隐私政策
隐私政策最后更新日期:2024 年 2 月
请阅读本政策,本政策向您说明在“个人信息处理者与联系人”章节(第 9 节)列明的相关 La Prairie 公司(“La Prairie”、“我们”)如何收集、处理和使用您的个人信息。
介绍
本政策还说明了您如何访问和更新您的个人信息,以及在适用情况下,决定我们如何使用您的个人信息,包括反对我们对您的个人信息作出某些处理(包括个性化营销),或者在我们依据您的同意处理您的个人信息的情况下,您有权撤回该同意。与您的选择和权利相关的更多信息在下方第 7 章节列明。
本政策适用于我们的个人信息收集活动,包括我们通过各种线上渠道(例如官方网站、微信小程序、微信公众号和社交网络)以及线下渠道(门店、客户服务和活动)收集的个人信息。本政策还会向您说明我们如何通过使用我们网站以及线上渠道的 cookies 和相关技术来收集信息。有些条款可能不适用于您,取决于您如何向我们提供个人信息或与 La Prairie 沟通。请注意,我们会把从一个渠道(例如微信小程序)收集的个人信息与我们从另一个渠道(例如 La Prairie 门店活动)收集的个人信息进行合并。关于这些处理活动的更多信息请见下文。
我们保留随时对我们的实践和本政策进行调整的权利。我们邀请您不时查看我们平台以了解本政策的任何更新或变更。如果我们对您个人信息的处理发生变更,我们将更新本政策并通知您,我们一般会在平台上发布更新后的政策。如果我们进行了对我们隐私实践有实质性影响的重大变更,我们也可能通过其他方式通知您,比如在本政策的变更生效前向您发送电子邮件。根据适用的数据保护法律的要求,我们将获取您对此类变更的同意。
当我们收集您的个人信息时,如果我们认为向您及时提供一些相关信息会对您有所帮助,我们也可能会向您提供一些额外的信息。
1. 我们收集哪些个人信息以及如何收集这些个人信息?
我们从各种线上和线下渠道向您直接收集或收集与您有关的个人信息,包括在以下情况下收集:(i) 当您使用我们的官方网站 (http://www.laprairie.com.cn)、我们的微信小程序、微信公众号或其他应用程序(统称为“平台”)与我们进行互动;(ii) 您通过我们的社交媒体页面、聊天服务、论坛或博客(如有)与我们互动;(iii) 您到访我们的精品店、门店或专柜;(iv) 您参加我们的活动和展示、会员计划或其他客户计划、比赛、促销或调查;或 (v) 进行美容咨询或与我们的美容顾问以及客服人员沟通。
我们的产品通过各种授权零售商出售。我们的零售商收集的任何个人信息均不会向我们提供,本政策不适用于该等个人信息,除非在提供您的个人信息时另有明确说明。
“个人敏感信息”是指一旦泄露或者非法使用,容易导致自然人的人格尊严受到侵害或者人身、财产安全受到危害的个人信息,包括自然人的生物识别、宗教信仰、特定身份、医疗健康、金融账户、行踪轨迹等信息,以及未满 14 周岁未成年人的个人信息。这类情况下可能涉及的任何个人敏感信息均以下划线的形式标注,以提请您的注意。
我们收集以下个人信息:
您提供的信息(例如,在我们的网站上创建账户、报名参加我们的会员计划或其他客户计划,或者在我们的任何精品店、门店或专柜向我们提供与您自身有关的信息);
官方网站
- 客户服务
您与我们的客服联系或沟通时,您可以选择通过电话热线的方式与我们联系。在您与我们的客服沟通的过程中,我们可能会收集您的个人信息,如您的购物记录、您的具体情况、护肤问题或您主动提供给我们的任何信息。
- 查找附近门店
当您使用官网查找附近门店时,我们会根据您的 IP 地址收集您的大致位置信息,以便为您提供从您所在位置到我们线下门店的大致距离。
微信小程序
- 登录账户
您无需注册或登录您的账户即可浏览微信小程序,在这种情况下,我们仅收集您的 Open ID、Union ID 和浏览记录。使用微信小程序创建账户时,您需要输入您的姓名、移动电话、称谓、国家/地区,您可以选择输入出生日期。我们会使用这些信息来验证您的身份并创建账户。
- 网上购物
您在微信小程序中下单时,我们会收集必要的订单数据以履行您的订单并开具相关电子发票。在收集您的微信头像和昵称之前,我们会征求您的同意。如果您已注册并登录账户,您还需提供收件人信息和收货地址。如果您需要开具发票,您可以在结账页面中提供您需要的发票类型、电子邮件地址和移动电话。
请注意,我们不会保存您的银行卡的详细信息(除非因退款时所需)。支付服务提供商会相应地处理您的支付详细信息。
- 客户服务
当您通过微信小程序上的在线客户服务/问卷调查与我们联系或沟通时,我们会记录您的微信头像和您选择提供的任何信息,其中可能包含您的个人信息。
- 预约
您可以预约在我们的线下门店体验我们的护理服务。在预约过程中,您需提供您的姓名、移动电话、城市、预约的 La Prairie 的线下门店、预约日期和时间段。我们会征求您许可,获取您的位置信息,以搜索附近门店。如果您拒绝提供此类位置信息,您仍可手动选择门店。
- 个性化营销
我们可能会处理和分析您的交易历史和用户行为,以便在我们的微信小程序中为您提供个性化内容和推荐。如果您想禁用我们的个性化促销,请使用第 9 节中提供的联系方式联系我们。如果您关闭个性化营销,我们将不再在微信小程序的相关页面或版块向您显示任何基于您的偏好的个性化内容或推荐,且我们将在该等页面或版块仅向您发送并非根据您的偏好定制的通用内容或推荐。
微信公众号
- 关注微信公众号
您关注我们的微信公众号时,我们会收集您的微信昵称和头像。
- 消息和沟通
您在微信公众号向我们发送消息或与我们的客服沟通时,我们会收集您发送给我们的文字、语音、图片和/或视频内容(可能包含您的个人信息),并记录咨询内容。
其他第三方线上平台服务
- 在 La Prairie 天猫旗舰店进行网上购物
您在 La Prairie 天猫旗舰店购买商品或接受服务时,我们将从天猫收集相关订单信息,这些信息将被加密。
- 在 La Prairie 天猫旗舰店注册会员
