PRIVACY POLICY
Effective Date: 19th May, 2022
1.ABOUT BIOLOGIQUE RECHERCHE AND THIS PRIVACY POLICY
This privacy policy (“Policy”) explains how your personal data are processed by B.R. SAS, and the BR owned legal entities & affiliates (mentioned in the Data Controllers & Contact section below), each entity acting as a data controller. It also tells you how you can access and update your personal data and make certain choices about how your personal data is used including a right to object to some of the processing we carry out or, where we rely on your consent, a right to withdraw this consent.
This Policy covers our data collection activities, including the personal data we collect through our various channels online (such as websites including www.MyBR.com, our apps, and our presence on social networks) and offline collection linked to this Policy (such as points of sale – Ambassades, boutiques or corners – customer service, skin diagnosis and events) (collectively “Services”). It also explains how we collect information using cookies and related technologies on our websites and apps.
Our products are sold through various authorized distributors (such as SPA centers or resorts). Unless otherwise indicated at the time that you provide your personal data, any personal data that our distributor partners collect is not provided to us and this Policy does not apply to such personal data.
1.1.UPDATES TO THIS POLICY
If we change the way we handle your personal data, we will update this Policy and notify you or seek your consent as and when appropriate, usually by placing an updated Policy on our websites. If we make significant changes that materially alter our privacy practices, we will notify you by other means, such as sending an email prior to the changes taking effect. We reserve the right to make changes to our practices and this Policy at any time. We invite you to check our website from time to time for any updates or changes to this Policy.
1.2.DEFINITIONS
Personal data or Data: Any information relating to an identified or identifiable individual (hereafter referred to as "data subject") or as defined under applicable privacy law.
Consent: any expression of will, free, specific, informed and unambiguous by which the data subject accepts, by a statement or by a clear positive act, that personal data concerning him/her be processed.
2.WHAT INFORMATION DO WE PROCESS ?
We obtain personal data from or about you from various online and offline sources or when you voluntarily provide us with such information, including when you:
• interact with our Services, including websites, mobile sites and apps;
• interact with us on our social media pages, chat services, forums or blogs;
• visit one of our Ambassades, boutiques or corners;
• use the Skin Instant Lab technology with one of our distributors;
• participate in our surveys ;
• participate in beauty consultations or interact with our beauty advisors and customer service;
• or otherwise communicate with us for any purpose.
We may combine the information we collect from other sources with any information that you provide to us.
2.1.INFORMATION PROVIDED BY YOU
For example, by creating a web account with us, or by providing information about yourself to us at one of our Ambassades, boutiques or counters. The personal data that we collect may include
• Contact information (such as your name, mobile phone number, home address and email address);
• Date of birth, title, preferred language;
• Skin diagnosis information to provide to you personalized product prescriptions;
• Dermo-cosmetic information (such as smoking, pregnancy, breastfeeding, allergies, pathologies, dermatological medical treatment, aesthetic medicine, surgery in the last 6 months, lymph nodes);
• Billing information (including delivery address and payment details). We reserve the right to request additional evidence or proof of billing information where, in our reasonable opinion, this is necessary. We use a third-party data controller, STRIPE, to process payment details;
• Website registration credentials (including email address and password). By creating an account, you can securely store your debit and credit card information (held by our third-party service provider) for easier and faster checkout, store and edit your delivery addresses and billing information and review your previous purchases and order history;
• Expressed personal preferences (such as communication and language settings);
• Interactions with us (such as your transaction history or skin diagnosis: information about your physical characteristics and skincare concerns obtained through a beauty consultation online or offline (in our Ambassades, boutiques or corners or using the Skin Instant Lab technology with our distributors) or when you visit our social media pages, or interact with customer service or our chat service); and/or
• Correspondence and communication between us and you.
2.2.INFORMATION AUTOMATICALLY COLLECTED FROM YOUR USE OF OUR PLATFORMS
When you access our Services and our websites, mobile sites or apps, social media pages we or our third-party partners may collect information automatically such as:
• Technical information, including, where available, your device’s IP address, operating system, browser type and version, time zone setting, browser plug-in types and versions, unique device identifiers and advertising identifiers; and
• Information about your visit, including the URL clickstream to, through and from our websites, mobile sites or apps (including date and time); products you viewed or searched for, the content (and any ads) that you view or interact with, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
• Some of this information is collected using cookies and related technologies.
