Privacy Policy
La Perla Beauty’s commitment to your privacy
At La Perla Beauty we are committed to protecting your privacy.
The Privacy Policy explains the types of Personal Data as this term is defined in the laws of the Member states of the European Union and the United Kingdom and Personal Information as this latter term Is defined within the California Consumer Privacy Act ("CCPA) If CCPA applies to you as a resident of the state of California (collectively referenced as "Personal Data" throughout this Privacy Policy) we collect, how we process that data, and how we will protect it, in accordance with applicable law. Please also read our Cookie Policy for information about how we use cookies and refer to our Terms & Conditions for additional information regarding our services. This Privacy Policy is issued by each of the controllers identified in section 2 below.
For any questions that may not be answered here, you can contact us at any time by emailing us
datasecurity@laperlab.com.
1. Provision of this Policy
The website accessible at www.beautybylaperla.com (our “Site”) is operated by La Perla Beauty (UK) Limited, a company organised and existing under the laws of United Kingdom, having its registered office at 5th Floor, 23 Savile Road London W1S 2ET, UK, Reg. n. 12254989, VAT n. 339 2536 86, with a French branch having its registered office at 14 rue Clément Marot, Paris, 75008, France VAT no. FR 81880466792 (“La Perla Beauty”, “we” or “us”). This Policy is provided by La Perla Beauty.
The term “our online services” refers to all services provided through; (i) our Site; or (ii) our pages on third party social media platforms such as Instagram, Facebook, Youtube, Twitter, and Pinterest.
The term “our services” refers to our online services and any of our other products and services offered from time to time. If you use any of our services, we will refer to you using the terms “user”, “visitor”, “you”, “your”, “yours” in this policy.
2. The controllers
The word “controller” means the entity that is responsible for deciding how and why your personal data is processed. In the context of the processing activities set out in this Privacy Policy, the relevant controllers are:
Controller entity |
Contact details |
La Perla Fashion Holding N.V. |
A: Schiphol Boulevard 127, G4.02, 1118BG Schiphol, The Netherlands |
La Perla Beauty (UK) Limited |
A: 5th Floor, 23 Savile Road London W1S 2ET T: N/A |
La Perla Beauty (France) SAS |
A: 14 rue Clément Marot, Paris, 75008, France T: +39 0516019520 |
3. Collection of Personal Data
We collect or receive your personal data from the following sources:
4. Categories of personal data we process
We collect the following categories of Personal Data and Personal Information:
5. Purposes of processing and legal bases for processing
The purposes for which we collect and process personal data, and the legal bases on which we perform such processing, are as follows:
Processing activity |
Legal basis |
Provision of Site, products, and services: providing our Site, products, or services (e.g., placing and holding items in your online shopping basket); providing promotional items upon request; communicating with you in relation to those Site, products, or services; taking your orders; processing your payments; delivering the items you have purchased; processing an exchange, return or reclamation of an order; providing access to services reserved for registered users, such as wish lists; and providing you with help and assistance via our Customer Care team, including contacting you about the delivery/collection of your order/return. |
· The processing is necessary in connection with any contract that you have entered into with us, or to take steps prior to entering into a contract with us; or · We have a legitimate interest in carrying out the processing for the purpose of providing our Site, products, or services (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
Operating our business: operating and managing our Site, our products, and our services; providing content to you; displaying advertising and other information to you; communicating and interacting with you via our Site, our products, or our services; and notifying you of changes to any of our Site, our products, or our services. |
· The processing is necessary in connection with any contract that you have entered into with us, or to take steps prior to entering into a contract with us; or · We have a legitimate interest in carrying out the processing for the purpose of providing our Site, our products, or our services to you (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
Gifts: If you provide us with someone else's data - for example, if you purchase a product to be delivered to a friend or as a gift, we will collect and process the personal data required to complete the transaction such as the name, delivery address and other contact details for your friend. If you are receiving an item as a gift, we will process your data only to fulfil the gift request and our contractual obligations. |
· The processing is necessary in connection with any contract that you have entered into with us, or to take steps prior to entering into a contract with us; or · We have a legitimate interest in carrying out the processing for the purpose of providing our Site, our products, or our services to you (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms). |
Communications, marketing and personalisation: communicating with you via any means (including via email, telephone, fax, text message, social media, post or in person) to provide news items and other information in which you may be interested, subject always to obtaining your prior opt-in consent to the extent required under applicable law; personalising our Site, products and services for you; maintaining and updating your contact information where appropriate; obtaining your prior, opt-in consent where required; enabling and recording your choice to opt-out or unsubscribe, where applicable. |
· The processing is necessary in connection with any contract that you have entered into with us, or to take steps prior to entering into a contract with us; or · We have a legitimate interest in carrying out the processing for the purpose of contacting you, subject always to compliance with applicable law (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
