Privacy Policy

Thank you for visiting our website www.beautical.com. The protection of personal data is extremely important to us and we do our best to process and protect personally identifiable information with the utmost care. Your trust is crucial to us and we treat your privacy with the utmost respect, in accordance with the Global Data Protection Regulation (GDPR).

01

Parties and Purpose

SERENDY SRL (hereinafter “SERENDY” or “we” or the “Data Controller”)

Avenue Louise 367, 1050 Brussels, Belgium

Company number (BCE / TVA): 0713570206

Email: [email protected]

Telephone: +32 2 315 56 90

SERENDY establishes this Privacy Policy in order to transparently inform Users of the website hosted at the following URL address: www.beautical.com (hereinafter the “Site”) what information may be collected on our website, how we use this information, and under what circumstances we may disclose the information to third parties.

The term “User” refers to any user, either any natural or legal person, who visits or interacts in any way with the Site.

As such, SERENDY determines all the technical, legal and organizational means and purposes for processing Users’ personal data. SERENDY undertakes to this end to take all necessary measures to guarantee the processing of personal data in accordance with the law of July 30, 2018, relating to the protection of individuals with regard to the processing of personal data (hereinafter after, “the Law”) and to the European Regulation of 27 April 2016 on the protection of data of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the “Regulation “).

SERENDY is free to choose any natural or legal person who processes users’ personal data at his request and on his behalf (hereinafter the “Subcontractor”). If applicable, SERENDY undertakes to select a Subcontractor offering sufficient guarantees as to the technical and organizational security measures for the processing of personal data, with regard to the Law and the Regulations.

This Privacy Policy applies only to information SERENDY collects through the Site and does not apply to our collection of information from other sources.

02

Processing of personal data

You can visit our website without providing any personal information. If you use our Site for informational purposes only and do not provide us with information about yourself, we do not collect any personal data, with the exception of the data that your browser transmits to enable you to visit the website as well as information that is transmitted to us through cookies used for statistical analysis of the use of our Site.

 

For the technical performance of the Site it is necessary that we process certain automatically transmitted information about you so your browser can display our Site and you can use the Site. This information is automatically collected for each visit of our Site and stored in our server log files. This information refers to the computer system of the requesting computer. The following information is collected thereby:

  • IP-address
  • browser type
  • browser language
  • operating system
  • internal resolution of the browser window
  • screen resolution
  • java script activation
  • java on / off
  • cookies on / off
  • colour depth
  • time of access
  • keywords used
  • pages viewed
  • consultation time per page
  • list of downloaded files
  • date and time of access

The use of the Site by Users may result in the communication of personal data. The processing of this data by SERENDY, in its capacity as Data Controller, or by service providers acting in the name and on behalf of SERENDY, will comply with the Law and the Regulations.

Personal data will be processed by SERENDY, in accordance with the purposes mentioned below, via:

  • navigation on the Site
  • purchase on the Site
  • customer account creation
  • use of cookies
  • sign-up to newsletter
  • participation in contests
  • customer service (complaints, order tracking)
  • loyalty programs

03

Purpose of processing personal data

You can visit our website without providing any personal information. If you use our Site for informational purposes only and do not provide us with information about yourself, we do not collect any personal data, with the exception of the data that your browser transmits to enable you to visit the website as well as information that is transmitted to us through cookies used for statistical analysis of the use of our Site.

 

For the technical performance of the Site it is necessary that we process certain automatically transmitted information about you so your browser can display our Site and you can use the Site. This information is automatically collected for each visit of our Site and stored in our server log files. This information refers to the computer system of the requesting computer. The following information is collected thereby:

  • IP-address
  • browser type
  • browser language
  • operating system
  • internal resolution of the browser window
  • screen resolution
  • java script activation
  • java on / off
  • cookies on / off
  • colour depth
  • time of access
  • keywords used
  • pages viewed
  • consultation time per page
  • list of downloaded files
  • date and time of access

The use of the Site by Users may result in the communication of personal data. The processing of this data by SERENDY, in its capacity as Data Controller, or by service providers acting in the name and on behalf of SERENDY, will comply with the Law and the Regulations.