如您有意在 La Prairie 天猫旗舰店注册 La Prairie 会员,我们会从天猫收集您的淘宝 ID、移动电话和姓名。
- 在 La Prairie 京东旗舰店注册会员
如您希望在 La Prairie 京东旗舰店注册 La Prairie 会员,我们会从京东收集您的手机号码和姓名。
- 在 La Prairie抖音店铺进行网上购物
您在 La Prairie抖音店铺购买商品或服务时,我们将从抖音收集相关订单信息,这些信息将被加密。
- 在 La Prairie 抖音店铺注册会员
如您希望在 La Prairie 抖音店铺注册 La Prairie 会员,我们会从抖音收集您的手机号码和姓名。
La Prairie 线下门店
您在 La Prairie 线下门店购物时,我们会收集必要的个人信息以满足您的需求。例如,如果您有意创建账户,我们可能会通过我们的顾客资料卡或其他系统收集您的称谓、姓名和移动电话,我们可能会收集的其他可选信息包括英文姓名、地址、邮编、城市、省份、国家/地区、电子邮件地址、出生日期、国籍和首选语言。
此外,我们有时候会举行促销或者其他活动,您在该等活动中可能会告知我们您认识的并可能会对我们的产品和服务感兴趣的人的信息。如果您向该等人士提供了本政策的副本,且该等人士同意您为此目的向我们提供有关他们的详细信息,我们仅将该等信息用于此目的,且不会向他们发送任何不相关的优惠信息。我们也可能会在向他们发送的消息中提到您是推荐人。
在您使用我们的平台、社交媒体页面或与我们的线上广告互动时自动收集的信息。
我们自动收集以下信息:
- 技术信息,包括您设备的 IP 地址、浏览器类型和版本、时区设置、浏览器插件类型和版本、操作系统、唯一设备识别码和广告识别符;以及
- 有关您访问的信息,包括指向、通过和源自我们平台的 URL 点击流(包括日期和时间);您查看或搜索的产品、您查看或与其互动的内容(和任何广告)、页面响应时间、下载错误、对特定页面的访问时长、页面互动信息(如滚动、点击和鼠标悬停等)以及离开页面浏览的方式。
这种信息中有些是通过使用 cookies 及相关技术收集的。如需了解更多信息,请查看第 5 章节“Cookies 及相关技术”的内容。
从第三方来源收集的信息
我们(在适用法律许可的情况下)不时从信任的第三方收集已经公开或者通过商业渠道(例如业务和零售合作伙伴、付款和送货服务、社交媒体网络、广告网络、分析数据提供商以及搜索信息提供商)可以获得的信息,例如您的偏好、兴趣和其他人口数据,将用于本政策中列明的目的。
为了确保信息的准确性以及向您提供更好的客户体验,我们会将我们从以上所列的不同来源和渠道收集的信息连接或合并在一起,以向您提供个性化服务、内容、针对性通讯和广告。(例如,我们将与您的网上购物有关的信息和我们从精品店、门店以及专柜收集的信息(例如美容咨询所提供的信息)合并在一起,使我们能够根据您的通讯偏好向您提供个性化的产品和护肤建议)。
您访问平台时不必提供个人信息。但如果您拒绝提供标记为“必需”的个人信息,您将无法使 用某些功能(如购买我们的产品),或者我们可能无法向您提供我们的产品和服务或与您进行沟通。但是,您可以选择是否接收我们发出的营销通讯,我们仅会在已经取得适当同意的情况下向您发送此类通讯。关于我们如何使用您的个人信息,请参考下文 第 7 章节获取更多与您的选择相关的信息。
除非您已向他人提供了本政策的副本并获得了他们的许可,否则您不应向我们提供有关他人的任何信息。
2. 为什么我们需要您的个人信息?
我们基于下列原因处理和使用您的个人信息:
- 为了履行合同或采取与履行合同相关的措施:该目的与您实施购买行为相关:这包括:
- 设置和管理您在我们的平台上的线上账户;
- 履行订单和处理您的交易(包括付款状态处理、信用卡检查以及预防欺诈活动);除其他事项外,这些检查活动可能要求核实您的身份,验证您的信用卡或借记卡,获取信用卡或借记卡的初始授权和/或授权个人购物);以及
- 发送与服务相关的通讯以及为您的咨询提供答复;
- 出于实现下列目的所必需。
- 使您能够使用我们平台的互动功能;
- 为征求您的意见或参加市场调查;
- o 在我们的平台、线下门店和其他指定合作伙伴网站,以及会员计划和其他客户计划中向您提供个性化服务、内容、定向通讯和广告。我们可以通过连接或合并从以上所列的不同来源和渠道收集的信息,或根据您的年龄和性别或者所预测的兴趣等因素进行分类,以实现此目的。我们与数据管理平台提供商合作,以协助完成该流程。其中有些活动可能涉及使用 cookies 及其他类似技术(请参考第 5 章节获取更多信息);
- 以监控您的账户,以便根据适用的法律防止、调查和/或报告欺诈、恐怖主义、失实陈述、安全事件或犯罪行为;
- 以调查您或者其他人针对我们的平台或我们的产品和服务提出的任何投诉;
- 以监控对我们平台的使用以及使用您的信息助力我们通过在线和线下方式,包括通过研究和人口研究、分析和数据清洗以及衡量我们广告活动成效等方式监控、改善和保护我们的产品、内容、服务、平台以及您对我们的体验;
- o 根据需要将个人信息用于与法律索赔、合规、监管和调查相关的目的(包括出于与法律程序或诉讼相关的原因披露此类个人信息),或执行或适用我们的使用条款或任何其他协议;或用于保护 La Prairie、我们的客户或其他人的权利、财产或安全;以及
- 为了我们内部公司报告之目的。
- 为了您给予同意之目的:
- 当您要求我们根据您的通讯偏好且在适用法律允许的范围内通过电话、邮件、短信、电子邮件或网络,或者通过我们的应用程序向您介绍我们的产品、服务、促销和其他活动或向您提供样品、礼品和奖品;
- 如果您同意我们根据下文第 5 章节放置 cookies 以及相关技术;
- 我们征得您同意的其他情况下,为了我们当时向您陈述之目的。
- 为了法律所规定的目的
- 为了响应政府或调查执法机关的要求。
尽管有上述约定,如果适用的数据保护法有所要求,我们不会在未经您同意的情况下,收集、处理或披露您的个人信息。
3. 我们如何披露和传输您的个人信息?
