of the contract represented by the Terms of Use accepted by you when placing the order on the website.
Retention period: Personal data will be stored for a period of seven years from the date of order.
5.9. Purpose: Handle returns and exchanges to build customer loyalty, preserve brand reputation, boost sales and profitability.
Personal data categories: Name, order ID, e-mail address, return product name, reasons for return, and any other personal data that you choose to include in the ‘Details’ section.
Legal basis: The processing of your personal data is based on the performance of the contract represented by the Refund Policy when confirming the Return Request Form.
Retention period: Personal data will be stored for a period of seven years from the date of order.
5.10. Purpose: Manage contests, sweepstakes, promotions, rewards or surveys to boost sales, improve brand awareness, and help acquire new customers.
Personal data categories: Name, e-mail address, personal preferences and personal views, photos, videos or other media or content.
Legal basis: The processing of your personal data is based on the performance of the contract represented by the Terms of Use when you are registering for contests, sweepstakes, promotions, rewards or surveys or when placing the order on the website.
Retention period: Personal data will be stored for a period of seven years from the date of organizing the promotional strategies.
5.11. Purpose: Collect your feedback about us or our products and services through satisfaction surveys in order to help us improve our products and services.
Personal data categories: Product name, nickname of your choice, approximate height and weight, usual size, usual shoe size, fitting, and any other personal data included in the review.
Legal basis: We rely on your freely expressed consent when you voluntary fill out our review form. You can withdraw your consent at any time, without affecting the legality of the processing based on consent before its withdrawal.
Retention period: Personal data will be stored for as long as we have your consent until withdrawal, in which case data will be deleted. However, we can proceed to the deletion of personal data when we decide that it is no longer relevant for achieving the purpose.
5.12. Purpose: Post your review on the website to build trust and credibility with potential customers and increase sales.
Personal data categories: Product name, nickname of your choice, approximate height and weight, usual size, usual shoe size, fitting, and any other personal data included in the review.
Legal basis: We rely on your freely expressed consent when you voluntary fill out our review form. You can withdraw your consent at any time, without affecting the legality of the processing based on consent before its withdrawal.
Retention period: Personal data will be stored for as long as we have your consent until withdrawal, in which case data will be deleted. However, we can proceed to the deletion of personal data when we decide that it is no longer relevant for achieving the purpose.
5.13. Purpose: Ensure functionality and security of our website, perform checks and technical support, prevent and identify frauds.
Personal data categories: First name, last name, email, IP address and log files.
When using the website, we also collect and process data such as: device identification, device’s network location data (such as country), data related to your interaction with the website, such as the sections visited and the number of clicks and scrolls.
Legal basis: Processing of your personal data is performed considering our legitimate interest to protect your personal data and to monitor and improve the information security of our products or services.
Retention period: We generally store your personal data for 3 (three) years, after which your data will be deleted.
In addition to the purposes mentioned above, we may process your personal data for the purpose of fulfilling our legal obligations under the laws governing our activity, including those regarding equal opportunities and non-discrimination, ensuring physical and IT security and protecting whistleblowers in the public interest. In these situations, the categories of data processed and the data storage periods are determined according to the applicable legal provisions.
Your data may also be processed, based on the legitimate interest of the Controller, for the purpose of exercising or defending a right or legitimate interest in a judicial, administrative or similar procedure, in which the Controller is involved or to respond to requests from public authorities, courts and tribunals or criminal investigation and prosecution bodies, based on and within the legal obligations the Controller is subject to. The categories of data processed and the storage periods are determined on a case-by-case basis, depending on the applicable legal procedures and provisions.
At the end of the retention periods specified above, personal data will be deleted or anonymized, as applicable to the specific situation.
6. TRACKING TECHNOLOGIES
Our website uses cookies, plug-ins and other online identifiers (collectively referred to as “cookies”) in order to ensure functional browsing or to provide a better browsing experience, to perform statistical analysis regarding accessed information, or to provide you with custom content and advertising appropriate to your preferences and interests.
Detailed information regarding the cookies we use may be found in our Cookie Policy.
7. AUTOMATED DECISION MAKING, INCLUDING PROFILING
We do not make decisions based solely on automated processing, including profiling, which produces legal effects concerning you or similarly significantly affects you.
8. DISCLOSURE AND TRANSFER OF PERSONAL DATA
We may transfer your personal data, to the extent that this is necessary, to the following categories of recipients: service partners, subcontractors, payment providers, courier service providers, archiving companies, IT service providers, software or hardware vendors, market research companies, marketing companies, public authorities, court or arbitral tribunals, as well as competent authorities to investigate criminal offenses.
