Free delivery on orders over €60
Privacy Policy
Article 1: Definitions
"Personal Data": any information relating to an identified or identifiable natural person, as defined by Regulation (EU) 2016/679 of 27 April 2016 and any other subsequent equivalent regulation. "Processing Purpose": refers to the objectives pursued by the Processing of Personal Data implemented by the Controller. "Applicable Data Protection Laws" or "Applicable Laws": refers to Law n°78-17 of 6 January 1978 relating to data processing, files and freedoms, as amended by Law n°2004-801 of 6 August 2004 relating to the automated processing of personal data, by the Law for a Digital Republic n°2016-1321 of 8 October 2016, as well as the General European Data Protection Regulation (EU) 2016/679 and Law n°2018-493 of 20 June 2018 relating to the protection of personal data and any other subsequent equivalent regulation, and/or any applicable and in force law or regulation relating to data protection. "Third Country": refers to any country not belonging to the European Union and not having adequate legislation concerning the processing of Personal Data as decided by the European Commission. "Data Controller": refers to the company UNBRANDED SKINCARE, a simplified joint stock company, registered with the Trade and Companies Register of PARIS under SIREN number 939 678 207, whose registered office is located at 60 rue François 1er, in PARIS (75008). "Processing": any operation or set of operations, whether or not carried out using automated processes and applied to data or sets of Personal Data, such as, for example, the collection, recording, organization, structuring, storage, communication by transmission, dissemination, extraction, consultation of Personal Data and defined by Regulation (EU) 2016/679 of 27 April 2016 and any other subsequent equivalent regulation. "Processor": refers to the third party who processes Personal Data on behalf of the Data Controller. "User": refers to the natural person whose Personal Data is collected to be processed hereunder.
Article 2: Purpose
This privacy policy (hereinafter the "Policy") applies to the Processing implemented by the Data Controller on the website www.unbranded-skincare.com (hereinafter referred to as the "Site"). The Data Controller undertakes to comply with the Applicable Data Protection Laws. 2 Personal Data is processed lawfully, fairly and transparently. The Personal Data collected is adequate, relevant and limited to what is strictly necessary with regard to the Processing Purposes.
Article 3: Purposes of Personal Data Processing
The Data Controller collects the User's Personal Data for:
- Monitoring and managing contact requests submitted via the contact form;
- Monitoring, managing, and executing orders placed on the Site by the User;
- Sending newsletters to the User containing information about the services offered by the Data Controller;
- Conducting statistical studies to improve the operation of the Site;
- Managing User's requests for access, rectification, and opposition rights.
- Performing the User's skin diagnosis and generating their personalized Skin Report, based on their responses to the questionnaire and the algorithmic analysis of the image of their face voluntarily provided; and, subject to the User's explicit consent, retaining their skin profile to send them product recommendations and personalized content adapted to their skin type.
Article 4: Personal Data Collected
The User is informed that the Data Controller collects and processes their Personal Data, including:
- For monitoring and managing contact requests submitted via the contact form: title, surname, first name, email address, and any data transmitted by the User;
- For monitoring and managing orders placed on the Site: title, surname, first name, email address, postal address, cosmetic preferences, skin type, and any exchanged data transmitted by the User and, where applicable, the User's date of birth and bank details; - For sending newsletters: surname, first name, email address;
- Data collected related to the User's navigation on the Site: IP address, pages viewed, abandoned shopping cart, location, advertisements on which the User clicked;
- When the User makes a request to exercise their rights: identity data, the purpose of the request, the email address;
- When the User's data is collected for statistical purposes: IP address, browser type, session data, and the User's operating system.