您个人信息的披露
出于本政策所述目的,我们可能会与以下人员共享您的个人信息(在适用的数据保护法允许的情况下):
委托处理
出于业务运营需要,我们可能会委托第三方服务提供商根据我们的指示代表我们提供服务,以支持我们的运营和服务。我们没有授权该等第三方使用或披露您的信息,除非该等第三方在代表我们履行服务或为遵守法律规定所需。例如,该等各方包括在门店为您服务的我们的授权零售商和分销商的员工,履行订单和管理退款以及提供数据托管与支持、内容个性化、广告与营销服务(包括数字和个性化广告)、数据清洗、管理、分类与分析的公司。
与第三方共享
就本隐私政策中所述目的而言,我们可能会与以下第三方共享您的个人信息。若与此类第三方共享您的个人信息,则您的个人信息将受到该等第三方的隐私政策的约束。
- 社交网络服务商:出于向您提供社交网络相关服务之目的,我们可能会与社交网络提供商共享您的个人信息;
- 礼宾服务或我们的零售合作伙伴(以履行您的订单);
- 数据分析服务提供商:出于向您提供个性化内容和提高我们服务质量之目的,我们可能会在必要和合法的范围内与数据分析服务商和其他相关服务商共享您的个人信息,更多详细信息请参见第 5 章节;或者
- 我们合理认为为遵守法律或监管义务或者执行或适用我们的使用条款或任何其他协议,或者为保护 La Prairie、我们的客户或其他人的权利、财产或安全所必要的情况下,与执法机构、法院、监管、政府机关或其他第三方共享。其中包括与其他公司和组织交换信息,以防止欺诈和减少信用风险。
如果我们或我们的绝大部分资产被第三方(包括通过破产)收购或合并,我们可能会将您的个人信息传输给我们业务的准收购方或最终收购方。如果发生此类事件,我们会要求接收您个人信息的一方继续遵守本政策。在传输您的个人信息之前,我们会向您发送适当的通知,告知接收方的公司名称或个人姓名以及联系方式。如果接收方改变信息处理目的或方法,我们将要求其再次获得您的单独的同意。
如果适用的数据保护法有所要求,我们不会在未经您同意的情况下,基于上述目的披露您的个人信息。此外,如果我们有意将您的个人信息用于本政策所列明以外的目的,我们将征得您的同意,除非适用的数据保护法另有规定。
我们还与包括社交媒体和搜索引擎合作伙伴在内的第三方共享信息:
我们会将您的个人信息与其他客户的信息聚合,创建一个与我们平台的使用、购买我们的产品以及其他与我们的客户有关的一般性的或分类性的信息的数据集。尽管该数据集已经过聚合和匿名化处理,即它不能直接识别您的个人身份,但它对我们平台、产品和服务的使用情况具有一定参考价值,且我们将与选定的第三方共享该等数据。
我们可能还会将与您有关的信息传输给广告技术提供商和我们的社交媒体以及搜索引擎合作伙伴,使它们能够识别您的设备且向您提供您感兴趣的内容和广告。该等信息可能包括您的姓名、通讯地址、电子邮件、设备 ID 或者其他经过加密处理的标识符。服务商通常以哈希算法或去识别化的方式处理信息。这些提供商可能会向您收集额外信息,例如您的 IP 地址以及与您的浏览器或操作系统有关的信息;并把与您有关的信息和与我们共同参与的信息共享合作团体内的其他公司所提供的信息合并在一起;可能在您的浏览器中放置或识别它们自己独特的 cookie。生成这些 cookies 的第三方拥有他们自己的隐私政策,我们无权访问或读写这些 cookies。
跨境数据传输
一般情况下,我们在位于中国境内的安全的数据中心存储和处理在中国境内收集的您的个人信息。未经您的事先同意和履行适用的数据保护法律要求的必要程序,我们不会将上述任何类别的个人信息传输至中国境外。
4. 我们保留您的个人信息多长时间?
您的个人信息将根据以下标准保存一定时间:(i) 实现本政策所述目的所需的时间;(ii) 适用法律规定的要求;或者(iii) 在适用情况下您提出的删除个人信息的要求。用于向您提供个性化通讯和服务的个人信息将在适用法律允许的期间内保存。
在适用的数据保护法要求的情况下,当销毁个人信息时,La Prairie 将从技术层面上采取合理的措施使个人信息不可恢复或不可复制,例如使用适当技术不可恢复地删除电子文档,并销毁或 烧毁任何其他记录、打印文件、文档或任何其他记录介质。
如需获得更多信息,请通过第 9 章节所述的联系方式联系我们。
5. Cookies 及相关技术
Cookies
Cookies 是什么?