Personal data will be processed by SERENDY, in accordance with the purposes mentioned below, via:

  • navigation on the Site
  • purchase on the Site
  • customer account creation
  • use of cookies
  • sign-up to newsletter
  • participation in contests
  • customer service (complaints, order tracking)
  • loyalty programs

04

Personal data likely to be processed

The User agrees, during the visit and during the use of the Site, that SERENDY collects and processes, according to the methods and principles described in this Privacy Policy, the following personal data:

  • your IP address and that of your device
  • the hypertext links on which you clicked
  • the websites you visited before arriving on the Site
  • the information collected by cookies and other similar tracking devices
  • your username, profile picture, gender, networks and other information that you choose to share when you use third-party sites (such as when you use the Facebook “Like” feature).
  • last name
  • first name
  • address
  • email address
  • telephone number
  • passwords
  • history of orders / preferred items
  • age / date of birth
  • sex
  • information on the management of your request (including information relating to the beauty products you order)
  • other personal data that you voluntarily provide to us

05

consent

By accessing and using the Site, the User declares that he has read and expressed his agreement in a free, specific, informed and unequivocal manner to the processing of personal data concerning him. This agreement relates to the content of this Privacy Policy.

Consent is given by the positive act by which the User has checked the box proposing the Privacy Policy as a hypertext link. This consent is an essential condition for carrying out certain operations on the Site or for allowing the User to enter a contractual relationship with SERENDY. Any contract binding SERENDY and a User relating to the services and goods offered on the Site is subject to the acceptance of the Privacy Policy by the User.

The User consents to the Data Controller processing and collecting, in accordance with the terms and principles included in this Privacy Policy, his personal data which he communicates on the Site or on the occasion of the services offered by SERENDY, for the purposes indicated above.

The User has the right to withdraw his consent at any time. Withdrawal of consent does not compromise the lawfulness of processing based on previously given consent.

06

Duration of storage of users' personal data

In accordance with article 13 §2 of the Regulation and the Law, the Data Controller only stores personal data for the time reasonably necessary to allow the purposes for which they are processed to be fulfilled.

This duration is in any case less than: 3 years

07

Data recipients and disclosure to third parties

Personal data can be transmitted to collaborators, subcontractors or suppliers of SERENDY who offer adequate data security guarantees, and who collaborate with SERENDY in the context of the marketing of products or the provision of services. They act under the direct authority of SERENDY and are notably responsible for collecting, processing or sub-processing this data.

In all cases, the recipients of the data and those to whom these data have been disclosed respect the content of this Privacy Policy. SERENDY ensures that they will process this data only for the intended purposes, in a discreet and secure manner.

In the event that the data is disclosed to third parties for direct marketing or prospecting purposes, the User will be informed beforehand so that he expresses his consent to the use of this personal data.

08

Transfer into Third countries

As part of the use of Google tools, SERENDY transfers the shortened IP address of the Users to the USA. The data transfer is based on the EU Commission implementing decision (EU) 2016/1250 of 12 July 2016 pursuant to Directive 95/46/EG of the European Parliament and of the Council on the adequacy of the protection provided by the EU-US data privacy shield.

Furthermore, SERENDY does not transfer the Users’ personal data to countries outside the EU or the EEA or to international organisations.

09

Rights of Users

At any time, the User can exercise his rights by sending a message by email to the following address: [email protected] or a letter by post addressed, attaching a copy of his identity card, to the following address: SERENDY, Avenue Louise 367, 1050 Brussels, Belgium.

— Right to access

the User for his personal data. The User has the right to obtain access to said personal data and the following information:

  • the purposes of the processing
  • the categories of personal data concerned
  • the recipients or categories of recipients to whom the personal data have been or will be communicated, in particular recipients who are established in third countries or international organizations
  • where possible, the envisaged period of retention of personal data or, when this is not possible, the criteria used to determine this period
  • the existence of automated decision-making, including profiling, referred to in Article 22 (1) and (4) of the Regulation, and, at least in such cases, useful information concerning the underlying logic, as well that the importance and the expected consequences of this processing for the data subject

The Data Controller may require the payment of reasonable fees based on administrative costs for any additional copy requested by the User.

When the User submits this request electronically (via the e-mail address for example), the information is provided in an electronic form in common use, unless the User requests otherwise.

The copy of his data will be communicated to the User no later than one month after receipt of the request.