Product safety communications: communications in relation to product safety, including product recalls and product safety advisory notices. |
· The processing is necessary for compliance with a legal obligation; or · We have a legitimate interest in carrying out the processing for the purpose of ensuring the safety, and proper use, of our products (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms). |
Management of IT systems: management and operation of our communications, IT and security systems; and audits (including security audits) and monitoring of such systems. |
· The processing is necessary for compliance with a legal obligation; or · We have a legitimate interest in carrying out the processing for the purpose of managing and maintaining our communications and IT systems (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms). |
Health and safety: health and safety assessments and record keeping; providing a safe and secure environment at our premises; and compliance with related legal obligations. |
· The processing is necessary for compliance with a legal obligation; or · We have a legitimate interest in carrying out the processing for the purpose of ensuring a safe environment at our premises (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · The processing is necessary to protect the vital interests of any individual. |
Financial management: sales; finance; corporate audit; and vendor management. |
· We have a legitimate interest in carrying out the processing for the purpose of managing and operating the financial affairs of our business (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
Surveys: engaging with you for the purposes of obtaining your views on our Site, our products, or our services. |
· We have a legitimate interest in carrying out the processing for the purpose of conducting surveys, satisfaction reports and market research (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
Security: physical security of our premises (including records of visits to our premises); CCTV recordings; and electronic security (including login records and access details). |
· The processing is necessary for compliance with a legal obligation; or · We have a legitimate interest in carrying out the processing for the purpose of ensuring the physical and electronic security of our business and our premises (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms). |
Investigations: detecting, investigating and preventing breaches of policy, and criminal offences, in accordance with applicable law. |
· The processing is necessary for compliance with a legal obligation; or · We have a legitimate interest in carrying out the processing for the purpose of detecting, and protecting against, breaches of our policies and applicable laws (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms). |
Legal compliance: compliance with our legal and regulatory obligations under applicable law. |
· The processing is necessary for compliance with a legal obligation. |
Improving our Site, products, and services: identifying issues with our Site, our products, or our services; planning improvements to our Site, our products, or our services; and creating new Site, products, or services. |
· We have a legitimate interest in carrying out the processing for the purpose of improving our Site, our products, or our services (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
Fraud prevention: Detecting, preventing and investigating fraud. |
· The processing is necessary for compliance with a legal obligation (especially in respect of applicable employment law); or · We have a legitimate interest in carrying out the processing for the purpose of detecting, and protecting against, fraud (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms). |
Establishment, exercise and defence of legal claims: management of legal claims; establishment of facts and claims, including collection, review and production of documents, facts, evidence and witness statements; exercise and defence of legal rights and claims, including formal legal proceedings. |
· The processing is necessary for compliance with a legal obligation; · We have a legitimate interest in carrying out the processing for the purpose of establishing, exercising or defending our legal rights (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · The processing is necessary for the establishment, exercise or defence of legal claims. |
Recruitment and job applications: recruitment activities; advertising of positions; interview activities; analysis of suitability for the relevant position; records of hiring decisions; offer details; and acceptance details. |
· The processing is necessary for compliance with a legal obligation (especially in respect of applicable employment law); or · We have a legitimate interest in carrying out the processing for the purpose of recruitment activities and handling job applications (to the extent that such legitimate interest is not overridden by your interests, fundamental rights, or freedoms); or · We have obtained your prior consent to the processing (this legal basis is only used in relation to processing that is entirely voluntary – it is not used for processing that is necessary or obligatory in any way). |
6. Who will process your Personal Data
Your Personal Data will be processed by personnel of La Perla Beauty who are authorised for this processing. In carrying out the processing, the data may also be transmitted to companies within the La Perla group structure. In addition, we disclose personal data to:
Your Personal Data will also be transmitted to third party processors that we use to provide our services. If we engage a third-party processor to process your personal data, the processor will be subject to binding contractual obligations to: (i) only process the personal data in accordance with the instructions given by La Perla Beauty (UK) Limited; and (ii) use measures to protect the confidentiality and security of the personal data; together with any additional requirements under applicable law.