2.3.INFORMATION COLLECTED FROM THIRD PARTY SOURCES
From time to time (where permitted by applicable law), we collect information such as your preferences, interests and other demographic data from trusted third-party sources that are either publicly or commercially available (business and retail partners, payment and delivery services, social media networks, advertising networks, analytics providers, and search information providers) which will be used for the purposes outlined in this Policy.
We also receive personal data (as indicated in section 2.1) you provide to authorized distributors of our products and services when using the Skin Instant Lab technology which will be used for the purposes outlined in this Policy.
When you pay for your products online, we get information from our payment processing service provider (STRIPE) who will carry out credit and antifraud checks on you and the payment method you provide in order to verify your identity, to validate your credit or debit card, to obtain an initial credit or debit card authorization and/or to authorize individual purchases.
3.FOR WHICH PURPOSES AND ON WHICH LEGAL BASIS DO WE PROCESS THE DATA?
We process your personal data for the reasons set out below:
• To fulfil a contract to which you are a party or take steps linked to a contract: this is relevant where you make a purchase from us, including
• setting up and managing your online account on our Services including websites, mobile sites or apps;
• providing skin consultation and diagnosis results leading to a personalized product prescription;
• fulfilling orders and processing your transactions (including the processing of your payment details, credit card checks and fraud prevention activities); these checks may be required, amongst other things, to verify your identity, to validate your credit or debit card, to obtain an initial credit or debit card authorization and/or to authorize individual purchases; and
• send service-related communications and to respond to your enquiries;
Where it is necessary, for the purposes which are based in our legitimate interest to communicate with you about our company and our products and services and to improve our client relationship and our products and services, being:
• to allow you to participate in the interactive features of the website;
• to ask your opinion or to take part in market research;
• to provide you with personalized services, content, targeted communications and advertising on our Services including websites, mobile sites and apps. We may do this by linking or combining the information that we collect from the different sources and channels outlined above or by creating segments based on various factors such as your age and gender or your skin concerns. We work with data management platform providers to assist with this process. Some of these activities may involve the use of cookies and other similar technologies;
Where it is necessary, for the purposes which are based in our legitimate interest to ensure correct use and the proper functioning of our websites, mobile sites or apps, to improve them and to ensure the establishment, exercise or defence of legal claims, being:
• to monitor your account to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime in accordance with applicable law;
• to investigate any complaints received from you or from others about our websites, mobile sites and apps or our products and services and
• to monitor the use of our websites, mobile sites and apps and use your information to help us monitor, improve and protect our products, content, Services, websites, mobile sites and apps, both online and offline and your experiences with us including via research and demographic studies; analytics and data cleansing and measuring the effectiveness of our advertising campaigns;
• to use personal data in connection with legal claims, compliance, regulatory and investigative purposes as necessary (including disclosure of such personal data in connection with legal process or litigation) or to enforce or apply our Terms of Use or any other agreements; or to protect the rights, property, or safety of B.R. SAS, our customers, or others;
• for our internal corporate reporting or recordkeeping purposes.
Where you give us consent:
• where you ask us to tell you about our products, services, offers and events at our Ambassades, boutiques or corners or by telephone, post, SMS, e-mail or online or via our applications or to send you samples, gifts and rewards in accordance with your communications preferences and to the extent permitted by applicable laws and where you agree to being contacted by any of our legal entities for these purposes.
• where you give us consent to place cookies and related technologies;
• on other occasions, where we ask for your consent, for the purpose for which we explain at the time.
• For purposes which are required by law
• In response to requests by government or law enforcement authorities conducting an investigation.