— Right of rectification

SERENDY guarantees the right of rectification and erasure of personal data to the user.

In accordance with article 16 of the Regulation, incorrect, inaccurate or irrelevant data can be corrected or deleted at any time. The User first makes the necessary changes himself from his user / other account, unless these cannot be done independently, in which case the request can be made to SERENDY.

In accordance with article 19 of the Regulation, the Controller notifies each recipient to whom the personal data have been communicated of any rectification of the personal data, unless such communication proves to be impossible or requires disproportionate efforts. The data controller provides the data subject with information on these recipients if the latter so requests.

— Right to erasure

The User has the right to obtain the deletion of his personal data as soon as possible in the cases listed in article 17 of the Regulation.

When the Data Controller has made personal data public and is required to erase it under the previous paragraph, the Data Controller, taking into account the available technologies and the costs of implementation, takes reasonable measures, including of a technical nature, to inform the other data controllers who process this personal data that the data subject has requested the erasure by these data controllers of any link to this personal data, or of any copy or reproduction thereof.

The two preceding paragraphs do not apply insofar as this processing is necessary:

  • the exercise of the right to freedom of expression and information;
  • to comply with a legal obligation which requires processing provided for by Union law or by the law of the Member State to which the controller is subject, or to perform a task of public interest or relating to the exercise the public authority vested in the controller;
  • the establishment, exercise or defence of legal claims.

In accordance with article 19 of the Regulation, the Data Controller notifies each recipient to whom the personal data has been communicated of any deletion of personal data or any limitation of the processing carried out, unless such communication proves impossible. or requires disproportionate effort. The data controller provides the data subject with information on these recipients if the latter so requests.

— Right to restrict processing

The User has the right to obtain the restriction of the processing of his personal data in the cases listed in article 19 of the Regulation.

In accordance with article 19 of the Regulation, the Controller notifies each recipient to whom the personal data has been communicated of any restriction of the processing carried out, unless such communication proves to be impossible or requires disproportionate efforts. The data controller provides the data subject with information on these recipients if the latter so requests.

— Right to data portability

In accordance with article 20 of the Regulations, Users have the right to receive from SERENDY personal data concerning them in a structured, commonly used and machine-readable format. Users have the right to transmit this data to another controller without SERENDY obstructing it in the cases provided for by the Regulations.

When the User exercises their right to data portability in application of the preceding paragraph, they have the right to obtain that personal data be transmitted directly from one controller to another, when this is technically possible.

The exercise of the right to data portability is without prejudice to the right to erasure. This right does not apply to the processing necessary for the performance of a task of public interest or falling within the exercise of public authority vested in the controller.

The right to data portability does not affect the rights and freedoms of third parties.

— Right to object and automated individual decision-making

The User has the right at any time to oppose the processing of his personal data due to his particular situation, including the automation of data carried out by SERENDY. In accordance with article 21 of the Regulation, SERENDY will no longer process personal data, unless there are legitimate and compelling reasons for the processing which prevail over the interests and rights and freedoms of the User, or for the establishment, exercise or defence of legal claims.

When personal data is processed for prospecting purposes, the User has the right to object at any time to the processing of personal data concerning them for such prospecting purposes, including profiling to the extent where it is linked to such prospecting.

When the data subject objects to the processing for prospecting purposes, personal data is no longer processed for these purposes.

— Right of appeal to a supervisory authority

The User has the right to file a complaint concerning the processing of his personal data by SERENDY with the Data Protection Authority, competent for Belgian territory. More information can be found on the website: https://www.autoriteprotectiondonnees.be.

The lodging of a complaint is made at the following address:

Data Protection Authority

Rue de la Presse 35, 1000 Brussels, Belgium

Phone. + 32 2 274 48 00

Fax. + 32 2 274 48 35

E-mail: [email protected]

The User can also lodge a complaint with the court of first instance of his domicile.

10

cookies

The Site uses cookies to distinguish Site Users. This provides Users with a better browsing experience and an improvement of the Site and its content. The objectives and methods of cookies are contained in this article.

— General principles

A “Cookie” is a file temporarily or permanently placed on the User’s hard drive when consulting the Website, for subsequent connection. Thanks to cookies, the server recognizes the User’s computer. Cookies can also be installed by third parties with which SERENDY collaborates.