The third party processors in question belong to the following categories: payment processors, banking operators, internet providers, ecommerce hosting maintainers, companies specialising in IT and telematics services; logistic partners; companies that execute marketing activities such as email marketing services; companies specialising in market research and data processing; companies providing publishing and distribution services.
7. Where your Personal Data is processed
Because of the international nature of our business, we transfer personal data within the La Perla group, and to third parties as noted in section 6, in connection with the purposes set out in this Policy. For this reason, we transfer Personal Data to other countries that may have different laws and data protection compliance requirements to those that apply in the country in which you are located, including but not limited to the United States.
Some of the third parties listed in the section 6, may be located in countries outside the European Union that nevertheless offer an adequate level of data protection, as established by specific decisions of the European Commission. (https://ec.europa.eu/info/law/law-topic/data-protection/data-transfers-outside-eu/adequacy-protection-personal-data-non-eu-countries_en)
If an exemption or derogation applies (e.g., where a transfer is necessary to establish, exercise or defend a legal claim) we rely on that exemption or derogation, as appropriate. Where no exemption or derogation applies, and we transfer your personal data from the EEA to recipients located outside the EEA who are not in Adequate Jurisdictions, we do so on the basis of Standard Contractual Clauses. You are entitled to request a copy of our Standard Contractual Clauses using the contact details provided in this Policy.
Please note that when you transfer any personal data directly to any La Perla Beauty entity established outside the EEA, we are not responsible for that transfer of your personal data. We will nevertheless process your personal data, from the point at which we receive such data, in accordance with the provisions of this Policy.
8. How long we keep your data
We will only retain your personal data for the length of time required to fulfil the purposes for which you provided it, unless the law permits or requires that we retain it for longer. The retention period will vary depending on the purpose of the processing.
After this period, your data will be permanently erased or otherwise irreversibly rendered anonymous.
Personal data is retained in accordance with the following criteria:
9. Your rights regarding your Personal Data
Subject to applicable law, if you are a resident of the European Union (EU) or a country or US state with data protection laws similar to the General Data Protection Regulation in the EU you may have the following rights regarding the processing of your personal data:
Subject to applicable law, if you are a resident of a Member State of the European Union you may also have the following additional rights regarding the processing of your personal data:
This does not affect your statutory rights.
To exercise one or more of these rights, or to ask a question about these rights or any other provision of this Notice, or about our processing of your personal data, please email (insert email) Please note that:
10. Direct Marketing
We process Personal Data to contact you via email, telephone, direct mail or other communication formats to provide you with information regarding Site, products, or services that may be of interest to you. We also process personal data for the purposes of displaying content tailored to your use of our Site, products, or services. If we provide our Site, products, or services to you, we may send or display information to you regarding our Site, products, or services, upcoming promotions and other information that may be of interest to you, including by using the contact details that you have provided to us, or any other appropriate means, subject always to obtaining your prior opt-in consent to the extent required under applicable law.