3.1. DISCLOSURE OF YOUR PERSONAL DATA
In addition to B.R. SAS, legal entities and affiliates mentioned in the Data Controllers & Contact section below, we may share your personal data (where permitted, in accordance with applicable privacy laws) with:
• authorized distributors for the purposes outlined above (mentioned in the Data Controllers & Contact section below);
• banks and our payment services provider (STRIPE) for the purpose of transaction processing;
• third parties, where we have your permission to do so (e.g. social networks providers, concierge service or our retail partners). Your personal data will become subject to the privacy policies of those third parties when your personal data is shared with them;
• prospective or eventual buyers of our business (if we or substantially all of our assets are acquired by or merged with a third party including through bankruptcy);
• any law enforcement agency, court, regulatory, government authority or other third-party where in our reasonable opinion this is necessary to comply with a legal or regulatory obligation or otherwise to enforce or apply our Terms of Use or any other agreements; or to protect the rights, property, or safety of B.R. SAS, our customers, or others. This includes exchanging information with other legal entities and organizations for the purposes of fraud protection and credit risk reduction; or
• our third-party service providers who perform services on our behalf based on our instructions. We do not authorize these parties to use or disclose the information except as necessary to perform services on our behalf or to comply with legal requirements. Examples of these parties include these third-party companies that fulfill orders and manage refunds, and provide data hosting and support, content personalization, advertising and marketing services (including digital and personalized advertising) and data cleansing, management, segmentation and analysis.
We also share information with third parties including social media and search engine partners:
We aggregate your personal data with the information of other customers, creating a dataset of information about the usage of our websites, mobile sites and apps, purchase of our products, and other general, grouped information about our customers. Although this dataset is aggregated and anonymized, meaning it cannot directly identify you as an individual, it provides a valuable insight into the use of our websites, mobile sites and apps and we will share it with select third parties at our discretion.
3.2.DATA STORAGE AND TRANSFERS
If you are based in the European Economic Area (EEA) and Switzerland the personal data that you provide through our websites is stored on servers in the US and supported from the US. We also transfer personal data about you (whether collected online or offline) to our legal entities and affiliates and other service providers who perform functions on our behalf which are based around the world including in countries outside of the European Economic Area (EEA) and Switzerland and this information may be stored and processed in those countries which may have different data protection standards to those which apply in your country of residence. For a list of the countries in which we operate, please see www.biologique-recherche.com
For European and Swiss individuals, where your personal data is transferred outside the EEA and Switzerland, and where this is to a group company or service provider in a country that is not subject to an adequacy decision by the EU Commission, we will take steps to ensure your information is adequately protected either by EU Commission or Swiss approved standard contractual clauses or through Binding Corporate Rules. A copy of the relevant mechanism can be obtained for your review on request.
3.3. Data retention
Your personal data will be retained for a certain period of time based on the following criteria:
• as long as necessary to fulfil the purposes outlined in this Policy;
• any applicable legal requirements; or
• any request for deletion from you in applicable situations.
Customer identification and account data is kept until the deletion of the account or after 2 years of inactivity then is archived in compliance with statutory limitation periods.
Prospect data is kept 3 years from the last contact from the prospect.
Personal data used to provide you with personalized communications and Services will be kept for a duration permitted by applicable laws. In any event, they are kept in a form that allows the identification of the persons concerned for a period not exceeding that necessary in view of the purposes for which they are treated.
When you make a booking with us for skin care/treatments or other services such as online consultation, we may need to collect some of your personal data by law, or under the terms of a contract we have with you. This means that if you decide not to give us your data, we might not be able to provide the service, and may have to cancel your booking or purchase. We will let you know if this is the case at the time, so you can decide.
4.KEEPING YOUR PERSONAL DATA SECURE
We are committed to protecting the personal data we collect and keeping your personal data secure is very important to us. B.R. SAS, and the BR owned legal entities & affiliates undertake to ensure that all security and privacy measures meet the security standards that can reasonably be expected considering the state of the art and applicable regulations, including hardware, software and logic, necessary to ensure the preservation and integrity of personal data and the security and protection of data from accidental or unlawful destruction, accidental loss, tampering, disclosure or unauthorized access.
We also make sure that people with a business need to know are able to access your data, including employees, agents, contractors and other third parties. They will only process your personal data on our instructions, and they are subject to a duty of confidentiality.
We have put in place procedures to deal with any suspected personal data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.
Unfortunately, sending information over the internet is not completely secure. Although we will do our best to protect your personal data, we cannot completely guarantee the security of your data transmitted to our site.
Third party links:
Our Services may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Services, we encourage you to read the privacy notice of every website you visit.
