LA ROCHE-POSAY

私隱政策及個人資料收集聲明

私隱政策

歐萊雅的抱負是成為「企業公民」的典範,協助令世界變得更美好。我們極其重視誠信和企業透明度,並致力奠基於信任和互惠的基礎,與我們的消費者建立穩固而長久的關係。保障和尊重閣下的私隱和選擇,是這份承諾蘊含的意義箇中一部分。對我們而言,尊重閣下的私隱至為重要;正因如此,我們於以下闡述「我們對私隱的承諾」,以及完整的私隱政策。

我們對私隱的承諾

1)

我們尊重閣下的私隱和選擇。

2)

我們確保私隱和安全是深植於我們一切行事當中的基礎。

3)

除非閣下要求,否則我們不會向閣下發送市場推廣通訊。閣下可隨時改變主意。

4)

我們絕對不會供出或出售閣下的資料。

5)

我們致力保障閣下的資料安全穩妥;這包括只與可靠的夥伴合作。

6)

我們致力保持我們使用閣下資料的方式公開和透明。

7)

我們不會以未曾知會閣下的方式使用閣下的資料。

8)

我們尊重閣下的權利,並於符合我們的法律和營運責任的前提之下,一直致力盡量滿足閣下的要求。

如欲了解更多有關我們的私隱守則的資訊,請查閱我們以下闡述的內容,包括我們可能直接向閣下接收或透過閣下與我們的互動而接收的個人資料類別、我們可能使用該等資料的方式、我們可能分享該等資料的對象、我們保護該等資料並保障其安全的方式,以及閣下關於個人資料的權利。誠然所有情況均未必適用於閣下;本私隱政策純粹讓閣下概覽我們或會進行互動的所有可能情況。

閣下與我們的互動愈頻繁,我們對閣下的了解亦會隨之加深,從而令我們更能為閣下提供度身訂造的服務。

當閣下與我們分享個人資料,或當我們向閣下收集個人資料時,我們將根據本政策使用該等個人資料。請仔細閱讀本資料以及我們的問答專頁 (如有)。

閣下將可於本私隱政策知悉甚麼內容?

我們的背景

何謂個人資料?

我們向閣下收集甚麼資料?我們又會如何使用該等資料?

我們如何收集或接收閣下的資料?

自動決策

個人剖

誰可存取閣下的個人資料?

我們於哪裡存置閣下的個人資料?

我們保留閣下的個人資料多久?我

的個人資料安全嗎?

第三方網站連結和社交媒體登入

社交媒體和用戶生成內容

閣下的權利和選擇

聯絡

請注意,閣下必須年滿 18 歲,方可使用我們的服務。如特定服務另有要求使用者的年齡為 18 歲以上,該等要求將於相關條款中列明,閣下亦必須遵從。


我們的背景


LA ROCHE-POSAY 屬於歐萊雅香港有限公司旗下品牌組合的一部分。歐萊雅香港有限公司負責管理閣下與我們分享的個人資料。我們提及「歐萊雅」、「我們」、「我們的」或「本公司」時,所指的就是歐萊雅香港有限公司。就《個人資料 (私隱) 條例 (第 486 章)》而言,歐萊雅是一「資料使用者」。

如欲查閱我們的聯絡詳情,請見「聯絡我們」部分。

歐萊雅代表多個不同品牌和產品。如欲了解更多關於歐萊雅及其代表品牌的資訊,請瀏覽 http://www.loreal.hk/en-hk/

歐萊雅是於全球 140 個國家營運的歐萊雅集團的一部分。如欲了解歐萊雅集團的詳情,請瀏覽
http://www.loreal.com/group

聯絡

如閣下對於我們處理和使用閣下個人資料的方式有任何疑問或顧慮,或希望行使閣下上述任何權利,請電郵至
[email protected] 或致函 與我們聯絡:

香港特別行政區
灣仔港灣道 30 號
新鴻基中心 35 樓
歐萊雅香港有限公司
客戶服務部
致:LA ROCHE-POSAY

閣下亦可電郵至 ,就有關閣下個人資料的處理方式提出任何疑問。


[LA ROCHE-POSAY]

私隱政策


何謂個人資料?

「個人資料」意指任何可供直接 (例如閣下的姓名) 或間接 (例如透過獨特編號等經過假名處理的資料) 辨識閣下身分的單一或多條資訊。這意味著個人資料包括電郵、住宅地址、流動電話號碼、使用者名稱、個人檔案頭像和個人偏好,以及購物習慣、用戶生成內容、財務資訊,以及身體狀況資訊。這亦可能包括獨特數字識認,例如閣下的電腦IP 位址或流動裝置的 MAC 網絡卡位址,以及 cookies。


我們向閣下收集甚麼資料?我們又會如何使用該等資料?

歐萊雅深信,閣下作為消費者,是我們服務的焦點對象。我們樂意聆聽閣下的意見和了解閣下,並為閣下創製和呈獻閣下喜歡的產品。我們亦深知許多消費者均熱衷於與我們對話;正因如此,我們提供多種方式,讓閣下可與我們分享閣下的個人資料,並讓我們可收集該等資料。


我們如何收集或接收閣下的資料?


我們或會透過我們的網站、表格、應用程式、裝置、歐萊雅產品、社交媒體上的品牌專頁或其他方式,向閣下收集或接收資料。該等資料或由閣下直接向我們提供 (例如當閣下創建帳戶、聯絡我們,或於我們的網站/應用程式或專門店/美容院購物時)、由我們收集 (例如利用 cookies 了解閣下如何使用我們的網站/應用程式),或由我們透過其他第三方接收,包括歐萊雅集團的其他實體。

當我們收集資料時,我們以星號標示必填項目,皆因我們必需該等資料以供:

-

我們履行與閣下的合約,例如付運閣下於我們的網站/應用程式上購買的產品;

-

向閣下提供閣下要求的服務,例如向閣下提供最新消息、生日優惠或帳戶狀態;或

-

遵從法律要求,例如開立發票。

如閣下不提供以星號標示的資料,我們將可能無法提供相關產品和服務。

我們於下表列舉更多詳情,以闡釋:

1)

閣下於哪些互動當中可能需要提供或由我們收集個人資料?此欄闡釋我們使用或收集閣下的資料時閣下正參 與的活動或情況,例如進行購物、登記收取最新消息,或瀏覽網站/應用程式。

2)

我們可向閣下直接收集或透過閣下與我們的互動接收哪些個人資料?此欄闡釋我們視乎情況而可能向閣下收 集的資料類別。

3)

我們會如何使用該等資料?何解?此欄闡釋我們可能處理閣下資料的方法,以及收集該等資料之目的。

4)

使用閣下個人資料的法律基礎為何?本欄闡釋我們或會使用閣下資料的原因。
視乎使用資料之目的而定,處理閣下資料的法律基礎可為:

閣下的同意;

我們的合法利益,當中可為:

改善我們的產品和服務:更具體而言,是指我們的商業利益,協助我們更清楚理解閣下的需要和期望,從而改善我們的服務、網站/應用程式/裝置、產品和品牌,讓我們的消費者有所裨益。

防止詐騙:確保付款完成,免於詐騙和挪用金錢。

保障我們的工具安全:保障閣下所使用的工具 (我們的網站/應用程式/裝置) 安全穩妥,並確保它們正常運作和不斷改良。

履行合約:更具體而言,是指履行閣下向我們要求的服務;或

法律依據,適用於法律要求處理閣下個人資料的情況。

關於閣下與我們的互動以及其對閣下資料構成的影響之資訊概覽

閣下於哪些互動
當中可能需要提
供或由我們收集
閣下的資料?

我們可向閣下直接收集
或透過閣下與我們的互
動接收哪些個人資料?

我們會如何使用閣下的資料?
何解?

使用閣下個人資料的法律基礎
為何?

