Privacy Policy Statement
Effective as of May 16, 2019
1. Your Privacy
- Shiseido Group, Shiseido Co., Ltd. and Shiseido Hong Kong Limited (referred to collectively as “Shiseido”, “we”, “our” or “us”) respect your legal rights of privacy when collecting, holding, storing, using, processing, transmitting or otherwise handling personal data and this Privacy Policy Statement explains our privacy practices. We are committed to comply with the requirements under the Personal Data (Privacy) Ordinance, Chapter 486 of the Laws of the Hong Kong Special Administrative Region. Nothing in this Privacy Policy Statement shall limit or restrict your rights as a data subject under the Personal Data (Privacy) Ordinance.
- Please read the following carefully to understand our policy and practices regarding how your personal data will be treated. This policy may from time to time be revised. If there is any inconsistency between the English and Chinese version of this Privacy Policy Statement, the English version shall prevail.
- Throughout this Privacy Policy Statement, the term “personal data” shall have the meaning ascribed to it in the Personal Data (Privacy) Ordinance.
2. Types of Personal Data Collected
- You may need to provide your personal data from time to time, including but not limited to your name, gender, age, passport or identity card number, date of birth, phone number, facsimile number, address, email address, credit card details, education level, occupation, household income, hobbies or preferred activities. Failure to provide such data and/or provision of incomplete or inaccurate data may prevent us from providing certain services to you.
- • If you are under the age of 18, you must obtain the consent from parents or guardians before disclosing any of your personal data to us, and we shall not collect your personal data without such prior consent.
3. Purposes for which we will collect and use your Personal Data
- Your personal data may be collected when you make a purchase, participate in promotional activities or apply to be a member of any of the brands of fragrance, cosmetics, beauty care and related products operated by us from time to time, including but not limited to Anessa, Clé de Peau Beauté, Drunk Elephant, ELIXIR, Ettusais, Ipsa, Issey Miyake Parfums, Narciso Rodriguez Parfums, Nars, Serge Lutens, SHISEIDO and Tory Burch.
- Certain personal data is required to be provided on an obligatory basis if you wish to receive certain services from us. These data will be marked as “mandatory” in the Member Record Form and you MUST provide your personal data to us if you want us to provide the service for which you are applying. If personal data is only required on a voluntary basis, it will not be marked “mandatory” and it is entirely up to you to decide whether you want to provide such information to us or not.
- Your supply of personal data is mandatory if you wish to receive one or more of the following services:
(a) Enrolment into and maintaining your membership as our member;
(b) Accumulating bonus points as our member;
(c) Communicating to you your entitlements and privileges as our member;
(d) Redemption of privileges as a member;
(e) Notification of any amendment to the membership program;
(f) Data cleansing and customers profile updates; and
(g) Other continuous customer support services directly in relation to your membership.
- We may use any personal data provided by you (whether on an obligatory and/or voluntary basis) to enable us to provide the following additional services to you and/or carry out the following activities:
(a) To enable us better to understand the demographics of our customers;
(b) For internal research and analysis to enable us to provide rewards, services and product information or offerings better tailored to your needs;
(c) Market research;
(d) To enable our beauty consultant/specialist to follow up;
(e) To distribute customer satisfaction survey; and
(f) To send our VIP newsletters and VIP program updates.
4. Disclosure of Personal Data
- In cases where we do collect personal data from you, we will:
(a) Inform you (by way of this Privacy Policy Statement or by a separate notification) that we are doing so and the purpose(s) for which we will use the personal data collected;
(b) Where relevant, give you the opportunity to opt-out and object to any of the purpose(s) for which we will use the personal data collected (including but not limited to the circumstances described in paragraph 5 below); and
(c) Tell you how we will store your personal data and how you can review, change and delete the personal data we have stored.
- All personal data collected and held by us will be kept confidential but we may provide and/or disclose such information to the following parties (whether within or outside Hong Kong) for the purposes set out in paragraph 3 above:
(a) Any member companies, subsidiaries, holding companies, associated companies, or affiliates of, or companies controlled by, or under common control with Shiseido;
(b) Any agent, contractor or third party service provider (“Third Party Service Providers”) who provides administrative, telecommunications, computer and other services to us in connection with the processing and storage of your data;
(c) Any actual or proposed assignee or transferee of all or any part of our assets, shares or services, or successor of Shiseido in carrying on all or any part of our business; and
(d) Government, judicial or regulatory authorities, law enforcement agencies or other organizations as required or authorized by applicable laws in or outside Hong Kong.
