PRIVACY POLICY

We are committed to respecting your data protection rights and ensuring the protection of your personal data.

This privacy policy applies to the general processing activities of Oliente AG Switzerland (Oliente).

This privacy policy explains the types of personal data we collect and how we process and protect it in connection with the services we offer.

The activities of our sales organizations are governed by their privacy policies. Please note that this privacy policy may be supplemented from time to time with information about specific and limited processing activities that we carry out (e.g. when we carry out a specific marketing campaign at an event). In this case, we will provide you with the necessary additional information separately and in a timely manner.


This Privacy Policy may also be updated from time to time, particularly when we introduce new products, services or offers. Such updated versions of the Privacy Policy will be posted here. We encourage you to visit this page frequently to stay informed.

1. DATA PROTECTION RESPONSIBLE PERSONS
OLIENTE AG Switzerland,

Poststrasse 24
6300 Zug
Switzerland
UID: CH-020.3.050.440-2
Email: customer service@oliente.com
Website: www.oliente.com


is responsible for the processing of your personal data collected on our website or offline in our stores.
If you have any questions about how we process your personal data, you can contact us by letter or email.

2. WHICH PERSONAL DATA DO WE PROCESS?

When we collect your personal information using forms, we mark required fields with an asterisk. In accordance with the principle of data minimization, these required fields contain only the information we need to provide goods and services to you. We cannot provide you with goods and services if you do not complete these fields.

We may collect the following information either directly from you or through third parties:
Information about the type of browser you use when visiting our website, your IP and device address, hyperlinks you click, websites you visited before visiting our site and other information collected by cookies or similar tracking elements (e.g. actions you have taken on our website or on third-party websites and information about how you deal with emails you receive from us).


Your location and information about your mobile device (such as your personalized device's unique identifier) ​​and your GPS data or Wi-Fi data. Your username, profile picture and any other information you share when visiting third-party websites (such as when you use the "Like" feature on Facebook).


Basic data:
Name, title, age, date of birth, gender, password.
Contact details:
Address, email address, private telephone number, mobile number.


Purchase details:
Purchases of goods or services you make on our website, mobile apps, prices of purchases, order history, return history, payment history, wish lists, invoices. Payment information (e.g. payment method).
Personalization data:
Brands you prefer, responses you give in surveys or competitions, your shopping habits and preferences, and information about your lifestyle (e.g. hobbies and interests).


Freeform data:
Any other content/information you provide to us through our websites and other information you provide in connection with a purchase or service request or other inquiry, including communications with our customer service regarding refunds or online purchases.
Loyalty card data:
Loyalty card member identification number, account status and details of points earned and redeemed.


Sensitive data:
In certain limited circumstances, we may process data about an adverse reaction to a product (this could be health data) or diagnostic data (such as skin colour and type so we can provide appropriate products). If we need to collect sensitive data from you, we will transparently inform you of our legal obligations and ask for your consent before we process such personal data.


Pictures:
Pictures and videos games and influencers.



3. FOR WHAT PURPOSES DO WE PROCESS YOUR PERSONAL DATA
DATA?


Which categories of personal data may we process?

3.1 Log data and contact form
For what purpose are they processed?
We (and third-party service providers acting on our or their own behalf) may use cookies and similar technologies to process data about you when you visit our websites for the following purposes:


1. To provide core website functionality such as browsing our websites and secure login, storing your
order progress and the use of some functions (e.g. contact form or customer service chat) that you request. These are called "necessary cookies".
2. To improve the performance of our websites, for example by using analytics tools to help us learn more about our visitors, personalise content or interact with you based on your behaviour on our websites. These are called "performance cookies".
3. To target our ads to you when you visit other websites or social media platforms based on your behavior on our websites. For this purpose, we share website usage information with third parties (e.g. advertisers, advertising agencies, ad networks, data sharing providers, etc.) who may set their own cookies outside of our websites and track your online activities across websites for their own purposes. These are called "advertising cookies".
How long do we store your personal data?
(please ask your IT)


What is the legal basis for the processing?
For "Necessary Cookies": our legitimate interests and the performance of our agreement with you. For other cookies: your consent when you click "Agree and continue" in our Cookie Consent Tool on our websites. You can edit your cookie preferences at any time through our Cookie Consent Tool or by changing your browser settings.