創建和管理帳戶

於歐萊雅網站/應用程式上、透過社交媒體登入, 或於專門店創建帳戶時所收集的資料。

視乎閣下與我們互動的多寡, 該些資料可能包括:

姓氏及稱謂;

性別;

電郵地址;

地址;

電話號碼;

相片;

生日或年齡組別;

帳戶編號、使用者名稱和密碼;

個人描述或偏好;

訂單詳情;以及

社交媒體檔案 (如閣下使用社交媒體登入, 或與我們分享是項個人資料)。

以供:

管理閣下的訂單;

管理任何閣下選擇參與的比賽、推廣活動、意見調查或抽獎;

回應閣下的疑問,或於其他情況與閣下互動;

為閣下呈獻常客計劃;

容許閣下管理個人偏好;

履行合約
向閣下提供閣下所要求的服務, 例如創建帳戶、填妥意見調查或購買產品。

向閣下發送市場推廣通訊(如閣下如此要求),而該等通訊或會根據閣下的「個人檔案」 (亦即基於我們所知悉的閣下個人資料和偏好) 度身訂造;

同意
向閣下發送直接促銷通訊。

根據閣下的美妝特徵呈獻度身訂造的服務;

監察和改良我們的網站/應用程式;

進行分析或收集統計數據; 以及

保障我們的網站/應用程式安全,並保護閣下和我們免遭詐騙;

合法利益
確保我們的網站/應用程式保持安全, 保障其免受詐騙影響,並協助我們更清楚理解閣下的需要和期望, 從而改善我們的服務、產品和品牌。

訂閱最新消息和商業通訊

視乎閣下與我們互動的多寡, 該些資料可能包括:

電郵地址;

姓氏及稱謂;

個人描述或偏好; 以及

社交媒體檔案 (如閣下使用社交媒體登入, 或與我們分享是項個人資料)。

以供:

向閣下發送市場推廣通訊(如閣下如此要求),而該等通訊或會根據我們所知悉的閣下個人資料和偏好 (包括閣下最愛的專門店之所在地) 建立的「個人檔案」度身訂造;以及

同意
向閣下發送直接促銷通訊。

進行分析或收集統計數據。

合法利益
為閣下度身訂造我們的市場推廣通訊、 了解其效用,並確保閣下獲取最切身的體驗; 以及協助我們更清楚理解閣下的需要和期望, 從而改善我們的服務、產品和品牌。

如閣下要求我們終止聯絡閣下,更新包括閣下在內的拒收電郵名單;

法律依據
如閣下要求我們不再向閣下發送任何直接促銷資訊,我們會將閣下的詳細資料保存至拒收電郵名
單。

購物和訂單管理

於歐萊雅網站/應用程式/社交媒體專頁或專門店進行購物的過程期間所收集的資訊

視乎閣下與我們互動的多寡, 該些資料可能包括:

姓氏及稱謂;

電郵地址;

地址 (送貨和開立發票);

電話號碼;

個人描述或偏好;

社交媒體檔案 (如閣下使用社交媒體登入, 或與我們分享是項個人資料);

交易資訊, 包括已購買的產品和專門店地址;

付款狀態和資訊; 或

付款紀錄

以供

於閣下已儲存購物車內容, 或將產品放進購物車而尚未完成結賬程序時,聯絡閣下以結算訂單;

當閣下心儀的產品可供購買時通知閣下;

處理和跟進閣下的訂單,包括將產品付運至閣下指示的地址;

管理閣下訂單的付款狀態。請注意,付款資訊 (信用卡號碼/Paypal 、支付寶或微信支付資訊/銀行賬戶詳情) 並非由我們收集,而是由支付服務提供者直接收集;

管理閣下就閣下的訂單向我們提供的任何聯絡資料;

履行合約:
向閣下提供閣下所要求的
(購物) 服務。

保障交易免受詐騙影響。請注意,我們使用第三方提供者的方案以偵測詐騙,並確保付款由閣下或閣下授權的人士進行和完成;

如閣下使用閣下的帳戶資訊進行購物,為閣下的個人檔案新增內容;

評估閣下的滿意度;

管理任何與訂單相關的糾紛;以及

進行統計用途。

合法利益
保障閣下和我們免遭欺詐交易影響, 並確保付款完成, 免於詐騙和挪用金錢。

網上瀏覽

閣下於瀏覽歐萊雅網站/應用程式及/或第三方網站/ 應用程式期間, 利用 cookies 或類近科技 (下稱「Cookies」*) 所收集的資訊。

如欲了解透過某網站/應用程式設置的特定 Cookies 資訊,請查閱相關的 Cookies 列表。

* Cookies 是當閣下瀏覽互聯網, 包括歐萊雅集團的網站時,儲存於閣下的 (電腦、平板電腦或流動電話) 裝置裡的小型文字檔案。

視乎閣下與我們互動的多寡, 該些資料可能包括:

關於閣下使用我們的網站/ 應用程式的資料:

閣下從何網站而來;

登入詳情;

閣下曾瀏覽的頁面;

閣下曾觀看的短片;

閣下點擊或按下的廣告;

閣下搜尋的產品;

閣下的所在地;

閣下逗留的時間;以及

閣下選擇用以創建個人購物車的產品。


技術資訊:

IP 位址;

瀏覽器資訊;以及

裝置資訊。


授予每位訪問者的獨特識別碼, 以及該等識別碼的屆滿日期。

如 有 必 要 , 我 們 將 利 用Cookies,連同閣下已與我們分享的其他個人資料 (例如過往訂單,或閣下對於我們的最新消息電郵的訂閱狀態),以達到以下目的:

容許我們的網站/應用程式正常運作,包括:

正常顯示內容;

創建和記錄購物車;

創建和記錄閣下的登入資訊;

提供個人專屬介面,例如語言;

閣下的裝置附載的參數,包括閣下的螢幕解像度等;以及

改善我們的網站/應用程式, 例如測試嶄新構思;

確保網站/應用程式安全穩妥,例如透過進行疑難排解,保護閣下免遭詐騙或不當使用我們的網站或服務;

進行統計:

避免同一訪問者被重覆記錄;

了解使用者對我們的廣告企劃的反應;

改善我們的優惠;

了解閣下如何知悉我們的網站/應用程式。

提供網上行為定向廣告:

根據閣下過往的行為模式,向閣下展示閣下可能感興趣的產品的網上廣告;以及

於社交媒體平台向閣下展示廣告和內容。

為閣下提供度身訂造的服務:

根據閣下的個人檔案和興趣,向閣下發送產品推薦、市場推廣信息或內容;

以度身訂造的方式顯示我們的網站/應用程式,例如記錄閣下的購物車或登入資訊、閣下使用的語言,以及使用者介面自定義 cookies (即閣下的裝置附載的參數,包括閣下的螢幕解像度和字型偏好等);以及

容許使用者於社交媒體上分享我們提供的內容 (為了展示網站而設的分享按鈕)。

合法利益:
確保我們向閣下提供正常運作的網站/應用程式、廣告和通訊,並持續改良 (i) 我們的網站/應用程式運作時所必需,以及 (ii) 保障我們的網站/應用程式安全穩妥的 cookies。

同意
所有其他 cookies。

推廣活動

於遊戲、比賽、推廣優惠、索取試用裝和意見調查期間所收集的資訊。

視乎閣下與我們互動的多寡, 該些資料可能屯括:

姓氏及稱謂;

電郵地址;

電話號碼;

出生日期;

性別;

地址;

個人描述或偏好;

社交媒體檔案 (如閣下使用社交媒體登入, 或與我們分享是項個人資料);以及

閣下與我們分享的其他與個人相關的資訊, 例如透過閣下的「我的帳戶」頁面、聯絡我們、提供個別內容如相片或評論、透過部分網站/應用程式提供 的 對 話 功 能 發問, 或參加比賽、遊戲或意見調查。