我们在平台、社交媒体页面和通讯中使用且允许第三方服务提供商使用 cookies、网络信标和其他类似技术。我们这样做是为了解您如何使用我们的服务、改善您的用户体验以及启用个性化功能和内容;优化我们的广告和营销以及使第三方广告公司能够协助我们针对您的兴趣通过互联网向您发送广告。
Cookies 是网站向您的计算机、移动设备或其他互联网连接设备发送的小型文本文件,目的是为了特别识别出您的浏览器或者在您的浏览器中存储信息或进行设置。
我们的 cookies 及其功能:
我们使用的 Cookies 可归类如下:
收集的数据一般会进行聚合,旨在为业务分析、网站/平台改进以及效能衡量提供趋势和使用模式的参考。我们的 cookies 或者其产生的分析结果也可能与我们的业务合作伙伴共享。我们收集的信息类型包括访问我们网站的访客数量、他们在何时访问我们的网站、访问的持续时间以及访问了网站和服务的哪些区域,但此等信息一般不用于识别您的个人身份。我们也可能会收到与我们的合作伙伴网站的访客相关的类似信息。
我们在我们的平台上使用以下第三方广告 cookies:
公司 | 描述 |
---|---|
百度统计 | 百度统计 cookie 使我们能够在网络和应用程序中发布基于搜索行为的广告和基于兴趣的广告,cookie 的存储将不受时间限制,但用户可以要求删除它。 |
网络服务器日志与网络信标
结合通过 cookies 获取信息,我们的网络服务器可以记录例如您的操作系统类型、浏览器类型、域名和其他系统设置、您的系统使用的语言以及您的设备所在国家/地区和时区等详细信息。该网络服务器日志还可以记录诸如将您链接至我们网站的网页地址,以及您连接互联网所使用的设备的 IP 地址等信息。这些信息有助于我们排除故障、改善效能和维持我们平台的安全性。为了控制哪一个网页服务器收集这些信息,我们可以在我们的网页上放置名为“网络信标”的标记。它们是将网页链接至特定网络服务器及其 cookies 的计算机指令。我们也可以使用 cookies 和类似技术(例如网络信标),以便使我们能确定我们向您发出的邮件是否已被打开或起作用,我们的邮件工具是否运转正常,或者使我们能够评估效能并提供与您更相关的内容和广告。
我是否能退出 cookies 以及类似技术?
如果您完全不想放置 cookies,或者仅允许使用特定的 cookies,您可以随时使用 Cookie 偏好中心来完成此操作。您也可以在任何时候使用您的浏览器设置撤回对我们使用 cookies 的同意并删除已经设置的 cookies。拒绝或禁用 cookies 可能会使您无法查看网站的某些内容或使用网站的某些功能。
因为网络信标与网页格式中包括的任何内容要求一样,您不能选择退出或拒绝。但是,您可以通过不下载您收到的消息中包括的图像来禁用电子邮件消息中的网络信标(本功能因您个人电脑上使用的电子邮件软件的不同而有所差异)。但是,由于具体电子邮件软件的功能,这样做或许不能一直禁用电子邮件消息中的网络信标或其他类似技术。要获得与此有关的更多信息,请参阅您的电子邮件软件或服务提供商提供的信息在某些情况下,也可以通过退出 cookies 或者修改您的浏览器中的 cookie 设置使网络信标失效。
SDK
我们嵌入一些 软件开发工具包(SDK)以提供最佳服务,这些 SDK 可能会在协助我们向您提供全方位服务的同时收集您的个人信息。我们在此将我们目前使用的 SDK 信息总结如下。如果您对这些 SDK 收集您的个人信息有任何疑问,请参阅该等第三方的隐私政策。
SDK 名称 | 目的 | 收集的个人信息类型 | SDK 提供商 | 隐私政策链接 | 是否将个人信息传输至国外 |
---|---|---|---|---|---|
百度统计 | 跟踪用户的浏览行为 | 唯一标识符 | [百度] | https://tongji.baidu.com/web/help/article?id=330&type=0&castk=LTE%3D | 否 |
6. 保护您的个人信息安全
我们致力于保护我们收集的个人信息,而且保护您的个人信息安全对我们而言非常重要。我们采取措施以确保您的个人信息免受未经授权或非法的处理、意外丢失、删除、使用、泄露、损坏、销毁或披露,且我们将访问您个人信息的权限仅授予有合理需要访问该等信息以向您提供产品和服务的人员。
通过线上表格、我们门店的定位或购物车功能,从您的浏览器发送到我们的平台的任何数据均受安全套接字层 (SSL) 技术的保护。SSL 是确保经过验证的通讯双方之间的数据隐私和数据完整性的密码协议。
我们的平台可能包含跳转至及源自第三方网站的链接。如果您使用任何上述网站的链接,则请注意,上述网站有自己的隐私政策,且对于这些政策或上述第三方如何使用您的个人信息,我们不承担任何责任或义务。在您向这些网站提交任何个人信息之前,请认真查阅这些政策。
如果您在我们的网站上创建账户,作为我们安全程序的一部分,您应按要求提供账户用户名和密码。您应对此类信息保密,且不应向任何第三方披露。
7. 您的权利
我们致力于向您提供与您的个人信息相关的选择。您可以通过以下机制控制您的个人信息:
访问权利和修改权利
您可以通过账户管理设置或我们平台中的支付和结算模块访问或修改您的账户信息和订单信息。对于创建账户所需的信息以及在使用我们的平台或线下渠道时产生的其他个人信息,您可以通过下文列出的联系方式联系我们,以访问或修改这些信息。
您注册的移动电话或电子邮件地址是您在 La Prairie 数据库中的唯一标识符。如果您不再使用上述信息,请在平台中创建一个新账户。
获取您个人信息副本的权利
您有权获取您的个人信息副本。在符合适用法律和技术可行的范围内,我们将按您的要求向您提供您的个人信息副本。如果您需要我们收集的您的个人信息的副本,您可以通过下文所列方式联系我们。
撤回同意的权利
如我们基于您的同意收集您的个人信息,您可以随时给予同意或撤回同意。您可以通过删除信息、禁用设备功能或通过下文所列方式联系我们,以更改允许我们进一步收集您的个人信息的授权范围或撤回向我们授予的该等授权。如果您撤回对使用个人信息的同意,而这些信息是实现我们服务的基本功能所必需的,或者是我们根据适用的数据保护法履行我们的义务所必需的,您可能无法正常使用相关服务。在收到您撤回同意的要求后,我们将停止处理相关个人信息,但这不会影响我们之前根据您的同意或授权对个人信息进行的处理。
限制或反对处理的权利
您有权限制或反对他人处理您的个人信息。我们会根据适用的数据保护法的要求,寻找一种可行的方法来限制或停止处理您的个人信息。您可以通过下文所列方式联系我们。
删除权利
在以下情况下,您有权要求删除您的个人信息:(a) 处理目的已实现、无法实现或者为实现处理目的不再必要,(b) La Prairie 停止向您提供产品或服务,或数据存储期已届满;(c) 您撤回同意;(d) La Prairie 在处理您的个人信息时违反了法律或法规;或者 (e) 您注销账户。我们将删除或匿名化您的个人信息,除非适用的数据保护法另有要求。
注销权利
如果您想注销您的账户,请通过下文所列方式联系我们。我们将删除或匿名化您的个人信息,除非适用的数据保护法要求我们保留某些个人信息,并且我们只会在法律要求的范围内处理这些数据,不会在我们的日常业务活动中使用这些数据。
取消订阅通知和消息的权利
广告、营销和个性化推荐(线下和线上):如果您想收到有关我们产品和服务、活动、会员计划和其他客户计划以及其他促销活动的通知,您可以通过勾选我们平台、POS 系统或者店内顾客资料卡上的相关勾选框或者通过回复我们的美容顾问或门店代表提出的问题来表明您的同意。我们的一些活动和通讯可能针对您的特定兴趣和偏好进行个性化处理(若法律有所规定,将在取得您的许可后进行)。
如果您不再希望接收我们的营销通讯(和/或您希望退出接收个性化的营销通讯),只需按照相关通讯中的退出说明、联系我们的美容顾问或门店代表或通过第 9 章节所列的联系方式随时告知我们。请注意,这并不会阻止您接收我们发送的服务消息(即非营销通讯,例如:有关您的订单状态的电子邮件更新或者与您的账户活动相关的通知)。
Cookies/类似技术和基于兴趣的广告:如果您完全不想放置 cookies,或者仅允许使用特定的 cookies,您可以随时使用 Cookie 偏好中心来完成此操作。您也可以在任何时候使用您的浏览器设置撤回对我们使用 cookies 的同意并删除已经设置的 cookies。
