1. Our Approach
If we use the term "Group", this means us and our subsidiaries, our ultimate holding company and its subsidiaries (or any of them). The term "services" refers to WHIND, GLAZE and Kjaer Weis, our mobile and tablet applications, our pages on third party social media platforms such as Instagram, Facebook, Twitter, Pinterest and Google+ and any other websites or apps we own or run from time to time. The term "our services”, "services", refers to our online services and any of our other products and services, offered from time to time.
We are a data controller of the personal information we process and are therefore, responsible for ensuring our systems, processes, suppliers and staff comply with data protection laws in relation to the information we handle. If you do not agree with this Policy, you should not submit information to us.
You can find out more about our responsibilities and about how and why we collect and use your personal information by reading this Policy. If anything is unclear or if you have any questions about this Policy, please contact us at email@example.com.
Cookies and Pixels
Cookies are small text files that are placed on your computer by websites that you visit. They are commonly used across the internet in order to make websites work, improve their personalization, or to provide information to the owners of the site about how it is working. A cookie often contains a unique identifier, which can be used to recognize your computer when it returns to a website that it has visited before.
Pixels work with cookies to help us understand how you use our website and to improve our advertising, similar to cookies. Pixels are different from cookies because they do not stay on your computer, they are temporary while you browse our Site and are ‘removed’ when you close our Site.
Cookies are commonly classified into ‘first party’ and ‘third party’ cookies, and this changes whether we or one of our partners serves you the cookie. First party cookies are served by us and are more likely used to ensure performance of our Site, while third party cookies are hosted by one of our partners and more likely used for analytics and measurement of marketing performance.
Cookies may also have different lifetimes – this means that they stay on your computer for a defined period before being automatically removed. Another common cookie type is a ‘session cookie’, these cookies are automatically removed when you close your browser.
2. The information we collect from others
When using our Sites, you may be linked to third-party service providers that will collect certain personal information from you. This information is not collected or used by us and it is a subject to privacy policies of such third parties.
We are not responsible for the privacy policies and practices of other websites even if you accessed the third-party website using links from our Sites or have access to them otherwise through our Sites and services. We recommend that you check the policy of each website you visit before deciding whether to proceed and contact the owner or operator of such website if you have concerns or questions.
When using our Sites for placing an order, you will be redirected to third-party websites or platforms for completing financial transaction. These websites and platforms will request certain information from you (including your credit card information) in order to carry out the payment. As we are the receiving party to this financial transaction, we will receive information about the transaction from the third-party payment providers.
3. The information we collect and how we collect it
Personal data, or personal information, means any information about a person from which they can be identified. We collect your data in several ways including when you choose to share it with us, when you shop with us or engage with our digital properties, and from our affiliates and partners. We intend to comply with applicable laws no matter how we obtain your data. We may collect, store, and use some or all of the following categories of information:
Digital Identifiable Data (Website Visitors, Account Holders and Customers)
When you visit our Sites, apps, and digital properties we automatically collect information about your use of the platforms including details of your visits such as pages viewed and the resources that you access. This information may include website traffic data, IP address, pages viewed, location data, browser, operating system, referral source, length of visit, clickstream data and other communication data. We may also obtain this information indirectly from cookies, tags and other digital tools. This information is not normally personally identifiable from the methods and systems we use. In some situations, this information could be combined with other sources to make it personally identifiable, but we limit access to ensure that this information remains anonymous. We may use this data in order to identify you, deliver goods and services to you, market you, personalize our goods and services to you, associate other data with you, analyze other data we collect, identify other potential customers (e.g., look like customers), develop new goods and services, and for security and fraud prevention.
Identity Information (Registered Users and Customers)
When creating a user account on our Sites, logging into or updating an existing account, or placing an order, we will collect the following information:
- personal contact details such as name, title, addresses, telephone numbers, and email addresses;
- date of birth and other progressive profiled physical characteristics such as your age, hair color, skin undertone, complexion and gender;
- billing information and account settings, purchasing history, product or service interests, product reviews, estimated income.
Please note that some information may be optional, while information that is necessary for certain actions (e.g., creation of a user account or placing an order) will be clearly marked as required fields. We obtain this data from you when you order or browse products and services (e.g., purchase history) and when you provide us that information (e.g., product reviews). We may also obtain commercial information from affiliates (e.g., purchase history on their sites) and partners (e.g., estimated income).
For example, when you use Google to login to our Sites, or when you register with or use our platforms to buy products, we may use this data in order to identify you, deliver goods and services to you, market to you, personalize our goods and services to you, associate other data with you, analyze other data we collect, identify other potential customers, develop new goods and services and for security and fraud prevention.
Cookies and Pixels
You have the right to choose whether to accept these cookies and can exercise this right by amending or setting the controls on your browser. Please note that if you choose to refuse all cookies you may not be able to use the full functionality of our Site. For example, you may need to re-enter login information multiple times to complete checkout.
Our pixels help our partners understand how our marketing campaigns should be run efficiently. We may share some of your personal details in an encrypted format with the pixel partners, for use exclusively for managing advertisements on their platforms. We do not share financial or address details with these partners.