完成閣下要求我們執行的指令,例如管理閣下於比賽、遊戲和意見調查的參與,包括考慮閣下的意見和建議;

履行合約
向閣下提供閣下所要求的服務。

進行統計用途;以及

合法利益
協助我們更清楚理解閣下的需要和期望,從而改善我們的服務、 產品和品牌。

向閣下發送市場推廣通訊(如閣下如此要求)

同意
向閣下發送直接促銷通訊。

用戶生成內容

當閣下於我們的社交平台提交內容,或同意讓我們重用閣下於社交媒體平台張貼的內容時所收集的資訊。

視乎閣下與我們互動的多寡, 該些資料可能包括:

姓 氏 及 稱 謂 或 別名;

電郵地址;

相片;

個人描述或偏好;

社交媒體檔案 (如閣下使用社交媒體登入, 或與我們分享是項個人資料);以及

閣下與我們分享的其他與個人相關的資訊,例如透過閣下的「我的帳戶」頁面、聯絡我們、提供個別內容如相片或評論,或透過部分網站/應用程式提供的對話功能發問。

根據閣下所接受的特定條款及細則:

張貼閣下的評論或內容;以及

推 廣 我 們 的 產品。

同意
重用閣下於網上張貼的內容。

進行統計用途。

合法利益
協助我們更清楚理解閣下的需要和期望,從而改善我們的服務、 產品和品牌。

使用應用程式和裝置

閣下使用我們的應用程式及/或裝置期間所收集的資訊。

視乎閣下與我們互動的多寡, 該些資料可能包括:

姓氏及稱謂;

電郵地址;

所在地;

出生日期;

個人描述或偏好;

相片;

身體狀況資料, 包括膚色和皮膚/頭髮類型;以及

地理位置。

以供

向閣下提供要求的服務, 例如虛擬測試我們的產品、透過應用程式或於相關電子商務網站購買我們的產品;關於閣下的日曬狀況和護髮程序的建議和通知;

分析閣下的身體狀況特徵,並推薦適合的產品 (包括度身訂造的產品) 和護理程序;

向閣下提供產品和護理程序推薦;

履行合約
向閣下提供要求的服務,包括於需要時由研究及創新團隊分析提供服務的必要演算序列。

於歐萊雅集團內部供科學家進行研究和創新;

監察和改善我們的應用程式和裝置;以及

進行統計用途。

合法利益
持續改善我們的產品和服務以符合閣下的需要和期望, 並供進行研究和創新用途。

查詢

當閣下提出關於我們的品牌、產品及其使用方法的疑問時 (例如透過我們的顧客服

視乎閣下與我們互動的多寡, 該些資料可能包括:

姓氏及稱謂;

電話號碼;

電郵地址;以及

閣下與我們分享而有關閣下查詢的其他個人資訊 (可能包括身體狀況和健康資料)。

回覆閣下的查詢;

於有需要時,將閣下轉介至相關服務;

同意
處理閣下的查詢。

進行統計用途;以及

合法利益
協助我們更清楚理解我們的顧客的需要和期望,從而改善我們的服務、產品和品牌。

進行產品推出後的安全監測:

監察與防止任何與使用我們的產品有所連繫的不良作用;

進行關於安全使用我們的產品的研究;以及

於有需要時實行和跟進所採取的糾正措施。

法律依據
遵從法律義務,以監察產品的任何不良作用。

推薦

視乎閣下與我們互動的多寡, 該些資料可能包括:

姓氏及稱謂;

電話號碼;以及

電郵地址。

按照使用者的要求,將我們的產品資訊及/或標記於願望清單的資訊發送予他人。

履行合約
處理相關要求。

合法利益
按照某位使用者的要求聯絡他人。


自動決策


我們利用第三方提供者的一個或多個方案,以供保障透過於我們的網站/應用程式/裝置進行的交易免於詐騙或挪用金錢。詐騙偵測是以簡單比較、聯繫、聚類分析、預計和異常檢測等方法為基礎,利用智能媒介、資料融合技術和多種資料探勘技術進行。

這種詐騙偵測過程可完全自動進行,或涵蓋由人們作出最終決定的人為干預。於任何情況下,我們均採取一切合理的預防和保障措施,限制存取閣下的資料。

由於需要進行自動詐騙偵測,閣下可能 (i) 當閣下的交易正由我們審核時,經歷訂單/要求處理延誤;以及 (ii) 一旦鑒定詐騙風險,被限制或豁免受惠於某項服務。閣下有權存取我們用以作為決定基礎的資訊。請見以下「閣下的權利和選擇」部分。


個人剖析


當我們發送或顯示度身訂造的通訊或內容時,我們或會採用符合「個人剖析」的部分技術,亦即任何自動處理個人資料的形式,涵蓋利用該等資料評估關於某位自然人的相關個人特點,尤其是用以分析或預計關於該位自然人的個人偏好、興趣、經濟狀況、行為、所在地、健康、可靠度或行動的特點。這意味著我們或會於上表所列的不同情況當中收集關於閣下的個人資料。我們集中處理和分析此項資料,以評估和預測閣下的個人偏好及/或興趣。

根據我們的分析,我們將發送或顯示按照閣下的興趣/需要度身訂造的通訊及/或內容。

閣下有權反對於特定情況使用閣下的資料進行「個人剖析」。請見下列「閣下的權利和選擇」部分。


誰可存取閣下的個人資料?


為了遵從我們的法律義務、防止詐騙及/或保障我們的工具安全並改善我們的產品和服務,或於取得閣下同意時,我們或會將閣下的個人資料於歐萊雅集團內部分享。

視乎收集資料之目的,以及僅以需知為基礎的情況下,閣下的部分個人資料或會於必要時由全球歐萊雅集團實體存取,以供為閣下提供要求的服務,而該等資料將於可能情況下以假名方式處理 (防止直接辨識身分)。

我們亦可能以假名處理方式 (防止直接辨識身分) 與歐萊雅研究及創新部門 (包括位於閣下所在國家以外的地區) 的科學家分享閣下的個人資料,以供研究和創新用途。

於許可的情況下,我們亦可能於旗下品牌之間分享閣下部分個人資料,包括透過 Cookies 所收集的資料,以統一和更新閣下與我們分享的資訊、根據閣下的特徵進行統計,並為閣下度身訂造我們的通訊。

關於 歐萊雅集團、其品牌所在地的更多詳情,請瀏覽歐萊雅集團網站。

我們或會與第三方或歐萊雅集團實體分享閣下的個人資料,以作市場推廣用途。

我們僅於取得閣下同意後,方與第三方分享閣下的個人資料以作直接促銷用途。於此情況下,閣下的資料將由作為資料使用者的該等第三方處理,並受其個別條款及細則和私隱通知約束。閣下應仔細檢閱彼等的文件,方同意將個人資訊披露予該等第三方。

閣下的個人資料亦可能由我們的可靠第三方提供者以我們的名義處理。

我們倚賴可靠第三方以我們的名義進行一系列業務營運工作。我們僅向彼等提供其執行服務所需的資料,並要求彼等不使用閣下的個人資料作任何其他用途。我們一直竭盡所能,確保我們合作的所有第三方均保障閣下的個人資料安全。例如,我們或會向以下各方委託服務,而該等服務需要處理閣下的個人資料:

支援和協助我們提供數碼和電子商務服務的第三方,例如社群聆聽、專門店一覽、常客計劃、身分管理、評價和評論、顧客關係管理、網絡數據分析和搜尋器,以及用戶生成內容策展工具;

廣告、市場推廣、數碼和社交媒體代理公司,協助我們提供廣告、市場推廣和企劃,並分析其效用,以及管理閣下的聯絡資料和疑問;

奉命將產品運送予閣下的第三方,例如郵政/付運服務;

