the company salut beauté, whose registered office is located at 5 avenue de bretteville 92200 neuilly-sur-seine, in its capacity as data controller within the meaning of the regulations in force regarding the protection of personal data, attaches great importance importance to the protection and respect of your privacy.
this document is intended to inform you about the categories of personal data that we may collect or hold about you, how we use it, with whom we share it, how we protect it, and the rights you have over your personal data.
1. the data we collect
by using the site, you are required to send us information, some of which is likely to identify you and therefore constitutes personal data (hereinafter the "data"). this is particularly the case when you register on the site, during your first connection.
this information contains in particular the following data:
registration data : means the basic data necessary for your registration on the site in order to be able to place an order for our products. these data are transmitted directly by you, by filling in the form dedicated to this purpose. these data are as follows:
- your last name;
- Your first name;
- your email;
- a personal and confidential password.
data necessary for the execution of your order : refers to the information we need to execute your order and deliver our products to you. these data are as follows:
- address and postal code;
- company name (optional);
- telephone number.
- transaction data : means the data you provide when you make purchases through our site, such as information relating to your means of payment. the bank data collected is transmitted to partner payment service providers who help to process your transactions securely and to meet your requests.
- data relating to navigation : refers to the data that we collect during your navigation on the site such as in particular the date, the time of the connection and/or navigation, the type of browser you use, the language of the browser, your IP address.
in the event that you connect to our services using the social network functionalities made available to you, we will have access to some of your account data on said social network in accordance with the general conditions of use of the social network concerned. we are also likely to collect some of your data, when you interact with functionalities of these social networks, such as the "like" functionalities.
when collecting data, you will be informed if certain data must be provided or if it is optional.
2. how do we use the data we collect?
we use the aforementioned data for the purposes listed below, and according to the following legal bases:
create and manage your account on the site.
execution of a contract
manage the commercial relationship (invoicing, delivery, after-sales service, product returns, etc.)
execution of a contract
send you our newsletters as well as marketing or advertising messages or content.
improve and optimize our services and allow us to better understand our users and how our services are used.
legitimate interest of hi beauty
manage our site and carry out internal technical operations within the framework of the resolution of malfunctions, data analysis, tests, research, analyses, studies, surveys.
legitimate interest of hi beauty
when the processing of your data is based on consent, you can withdraw it at any time.
salut beauté may also need to process your data in response to a legal or judicial request (court order or other) or to comply with its legal, regulatory, judicial or administrative obligations.
finally, salut beauté can process your data to detect or prevent fraudulent activities or breaches of the security of our services, in application and in compliance with legal and regulatory provisions, or even analyze reports of users who have behaved in contravention of our general conditions of sale.
3. Who are the recipients of the data we collect and for which seasons do we send them this data?
3.1 data transferred to public authorities and/or bodies
in accordance with the regulations in force, your data may be transmitted to the competent authorities on request and in particular to public bodies, court officers, ministerial officers, bodies responsible for collecting debts, exclusively to meet legal obligations , as well as in the case of the search for the perpetrators of offenses committed on the Internet.
3.2 data transferred to third parties
we work closely with third-party companies that may have access to your data, and in particular with:
- our technical service providers (subcontractors) whom we use for the purpose of operating and improving our services, in particular concerning data hosting, studies, analyzes and statistics, the use of our site and/or the proper functioning of the site and provide the necessary assistance to its users.
we only provide these third parties with the data they need to perform their services, and we require that they do not use your data for any other purpose.
these third parties only act in accordance with our instructions and are contractually bound to ensure a level of security and confidentiality of your data identical to that which we guarantee to you, in accordance with the GDPR.
4. how long do we keep your data?
in this respect, your data is kept:
- for the duration of your registration on our site;
- in any case, for a period of 3 years from the suspension / termination of your account;
- for the legal period of 13 months for cookies and other tracking technologies that we use to optimize the use of our site.
your data is erased when the retention periods expire. nevertheless, your data may be archived beyond the durations provided for above for the defense of our interests in court and for the purposes of research, observation and prosecution of criminal offenses for the sole purpose of allowing, as necessary, the provision of your data to the judicial authority.
archiving implies that your data will no longer be available online but will be extracted and stored on an independent and secure medium.
5. is your data transferred, how and where?
in principle, your data is securely hosted within the European Union and is not transferred outside the territory of the European Union.
however, in the event that we are required to transfer them (for example to technical service providers) outside the European Union, we will always do so in a secure manner and in accordance with the regulations in force:
- either by transferring the data to a recipient located in a country that has been the subject of an adequacy decision by the European Commission certifying that it has an adequate level of protection;
- either by executing or having executed the European standard contractual clauses which have been approved by the European Commission as ensuring an adequate level of protection for your data;
- either through the use of binding internal corporate rules validated by the competent data protection authorities;
- or by using all appropriate guarantees referred to in Article 46 of the GDPR.
6. how is your data protected?
we take appropriate technical and organizational measures to prohibit unauthorized access to or modification, disclosure, loss or destruction of your data. it is important that you preserve the confidentiality of your identifiers in order to prevent unlawful use of your account, in accordance with our general conditions of sale .
7. what are your rights over your data?
In accordance with applicable laws and regulations on the protection of personal data, you have a number of rights relating to your data, namely:
- a right of access and information : you have the right to be informed in a concise, transparent, intelligible and easily accessible manner of how your data is processed. you also have the right to obtain (i) confirmation that data concerning you is being processed and, where applicable (ii) to access this data and obtain a copy thereof.
- a right of rectification : you have the right to obtain the rectification of inaccurate data concerning you. you also have the right to complete incomplete data concerning you, by providing an additional declaration. in the event of exercise of this right, we undertake to communicate any rectification to all the recipients of your data.
- a right of erasure : in certain cases, you have the right to obtain the erasure of your data. however, this is not an absolute right and we may for legal or legitimate reasons retain such data.
- a right to limit processing : in certain cases, you have the right to obtain the limitation of processing of your data.
- a right to data portability : you have the right to receive your data that you have provided to us, in a structured, commonly used and machine-readable format, for your personal use or to transmit it to a third party of your choice. this right only applies when the processing of your data is based on your consent, on a contract or when this processing is carried out by automated means.
- a right to object to processing : you have the right to object at any time to the processing of your data for processing based on our legitimate interest, and those for commercial prospecting purposes. this is not an absolute right and we may for legal or legitimate reasons refuse your request for opposition.
- the right to withdraw your consent at any time : you can withdraw your consent to the processing of your data when the processing is based on your consent. the withdrawal of consent does not affect the lawfulness of the processing based on the consent given before this withdrawal.
- the right to file a complaint with the CNIL : you have the right to contact the CNIL to complain about our personal data protection practices, if applicable.
- the right to give instructions concerning the fate of your data after your death : you have the right to give us instructions concerning the use of your Data after your death.
To exercise these rights, you can contact us at the following address: firstname.lastname@example.org .
note that we may require proof of your identity to exercise these rights.
we may occasionally modify this policy, in particular to comply with any regulatory, jurisprudential, editorial or technical developments. where appropriate, we will change the “last updated” date and indicate the date on which the changes were made. When necessary, we will inform you and/or seek your consent. We advise you to check this page regularly to take note of any changes or updates to our policy.
for any question relating to this policy or for any request relating to your data, you can contact us by sending an e-mail to the following address: email@example.com .
version updated on February 22, 2021.