Personal data may be disclosed or transferred to the categories of recipients mentioned above in order to provide our Services at the highest quality level, ensure the intervention of specialists by outsourcing parts of our business or to provide access to services and benefits according to our business partnerships, or to ensure compliance with the specific legal obligations to which we are subject according to the activity carried out.
In the event that personal data is transferred to third countries we will apply the technical and organizational measures required by law and we will inform you about the transfer in accordance with the legal requirements.
9. SECURITY OF PERSONAL DATA
The security of your personal data is important to us. Therefore, we maintain a variety of appropriate technical and organizational measures to protect your personal data from loss, misuse, and unauthorized access or disclosure. We limit access to personal data to employees or contractors who we believe reasonably need to retrieve that information to provide our Services. Considering the current state of technology, we have implemented reasonable physical, technical and procedural safeguards designed to protect your personal data, such as limiting access, encrypting, anonymizing, or storing it on secure media.
It is very important that you, as a data subject, know the risks and take the measures to protect your personal data, for example by checking the sources of information, avoiding access to suspicious or unknown links, regularly changing passwords and using appropriate anti-virus and anti-malware solutions.
10. YOUR RIGHTS AND HOW TO EXERCISE THEM
The law grants data subjects enforceable and effective rights concerning their personal data which can be exercised under particular conditions.
You have the following rights regarding your personal date:
-
Right to be informed: You have the right to be informed regarding the processing of your personal data, as we are doing through this Policy.
-
Right of access: You have the right to obtain confirmation whether or not we process your personal data, as well as information on the specifics of the processing activities, and get access to that personal data.
-
Right to rectification: You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you. Taking into account the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.
-
Right to erasure: You have the right to obtain from us without undue delay the erasure of your personal data, to the extent that the legal requirements are met. Personal data will be erased when the legal requirements are met.
-
Right to restriction of processing: If the applicable legal provisions are met, you have the right to obtain the restriction of processing of your personal data.
-
Right to data portability: If the applicable legal provisions are met, you have the right to receive your personal data which you have provided to us, in a structured, commonly used and machine-readable format, and the right to transmit those data to another Controller.
-
Right to object: In certain situations, such as when we process personal data based on legitimate interest, you have the right to object to the processing of your personal data. In the event of unjustified opposition, as Controller we are entitled to further process your personal data.
-
Right to object to commercial communication: You may also object to the processing of your personal data for the purpose of sending commercial messages.
-
Right not to be subject to decisions based solely on automated processing, including profiling: If the applicable legal provisions are met, you have the right not to be subject to a decision based solely on automatic processing, including profiling, which has legal effects on you or affects you similar to a significant extent.
-
Right to Opt-Out of Sale or Sharing of Personal Data: If we sell your personal data to third parties or share it with third parties for cross-context behavioral advertising, you have the right, at any time, to stop us from selling or sharing your personal data.
-
Right to address to the Supervisory Authority: You have the right to file a complaint with the competent Supervisory Authority on any violation of your rights regarding the processing of your personal data. If you want to contact the Supervisory Authority from your place of residence in EU, you may find the contact details at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
-
Consent withdrawal: To the extent that we process your personal data based on your given consent, you can withdraw your consent at any time, without affecting the lawfulness of the processing based on the consent prior to its withdrawal.
-
Right to No Retaliation: If you choose to exercise any of these rights, we will not discriminate against you in any way. However, if you exercise certain rights, understand that you may be unable to use or access certain features of our websites or services, or we may be unable to execute the employment or collaboration agreement with you.
Except for the right to contact the Supervisory Authority, which you can exercise using the contact details indicated above, you can exercise your legal rights by contacting us by e-mail at info@haku-clothing.live.
We will respond to your requests without undue delay and in any case within one month of receiving the request. This period may be extended by two months where necessary, taking into account the complexity and number of requests. We will inform you of any such extension within one month of receiving your request, stating the reasons for the delay.
In the event that we do not take action on your request, we will inform you, without undue delay and no later than one month after the receipt of your request, of the reasons for not taking action. In such a case, you have the possibility to lodge a complaint with the competent Supervisory Authority or to take a legal action.
11. UPDATES
This Policy is subject to periodic reviews and updates to ensure that it always corresponds to reality, and it is in line with the applicable legal requirements. For this reason, please regularly consult this Policy to keep up to date with any changes. Any major changes to this Policy will be notified accordingly.
12. CONTACT
If you have any questions or concerns regarding the processing of your personal data, this Policy or how it applies, or you wish to exercise any of your rights, you can contact us by e-mail at: info@haku-clothing.live.