支援和協助我們提供資訊科技服務的第三方,例如平台提供者、網站寄存服務、為我們的資料庫以及可能包含閣下資料的軟件和應用程式進行的維護和支援 (該等服務意味著閣下的資料有時可能需要被存取, 以執行所需任務);

支付服務供應者和信貸資料服務機構,以供於與閣下締約的情況當中,評估閣下的信貸評分和確認閣下的詳細資料;以及

協助我們處理顧客服務和產品推出後的安全監測的第三方。


我們亦可能將閣下的個人資料披露予第三方:


倘我們出售任何業務或資產,我們或會向該等業務或資產的潛在買家披露閣下的個人資料。如歐萊雅或其部分資產被第三方收購,歐萊雅持有之與該等資產相關的顧客個人資料將成為轉移資產的一部分。於該等情況下 (如適用),買家將以新的資料使用者身分處理閣下的資料,並受其個別私隱政策管轄;

如我們為了遵從法律義務、執行或應用我們的使用/銷售條款或其他閣下已同意之條款及細則;或保障歐萊雅、我們的顧客或僱員的權利、財產或安全,而有責任披露或分享閣下個人資料;

如我們已取得閣下同意如此行事;或

如法律許可我們如此行事。


我們可能將閣下的個人資料披露予我們的合作夥伴:


倘閣下利用的服務由歐萊雅及其合作夥伴共同創設 (例如品牌聯乘應用程式)。在該等情況下,歐萊雅及該夥伴將各自以其個別目的處理閣下的個人資料,而因此閣下的個人資料將:

由歐萊雅根據本私隱政策處理;以及

由該夥伴同樣以資料使用者的身分,在其個別條款及細則的規範下,根據其個別私隱政策處理;

倘閣下已透過專屬選項 (例如透過由歐萊雅訂立品牌並提供予其合作夥伴的應用程式) 同意接收由歐萊雅合作夥伴發送的市場推廣和商業通訊。於此等情況下,閣下的資料將由該夥伴以資料使用者的身分,在其個別條款及細則的規範下,根據其個別私隱政策處理;以及

我們或會刊登來自社交網絡的輔助內容。倘閣下於我們的網站/應用程式查閱來自社交網絡的內容,來自該等社交網絡的 Cookie 可能會儲存於閣下的裝置。我們懇請閣下閱讀此等社交網絡的 Cookie 政策以了解更多資訊。


我們不會供出或出售閣下的個人資料。


我們於哪裡存置閣下的個人資料


我們向閣下收集的資料或會轉移至和存置於香港特別行政區以外的地點,並由該等地點存取。該等資料亦可能由我們或我們的服務提供者於香港特別行政區以外地點工作的員工處理。

歐萊雅僅以安全而合法的方式將資料轉移至香港特別行政區以外地點。由於部分國家或不設管轄個人資料之應用和轉移的法律,我們採取必要步驟,確保第三方遵守於本政策列明的承諾。此等步驟可能包括審核第三方的私隱和保安標準,及/或與之締結適當合約。

如欲了解更多資訊,請按照以下「聯絡」部分的方式聯絡我們。


我們保留閣下的個人資料多久


我們保留閣下個人資料的期限,僅限於我們需要持有該等資料以迎合閣下的需要或遵從我們的法律義務的期間。我們利用以下準則,界定保留閣下資料的期限:

如閣下購買產品和服務,我們將於雙方的契約關係生效期間保留閣下的個人資料;

如閣下參與推廣優惠,我們將於該推廣優惠期間保留閣下的個人資料;

如閣下聯絡我們進行查詢,我們將於處理閣下查詢的必要期間內保留閣下的個人資料;

如閣下創建帳戶,我們將保留閣下的個人資料,直至閣下要求我們將該等資料刪除,或經過根據當地法規和指示所定義的凍結期間後 (沒有與品牌主動進行互動);

如閣下同意接收直銷信息,我們將保留閣下的個人資料,直至閣下取消訂閱或要求我們刪除該等資料,或經過根據當地法規和指示所定義的凍結期間後 (沒有與品牌主動進行互動);以及

如 cookies 儲存於閣下的電腦,我們將於它們發揮作用的必要期間內 (例如購物車 cookies 的工作階段期限或工作階段識別碼 cookies),並於其後根據當地法規和指示所定義的期限內保留該等 cookies。


我們或會保留部分個人資料,以遵從我們的法律或監管義務,並容許我們管理我們的權利 (例如於法庭提出申索), 或作統計或記錄用途。

當我們不再需要使用閣下的個人資料,該等資料將從我們的系統和記錄移除或以匿名方式處理,從而令閣下不再從中被辨識。


閣下的個人資料安全嗎?


我們致力保障閣下的個人資料安全,並為此採取一切合理預防措施。我們亦以締約方式要求為我們處理閣下個人資料的可靠第三方遵從此守則。

我們竭盡所能保護閣下的個人資料,而每當我們接收閣下的個人資料後,都利用嚴謹程序和保安措施,嘗試防止未經授權的存取。由於透過互聯網傳送資料並非絕對安全,我們無法保證閣下傳送至我們網站的資料安全。因此,閣下必需自行承受任何資料傳送的風險。


第三方網站連結和社交媒體登入


我們的網站和應用程式或會不時含有連結,來往我們的合作夥伴網絡、廣告商和聯營企業的網站。如閣下開啟連結前往任何此等網站,請注意此等網站另有其個別私隱政策,而我們對於此等政策將不會負上任何義務或法律責任。請於提交任何個人資料至此等網站前檢閱此等政策。

我們亦可能會為閣下提供使用社交媒體登入的渠道。請注意,如閣下使用社交媒體登入,視乎閣下的社交媒體平台設定,閣下或將與我們分享閣下的個人檔案資訊。請到訪相關社交媒體平台並檢閱其私隱政策,以了解閣下的個人資料於此等情況下如何被分享和使用。


社交媒體和用戶生成內容


我們的部分網站和應用程式容許使用者提交其個人內容。請緊記提交至我們的社交媒體平台之任何內容均可供公眾閱覽,因此閣下於提供若干個人資料,例如財務資訊或地址詳情時,應當小心謹慎。如閣下於我們的社交媒體平台張貼個人資料,而我們並不建議閣下分享該等資料,我們對於其他個別人士採取的任何行動概不負責。

閣下的權利和選擇

歐萊雅尊重閣下就個人私隱所擁有的權利;閣下能夠掌控個人資料至為重要。閣下擁有以下權利:

閣下的權利

這意味著甚麼?

知會的權利

閣下有權就我們使用閣下個人資料的方式, 以及閣下的權利,獲取清晰、透明而易於理解的資訊。這正是我們於本政策向閣下提供此等資訊的原因。

存取的權利

閣下有權存取由我們持有而與閣下有關的個人資料 (受特定限制約束)。我們或會視乎提供該等資訊的行政成本而收取合理費用。明顯缺乏根據、過量或重覆的要求或不獲回覆。如欲存取閣下的個人資料,請透過下列詳情聯絡我們。

更正的權利

如閣下的個人資料有誤或過時及/或出現缺漏,閣下有權將之更正及/或補充。如欲進行,請透過下列詳情聯絡我們。如閣下擁有帳戶, 請透過閣下帳戶的「我的帳戶」功能自行更正閣下的個人資料。

反對包括個人剖析在內的直銷的權利

閣下可隨時取消訂閱我們的直銷通訊或從相關清單退出。最簡易的做法是點擊我們向閣下發送的任何電郵或通訊裡的「取消訂閱」連結。否則,閣下亦可利用下列的聯絡詳情與我們聯絡。如閣下欲反對任何個人剖析,請透過以下詳情聯絡我們。