We use cookies and other similar technologies (“Cookies”) to improve our products and your experience on the Site by collecting information about how you use the Site. Some of the Cookies we use are necessary in order to activate the essential functionality of the Site, for example to provide a secure connection or to remember where you were in an order, but we also use Cookies which allow us to analyse the use of the Site (in order to be able to measure and improve its performance) as well as advertising Cookies used by advertising companies to broadcast advertisements that correspond to your interests.

We could also adapt the Site and our products to your interests and needs, by collecting information on your device and associating it with your personal data, in order to ensure that the Site offers you the best web experience. possible.

The User can personalize or deactivate cookies by configuring their browser.

By using the Website, the User expressly agrees with the management of cookies as described in this article.

— Type of cookies and purposes pursued

Different types of cookies are used by SERENDY on the Site:

  • Technical cookies: they are necessary for the operation of the Website, allow the communication of the data entered and are intended to facilitate the browsing of the User;
  • Statistical and audience measurement cookies: these cookies allow the recognition of the User and are used to count the number of Users of the Website over a certain period. As soon as they also indicate the browsing behaviour, they are an effective means to improve the browsing of the User, by posting proposals and offers likely to interest him. They also allow SERENDY to spot possible bugs on the Website and to correct them.
  • Functional cookies: these cookies facilitate the use of the Website by retaining certain choices made (for example user name or language);
  • Tracking cookies: SERENDY uses tracking cookies via Google Analytics, to measure the interaction of Users with the content of the Site and produce anonymous statistics. These statistics allow SERENDY to improve the Website. Google supports the explanation of these cookies at the following address:

https://policies.google.com/privacy?hl=en

— Cookie retention period

Cookies are kept for the time necessary to achieve the intended purpose. The cookies likely to be stored on the User’s hard drive and their retention period are as follows:

— Cookies management

If the User does not want the Site to place cookies on his hard drive, it is easy for him to manage or delete them by modifying the parameters of his browser. The programming of the browser also allows the User to receive a notice or a notification as soon as a Website uses cookies and thus decide to accept this, or to refuse it.

If the User deactivates certain cookies, he accepts that the Website may not function optimally. Certain parts of the Website may therefore not be usable or may be so partially.

If the User wishes to manage and / or delete certain cookies, he can do so by using the following link (s):

For Users with browser:

If the User refuses that Google Analytics cookies are used, he is invited to configure his browser in this sense, on the following website:

http://tools.google.com/dlpage/gaoptout

11

Liability limitation of the Data Controller

The Site may contain links to other websites owned by third parties not linked to SERENDY. The content of these sites and their respect for the Law and the Regulations are not the responsibility of SERENDY.

The holder of parental authority must give his express consent so that the minor under the age of 18 can disclose personal information or data on the Site. SERENDY strongly advises those exercising parental authority over minors to promote responsible and secure use of the Internet. The Data Controller cannot be held responsible for having collected and processed information and personal data from minors under the age of 18 whose consent is not effectively covered by that of their legal parents or for incorrect data – in particular concerning the ‘age- introduced by minors. In no case will personal data be processed by the Data Controller if the User specifies that he is under the age of 18.

SERENDY is not responsible for the loss, corruption or theft of personal data caused in particular by the presence of viruses or following computer attacks.

12

security

The Data Controller implements organizational and technical measures to guarantee a level of security appropriate to the processing and collection of data. These security measures depend on the costs of implementation with regard to the nature, context and purposes of the processing of personal data.

The Data Controller uses standard encryption technologies within the IT sector when transferring or collecting data on the Site.

13

Modification of the Privacy Policy

SERENDY reserves the right to modify this Confidentiality Policy in order to comply with legal obligations in this area. The user is therefore invited to regularly consult the Privacy Policy in order to become aware of modifications and adaptations. Such a modification will be posted on the Site or sent by email for the purposes of enforceability.

14

Applicable law and competent jurisdiction

This Privacy Policy is exclusively governed by Belgian law. Any dispute will be brought before the courts of the judicial district of the headquarters of SERENDY.

15

Contact

For any question or complaint relating to this Privacy Policy, the User can contact the Data Controller via the following address: [email protected]

This website uses cookies to ensure you get the best experience.