- When the User requests a skin diagnosis: surname, first name, email address, data relating to skin type, cosmetic preferences, and lifestyle habits;
Article 5: Retention Periods for Personal Data
The Data Controller will retain Personal Data for the period necessary for the purposes for which it was collected and processed: - For the monitoring and management of contact requests: for three (3) years from the receipt of the User's contact request, if it does not lead to the conclusion of a contract; - For the monitoring, management and execution of orders: for the duration of the contract. The data is then archived for the legal prescription periods applicable to each data (e.g. 5 years for customer data and proof of contract existence, 10 years for invoices and accounting documents); - For sending newsletters: for three (3) years from the User's last active contact (= newsletter subscription). If the User unsubscribes from the newsletter, the data is immediately deleted; - For the statistical study of Site traffic: for one (1) year from the User's visit to the Site for cookies and tracers and for two (2) years from their collection for data derived from said cookies and tracers; - To respond to the User's requests for the exercise of rights: for one (1) month from the receipt of the request, plus a period equivalent to any suspension of the legal response period, in the event of an incomplete User request. The data is then archived for five (5) years, for evidentiary purposes; - For skin diagnosis and skin profile management: for six (6) months from the User's skin diagnosis request, subject to their explicit consent; - For online payment of an order: banking data is deleted once the transaction is completed or archived for evidentiary purposes in accordance with the provisions in force. Subject to the User's explicit agreement, their banking data – with the exception of the visual cryptogram – may be kept until the expiration date of their bank card. At the end of these active or archived retention periods, the collected personal data will be deleted.
Article 6: Legal Basis for Processing Personal Data
The Data Controller processes Personal Data on a precisely identified legal basis, namely: - The legitimate interest of the Data Controller in processing Personal Data; - The execution of pre-contractual measures or the contract that the Data Controller has concluded with the User, when a contractual relationship has been established; - Compliance with legal obligations, particularly when managing invoicing or managing requests for the exercise of rights; - The User's free, informed, explicit and unambiguous consent.
Article 7: Commitments of the Data Controller
The Data Controller undertakes to:
- Process Personal Data solely for the Processing Purposes described above;
- Process Personal Data in accordance with Applicable Laws;
- Guarantee the confidentiality of Personal Data by taking all appropriate technical and organizational measures to (i) prevent unauthorized access to Personal Data, (ii) perform identity and access controls via an authentication system and a password policy, (iii) opt for an authorization management system and (iv) processes and devices enabling the tracking of all actions performed on its information system and to perform, in accordance with applicable regulations, reporting actions in the event of an incident impacting Personal Data;
- Ensure that persons authorized to process Personal Data undertake to respect confidentiality or are subject to a confidentiality obligation and receive the necessary training in Personal Data protection;
- Take into account, with regard to its tools, applications or services, data protection principles, from the design stage;
- Erase, anonymize or archive Personal Data after the retention period. The Data Controller will in no case be responsible for security incidents related to the use of the Internet, particularly in the event of loss, alteration, destruction, disclosure or unauthorized access to User data or information.
Article 8: Processors/Transfers of Personal Data
The User accepts that their Personal Data collected by the Data Controller may be transmitted to the Processors/Service Providers with whom it has a contractual relationship solely for the purposes of executing the aforementioned Processing Purposes, provided that these third-party recipients of Personal Data are subject to regulations guaranteeing an appropriate and adequate level of protection, as defined by the Applicable Laws. In the event of transfer of all or part of the Personal Data subject to Processing to a Third Country or to an international organization, the Data Controller undertakes to provide appropriate safeguards, in accordance with Applicable Laws, and to ensure that its Processors comply with them. In no case does the Data Controller sell, rent, or otherwise use, other than for the aforementioned Processing Purposes, the Personal Data it receives. The disclosure of Personal Data to third parties is carried out by the Data Controller only for the purposes of executing the Processing Purposes and to third parties acting as Processors under the conditions referred to herein.
Article 9: User's Exercise of Rights
The following rights are guaranteed to the User by the Data Controller: right of access, rectification, erasure and opposition, right to restriction of processing, right to data portability, right not to be subject to automated individual decision-making (including profiling). 5 The User can obtain a copy of their Personal Data, upon written request addressed to the Data Controller. By sending a written request, and at any time, the User can obtain a correction or deletion of their Personal Data, within the limits of the Data Controller's rights. Any request must be addressed to the Data Controller in writing at the postal address or the following e-mail address: - E-mail address: hello@unbranded-skincare.com ; - Postal address: UNBRANDED SKINCARE, 60 rue François 1er, in PARIS (75008). If the User considers that the Data Controller has not respected their rights regarding Personal Data protection, they can file a complaint with the CNIL.
Article 10: Privacy Policy Update
The Data Controller regularly updates this Policy, which remains available on the Site at all times.