隨時撤銷根據閣下同意進行的資料處理之同意的權利

如我們就閣下資料進行的處理乃根據閣下同意進行,閣下有權撤銷該等同意。此舉不應影響於撤銷之前根據閣下同意進行的資料處理之合法性。我們參照加插於「我們向閣下收集甚麼資料? 我們又會如何使用該等資料」部分的表格,尤其是「我們處理閣下資料的法律基礎為何」一欄,辨識我們根據閣下同意所進行的資料處理。如閣下欲對此提出反對並撤銷同意,請透過以下詳情聯絡我們。


為處理閣下的要求,我們或會要求閣下提供身分證明。

本私隱政策備有中文版本。如有歧義,概以英文版本為準。

2020 年 6 月 24 日

個人資料收集聲明

收集閣下的個人資料

我們 (歐萊雅香港有限公司) (下稱「我們」或「歐萊雅」) 旗下的 LA ROCHE-POSAY (「品牌」) 將根據本《個人資料收集聲明》,收集及儲存閣下的個人資料 (「閣下資料」)。閣下必須提供以星號 (*) 標示的個人資料,而提供並無以星號 (*) 標示的個人資料純屬自願,惟閣下倘不提供相關資料,我們可能無法向閣下提供我們的產品及服務。

使用閣下個人資料的目的

我們將把閣下資料用作以下目的 (需視乎情況):

a)

就閣下於我們的網上商店或零售店舖 (包括我們的零售店舖 / 百貨公司夥伴) 購買我們的產品及 / 或服務以及閣下的網上購物帳戶,處理、管理交易和與閣下聯絡;

b)

建立和管理閣下的品牌會籍和會員獎賞 (包括查詢及累積或兌現會員積分) ,並就此與閣下聯絡;

c)

就閣下參與歐萊雅舉辦的任何競賽、抽獎、遊戲、比賽、活動或推廣,向閣下提供免費產品、試用裝或禮品;

d)

就閣下查詢我們的產品及 / 或服務事宜與閣下通訊;

e)

為促成上述任何目的而識別和確認身分;

f)

作內部研究、評估和數據分析;

g)

(視乎閣下有否給予任何書面同意) 作直銷用途;及

h)

任何其他直接相關目的。


(統稱「使用目的」)。

我們或會在閣下給予書面同意的情況下,透過電話、短訊、電郵或美容顧問在社交媒體平台通訊軟件 (例如Facebook 訊息、Instagram 訊息、WhatsApp 訊息、微信訊息等) 的互動對話,與閣下聯絡並通訊。

轉移閣下的個人資料

我們或會因應使用目的,向以下各方轉移、分享或供其存取閣下資料:

a)

歐萊雅或其集團旗下任何成員公司或附屬公司 (包括位於香港境內或境外的該等公司) (統稱「歐萊雅集團」);

b)

向歐萊雅或歐萊雅集團任何成員提供付款、資訊科技、研究、客戶概況分析、數據分析、市場推廣、電話中心、行政服務及為支持歐萊雅或歐萊雅集團任何成員業務營運所提供的任何其他服務之第三方服務提供者或代理;

c)

與閣下就購買我們的產品及 / 或服務付款相關的信貸資料服務機構,以及信用卡、扣帳卡及 / 或簽帳卡公司及 / 或銀行;及

d)

社交媒體平台提供者 (包括位於中國及美國的提供者)。

使用閣下的個人資料作直銷用途

未經閣下同意,我們不得使用及 / 或轉移閣下的個人資料作直銷用途。倘獲閣下同意,我們會利用閣下資料,就 (視乎情況) 品牌於香港特別行政區及澳門特別行政區供應的美容、護膚、化妝、護髮、頭髮造型、香水、香氛、蠟燭、潔手及其他相關產品及服務,經閣下指示的通訊渠道 (例如電話、短訊、電郵及 Facebook 訊息等) 向閣下傳送推廣內容、資訊及最新信息。

閣下的權利和我們的聯絡方法

閣下有權要求存取及修改由我們持有而與閣下相關的資料。如欲存取或修改閣下的個人資料,請透過電郵至[email protected] 與我們的法律部聯絡。如欲取消訂閱我們的直銷通訊或有任何一般查詢,請透過[email protected] 與我們聯絡。

如欲獲取我們如何使用閣下的個人資料的進一步資訊,請參閱我們的《私隱政策》: https://www.laroche- posay.hk/cn/site/pages/ShowMediaApp.aspx?MediaAppCode=PDF_Privacy_Policy_HK.

本《聲明》原文以英文撰寫,有可能翻譯為中文。如譯本與英文版本有任何不符之處,概以英文版本為準。

LA ROCHE-POSAY

PRIVACY POLICY

L’Oréal’s ambition is to be an exemplary corporate citizen to help make the world a more beautiful place. We place great value on honesty and clarity, and we are committed to building a strong and lasting relationship with our consumers based on trust and mutual benefit. Part of this commitment means safeguarding and respecting your privacy and your choices. Respecting your privacy is essential to us. This is why we set out “Our Privacy Promise” and our full Privacy Policy below.

OUR PRIVACY PROMISE

1)

We respect your privacy and your choices.

2)

We make sure that privacy and security are embedded in everything we do.

3)

We do not send you marketing communications unless you have asked us to. You can change your mind at any time.

4)

We never offer or sell your data.

5)

We are committed to keeping your data safe and secure. This includes only working with trusted partners.

6)

We are committed to being open and transparent about how we use your data.

7)

We do not use your data in ways that we have not told you about.

8)

We respect your rights, and always try to accommodate your requests as far as is possible, in line with our own legal and operational responsibilities.

For more information about our privacy practices, below we set out what types of personal data we may receive from you directly or from your interaction with us, how we may use it, who we may share it with, how we protect it and keep it secure, and your rights around your personal data. Of course all situations may not apply to you. This Privacy Policy gives you an overview of all possible situations in which we could interact together.

The more you interact with us, the more you let us know you and the more we are able to offer you tailored services.

When you share personal data with us or when we collect personal data about you, we use it in line with this Policy. Please read this information and our Q&A page (if any) carefully.

Please note that you must be at least 18 years old or older to use our services, or older where the terms for a specific service require this.

WHO WE ARE


LA ROCHE-POSAY is a part of the L’Oreal Hong Kong Limited brand portfolio. L’Oreal Hong Kong Limited is responsible for the personal data that you share with us. When we say “L’Oréal”, “us”, “our” or “we”, this is who we are referring to. L’Oréal is a “data user” for the purposes of the Personal Data (Privacy) Ordinance (Cap. 486).


Please see the “Contact Us” section for our contact details.


L’Oréal represents several different brands and products. For more information on L’Oréal, and the brands it represents, please see http://www.loreal.hk/en-hk/.


L’Oréal is part of the L’Oréal Group, which operates in 140 countries around the world. For details on the L’Oréal Group, please see http://www.loreal.com/group.

CONTACT

If you have any questions or concerns about how we treat and use your personal data, or would like to exercise any of your rights above, please contact us at [email protected] or please writing at

Customer Care Department

L’Oreal Hong Kong Limited 35/F, Sun
Hung Kai Centre 30 Harbour Road
Wan Chai, Hong Kong SAR Attn:
LA ROCHE-POSAY

You may also contact [email protected] for any questions related to the processing of your personal data.

WHAT IS PERSONAL DATA?


“Personal data” means any information or pieces of information that could identify you either directly (e.g. your name) or indirectly (e.g. through pseudonymized data such as a unique ID number). This means that personal data includes things like email/home addresses/mobile phone, usernames, profile pictures, personal preferences and shopping habits, user generated content, financial information, and welfare information. It could also include unique numerical identifiers like your computer’s IP address or your mobile device’s MAC address, as well as cookies.


WHAT DATA DO WE COLLECT FROM YOU AND HOW DO WE USE IT?

L'Oréal believes that you, the consumer, are at the heart of what we do. We love hearing from you, learning about you, and creating and delivering products that you enjoy. And we know that many of you love talking to us. Because of this, there are many ways that you might share your personal data with us, and that we might collect it.