You may unsubscribe ("opt-out") from our promotional email list at any time by simply clicking on the unsubscribe link included in every promotional electronic communication we send. Please note that it may take up to 2 weeks to process your unsubscribe request during which time you may continue to receive communications from us. After you unsubscribe, we will not send you further promotional emails, but in some circumstances we will continue to contact you to the extent necessary for the purposes of any Site, products, or services you have requested.
10. California Residents
While many browsers permit you to send a signal about your Do Not Track (“DNT”) preferences, we do not respond to DNT signals sent from browsers.
California Civil Code Section 1798.83, The California Consumer Privacy Act (“CCPA”) permits you to request certain information regarding our disclosure of Personal Information to third parties for their direct marketing purposes. To make such a request, please send an email to privacy@laperlabeauty.com.
CCPA also provides California residents with additional rights related to data privacy. If you have any questions about this section or whether it applies to you, please contact us at privacy@laperlabeauty.com.
Pursuant to the CCPA California residents may, subject to certain exceptions within CCPA:
11. Children’s Online Privacy Protection Act
La Perla Beauty complies with the Children's Online Privacy Protection Act (COPPA), which requires the consent of a parent or guardian for the collection of personally identifiable information from children under 13 years of age. La Perla Beauty does not knowingly collect, use or disclose personal information from children under 13, or equivalent minimum age in the relevant jurisdiction, without verifiable parental consent. However, it is possible that we may inadvertently receive information pertaining to children under 13. If you believe that we have received information about your child that is under the age of 13, please do not hesitate to notify us at (insert email address). When we receive your notification, we will obtain your consent to retain the information or will delete it permanently.
12. Security
We have implemented appropriate technical and organisational security measures designed to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, unauthorised access, and other unlawful or unauthorised forms of processing, in accordance with applicable law.
Because the internet is an open system, the transmission of information via the internet is not completely secure. Although we will implement all reasonable measures to protect your personal data, we cannot guarantee the security of your data transmitted to us using the internet – any such transmission is at your own risk and you are responsible for ensuring that any personal data that you send to us is sent securely.
14. How do we protect your personal information?
We use many different measures to help protect information transmitted over or stored on our systems. For example, your Personal Information is contained behind secured networks, and is encrypted when transmitted to us via Secure Socket Layer (SSL) technology, to try and keep the information secure. In addition, the payment information you provide us is processed by a third-party payment gateway (Stripe) and processor (Stripe). We regularly review our information collection, storage and processing practices, including physical security measures, to guard against unauthorized access to systems. Our Website is hosted by Big Commerce a platform for online merchants. For more information about Big Commerce's privacy practices, please see the privacy policy here.
14. Children under 18
Our Website is not intended to be used by children under 18 years old. You represent and warrant that you are at least 18 years of age. If you are under age 18, you may not use the Website or services. We do not knowingly collect personal information from, or target our Website or services to children under the age 18. We understand that there may be exceptions to this rule including, but not limited to children who are emancipated. If we discover that the Website is being used inappropriately, we will take steps, if possible, to disable access so that the individual may no longer access our Website.
14. Changes to this Policy
We reserve the right to modify this Privacy Policy at any time. The provisions contained in this privacy statement supersede all previous notices or policies regarding our privacy practices with respect to this Website. Any and all changes will be made here, to this Privacy Policy.
We encourage you to check our Website frequently to see the current privacy policy to be informed of how we are committed to protecting your information and providing you with improved content on our Website in order to enhance your online experience. Upon any material changes to the policy statement, we will post those changes to this Privacy Policy so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it.
15. Contacting Us
If you have any questions about your personal information or this policy, please contact us by email at privacy@laperlabeauty.com, or by using the contact details below:
La Perla Beauty UK, Ltd.
5th Floor, 23 Savile Row
London
W1S 2ET