5.YOUR RIGHTS
We strive to provide you with choices regarding the personal data you provide to us. The following mechanisms give you control over your personal data:
Advertising, marketing and personalization (offline and online):
If you wish to be notified about our products and services, you can indicate your communication preferences through the relevant checkbox(es) on our Services or by answering the question(s) presented by our beauty experts or store representatives. Some of our activities and communications may be personalized to your specific interests and preferences (which will be done with your permission, if required by law).
If you wish to stop receiving our marketing communications (and/or wish optout of personalized marketing communications), simply let us know at any time. Please note that this will not stop you from receiving service messages (i.e. non-marketing communications, such as e-mail updates on your order status or notifications about your account activities) from us.
California “Shine the Light” Law
California’s “Shine the Light” law permits California residents to prevent disclosure of personal information to third parties for their own direct marketing purposes. If you do not want us to share your personal information with third parties, you can opt out of such sharing by submitting an email with the subject line “Request for California Privacy.” to : dpo@biologique-recherche.com
Cookies/Similar Technologies and Interest Based Advertising/Analytics:
You can accept or refuse all or some cookies at any time by using our Cookie management page at the bottom of each page of the site .
We may partner with ad networks and other ad serving providers that serve ads on behalf of us and others on non-affiliated platforms. Some of those ads may be personalized, meaning that they are intended to be relevant to you based on information advertising providers collect about your use of the Sites over time, including information about relationships among different browsers and devices. This type of advertising is known as interest-based advertising. We adhere to the {Digital Advertising Alliance (“DAA”) Self-Regulatory Principles in connection with this activity}.
For more information on how to opt out of receiving interest-based advertisements, or to learn more about interest-based advertising please visit the Network Advertising Initiative at www.networkadvertising.org/choices/ or the Digital Advertising Alliance at www.aboutads.info/choices/. For interest-based advertising in apps please use the DAA’s “AppChoices application” available at www.aboutads.info/appchoices. If you opt out, you may need to renew your opt-out choices exercised through the DAA AppChoices tool. Note that electing to opt out will not stop advertising from appearing in your application. It may make the ads you see less relevant to your interests.
We may also work with third parties that collect data about your use of the Sites over time for non-advertising purposes. We use Google Analytics to improve the performance of the Apps and for analytics and marketing purposes. For more information about how Google Analytics collects and uses data when you use our Sites visit www.google.com/policies/privacy/partners, and to opt out of Google Analytics, visit tools.google.com/dlpage/gaoptout.
5.1.HOW DO YOU EXERCISE YOUR RIGHTS?
In accordance with applicable law, you are entitled to ask us for a copy of your personal data, to correct it, erase or restrict its processing, or to ask us to transfer some of this personal data to other organizations. You also have rights to object to processing of direct marketing purposes and, where we have asked for your consent to process your personal data, to withdraw this consent. Where we process your personal data because we have a legitimate interest in doing so (as explained above), you also have a right to object to this processing, on grounds relating to your particular situation. These rights may be limited in some situations – for example, where we can demonstrate that we have a legal requirement or contractual obligation to process your personal data. In some instances, this may mean that we are able to retain your personal data even if you withdraw your consent. In such a case, we will apply appropriate measures and safeguards to protect your personal data.
In France, you also have the right to provide instructions for the management of your personal data after your death.
If you wish to exercise any of these rights, please contact us using this email address specially created for processing purposes: dpo@biologique-recherche.com
6.DATA CONTROLLERS AND CONTACT
If you have any questions about this Policy or privacy matters generally or to make a complaint about our compliance with applicable privacy laws, please contact us using the Contact page of our website and our customer services team will be happy to assist you.
If you wish to exercise your preferences and rights as detailed above, you can either use the Contact page, or send an email to the following address:info@biologique-recherche.com
We will acknowledge and investigate any complaint you make (including a complaint that we have breached your rights under applicable privacy laws). We hope that we can satisfy queries but if you have unresolved concerns, you also have the right to contact the relevant data protection authority in your country of residence or place of the alleged infringement.