How do we collect or receive your data?

We might collect or receive data from you via our websites, forms, apps, devices, L’Oréal products or brands pages on social media or otherwise. Sometimes you give this to us directly (e.g. when you create an account, when you contact us, when you purchase from our websites/apps or stores/beauty salon), sometimes we collect it (e.g. using cookies to understand how you use our websites/apps) or sometimes we receive your data from other third parties, including other L’Oréal Group entities.

When we collect data, we indicate the mandatory fields via asterisks where such data is necessary for us to:

-

perform our contract with you (e.g. to deliver the products you have purchase on our websites/apps);

-

provide you with the service you have asked for (e.g. to provide you with a newsletter, birthday offers or account status); or

-

comply with legal requirements (e.g. invoicing).

If you do not provide the data marked with an asterisk, this may affect our ability to provide the products and services.

We set out further details in the table below, explaining:

1)

During what interaction your data may be provided or collected? This column explains what activity or situation you are involved in when we use or collect your data. For example, whether you are making a purchase, signing up to a newsletter, or browsing a website/app.

2)

What personal data may we receive from you directly or resulting from your interaction with us? This column explains what types of data we may collect about you depending on the situation.

3)

How and why we may use it? This column explains what we may do with your data and the purposes for collecting it.

4)

What is the legal basis for using your personal data? This column explains the reason we may use your data.

Depending on the purpose for which the data is used, the legal basis for the processing of your data can be:

Your consent;

Our legitimate interest, which can be:

Improvement of our products and services: more specifically, our business interests to help us better understand your needs and expectations and therefore improve our services, websites / Apps / devices, products and brands for our consumers’ benefit.

Fraud prevention: to ensure payment is complete and free from fraud and misappropriation.

Securing our tools: to keep tools used by you (our websites/Apps/devices) safe and secure and to nsure they are working properly and are continually improving.

The performance of a contract: more specifically to perform the services you request from us; or

Legal grounds where a processing is required by law.


Information overview on your interactions with us and their consequences on your data

During which interactions may you provide and we may collect your data?

What personal data may we receive from you directly or resulting from your interaction with us?

How and why we may use your data?

What is the legal basis for using your personal data?

Account Creation and management

Information collected during the creation of an account on L’Oréal websites/apps, through a social media login, or in store.

Depending on how much you are interacting with us, those data may include:

name and surname;

gender;

email address;

address;

phone number;

photo;

birthday or age range;

ID, username, and password;

personal description or preferences;

order details; and

social media profile (where you use social login or share this personal data with us).

To:

manage your orders;

manage any competitions, promotions, surveys or lucky draws you choose to enter;

respond to your questions and otherwise interact with you ;

offer you a loyalty program;

allow you to manage your preferences;

Performance of a contract

To provide you with the service you requested (e.g. create an account, complete a survey, or purchasing a product).

send you marketing communications (where you have asked us to) which may be tailored to your “profile” (i.e. based on the personal data we know about you and your preferences);

Consent

To send you direct marketing communications.

offer personalized services based on your beauty characteristics;

monitor and improve our websites/apps ;

run analytics or collect statistics; and

secure our websites/apps and protect you and us against fraud;

Legitimate Interest

To ensure our websites/apps remain secure, to protect them against fraud, and to help us better understand your needs and expectations and therefore improve our services, products and brands.

Newsletter and commercial communications subscription

Depending on how much you are interacting with us, those data may include:

email address;

name and surname;

personal description or preferences; and

social media profile (where you use social login or share this personal data with us).

To:

send you marketing communications (where you have asked us to) which may be tailored to your “profile” based on the personal data we know about you, and your preferences (incl. location of your favourite store); and

Consent

To send you direct marketing communications.

run analytics or collect statistics.

Legitimate Interest

to tailor our marketing communications, understand their effectiveness, and ensure you receive the most relevant experience; and to help us better understand your needs and expectations and therefore improve our services, products and brands.

Keep an up to date suppression list if you have asked not to be contacted;

Legal grounds

To keep your details on a suppression list if you have asked us not to send you any direct marketing anymore.

Purchases and order management

Information collected during the purchase process made on L’Oréal website/apps/social pages or in store

Depending on how much you are interacting with us, those data may include:

name and surname;

email address;

address (delivery and invoicing);

phone number;

personal description or preferences;

social media profile (where you use social login or share this personal data with us);

transaction information including purchased products and store location;

payment and information; or

purchase history

To

contact you to finalize your order where you have saved your shopping cart or placed products in your cart without completing the checkout process;

inform you when a product you wanted to purchase is available;

process and follow your order including delivering the product to the address you indicated;

manage the payment of your order. To be noted, payment information (credit card number / Paypal, Alipay or WeChat Pay information / bank account details) are not collected by us but directly by payment service providers;

manage any contact you have with us regarding your order;

Performance of a contract:

To provide you with the service you requested (purchase).

secure the transactions against fraud. To be noted, we use a third party provider’s solution to detect fraud and ensure the payment is complete and made by you or someone authorized by you;

enrich your profile if you place a purchase using your account information;

measure satisfaction;

manage any dispute relating to a purchase; and

for statistics purposes.

Legitimate interest

To protect you and us from fraudulent transaction and to ensure the payment is complete and free from fraud and misappropriation.

Online browsing

Information collected by cookies or similar technologies (“Cookies”*) as part of your browsing on L’Oréal website / apps and/or on third- party website / apps.

For information on specific Cookies placed through a given website/app, please consult the relevant cookie table.

Depending on how much you are interacting with us, those data may include:

data related to your use of our websites/apps:

where you came from;

login details;

pages you looked at;

videos you watched;

ads you click on or tap;

products you search for;

your location;

duration of your visit; and

products you selected to create your basket.


Technical information:

IP address;

browser information; and

device information.


A unique identifier granted to each visitor and the expiration date of such identifier.

We use Cookies, where relevant, with other personal data you have already shared with us (such as previous purchases, or whether you’re signed up to our email newsletters) or the following purposes:

to allow proper functioning of our website/apps:

proper display of the content;

creation and remembering of a cart;

creation and remembering of your login;

interface personalisation such as language;

parameters attached to your device including your screen resolution, etc; and

improvement of our websites/apps, for example, by testing new ideas;

to ensure the website/app is secure and safe and protect you against fraud or misuse of our websites or services, for example through performing troubleshooting;

Legitimate interest:

To ensure we are providing you with websites / apps, advertising and communications that are working properly and are continually improving for cookies that are (i) essential for the functioning of our websites / apps, (ii) used to keep our websites/apps safe and secure.

* Cookies are small text files stored on your device (computer, tablet or mobile) when you are on the Internet, including on L’Oréal Group’s websites.

to run statistics:

to avoid visitors being recorded twice;

to know users’ reaction to our advertising campaigns;

to improve our offers; and

to know how you discovered our websites / apps.

to deliver online behavioural advertising:

to show you online advertisements for products which may be of interest to you, based on your previous behaviour; and

to show you ads and content on social media platforms.

to tailor our services for you:

to send you recommendations, marketing, or content based on your profile and interests;

to display our websites/apps in a tailored way like remembering your cart or login, your language, the user-interface customization cookies (i.e. the parameters attached to your device including your screen resolution, font preference, etc); and

to allow sharing of our content on social media (sharing buttons intended to display the site).

Consent

For all other cookies.

Promotional operations

Information collected during a game, contests, promotional offer, sample requests, surveys.

Depending on how much you are interacting with us, those data may include:

name and surname;

email address;

phone number;

birth date;

gender;

address;

personal description or preferences;

social media profile (where you use social login or share this personal data with us); and

other information you have shared with us about yourself (e.g. via your “My Account” page, by contacting us, or by providing your own content such as photos or a review, or a question via the chat function available on some websites/apps, or by participating in a contest, game, survey).

to complete tasks that you have asked us to, for example to manage your participation in contests, games and surveys, including to take into account your feedback and suggestions;

Performance of contract
To provide you with the service you requested.

for and statistics purposes;

Legitimate Interest

To help us better understand your needs and expectations and therefore improve our services, products and brands.

to send you marketing communications (where you have asked us to)

Consent

To send you direct marketing communications.