Based on the functionalities of your browser, you should be able to view the cookies that are stored for a website and to also change your preferences for which cookies are allowed. This is done on a site-specific basis and can be reset back to defaults through the same process. It is also possible to switch into “Private” or “Incognito” browser mode in order to reduce the amount of tracking that is carried out by your browser. This will not have the same effect as blocking cookies but provides an alternative method of reducing the performance of them.
We also collect Identity Information when you contact us (by email, telephone or otherwise) to ask a question or request information.
4. How we will use your personal data
Providing our services
To fulfil a contract, or take steps linked to a contract: in particular, in facilitating and processing transactions that take place on the Sites, such as when you purchase an item from our marketplace.
As part of the provision of our services, we use the personal information that we collect from you to:
- register you as a user of our services;
- process your orders and provide your details to third parties (e.g., postal or delivery service) in order to successfully process such orders;
- manage our relationship with you (for example by notifying you about changes to our terms or asking for feedback on our service).
Monitoring, administering and improving
We use your personal information to help us to monitor our performance, administer and improve our service by:
- tracking and analyzing activity to identify patterns and help us improve our Sites and communications;
- troubleshooting, conducting data analysis, testing, system maintenance, support, reporting and hosting of data;
- using data analytics to improve customer relationships and experiences;
- analyzing information so that we can prioritize features that are relevant and popular;
- educating, training and developing our staff’s performance;
- ensuring network and information security, including preventing unauthorized access to our computer and electronic communications systems and preventing malicious software distribution;
- managing our legal and operational affairs (including, managing risks relating to content and fraud matters);
- other business administration such as management and planning, including accounting and auditing;
Where you give us consent
- providing you with marketing information about products and services which we feel may interest you related to our brands;
- If you wish to withdraw your consent at any time, please contact us at firstname.lastname@example.org click ‘Unsubscribe’ in any of our emails or other marketing channels.
- Protecting the rights and property of Waldencast and others and complying with our legal obligations, including to detect, investigate and prevent fraud and other illegal activities and to enforce our agreements to which you are a party;
- Carrying out any other purpose described to you at the time the personal information was collected.
5. The sharing of personal information
- With other companies and affiliates associated with Waldencast to enable us to run data analysis, to develop new products or services, for marketing purposes, and for other business development purposes. We may also share personal information to allow another Waldencast company to perform services on our behalf, to contact you with offers related to all of our brands, services or products that may be of interest to you and to provide you with their products and services. Any such corporate affiliate may use your information only according to the terms of this privacy notice. If you are located in a jurisdiction where such sharing requires your permission, we will only do so with your consent;
- With our partners, such as organizations with whom we organize contests or events and our retail partners;
- With other website visitors when you choose to participate in certain interactive areas of our websites, such as by posting a product review;
- In connection with a corporate transaction, such as any purchase, sale, lease, merger or other type of acquisition, disposal or financing involving Waldencast;
- With our professional advisors, such as our legal, financial, insurance and other advisors in connection with the corporate transactions described above or the management of our business and operations;
- With law enforcement and individuals involved in legal proceedings, when it is necessary for us to comply with applicable law or legal process, to respond to legal claims, or to protect the rights, property or personal safety of Waldencast, our users, employees or the public;
- When you write product reviews on our Sites;
- With your consent or at your discretion.
6. Marketing Choices regarding your personal information
Where we have your consent to do so, we send you marketing communications including but not limited to, by email, by messaging tools (i.e. chatbots) and text messages related to promotions, products, events, cart reminders, special offers or other Waldencast Group related news, as well as other information that we think will be of interest to you related to all of our brands. Message frequency will vary. Waldencast Group reserves the right to alter the frequency of messages sent at any time, so as to increase or decrease the total number of sent messages. Waldencast Group also reserves the right to change the short code or phone number from which messages are sent. Consent to receive automated text messages is not a condition of any purchase. Message and data rates may apply.
Not all mobile devices or handsets may be supported and our messages may not be deliverable in all areas. Waldencast Group, its service providers and the mobile carriers are not liable for delayed or undelivered messages.
You can ‘opt-out’ of such communications if you would prefer not to receive them in the future by unsubscribing to emails or by responding to generated text message with the appropriate Stop message as shared with you when we reach out. For Kjaer Weis, please reply with any of the following replies: STOP, END, CANCEL, UNSUBSCRIBE, or QUIT.
Otherwise, you may revoke your consent by contacting us at the following email address: email@example.com
You also have choices about cookies, as described within our Cookies Policy. By modifying your browser preferences, you have the choice to accept all cookies, to be notified when a cookie is set, or to reject all cookies. If you choose to reject cookies, some parts of our Sites may not work properly in your case.
7. Our grounds for processing
In accordance with the relevant data protection laws, we only have the right to use your personal information where we can identify a lawful basis for doing so. Your consent to the processing as specified in this Policy is our primary lawful basis. In some circumstances, we may also rely on another lawful basis. Most commonly, these will be:
- where we need to use the information to perform the contract, we have entered into with you;
- where it is necessary for our legitimate interests (or those of a third party), and your interests and fundamental rights do not override those interests;
- where we need to comply with a legal or regulatory obligation.