这些权利在某些情况下可能受到限制 - 例如,当我们可以证明我们有合法要求或合同义务来处理您的个人信息时。某些情况下,这意味着,我们可以保留您的个人信息(即使您撤回了同意)。在这种情况下,我们将采取适当的措施和保护机制来保护您的个人信息。在适用的数据保护法允许的情况下,我们可能会就回应您的请求收取合理的费用,但届时我们会发送收费通知。如果您想行使任何该等权利,请通过第 9 章节所列的联系方式联系我们。我们会验证您的身份,并在十五 (15) 个工作日内向您回复解决方案或结果。
8. 未成年人保护
我们不会有意收集与未成年人相关的信息。但在某些情况下,由于出生日期是可选填项,我们无法确定用户的年龄。因此,如未成年人未经其法定监护人同意,不应注册账户或向我们提供个人信息。如果您认为我们在未经监护人明确同意的情况下收集了未成年人的个人信息,请通过第 9 章节中列出的联系方式联系我们,我们会删除这些信息。
9. 个人信息处理者与联系人
如果您对本政策或隐私事项有任何问题,或有意就我们遵守适用的数据保护法的情况提出投诉,请使用我们网站底部的电话号码(400-820-0533)联系我们,我们的客户服务团队很乐意帮助您,您也可联系下文所述的个人信息处理者。
如果您想行使您的上述选择和权利,您也可以通过上述电话号码联系我们。
我们将确认和调查您提出的任何投诉(包括关于我们违反您在适用数据保护法下的权利的投诉)。我们希望我们可以向您提供令人满意的答复。但是,如果您有任何未解决的疑虑,您有权联系您住所所在地的司法管辖区或者涉嫌侵权的发生地的相关数据保护机构。
负责所有活动(线上和线下)的个人信息处理者
南京西路 1717 号
会德丰国际广场 5503 室,邮编 200040
10. LA PRAIRIE CORPORATE PRIVACY POLICY
PRIVACY POLICY - 18 DECEMBER 2024
1.General Information
1.1 Processing of Personal Data
The purpose of this privacy policy is to provide you with information concerning the processing of personal data when using our corporate and careers websites, and for related services if you are a service provider, business partner, or third-party vendor. This privacy policy applies to all websites or services that feature this privacy policy.
For more information about our data processing activities related to our application process, employees and contingent workers, please visit our dedicated Privacy Notice for Employees, Job Applicants and Contingent Workers, also available on our corporate careers website.
For more information about our data processing activities related to our clients, clienteling activities and our e-commerce platforms, please visit our dedicated Privacy Policy, also available in all relevant languages depending on your region.
Personal Data refers to any information relating to an identified or identifiable natural person. This includes, but is not limited to, information such as name, address, email address, phone number, or any other data that can be used to directly or indirectly identify an individual. The definition and treatment of personal data are governed by applicable data protection laws and regulations in the relevant jurisdiction, which may include specific rules regarding the collection, processing, storage, and transfer of such data.
1.2. Controller
Responsible for the processing of personal data is:
La Prairie Group AG
Bellerivestrasse 36, 8008, Zürich Switzerland
+41 44 947 82 10
Contact details of the Data Protection Officer:
Data.Privacy[at]LaPrairieGroup.ch, or under the postal address of the controller for the attention of the “Data Protection Officer”.
Specific data processing activities might occur under the responsibility of other controllers, including our local affiliates, in connection with local processing activities. It is indicated in the respective description of those activities below, where this is the case. For a list of contact details for all La Prairie affiliates, please visit our dedicated page here.
1.3. Rights of the Data Subject
As a data subject affected by the data processing activity, you have the following rights with regard to your personal data, subject to the applicable data protection laws and regulations in your relevant jurisdiction:
- Right of access;
- Right to rectification and to erasure;
- Right to restriction of processing;
- Right to data portability; and
- Right to object.
1.4 Recipients (general information)
Furthermore, you have the right to lodge a complaint with a supervisory authority concerning the processing of your personal data.
When we work on your above-mentioned right, we may ask you for proof of your identity. For more information on how we process your data in this context, see Section 3.1.