User Generated Content

Information collected when you submitted some content on one of our social platforms or accepted the re- use of content you posted on social media platforms by us.

Depending on how much you are interacting with us, those data may include:

name and surname or alias;

email address;

photo;

personal description or preferences;

social media profile (where you use social login or share this personal data with us); and

other information you have shared with us about yourself (e.g. via your “My Account” page, by contacting us, or by providing your own content such as photos or a review, or a question via the chat function available on some websites/apps).

In accordance with the specific terms and conditions accepted by you:

to post your review or content; and

to promote our products.

Consent

To reuse the content you posted online.

For statistics purposes.

Legitimate Interest

To help us better understand your needs and expectations and therefore improve and promote our services, products and brands.

Use of Apps and devices

Information collected as part of your use of our Apps and/or devices.

Depending on how much you are interacting with us, those data may include:

name and surname;

email address;

location;

birth date;

personal description or preferences;

photo;

welfare data including skin tone, skin/hair type; and

geolocation.

To

provide you with the service requested (for example, virtually test our products, purchase our products through the App or on related e-com websites; advice and notifications regarding your sun exposure, your hair routine);

analyse your welfare characteristics and recommend the appropriate products (including bespoke products) and routines;

provide you product & routine recommendations;

Performance of a contract

To provide you with the service requested (including, where needed, analysis by the research and innovation team of the algorithm necessary to provide the service).

for research and innovation by scientists within L’Oréal Group;

for monitoring and improvement of our Apps and devices; and

for statistics purposes.

Legitimate Interest

To always improve our products and services to match your needs and expectations and for research and innovation purposes.

Enquiries

Information collected when you ask questions (e.g. through our consumer care) relating to our brands, our products and their use.

Depending on how much you are interacting with us, those data may include:

name and surname;

phone number;

email address; and

other information you have shared with us about yourself in relation to your enquiry (which may include welfare and health data).

To answer your enquiries;

where needed, to connect you with the relevant services;

Consent

To process your enquiry.

for statistics purposes; and

Legitimate interest

To help us better understand our customers’ needs and expectations and therefore improve our services, products and brands.

for post-market surveillance:

to monitor and prevent any undesirable effect linked to the use of our products;

to perform studies relating to the safe use of our products; and

to perform and follow- up on corrective measures taken, where needed.

Legal grounds

To comply with the legal obligation to monitor undesirable effects of its products.

Sponsorship

Depending on how much you are interacting with us, those data may include:

name and surname;

phone number; and

email address.

To send information on our products and or information tagged in a wish list to a person at another person’s request.

Performance of a contract

To process the request.

Legitimate interest

To contact the person at another person’s request.


Automated Decision Making

For purposes of securing transactions placed through our websites/apps/devices against fraud and misappropriation, we use third party provider’s solution(s).The method of fraud detection is based on, for example, simple comparisons, association, clustering, prediction and outlier detections using intelligent agents, data fusion techniques and various data mining techniques.

This fraud detection process may be completely automated or may involve human intervention where a person takes the final decision. In any case, we take all reasonable precautions and safeguards to limit access to your data.

As a result of automatic fraud detection, you may (i) experience delay in the processing of your order / request whilst your transaction is being reviewed by us; and (ii) be limited or excluded from the benefit of a service if a risk of fraud is identified. You have the right to access information on which we base our decision. Please see “Your Rights and Choices” section below.


Profiling

When we send or display personalized communications or content, we may use some techniques qualified as “profiling” (i.e. any form of automated processing of personal data consisting of using those data to evaluate certain personal aspects relating to a natural person, in particular to analyse or predict aspects concerning that natural person’s personal preferences, interests, economic situation, behaviour, location, health, reliability, or movements). This means that we may collect personal data about you in the different scenarios mentioned in the table above. We centralize this data and analyse it to evaluate and predict your personal preferences and/or interests.

Based on our analysis, we send or display communications and/or content tailored to your interests/needs.

You have the right to object to the use of your data for “profiling” in certain circumstances. Please see “Your Rights and Choices” section below.

Who may access your Personal data?

We may share your personal data within L’Oréal Group to comply with our legal obligations, to prevent fraud and/or to secure our tools, to improve our products and services, or after having obtained your consent to do so.

Depending on the purposes for which they were collected, and only on a need-to-know basis some of your personal data may be accessed by L’Oréal Group entities worldwide, where possible in a pseudonimized way (not allowing direct identification), and where necessary to provide you with requested services.

We may also share your personal data in a pseudonimized way (not allowing direct identification) with L’Oréal Research & Innovation scientists, including those located outside of your country, for research and innovation purposes.

Where permitted, we may also share some of your personal data including those collected through Cookies between our brands to harmonize and update the information you share with us, to perform statistics based on your characteristics and to tailor our communications.

Please visit the L’Oréal group website, for further details on the L’Oréal Group, its brands and its locations.

We may share your personal data for marketing purposes with third party or entities of the L’Oréal Group.

We only share your personal data with third parties for direct marketing purposes with your consent. In this context, your data is processed by such third party, acting as a data user, and its own terms and conditions and privacy notice apply. You should carefully check their documentation before consenting to the disclosure of your information to that third party.

Your personal data may also be processed on our behalf by our trusted third party providers.

We rely on trusted third parties to perform a range of business operations on our behalf. We only provide them with the information they need to perform the service, and we require that they do not use your personal data for any other purpose. We always use our best efforts to ensure that all third parties we work with keep your personal data secure. For instance, we may entrust services that require the processing of your personal data to:

third parties that assist and help us in providing digital and e-commerce services such as social listening, store locator, loyalty programs, identity management, ratings and reviews, CRM, web analytics and search engine, user generated content curation tools;

advertising, marketing, digital and social media agencies to help us to deliver advertising, marketing, and campaigns, to analyse their effectiveness, and to manage your contact and questions;

third parties required to deliver a product to you e.g. postal/delivery services;

third parties that assist and help us in providing IT services, such as platform providers, hosting services, maintenance and support on our databases as well as on our software and applications that may contain data about you (such services could sometimes imply access to your data to perform the required tasks);

payment service providers and credit reference agencies for the purpose of assessing your credit score and verifying your details where this is a condition of entering into a contract with you; and

third parties that assist us for customer care and post-market surveillance purposes.

We may also disclose your personal data to third parties:

in the event that we sell any business or assets, in which case we may disclose your personal data to the prospective buyer of such business or assets. If L’Oréal or a part of its assets is acquired by a third party, personal data held by it about its customers relating to those assets is one of the transferred assets. Where appropriate, in such case, the buyer acting as the new data user processes your data and its privacy policy governs the processing of your personal data;

if we are under a duty to disclose or share your personal data in order to comply with a legal obligation, or in order to enforce or apply our terms of use/sales or other terms and conditions you have agreed to; or to protect the rights, property, or safety of L’Oréal, our customers, or employees

if we have your consent to do so; or

if we are permitted to do so by law.

We may disclose your personal data to our partners:

in the event the service you subscribe to was co-created by L’Oréal and a partner (for example, a co-branded app). In such case, L’Oréal and the partner process your personal data each for their own purposes and as such your data is processed:

by L’Oréal in accordance with this Privacy Policy; and

by the partner acting also as a data user under its own terms and conditions and in accordance with its own privacy policy;

in the event you agreed to receive marketing and commercial communications from a L’Oréal partner through a dedicated opt-in (for instance, through an App branded by L’Oréal and made available to its partners). In such case, your data is processed by the partner acting as a data user under its own terms and conditions, and in accordance with its privacy policy; and

we may publish on our supports content from social networks. In the event you consult content from social networks on our website/apps, a Cookie from such social network may be stored on your device. We invite you to read the Cookie Policy of these social networks for more information.