6.1.LIST OF BR OWNED LEGAL ENTITIES
ATHENA: ATHENA NORTH AMERICA HOLDING INC / BR US: BR USA LLC / BR LA: BR AMBASSADE LOS ANGELES, LLC / BR KSA: BR ARABIA LIMITED / BR IT: B.R. ITALIA S.R.L. / BR ASIA: BIOLOGIQUE RECHERCHE ASIA CO., LTD / BR CN: BR BEAUTY AND COSMETIC PRODUCTS (SHANGAI) CO., LTD / BR TH: BIOLOGIQUE RECHERCHE (THAILAND) CO , LTD
6.2.LIST OF AFFILIATES
BR FRANCE / BR USA / BR CHINA
6.3.LIST OF B.R SAS DISTRIBUTORS
SKINKO / AFRIQUE DU SUD, ALMUJTAMA/ EVOLVING FOR TRADE ESTABLISHMENT / ARABIE SAOUDITE, FACEOLOGY/ Sh.P.K Agnesa Ziba P.F. / ALBANIE, FACEOLOGY/ DOOEL / MACÉDOINE DU NORD, CONTOUR D / BOSNIE-HERZÉGOVINE/, BIENESTAR Y BELLEZA BIBE S.A.S. / COLOMBIE, SESPO LTD / CROATIE, DEEP OCEAN INTL. TRADING LLC/ ÉMIRATS ARABES UNIS, GCS Limited / KENYA, SALLON DE BEAUTE / KOSOVO, PROFESSIONAL PRODUCTS / LIBAN, CASTERGON / MEXIQUE, NEW ESTETIK / MONTÉNÉGRO, Apples and Oranges Total Body Therapy / NIGERIA, INSTITUT DANIELLE BEJJANI / QATAR, JVB / SERBIE, MBI KOZMETIK / TURQUIE, HOUSE of BEAUTY LLC / ÉMIRATS ARABES UNIS, E.C.C.O. BIOLOGIQUE RECHERCHE LTD / ISRAËL, FORTUNA 22 EOOD / Bulgarie, BANK OF ALLURE / Lettonie/Estonie, UAB GROZIO AMBASSADORES / Lituanie, BEAUTY BOUTIQUE UKRAINE / Ukraine, BR SWITZERLAND / Suisse, UNIQUE WORLD’S COSMETICS / Kazakhstan, ELAYLA / Azerbaïdjan, LLC ELITE UHOD / Biélorussie, LEGNA PRIME / Roumanie/Moldavie, BIOLOGIQUE CONCEPT / Russie, BranchSIA Biologique Recherche Nord / Russie, DANAEVA / Ouzbékistan, BEAUTY EXPERTS / Pologne, TONUSI PIRVELI LTD / Géorgie, LIVING BEAUTY INC / CANADA, BR USA / États-Unis, BR INVESTIGACION / Argentine, INCENTIVAR SOLUTIONS / Portugal, BIOLOGIQUE ESPANA / Espagne, BIOLOGIQUE RECHERCHE CR, s.r.o/. République tchèque/ Slovaquie/ Allemagne/ Autriche, PROFESSIONAL BEAUTY SERVICES / GRÈCE, IMPOPHAR / CHYPRE, INTER BEAUTY² / MAROC, MORENO / CÔTE D’IVOIRE, VEDAS / Irlande, REVIVE KLINIKEN / Suède/ FINLANDE / NORVÈGE, SKINEXPERT DK APS / DANEMARK/ ISLANDE, SKIN CARE DISTRIBUTION/ AUSTRALIA / Australie et Nouvelle-Zélande, Beijing Dieshang Health Tech. Co.- Ltd / Chine, BEAUTE BR co. / Corée du Sud, LIFE BALANCE LIMITED / Hong-Kong, SOULSKIN DISTRIBUTION Pvt Ltd. / Inde, PT. REGENESIS INDONESIA / Indonésie, THE DAY SPA CO. LTD / Japon, WELLNESS POT / Malaisie, COSMO GROUP / Pakistan, Binome Wellness Concepts Inc / Philippines, AESTHETIC BRANDS / Royaume-Uni, RYO ESTHETICS PTE. LTD. / Singapour, ALMEDA ENTERPRISE COMPANY LTD / Taïwan, BR Thailand / Thaïlande, TAM SON INTERNATIONAL JOIN STOCK COMPANY / Vietnam