PRIVACY POLICY
This privacy policy (“Privacy Policy”) aims to provide information on the purposes and conditions under which personal data are processed in connection with the use of the Website.
Within the scope of its activities, LBD is committed to protecting the confidentiality of the information in its possession in accordance with the General Data Protection Regulation No. 2016/679 of 27 April 2016 (“GDPR”) and the French Data Protection Act No. 78-17 of 6 January 1978 as amended, under the supervision of the Commission Nationale de l’Informatique et des Libertés (“CNIL”), the French authority responsible for the protection of personal data.
1. COLLECTION, USE AND RETENTION OF DATA
Privacy policy of the website www.agamy-happyhairday.com (hereinafter: the “Website”), published by the company LA BROSSE ET DUPONT (hereinafter “LBD”), identified in the “Legal notice” section, acting as the data controller for the processing of personal data carried out on the Website.
1.1 DATA COLLECTION
LBD collects certain personal data from you, in particular through the “contact” and “my account” sections of the Website, for your product orders or when you take part in a competition organised on the Website and/or subscribe to the newsletter.
Personal data are defined as “any information relating to an identified or identifiable natural person; an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier, or to one or more factors specific to their physical, physiological, genetic, mental, economic, cultural or social identity.”
If you provide LBD with personal data that you have directly or indirectly collected from another person, it is your responsibility to have collected and processed such data in compliance with the obligations imposed on you by applicable legal and regulatory provisions on data protection.
1.2 DATA COLLECTED
The personal data that may be collected by LBD on the Website are:
- your first name, surname, email address, delivery postal address, billing postal address, telephone number, payment data,
- the information you provide in messages sent via the Website, as well as the choices you make on it (registration, unsubscription, etc.);
- information on your use of the Website recorded via cookies or other trackers: your IP address, internet service provider, type of browser used, operating system, pages visited on the Website, date and time of access, or behavioural data relating to the analysis of your actions and choices on the Website.
1.3 PURPOSES AND LEGAL BASES
LBD uses your personal data only within the limits authorised by the applicable regulations and in accordance with the legal bases provided by the GDPR.
When you voluntarily provide personal data about yourself, you undertake to provide accurate information that does not harm the interests or rights of third parties. You guarantee its truthfulness and completeness and will be solely responsible for any error, omission, failure or update.
The information you provide on the Website enables LBD to:
- create and manage your account on the Website;
- provide the services or information requested;
- execute your product order and delivery;
- manage the payment of the said products;
- send you personalised communications and LBD’s newsletter by email;
- register and manage your participation in a competition;
- ensure that the content of the Website is presented in the most effective way for you and for the internet connection you use;
- produce anonymous statistics on Website activity to measure, in particular, the satisfaction and quality of services offered and thus improve and optimise the Website;
- manage the security of the Website.
The processing carried out by LBD on the Website is:
- necessary to enable LBD to comply with:
- its contractual obligations (in particular, tracking your product orders),
- its legal obligations (in particular, handling requests to exercise data subject rights), or
- necessary and serves the legitimate interests of LBD without overriding your own interests (in particular, processing to manage and improve the Website or to ensure its security).
Other processing is subject to your consent (in particular, participation in competitions and subscriptions to newsletters).
You may, at any time, withdraw your consent to receive newsletters from LBD by clicking on the unsubscribe link or by exercising your right to object under the conditions of Article 2.1.
In the same way and under the same conditions, you may object to personalised email communications that may be sent to you by LBD following an order on the Website relating to similar products and/or services.
LBD undertakes not to process your data for purposes and/or on legal bases other than those provided herein without having previously informed you and, where required, obtained your consent.
1.4 COOKIES
The Website uses cookies. Cookies are trackers that are placed and/or read, for example when visiting a website, and stored in the browser you use. They contain data relating to your connections, in particular the name of the server that wrote them, most often a unique identifier number and an expiry date. They enable the Website to recognise your browser, computer and/or mobile device on each of your visits.
Below is the list of cookies used on the Website, their purpose and how to disable them.
FUNCTIONAL COOKIES:
These cookies improve the quality of browsing on the Website, in particular by saving your preferences expressed during the visit. The information collected via these cookies is anonymous and does not allow you to be identified.
AUDIENCE MEASUREMENT COOKIES:
These cookies are used by the Website to perform measurements strictly necessary for the proper administration of the Website and to produce anonymous statistics. They make it possible to recognise visitors to the Website, count them and identify how they move around the Website when using it. This improves the functioning of the Website, for example by ensuring that users easily find what they are looking for.
These cookies are used only in the configuration validated by the CNIL (https://www.cnil.fr/sites/default/files/atoms/files/matomo_analytics_-_exemption__guide_de_configuration.pdf), for which your consent is not required.
TARGETING COOKIES:
Subject to your prior acceptance, these cookies allow targeted advertising to be sent to you based on your interests. They are used in particular to limit the number of times you see an advert and to help measure the effectiveness of an advertising campaign. Refusing these cookies does not affect the use of the Website. However, refusing them will not stop advertising on the Website or on the internet. It will only result in showing adverts that are not tailored to your interests or preferences. These cookies are mainly third-party cookies and depend on advertising networks.
COOKIES ALLOWING THIRD PARTIES TO PROVIDE SOCIAL SHARING TOOLS:
Subject to your prior acceptance, when you use one of the sharing buttons on the Website, a cookie may be installed by the relevant social network in order to instantly share content on that social network. The Website does not block social network cookies and has no control over their placement. You are invited to consult the cookie policy of each social network concerned for further information.