3.2 Purchasing goods or services online. What categories of personal data may we process?
Basic data, contact data, purchase data, loyalty data, VAT data (if applicable) and payment data.
For what purpose are they processed?
We process your personal data to process your purchases of goods and services in our stores and online shop and – where applicable – to deliver the products you have ordered to you or to provide the services you have requested.
How long do we store your personal data?
If you have an account or loyalty card: We will retain your personal data for as long as your account or loyalty card is active and for a further 3 (three) years after your last activity, unless we are legally required to retain it for a longer period. If you do not have an account or loyalty card: We may collect your VAT details (if applicable) and retain them for the period required by law.
What is the legal basis for the processing?

We process this data to fulfill our agreement with you.

3.3 Direct marketing
Which categories of personal data may we process?
Log data, basic data, contact data, purchase data, personalization data and
loyalty data.
For what purpose are they processed?
We process your personal data to inform you about products, services, special offers, promotions and other information by post, email, newsletter, SMS, push notifications or telephone. These communications may contain suggestions for products (including those from relevant third parties) that we believe may be of interest to you. In order to determine which products or services you may be interested in, we process your personal data, including in particular your purchase history, your behavior on our websites and those of third parties, your behavior when receiving an email from us and your preferences, so that we can include you in segments in accordance with our segmentation strategy. We also process your personal data to provide you with targeted content
to show you online offers and advertisements for products and services that you may see on our websites. This is done using cookies or by directly sharing your email address, postal address, telephone number, or other data (if you have consented to social media targeting). Please note that you may.
Even if you unsubscribe from cookies or social media/search engine retargeting, you may still receive advertising from us that has not been customized.
How long do we store your personal data?
If you have signed up for the newsletter only: Until the date you unsubscribe from our direct offers. If you are a loyalty program member or have an account with us: For 3 (three) years after your last activity, unless we are legally obliged to keep the data for longer.
What is the legal basis for the processing?
If you are a loyalty program member or have already purchased a product from us, we process this information based on legitimate interests. In all other cases, we will obtain your consent in advance.

3.4 Surveys and reviews
Which categories of personal data may we process?
Basic data, contact data, personalization data and free-form data, all data provided in the form and sensitive data.
For what purpose are they processed?
We process your personal data to conduct surveys to improve our products and services.
How long do we store your personal data?
Until the business purpose is achieved or as required by law.
What is the legal basis for the processing?
We process this information on the basis of legitimate interests and your consent where sensitive data is collected.

3.5 Prize draws and competitions
Which categories of personal data may we process?
Basic data, contact data, personalization data and free-form data, images (photos/videos) and all data provided in the form.
For what purpose are they processed?
We process your personal data to enable you to participate in prize draws, competitions or games and, if you register for
decide to participate in order to determine the winners and to provide you with any prize you may win.
How long do we store your personal data?
For 3 (three) months after the conclusion of the competition or game, unless we are legally obliged to store the data for a longer period.
What is the legal basis for the processing?
We process this information on the basis of legitimate interests.

3.6 Loyalty points
Which categories of personal data may we process?
basic data, contact data, purchase data and loyalty data
For what purpose are they processed?
We process your personal data to calculate the points you have collected and to inform you about them.
How long do we store your personal data?
As long as you are a member of one of our loyalty programs. If your last activity was more than 3 (three) years ago, we will delete or anonymize your personal data unless we are legally obliged to keep it for longer.
What is the legal basis for the processing?
The processing of your personal data is necessary for us to fulfill our agreement with you.