We do not offer or sell your personal data.

Where we Store your Personal data

The data that we collect from you may be transferred to, accessed from, and stored at a destination outside Hong Kong SAR. It may also be processed by staff members operating outside the Hong Kong SAR who work for us or for one of our service providers.

L’Oréal transfers personal data outside of the Hong Kong SAR only in a secure and lawful way. As some countries may not have laws governing the use and transfer of personal data, we take steps to make sure that third parties adhere to the commitments set out in this Policy. These steps may include reviewing third parties’ privacy and security standards and/or entering into appropriate contracts.

For further information, please contact us as per the “Contact” section below.

How Long Do We Keep Your Personal data

We only keep your personal data for as long as we need it for the purpose for which we hold your personal data, to meet your needs, or to comply with our legal obligations.
To determine the data retention period of your data, we use the following criteria:

where you purchase products and services, we keep your personal data for the duration of our contractual relationship;

where you participate in a promotional offer, we keep your personal data for the duration of the promotional offer;

where you contact us for an enquiry, we keep your personal data for the duration needed for the processing of your enquiry;

where you create an account, we keep your personal data until you require us to delete it or after a period of inactivity (no active interaction with brands) defined in accordance with local regulations and guidance;

where you have consented to direct marketing, we keep your personal data until you unsubscribe or require us to delete it or after a period of inactivity (no active interaction with brands) defined in accordance with local regulations and guidance; and

where cookies are placed on your computer, we keep them for as long as necessary to achieve their purposes (e.g. for the duration of a session for shopping cart cookies or session ID cookies) and for a period defined in accordance with local regulations and guidance.

We may retain some personal data to comply with our legal or regulatory obligations, as well as to allow us to manage our rights (for example to assert our claims in Courts) or for statistical or historical purposes.

When we no longer need to use your personal data, it is removed from our systems and records or anonymised so that you can no longer be identified from it.

Is Your Personal data Secure?

We are committed to keeping your personal data secure, and taking all reasonable precautions to do so. We contractually require that trusted third parties who handle your personal data for us do the same.

We always do our best to protect your personal data and once we have received your personal data, we use strict procedures and security features to try to prevent unauthorised access. As the transmission of information via the internet is not completely secure, we cannot guarantee the security of your data transmitted to our site. As such, any transmission is at your own risk.

Links to Third Party Sites and Social Login

Our websites and Apps may from time to time contain links to and from the websites of our partner networks, advertisers and affiliates. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we are not responsible or liable for these policies. Please check these policies before you submit any personal data to these websites.

We may also offer you the opportunity to use your social media login. If you do so, please be aware that you share your profile information with us depending on your social media platform settings. Please visit the relevant social media platform and review its privacy policy to understand how your personal data is shared and used in this context.

Social Media and User Generated Content

Some of our websites and Apps allow users to submit their own content. Please remember that any content submitted to one of our social media platforms can be viewed by the public, so you should be cautious about providing certain personal data e.g. financial information or address details. We are not responsible for any actions taken by other individuals if you post personal data on one of our social media platforms and we recommend that you do not share such information.

YOUR RIGHTS AND CHOICES

L’Oréal respects your right to privacy: it is important that you are able to control your personal data. You have the following rights:

Your rights

What does this mean?

The right to be informed

You have the right to obtain clear, transparent and easily understandable information about how we use your personal data, and your rights. This is why we are providing you with the information in this Policy.

The right of access

You have the right to access to the personal data we hold about you (subject to certain restrictions).
We may charge a reasonable fee taking into account the administrative costs of providing the information.
Requests manifestly unfounded, excessive or repetitive may not be answered to.
To do this, please contact us at the details below.

The right to rectification

You have the right to have your personal data rectified if it is incorrect or outdated and/or completed if it is incomplete.
To do this, please contact us at the details below. If you have an account, please correct your own data via your “My Account” function.

The right to object to direct marketing, including profiling

You can unsubscribe or opt out of our direct marketing communication at any time.
It is easiest to do this by clicking on the “unsubscribe” link in any email or communication we send you. Otherwise, you can contact us using contact detail below.

If you would like to object to any profiling, please contact us at the details below.

The right to withdraw consent at any time for data processing based on consent

You can withdraw your consent to our processing of your data when such processing is based on consent. The withdrawal of consent shall not affect the lawfulness of processing based on consent before its withdrawal. We refer to the table inserted in section “what data do we collect from you and how do we use it” especially the column “What is our legal basis for processing your data?” to identify where our processing is based on consent.
If you would like to object to withdraw your consent, please contact us at the details below.



To deal with your request, we may require proof of your identity.

A Chinese version of this Privacy Policy is available. In the event of discrepancy, the English version shall prevail.

24 June 2020

PERSONAL INFORMATION COLLECTION STATEMENT COLLECTION OF YOUR

PERSONAL DATA

We, L’Oreal Hong Kong Limited trading as LA ROCHE-POSAY (“Brand”), will collect and store your personal information pursuant to this Personal Information Collection Statement It is mandatory for you to provide your personal information marked with asterisks (*) and voluntary for those without an asterisk (*); but if you do not, we may not be able to provide you with our products and services.

PURPOSES FOR WHICH YOUR PERSONAL DATA ARE USED

We will use Your Data for the following purposes (as the case may be):

a)

fulfilling, managing and contacting you about your purchase of our goods and/or services at our online or retail stores (including our retail/department store partners), and your online purchase accounts;

b)

creating, managing and contacting you about your Brand membership and member rewards (including enquiries and implementation on loyalty points accrual or redemption);

c)

providing you with free products, samples or gifts in relation to any contest, lucky draw, game, competition, event or promotion which is organised by L’Oréal as you may participate;

d)

communicating with you regarding your enquiries about our goods and/or services;

e)

identification and verification to facilitate any of the above purposes;

f)

internal research, profiling and analytics;

g)

(subject to any written consent you may give) direct marketing purpose; and

h)

any other directly related purposes.


致消費者的私隱政策及個人資料收集聲明


(collectively, the “Use Purposes”).

Where you have given your written consent, we may contact and communicate with you by phone call, SMS, email, mail or via interactive conversations over social media platform messengers (e.g. Facebook message, Instagram message, WhatsApp message, WeChat message, etc.) with our beauty advisors.

TRANSFER OF YOUR PERSONAL DATA

For the Use Purposes, we may transfer, grant access to or share Your Data with:

a)

L’Oréal or any member of its group companies or affiliates, whether located within or outside of Hong Kong SAR (together the “L’Oréal Group”);

b)

any of L’Oréal’s or L’Oréal Group member’s third party service providers or agents who provides payment, IT, research, profiling, analytics, marketing, call centre, administrative and any other services which support the business operation of L’Oréal or any L’Oréal Group member;

c)

in relation to payment for your purchase of our goods and/or services, credit reference agencies, credit, debit and/or charge card companies and/or banks; and

d)

social media platform providers (including those which may be located in the PRC and the United States).

USE OF YOUR PERSONAL DATA FOR DIRECT MARKETING

We cannot use and/or transfer your personal information for direct marketing without your consent. If you opt-in, we will use Your Data to send you promotions, news and updates regarding (as the case may be) beauty, skincare, make-up, hair care, hair styling, fragrances, scents, candles, hand wash and related products and services from our Brand in Hong Kong SAR and Macau SAR via the communication channels you indicate (e.g. phone call, SMS, email, mail, Facebook message etc.)

YOUR RIGHTS AND CONTACT US

You have the right to request access to or correction of information held by us about you. If you wish to access or correct your personal information, please contact our Legal Department at [email protected]. For any unsubscribe from direct marketing or other general enquiries, please contact us at [email protected]