COOKIE MANAGEMENT:
You can manage, disable or authorise cookies by indicating your choices in the tag manager accessible during your first visit via the “learn more” cookie banner or accessible at any time during your browsing in the bottom left-hand corner.
You can also manage your cookies globally by modifying the settings of your internet browser by following the links below:
Chrome: https://support.google.com/chrome/answer/95647?hl=EN
Internet Explorer / Edge: https://support.microsoft.com/en-gb/windows/delete-and-manage-cookies-168dab11-0753-043d-7c16-ede5947fc64d
Firefox: https://support.mozilla.org/en-US/kb/enable-and-disable-cookies-website-preferences
Safari: https://support.apple.com/en-gb/HT1677
Depending on their settings, browsing may be altered and access to the Website more or less limited. In particular, disabling functional cookies will affect or even make visiting the Website impossible.
1.5 DATA RETENTION PERIOD
LBD applies specific management and retention policies and procedures, so that personal data are erased at the end of defined periods depending on what is strictly necessary.
LBD retains your data for as long as:
- it maintains an ongoing relationship with you;
- it is necessary for the provision of services available on the Website and for the purposes set out above;
- it is necessary for it to comply with its legal, regulatory and/or contractual obligations.
Personal data are thus retained in the active database for three (3) years from the last interaction between LBD and you or from the end of the contract entered into with you, except for electronic contracts with a value greater than one hundred and twenty (120) euros, which will be archived for ten (10) years from the end of the relationship.
Certain data may be retained for a different period, for backup, archiving or audit purposes, until the expiry of the applicable limitation periods.
By way of illustration, the mandatory retention period for invoices is ten (10) years; in the context of your participation in a competition, your personal data will be kept for six (6) months from its conclusion; cookies will be retained for thirteen (13) months from their collection.
1.6 DATA RECIPIENTS
LBD is the sole recipient of the data collected and is responsible for processing them.
LBD will only transfer your personal data to a third party when:
- LBD must share such information with its contractual partners, subcontractors and service providers involved in the provision of the Website and the services available on it. Only the data necessary for the processing of requests and/or services provided on the Website may be communicated to such parties;
- LBD must comply with a legal or regulatory obligation and/or prevent fraud;
- you have given your prior consent to LBD to share your data; or
- LBD receives a request from a judicial authority or any administrative authority authorised by law to request such information.
1.7 DATA TRANSFERS
LBD stores all your personal data within the territory of the European Union.
If some of your personal data were to be transferred and stored outside the European Union by its service providers, LBD undertakes to do everything possible to ensure that they adopt the relevant organisational and technical measures necessary to protect and secure your personal data. In any case, data transfers are carried out with appropriate guarantees in accordance with European regulations, meaning either to countries benefiting from an adequacy decision or because they are governed by Standard Contractual Clauses validated by the European Commission.
1.8 DATA SECURITY
LBD ensures the confidentiality of the personal data collected and implements appropriate organisational and technical measures to guarantee a level of security appropriate to protect such personal data against unauthorised access, unlawful processing, accidental loss, destruction and damage.
LBD is not responsible for information and personal data that may be transmitted to third parties when such transfer is due to a security defect affecting your device or browser.
2. DATA SUBJECT RIGHTS
2.1 RIGHT OF ACCESS, MODIFICATION, RECTIFICATION AND ERASURE
You have the right (under the circumstances, conditions and subject to the exceptions provided by applicable law) to:
- request access to the personal data processed by LBD about you: this right enables you to know whether LBD holds your personal data and, if so, to obtain information and a copy of such data;
- request the rectification of your personal data: this right allows you to have your data corrected if it is inaccurate or incomplete;
- object to the processing of your personal data: this right allows you to ask LBD to stop processing your data;
- request the erasure of your personal data: this right allows you to ask LBD to delete your data, including when they are no longer necessary;
- request the restriction of processing of your personal data: this right allows you to ask LBD to process your data only in limited circumstances, in particular with your consent;
- request the portability of your personal data: this right allows you to receive a copy (in a structured, commonly used and machine-readable format) of the data you have provided to LBD, or to ask LBD to transfer those data to another controller;
- insofar as the processing of your personal data is based on your consent, you have the right to withdraw such consent at any time by contacting LBD using the details provided in Article 4 and accompanying your request with proof of your identity. Please note that this will not affect LBD’s right to process your personal data obtained prior to the withdrawal of your consent, nor its right to continue certain processing on other legal bases; and
- lodge a complaint with a personal data protection supervisory authority. In France, the competent authority is the CNIL.
2.2 SPECIFIC PROVISIONS FOR MINORS
The Website is not aimed at minors under the age of 16.
However, if information about a minor under the age of 16 were to be collected by the Website, the minor’s legal representative must give prior consent and validate the communication of the personal data concerned.
3. UPDATING THE PRIVACY POLICY
LBD may amend the Privacy Policy, in particular to take into account legislative and regulatory developments or changes in LBD’s organisation. If LBD wishes to use your personal data in a different way from that stipulated in the Privacy Policy in force at the time of collection, these changes will be notified visibly on the Website and you will also be informed by email if you are registered on the Website and/or to the newsletter.
4. CONTACT
For any request relating to the Website’s Privacy Policy, you are invited to contact LBD’s Data Protection Officer:
- By email: cil@labrosseetdupont.com
- By post: La Brosse et Dupont – Data Protection Officer – Immeuble Niagara – 10 Allée des Cascades – Paris Nord 2 – 93420 Villepinte.