In addition to the recipients that are listed within the recipients paragraph of each section below, we transfer the collected data to the relevant internal departments for processing and to other affiliated companies within the La Prairie and Beiersdorf Group or to external service providers, contract processors in accordance with the purposes required. We also forward the data to the following recipients:
- Platform/hosting providers may have access to personal data from jurisdictions outside of your own. In such cases, appropriate safeguards are implemented, including legally binding agreements or contractual mechanisms that comply with applicable data protection laws and regulations. Where personal data is transferred to jurisdictions covered by specific adequacy decisions or similar rulings, those rulings will apply. For more information (such as a copy of the safeguards), you can contact us as outlined under Section 1.2.
- Analytical service providers may have access to personal data from jurisdictions outside of your own. In these instances, appropriate safeguards, such as legally binding agreements or other contractual mechanisms, are in place to ensure compliance with the relevant data protection laws and regulations. If the transfer is made to jurisdictions with recognized adequacy decisions or similar provisions, those rulings apply. For further details, including information about these guarantees, please contact us as mentioned under Section 1.2.
- IT support service providers may have access to personal data from jurisdictions outside of your own. To protect this data, legally binding agreements or similar mechanisms are used to ensure the protection of personal data in line with applicable data protection laws. In cases where an adequacy decision or equivalent applies, that decision will govern the transfer. More information, including copies of guarantees, is available upon request, as outlined in Section 1.2.
- Authorities: In the event of a legal obligation, we reserve the right to disclose your information if required to do so by competent authorities or law enforcement bodies in accordance with applicable data protection laws and regulations.
Further information can be found within the recipients paragraph of each section.
2. Collection and Processing of Personal Data when visiting our Website
When visiting and using our website we already collect personal data. You can find within this section more information about website specific processes and tools especially from external partners. Further information about processes which can also occur in an offline context can be found in Section 3.
2.1.Hosting
Purpose/Information:
When visiting and using our website for information purposes only, i.e. if you do not register or otherwise provide us with information, we only collect the personal data that your browser transmits to our server, which are technically necessary for us to display our website to you and to guarantee stability and security.
Used Cookies/Tools: Type A. More information can be found in the “Cookies/Tools” section.
Recipients:
-Platform/hosting providers
-IT support service providers
Further recipients can be found in the general recipients Section 1.4.
Deletion:
The deletion of the log files takes place after 7 days.
2.2. Login functionalities
Our careers website might provide different login functionalities as described below.
2.2.1 Career Opportunities Login Profile
Purpose/Information:
Our careers website allows you to create a centralised login profile and includes a separate consent during the registration process: When registering, La Prairie Group AG provides you with the opportunity to create an account with a password (login profile). This login profile will be created within the centralised login profile database and shall verify that you are the valid owner of the account and/or email address. This login database is in general only connected to the service you are registering to and handles only the verification part of your login profile. You will be asked to read and agree to our Privacy Notice for job applicants, a copy of which is also available under Section 3.4. The login profile will therefore also be accessible to the respective local La Prairie affiliate company from which you are demanding the service.
Used Cookies: Type A. More information can be found in the “Cookies/Tools” section.
Controller:
See Section 1.2 above.
Recipients:
Platform/Hosting providers
Further recipients can be found in the general recipients Section 1.4.
Deletion / Withdrawal:
Your login profile will be automatically deleted as soon as you have deleted your account on our careers website, unless this conflicts with legal storage obligations or statutes of limitations. An automatic deletion of candidate accounts in general take place after 12 months of inactivity.
2.3. Cookies/Tools
This website uses cookies or other technologies/tools like pixels, local storage, tags, IDs or external services (hereinafter referred to as “Cookies/Tools”) and are used on when visiting and using our website. Cookies are small text files that are stored by your browser on your device to save certain information or image files, such as pixels. The next time you visit our website on the same device, the information saved in the cookies will subsequently be accessed on your device and transmitted either to our website (“First Party Cookie”) or to another website to which the cookie belongs (“Third Party Cookie”).
Through the information saved and returned, the respective website can recognise that you have already accessed and visited it with the browser you use on that device. We use this information to be able to design and display the website in an optimum way in line with your preferences. In that respect, only the cookie itself is identified on your device. Beyond this extent, your personal data will only be saved upon your express consent or if it is strictly necessary to be able to use the service offered to and accessed by you accordingly.
This website uses the following types of cookies/tools, the scope and functionality of which are explained below:
- Type A: Technical/Audience Measurement – to ensure that the demanded service can be provided including basic analysis.
- Type B: Functional and Performance – Additional tools to measure the performance/attractiveness of our website and to provide further additional (personalised) functionalities.
- Type C: Marketing/Advertising – Cross websites tools for marketing profiling based on user behaviour.
You can find more information on in the description of the tools implemented on our websites in this privacy policy.
For additional cookies relevant to this website that are not listed below, please refer to our Privacy Preference Center which is accessible by clicking “Cookies Settings” at the bottom of the page. This will allow you to review and manage your cookie preferences, including detailed information about the types of cookies used, their purposes, and the ability to opt in or out of specific categories of cookies, where applicable.
Please note that the tools listed in the following subsection might not be constantly in use.
2.3.1 OneTrust Cookie Consent – Central cookie management platform
Purpose/Information:
This website is using the consent management tool “OneTrust Cookie Consent” (www.onetrust.com) to obtain consent for data processing and use of cookies or comparable functions. "OneTrust Cookie Consent“ stores information about the categories of cookies the site uses and whether visitors have given or withdrawn consent for the use of each category. This enables site owners to prevent cookies in each category from being set in the user’s browser, when consent is not given.
By processing the data, OneTrust Cookie Consent helps us to fulfil our legal obligations (e.g. obligation to provide evidence). Our interests in processing lie in the storage of user settings and preferences with regard to the use of cookies and other functionalities. "OneTrust Cookie Consent" stores your data as long as your user settings are active.
The provision of your personal data is required for the performance of the contract or a situation similar to a contract. You are not obliged to provide your personal data. If your personal data is not provided, you cannot use the described service.
Cookies/Tools: Type A. More information can be found in the “Cookies/Tools” section.
Recipients:
Main service provider is OT Technology Spain, Passeo de la Castellana 77, 28046 Madrid, Spain.
Further recipients can be found in the general recipients Section 1.4.