3.7. After-Sales
Which categories of personal data may we process?
Basic data, contact data, purchase data, loyalty data, log data, payment data and free-form data In some very limited cases: Sensitive data and images (photos)
For what purpose are they processed?
We process your personal data whenever you contact us, to respond to your requests and comments, to process potential claims and requests in accordance with your rights as a data subject and to provide you with reimbursement if necessary.
How long do we store your personal data?
General enquiries and comments regarding our services, store standards, product availability, etc.: 3 (three) years after our last communication with you. Communications relating to personal injuries, accidents or other health and safety issues must be kept for a longer period in the event of legal claims or settlements.
What is the legal basis for the processing?

The processing of your personal data is necessary for us to fulfill our agreement with you.

3.8. Fraud prevention and regulatory purposes
Which categories of personal data may we process?
Basic data, contact data, purchase data, loyalty data, log data, payment data and free-form data In some very limited cases: Sensitive data and images (photos)
For what purpose are they processed?
We process your personal data to comply with our legal obligations, including cosmetics regulations (e.g. we may process certain data related to your health or symptoms and reactions you have experienced when using our products) and data protection and money laundering regulations. We also process your personal data to prevent fraud or other
To prevent or detect crime, to protect loyalty program member/account holder login information, to maintain the integrity of the website systems hardware and software, and to combat counterfeiting and selective distribution.
How long do we store your personal data?
We archive your data for regulatory purposes for the duration of legal or regulatory measures.
What is the legal basis for the processing?
The processing of your personal data is necessary to fulfill our legal obligations and/or to protect our legitimate interests.

4. Minors

Our websites and services are intended for adults and not for minors. However, if we have inadvertently collected information about a minor, the minor's legal guardian may exercise the minor's right on his/her behalf and behalf at any time.

5. Transfer of data

We will not share your personal information with any parties other than those listed below:
to third parties (companies or individuals) These providers – which may be: (i) advertising and media consultants; (ii) market research consultants; (iii) technical service providers; (iv) web designers and developers; (v) cloud computing providers; (vi) electronic data storage providers; (vii) customer service providers; (x) recruitment agencies; (xi) deliveries to retail or branch locations; (xii) payment service providers (the list is not exhaustive) – may have access to your personal data if such information is necessary to perform their functions. They must not use your personal data for any other purpose. To government bodies and regulators (e.g. tax authorities), courts, authorities and external consultants (e.g. lawyers, accountants, insurers, insurance brokers
and examiners, etc.)

To other parties where necessary to comply with legal or regulatory obligations under applicable laws, court orders or subpoenas
must.



6. Google Analytics and Captcha

6.1 Google Analytics
We sometimes use Google Analytics on our websites, a third-party service that may be located anywhere in the world (in the case of Google Analytics, it is Google LLC in the USA, www.google.com).
Google Analytics enables us to measure and evaluate the (non-personal) use of the website. For this purpose, permanent cookies set by the service provider are also used. The service provider does not receive any personal data (nor does it store IP addresses), but can track your use of the website, combine this information with data from other websites that you have visited and that are also tracked by the service provider, and use these findings for its own purposes (e.g. for tailored advertising). If you register with the
If you have registered with a service provider, this provider can also identify you. The processing of your personal data by the service provider is therefore the responsibility of the service provider in accordance with its own data protection regulations. The service provider only tells us how our respective website is used (no personal information about you). We have activated IP anonymization on this website, which means that the IP addresses of visitors to the Lealy website that must be transmitted to the Google Analytics server are automatically shortened by the last digits within a very short time.
For more information, see Google Marketing Platform.

6.2 Friendly Captcha (bot/spam protection)
Our website uses the service “Friendly Captcha” (www.friendlycaptcha.com). This service is offered by Friendly Captcha GmbH, Am Anger 3-5, 82237 Wörthsee, Germany.

Friendly Captcha is a data protection-friendly solution to make it more difficult for automated programs and scripts (so-called "bots") to use our website. We use Friendly Captcha to protect online forms on our website. Friendly Captcha is designed to check whether the data entered on our websites (e.g. in a contact form) is entered by a human or by an automated program.