8. Information security and retention
The Internet is not a secure medium. However, we have put in place various security procedures as set out in this Policy.
Please be aware that communications over the Internet, such as emails and online messages are not secure unless they have been encrypted. Your communications may route through a number of countries before being delivered – this is the nature of the Internet. We cannot accept responsibility for any unauthorized access or loss of personal data that is beyond our control.
We believe that we have appropriate policies, rules and technical measures to protect the personal data that we have under our control (having regard to the type and amount of that personal data) from unauthorized access, improper use or disclosure, unauthorized modification, unlawful destruction or accidental loss.
We have put in place appropriate security measures to prevent your personal information from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed. We also have procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so.
We will only retain your personal information for as long as is necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.
To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the information, the potential risk of harm from unauthorized use or disclosure of your information, the purposes for which we process it and whether we can achieve those purposes through other means, and the applicable legal requirements. The approximate retention period related to the mentioned purposes is 2 years in total.
9. Advertising and analytics services provided by others
This information may be used by Waldencast Group and others, among other things, to analyze and track data, to determine the popularity of certain content, to deliver advertising and content targeted to your interests on our website and other websites, and to better understand your online activity. For more information about interest-based ads, or to opt out of having your web browsing activity used for behavioral advertising purposes, please visit www.aboutads.info/choices.
We may also work with third parties to serve ads to you as part of a customized campaign on third-party platforms (such as Facebook, Snapchat or Instagram). As part of these ad campaigns, we or third-party platforms may convert information about you, such as your email address and phone number, into a unique value that can be matched with a user account on these platforms to allow us to learn about your interests and to serve you advertising that is customized to your interests. Please note that the third-party platforms may offer you choices about whether you see these types of customized ads.
Affiliate marketing service providers, may collect personal information when you interact with our digital property, including IP addresses, digital identifiers, information about your web browsing and app usage and how you interact with our properties and ads for a variety of purposes, such as personalization of offers or advertisements, analytics about how you engage with websites or ads and other commercial purposes. For more information about the collection, use and sale of your personal data and your rights, please contact us at firstname.lastname@example.org for the vendor details.
10. International transfer of personal information
11. Your rights in relation to your personal information
Under certain circumstances, as prescribed in the applicable law you have the right to:
- Request access to your personal information (commonly known as a “data subject access request”). This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it;
- Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected;
- Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it;
- Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground;
- Request the restriction of processing of your personal information. This enables you to ask us to suspend the processing of personal information about you, for example if you want us to establish its accuracy or the reason for processing it;
- Request the transfer of your personal information to another party.
You will not have to pay a fee to access your personal information (or to exercise any of the other rights). However, we may charge a reasonable fee if your request for access is clearly unfounded or excessive. Alternatively, we may refuse to comply with the request in such circumstances.
We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that personal information is not disclosed to any person who has no right to receive it.
If you wish to exercise your rights in relation to the processing of your information by any of our Partners, you should contact us via our e-mail address email@example.com.
Our Sites are not directed to children (persons under the age of 14), and we do not knowingly collect, either online or offline, personally identifiable information from children.
12. Your California Privacy Rights
This section applies only to California residents. Pursuant to the California Consumer Privacy Act of 2018 (“CCPA”), if you are a California resident, you have the right to: (1) request a copy of the specific personal information we have collected about you within the previous twelve months, including personal information we have shared with another company for a business purpose, (2) request that we delete your personal information, and/or (3) request that we stop selling your personal information.
Such requests may be made up to two times in a rolling twelve-month period. When you make such a request, the personal information provided may be limited to personal information we collect about you in the previous twelve months. With respect to deletion requests, note that, if you choose to delete your personal information, then you may not be able to use certain functions of our Site that require personal information to operate.
With respect to selling requests, please note that we have not sold personal information for monetary consideration in the preceding twelve months, and we do not plan to do so in the future unless you give us your consent or instruct us to do so. However, under some circumstances a transfer of personal information to a third party without monetary consideration may be considered a “sale” under CCPA. For purposes of CCPA, all categories of personal information, except for background and criminal information, biometric information, and government identifiers, may be transferred internally or to third parties. Such transfers under certain circumstances may be considered a sale. We will not discriminate against you for choosing to exercise your right to opt out of having your personal information sold as defined under CCPA.
If you are a California resident, you also have the right to ask us one time each year if we have shared personal information with third parties for their direct marketing purposes. We share personal information with third parties for the direct marketing of our products only if we have your affirmative consent (opt in).
California residents may make such requests in two ways: (1) by sending us an email at firstname.lastname@example.org or (2) by writing to us at Waldencast UK LTD, Michelin House, 81 Fulham Road, Chelsea, London, SW3 6RD, UNITED KINGDOM.
We reserve the right to update this Policy at any time, and we will provide you with a new Policy when we make updates. We may also notify you in other ways from time to time about the processing of your personal information.
14. How to contact us
You can learn more about how privacy works by contacting us. If you have questions about this Policy, you can contact us via the below provided contacts. Additionally, we may also resolve any disputes you have with us in connection with our privacy policies and practices through direct contact.
Date of Last Revision: May 04, 2022