Deletion:
The data will be stored for up to one year The choice you have made (consent/setting) will be stored for one year and can be viewed within the Cookie Settings. The Cookie Settings are located on the bottom of the main page. You can always delete your choice by deleting the cookies within your browser.
2.3.2 Google Analytics
Purpose/Information:
This website uses Google Analytics, a web analysis service of Google Ireland Ltd. (“Google”).
Google Analytics uses a specific form of cookie, which is stored on your computer and enables an analysis of your use of our website. The cookies set by Google Analytics for measurement are first party cookies, which means that data subjects’ cookie values will be different for each customer (i.e. there is not a single Google Analytics cookie ID that is used on all sites using Google Analytics). The information about your use of this website generated by the cookie is generally transmitted to a Google server in the USA and stored there.
Google uses this information on our behalf to analyse your use of this website in order to compile reports on website activities and provide additional services related to website and internet use.
We use Google Analytics to analyse and regularly improve the usage of our website. We can use the statistics obtained to improve our offer and make it more interesting for you as a user. In addition, we gain information about the functionality of our site (for example to detect navigation problems).
In the configuration of Google Analytics, we ensured that Google receives this data as a processor and is therefore not allowed to use this data for its own purposes. The "Google Analytics Advertising Features" configuration is independent from this and is described in the appropriate section below, provided it is also used on this website.
Cookies/Tools: Type B. More information can be found in the “Cookies/Tools” section.
Recipients:
Main service provider: Google Ireland Ltd., Ireland.
Transfers of personal data to third countries as defined by applicable data protection legislation may occur. Where required, appropriate safeguards are implemented to ensure an adequate level of data protection. For countries covered by an adequacy decision under applicable data protection legislation, the adequacy decision applies. For more information, including details about applicable safeguards, you can contact us as mentioned in Section 1.2.
Further recipients can be found in the general recipients Section 1.4.
Deletion/Withdrawal:
You can deactivate this tool via the Cookie Settings. The Cookie Settings are located on the bottom of the main page.
Cookie lifetime: up to 24 months (this applies only to cookies which have been set by this website)
2.3.3 Google Analytics Advertising Features
This website also uses the extended functions of Google Analytics (Google Analytics Advertising Features) in addition to the standard functions. The Google Analytics Advertising Features implemented on this website include:
- Google Display Network Impression Reporting
- Google Analytics Demographics and Interest Reporting
- Remarketing Audiences based on specific behaviour, demographic, and interest data, sharing those lists with Google Ads
- Integrated services that require Google Analytics to collect data for advertising purposes, including the collection of data via advertising cookies and identifiers
- Google Signals in order to receive more insights about you when you are signed in to your Google account in the browser with which you are accessing this website. This feature is only active if you have additionally consented within your Google settings to the data sharing/Ads Personalisation.
We therefore use first-party cookies (e.g. Google Analytics cookies) and Google advertising cookies and identifiers together in order to optimise our website.
Cookie/Tools: Type C. More information can be found in the “Cookies/Tools” section.
Information about Google Consent Mode:
Additionally, this website uses Google Consent Mode. Consent Mode sends statistical data via cookie-less pings about whether a user has clicked on an ad or link and has landed on our website (conversion). The statistical data is then used with a mathematical modelling to enhance the internal reporting. A ping contains by default technical information like the IP-address, platform type or screen resolution. As these data or the combination of it might theoretically be considered as personal data by Google Ireland Ltd, additional measures have been implemented to ensure that the ping data is not personal data: Certain information of the ping are being set to a default value by our server before sending it to Google analytics.
Recipients/Source:
Main service provider and source: Google Ireland Ltd., Ireland.
Transfers of personal data to third countries as defined by applicable data protection legislation may occur. Where required, appropriate safeguards are implemented to ensure an adequate level of data protection. For countries covered by an adequacy decision under applicable data protection legislation, the adequacy decision applies. For more information, including details about applicable safeguards, you can contact us as mentioned in Section 1.2.
Further recipients can be found in the general recipients Section 1.4.
Deletion/Withdrawal:
You can deactivate this tool via the Cookie Settings. The Cookie Settings are located on the bottom of the main page.
Cookie lifetime: event data is stored for up to 50 months; your personal data as a user is stored for up to 14 months (this applies only for cookies which have been set by this website).
2.3.4 Google Tag Manager
Purpose/Information:
This website uses the Google Tag Manager. This service allows website tags to be managed through an interface. The Google Tag Manager only implements tags. This means that no cookies are used and no personal data are stored. The Google Tag Manager triggers other tags, which in turn collect data if necessary. However, the Google Tag Manager does not access this data. If a deactivation has been made at domain or cookie level, it remains valid for all tracking tags if they are implemented with the Google Tag Manager.
Cookie/Tools: Type A. More information can be found in the “Cookies/Tools” section.
Recipients:
Main service provider: Google Ireland Ltd, Ireland.
Transfers of personal data to third countries as defined by applicable data protection legislation may occur. Where required, appropriate safeguards are implemented to ensure an adequate level of data protection. For countries covered by an adequacy decision under applicable data protection legislation, the adequacy decision applies. For more information, including details about applicable safeguards, you can contact us as mentioned in Section 1.2.
Further recipients can be found in the general recipients Section 1.4.
Deletion:
Aggregated event data is stored for up to 50 months; your personal data as a user is not stored in Google Tag Manager and therefore no retention period applies.
3. Further services offered (on- and offline)
In addition to the online use of our website, we offer various other services, for which we process your personal data also in an offline context.
Contrary to Section 1.2, in some cases a legal entity within the La Prairie corporate group is the Controller for the services offered below; this will have already been identified within the communication itself. If reference is therefore made to sections of this privacy policy, and a Controller has already been named, e.g. in the footer/signature of an email or campaign card, this legal entity is the Controller in accordance with applicable data protection laws and regulations.
3.1. Contacting/Communication/Collaboration
Purpose/Information:
When communicating and/or collaborating with us, e.g. by email or via contact form on our website, or data exchange platform, be it e.g. as a business partner or customer, the data you provide (including but not limited to your email address, your name and your telephone number, or personal data submitted during the conversation) will be stored and processed by us in order to e.g. answer your questions, requests or for the purpose of business related correspondence.