For this purpose, we have integrated a program code from Friendly Captcha into the forms on our website so that the visitor's device can establish a connection to the Friendly Captcha servers in order to receive a calculation task. The visitor's device solves the calculation task, which requires certain system resources, and sends the calculation result to our web server. The server contacts the Friendly Captcha server via an interface and receives a response stating whether the task was solved correctly by the device. Depending on the result, we can add security rules to requests via our website and thus, for example, process them further or reject them.

Friendly Captcha does not set or read any cookies on the visitor’s device.

IP addresses are only stored in hashed (one-way encrypted) form for a maximum of 30 days and do not allow us or Friendly Captcha to draw any conclusions about an individual. The data is used exclusively for the protection against spam and bots described above.

For more information on data protection when using Friendly Captcha, please visit friendlycaptcha.com/legal/privacy-end-users/.

7. Social Media

We are present on social media platforms and other online platforms in order to communicate with interested parties and inform them about our services. Personal data may also be processed outside Switzerland and the European Economic Area (EEA).
The general terms and conditions (GTC) and terms of use as well as data protection declarations and other provisions of the individual operators of such online platforms also apply. These provisions provide information in particular about the rights of data subjects, which includes in particular the right to information.
We are jointly responsible for our social media presence on Facebook, including the so-called page insights, with Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04-S2K4, Ireland in Ireland, if and to the extent that the GDPR is applicable. The page insights provide information about how visitors interact with our Facebook presence. We use page insights to provide our social media presence on Facebook in an effective and user-friendly manner. Further information about the type, scope and purpose of data processing, information on the rights of data subjects and the contact details of Facebook and the Facebook data protection officer can be found in the privacy policy of
Facebook.
For our social media presence on Instagram, including the so-called page insights, we are jointly responsible with Meta Platforms Ireland Limited, Merrion Road, Dublin 4, D04-S2K4, Ireland in Ireland, if and to the extent that the GDPR is applicable. The page insights provide information about how visitors interact with our Facebook presence. We use page insights to improve our social media
To be able to provide our presence on Instagram in an effective and user-friendly manner. Further information on the type, scope and purpose of data processing, information on the rights of data subjects and the contact details of Facebook and Meta's data protection officer can be found in Meta's privacy policy. For our social media presence on Linkedin, including the so-called page insights, we are jointly responsible with LinkedIn Corporation, 1000 W. Maude Avenue, Sunnyvale, CA 94085, USA, if and to the extent that the GDPR is applicable. The page insights provide information on how visitors interact with our Facebook presence. We use page insights to improve our social media
To be able to provide a presence on Facebook in an effective and user-friendly manner. Further information on the type, scope and purpose of data processing, information on the rights of data subjects and the contact details of Linkedin and the data protection officer of Linkedin can be found in the privacy policy of Linkedin.

8. No transfer of data outside of Oliente AG

Many of our service providers are located in countries, such as within the European Economic Area (EEA) or the United Kingdom, that provide adequate data protection. If we need to transfer your personal data to a third party company located in a country whose data protection laws do not provide the same level of protection, we will ensure adequate data protection, such as by using standard contractual clauses.

9. Your rights

You have the following rights under the laws applicable to you and you can exercise these rights by contacting our Data Protection Officer:
You can obtain confirmation as to whether or not we process your personal data, and where we do, request a copy of it. You can have inaccurate or incomplete personal data rectified. You can have personal data erased in certain circumstances. Please note that these are not absolute rights and we may have legal or legitimate grounds to refuse your request. You can object to processing where such processing is based on our legitimate interests, but we may demonstrate compelling legitimate grounds to continue processing. You also have the right to object to the processing of your personal data for marketing purposes at any time. (To unsubscribe from our marketing communications, you can change your account settings. To do so, log in to your account or simply click the unsubscribe link at the bottom of the relevant communication). You can limit the processing of your personal data. You have the right to receive your personal data that you have provided to us in a structured, common and machine-readable format and to transmit it to another data controller (personal data portability).
If you have consented to processing activities for personal data, you can withdraw this consent at any time for future processing operations. However, such withdrawal will not affect the lawfulness of data processing before the withdrawal of consent.
You can lodge a complaint with the competent supervisory authority.