- Our Third Party Service Providers are under a duty of confidentiality and are contractually bound to protect your personal data privacy and to only use your personal data in connection with the purposes specified in paragraph 3 above and not for their own purposes (including direct marketing).
5. Use of Data in Direct Marketing
- We may also use your personal data including name, telephone number, address and email for direct marketing. By law, we may not use your personal data for this purpose unless we have received your consent (including an indication of no objection).
- Upon your consent, your personal data may be used for:
(a) Communicating to you regarding new product launch and other promotional offers, including where applicable, skincare products, cosmetics products, make up products, body care products, make up services, body care services and facial services;
(b) Communicating to you regarding our promotional events including where applicable, makeup classes and/or demonstrations, skincare seminars, other beauty classes, PR events, VIP gatherings, value sets, shop opening events, store announcement/ events, exhibitions and news update;
(c) Communicating on-counter or out of counter services and events related to skincare, makeup or beauty services for promotion or rewarded purpose;
(d) Marketing reward programs, birthday celebration offers, free sampling, digital campaigns, roadshow/ outpost, in store promotion updates;
(e) Communicating joint promotion or events with shopping malls, department stores, credit cards, banks, trades, celebrities, magazines, television, websites, mileage programs, cultural, art or musical societies/ organizations, charities or nonprofit organizations; and
(f) Cross brand joint promotions and/ or events with brands within Shiseido.
- If at any other point of time you do not wish us to use your personal data for use in direct marketing as described above, you may exercise your opt-out rights by notifying us through the communication channels as stated.
- In paragraph 10 below. Please note that in order to opt-out from receiving direct marketing you may be required to provide your personal details for our processing and identity confirmation.
6. Security
- All personal data provided by you will be properly stored in our customer service system and can only be accessed by authorized persons who have received training on our privacy policies.
7. Cookies
- Cookies are small, often encrypted text files, located in browser directories which serve to keep a record in your computer or mobile device that you have visited this website. Cookies used on this website do not have the function of identifying an individual user and the information collected by a Cookie does not include your e-mail address, names or other personal data. Shiseido may use Cookies in this website for the following purposes:
(a) When there is a website crossing over several pages of this website and such necessary information is temporarily recorded in order for users to use this website conveniently.
(b) When Shiseido or a company consigned by Shiseido conducts survey analysis of the access trends of users on this website in order to provide better service through this website.
8. Transfer of Personal Data
- Your personal data will generally be held on our servers hosted in [Hong Kong]. However, for the purpose of transferring or processing your personal data into our central database of global customer information or to any of the people specified in paragraph 4 above, we may transfer it to our office(s) outside Hong Kong. We are committed to take all reasonably necessary steps and exercise all due diligence to make sure all personal data collected, held, stored, used, or otherwise processed in our offices outside Hong Kong are treated securely, in accordance with this Privacy Policy Statement and in compliance with the Personal Data (Privacy) Ordinance.
9. Your Right to Access, Correction and Deletion
- Under the Personal Data (Privacy) Ordinance, you have the right to check whether we hold personal data relating to you and request access, correction and deletion of any of your personal data in our records. If you at any other point of time wish to exercise any of such rights, please email our Personal Data Privacy Officer as specified in paragraph 10 below.
- You may also request us to delete you or your personal data from any active mailing or distribution list. If you no longer wish to receive any future promotional or direct marketing material from us, please email our Personal Data Privacy Officer as specified in paragraph 10 below, marking your communication “Confidential”. In response, we may ask you to provide certain details about yourself to ascertain the authenticity and validity of the request.
10. Personal Data Privacy Officer
- The person to whom (1) requests (i) for access to data or correction of data, (ii) for general information regarding our policies and practices with respect to personal data and (iii) about the kinds of personal data that we hold and (2) general questions and complaints should be addressed is as follows:
Personal Data Privacy Officer
Address: 17/F., One Kowloon, 1 Wang Yuen Street, Kowloon Bay, Hong Kong
Email:info@nars.com.hk
Please indicate your name, member ID or contact number for us to follow up your request.
You may be asked to provide additional information to authenticate your identity in order for us to follow up your request.
11. Retention of Data
- We will keep your personal data only for as long as necessary to fulfill the purpose(s) for which the data is or is to be used (including any directly related purpose(s)). Pursuant to our internal policy, we will keep a record of all transactions with you in our course of business for a reasonable period of time for review and verification purposes. Personal Data which is no longer necessary for the purposes for which the data was originally collected will be destroyed. You also have the right to request deletion of your personal data in our possession as stated in paragraph 8 above.
- If there is any discrepancy between the Chinese and English versions of this Statement, the English version shall prevail.