With regard to the cooperation with our suppliers, we have implemented an internal evaluation process of due diligence which, in our legitimate interest, is intended to improve the business relationship. As a rule, we only process information about the company, but conclusions can be drawn about you as the contact person of that company, if the communication with suppliers is examined with regard to response times, reliability and transparency.
We may ask you when you contact us by telephone as a customer whether the telephone call may be recorded for quality assurance and training measures. If you agree to the recording, we will process all information that you share with us during the call (communication content, possibly also sensitive (health) data, as well as your phone number and other personal data).
When processing data arising in the course of communication, we have a legitimate interest in processing the data in accordance with legal requirements, for internal verification or in accordance with the respective communication request.
In certain cases, the provision of your personal data as a business partner or customer is required for the performance of the contract or a situation similar to a contract. Additionally, your personal data may be required for related purposes, such as compliance with legal obligations, responding to or conducting investigations, or handling legal or regulatory proceedings. You are not obliged to provide your personal data. If your personal data is not provided, you cannot use the described service.
Recipients and sources:
If you are a business partner, we will regularly check your creditworthiness in certain cases (e.g. when concluding contracts). Our legitimate interest is the minimization of our financial risk. For this purpose, we cooperate with credit agencies from which we receive the necessary data. For this purpose we transmit your name and your contact data to the credit agencies.
If you are a business customer or partner, it may be necessary to transfer your personal data to prospective buyers as part of a company transaction. In the course of due diligence, usually anonymised data is processed. However, it may be necessary in specific individual cases to process personal data. Our legitimate interest lies in the execution of the company transaction.
We may transfer your collected data to our relevant internal departments for processing and to other affiliated companies within the La Prairie and Beiersdorf Group, to external service providers, contract processors, or, where necessary, to public authorities in compliance with legal obligations, regulatory requirements, or in response to lawful requests, all in accordance with the purposes required.
In the event of a legal obligation, we reserve the right to disclose information about you if we are required to surrender it to competent authorities or law enforcement bodies.
Additionally, we also forward the data to the following recipients:
- Platform/hosting providers;
- Analytical service providers; and/or,
- IT support service providers.
3.2. Job posting updates
For all recipients listed above, transfers of personal data to recipients in countries outside of the applicable jurisdiction may occur. Where required by law, appropriate safeguards, such as standard contractual clauses or other legally recognized mechanisms, are implemented to ensure adequate protection of personal data. For countries or entities subject to an adequacy decision, such a decision will apply. For more information or to request a copy of the relevant safeguards, please contact us at Data.Privacy[at]LaPrairieGroup.ch.
Further recipients can be found in the general recipients Section 1.4.
Deletion /Objection:
Your data will be retained only for as long as necessary to fulfil the purposes for which it was collected, unless statutory retention obligations exist or periods of limitation must be observed.
Call recordings are stored for a maximum of 90 days.
You can object to these processes according to the requirements under Section 4.
Purpose/Information:
Job posting updates provide candidates with notifications about new job opportunities and relevant updates tailored to their preferences. By subscribing to these updates, candidates receive notifications based on their selected interests and preferences, such as keywords for specific roles, locations, or departments.
The updates are customized based on the preferences candidates set in their profiles. Candidates can adjust the frequency of these notifications through their candidate profiles under “Job Alerts” to receive updates every set amount of days on a recurring basis.
Recipients:
-Platform/hosting provider
Transfers of personal data to third countries as defined by applicable data protection legislation may occur. Where required, appropriate safeguards are implemented to ensure an adequate level of data protection. For countries covered by an adequacy decision under applicable data protection legislation, the adequacy decision applies. For more information, including details about applicable safeguards, you can contact us as mentioned in Section 1.2.
Further recipients can be found in the general recipients Section 1.4.
Deletion / Withdrawal:
Candidates can unsubscribe from job posting updates at any time by logging into their candidate profile and updating their notification preferences. Job alerts and subscriptions will also be automatically deleted after 12 months of inactivity, at which point the entire candidate profile will be deleted.
3.3. Postal mailings
Purpose/Information:
As a selected customer or business partner, you may receive shipments from us by post (letter), including documents, products, or other materials necessary for the performance of a contract or based on our legitimate interests in facilitating business operations. These shipments are provided in the context of our professional relationship.
Recipients:
-Platform/hosting provider
-Communication service provider
-Shipping service provider
Transfers of personal data to third countries as defined by applicable data protection legislation may occur. Where required, appropriate safeguards are implemented to ensure an adequate level of data protection. For countries covered by an adequacy decision under applicable data protection legislation, the adequacy decision applies. For more information, including details about applicable safeguards, you can contact us as mentioned in Section 1.2.
Further recipients can be found in the general recipients Section 1.4.
Deletion / Objection:
Your data will be deleted as soon as the purpose for the shipment has been fulfilled unless legal storage obligations or statutes of limitations require otherwise. You can object to further postal mailings as described in the Section 4 below. We further delete your personal data after the contractual relationship between us has been terminated.
3.4. Data Privacy Statement for applicants (recruitment)
For more information about the application process please go to our dedicated Privacy Notice for Employees, Job Applicants and Contingent Workers, also available on our corporate careers website.
4. Objection or Withdrawal of your consent to the Processing of Personal Data
If you have given your consent to the processing of your data, you can withdraw your consent at any time. Such a withdrawal influences the permissibility of processing your personal data after you have given it to us. Withdrawing consent does not affect the lawfulness of any data processing that occurred prior to the withdrawal.
If we base the processing of your personal data on our legitimate interests, if relevant and as permitted by applicable law, you may object to the processing. This is the case if processing is not necessary in particular to fulfil a contract with you, which is described by us in the description of the functions/services. When exercising such objection, we ask you to explain the reasons why we should not process your personal data as we have done. In the event of your justified objection, we will examine the situation and either stop or adjust data processing or point out to you our compelling reasons worthy of protection, on the basis of which we will continue processing.
Of course, you can object to the processing of your personal data for purposes of advertising and data analysis at any time. You can inform us about your objection under the above-mentioned contact details for the controller.