Privacy and Cookie Policy

Date of Last Update: October 20, 2016


Thank you for visiting www.jomalone.eu (the "site"). The site is owned and operated by Estée Lauder Cosmetics Limited (a company registered in England and Wales with company number 00659213 and a registered office at One Fitzroy, 6 Mortimer Street, London, W1T 3JJ) ("we", "us", or "our") from our offices at Constellation House, 3 Kites Croft Business Park, Warsash Road, Fareham, PO14 4FL, United Kingdom and not from any other location. Any translation of this page (or any portion of the site) into a language other than English is solely for the convenience of our customers and does not imply, directly or indirectly, that the site is operated from any other location or country.


We respect your concerns about privacy and value the relationship we have with you. This Privacy and Cookie Policy ("Privacy Policy") (and our Website Terms of Use) describes the types of personal information we collect about our customers, how we process the information, with whom we share it, and the choices available to our customers regarding our use of the information. We also describe the measures we take to protect the security of the information and how our customers can contact us about our privacy practices. Please read the following carefully to understand our views and practices regarding your personal data and how we will treat it.


BY EXPRESSLY ACCEPTING THE TERMS OF THIS PRIVACY POLICY AND USING OUR SOCIAL MEDIA PLATFORMS, OUR SOCIAL NETWORKING OR MOBILE APPLICATIONS, YOU ARE ACCEPTING AND CONSENTING TO ALL OF THE PRACTICES DESCRIBED IN THIS PRIVACY POLICY.


For the purposes of the Data Protection Act 1998, the data controller is Estée Lauder Cosmetics Limited (a company registered in England and Wales with company number 00659213 whose registered office is located at One Fitzroy, 6 Mortimer Street, London, W1T 3JJ). As noted in clause 2 below, your data will also be processed by our affiliate(s) in the country where you live and our affiliate(s) will qualify as "data controller(s)" under the privacy laws applicable in that country.


CONSENTING TO THIS PRIVACY POLICY MEANS YOU ARE CONSENTING TO THE TRANSFER OF DATA FROM ESTEE LAUDER COSMETICS LIMITED TO OUR AFFILIATE IN THE COUNTRY WHERE YOU LIVE.


1. Information We Collect


1.1 We may obtain personal information about you from the sources described in this Privacy Policy. We may collect information from you when you visit our site, our social media platforms, or our social networking or mobile applications. When you visit this site, our social media platforms, or social networking or mobile applications, we may also collect certain information by automated means, using technologies such as cookies, web server logs and web beacons as described below.


1.2 You may also choose to provide personal information to us in a number of ways, such as when you contact us, participate in an offer or promotion, or when you make a purchase on our site, at our counters or in our stores.


1.3 The types of personal information you may provide to us and we may collect from you (such as when you complete online forms, make a purchase or contact us) includes: contact information (such as name, postal address, email address, and mobile or other phone number); age and date of birth; gender; username and password; payment information (such as your payment card number, expiry date, delivery address, and billing address); your online and in-store purchase history; product preferences; contact information for friends or other people you would like us to contact (subject to adequate advance notice to and consent from such friends or other people as required by applicable law); and content you provide (such as photographs, videos, reviews, articles and comments).


1.4 Information provided to us by third party social networks or mobile applications (depending on your personal privacy settings on such third party websites) or when you visit our social media platforms or use one of our social networking or mobile applications includes: your name, profile picture, likes, location, friend list and other information described in the social networking application sign-up page, or your geo-location details when using one of our mobile applications.



2. How We Use The Information


2.1 Although we operate the site, our affiliate(s) in the country where you live (i.e., where your billing address is) ("affiliate") will process your data and act as "controller(s)" under the privacy laws of that country. Our affiliate will be the entity that sends you promotional materials or other communications; provides services to you; processes your payment and/or gift card transactions and returns; responds to your enquiries; communicates with you about, and administers your participation in, special events, prize promotions, programmes, surveys and other offers; and operates and communicates with you about our social networking or mobile applications. We may use the information you provide to operate, evaluate and improve our business (including developing new products and services; enhancing and improving our services; managing our communications; analysing our products; performing data analytics; and performing accounting, auditing and other internal functions); to create and manage your online account (including access to your online and in-store purchase history); and to comply with applicable legal requirements, relevant industry standards and our policies.


2.2 These are our local country affiliates:

Your billing address country: Our local affiliate
Spain Estee Lauder S.A.
Poligono Industrial
Las Mercedes
C/Nanclares De Oca, 3
28022 Madrid
Spain
Portugal Socosmet, Sociedade de Cosmetica, LDA
Amoreiras Square
Rua Carlos Alberto da Mota Pinto, 17, 3.° A
1070-313 Lisbon
Portugal
Italy Estee Lauder S.R.L.
Via Turati, 3
Milano 20121
Italy
Belgium Estee Lauder Cosmetics S.A./N.V.
Airport Plaza-Kyoto Building
Leonardo Da Vincilaan 19
1831 Diegem
Belgium
Germany Estee Lauder Cosmetics GmBH
Domagkstrasse 10
D-80807 Munich
Germany
Austria Estee Lauder Cosmetics GmBH
IZD Tower
Wagramerstrasse 19
20th Floor, A-1220 Vienna
Austria
Netherlands Estee Lauder B.V.
Bisonspoor 338 - Toren 6
3605 Jw Maarssen
The Netherlands

 

2.3 We also may use the information in other ways for which we will provide specific notice and, if necessary, obtain your consent, prior to collection.


2.4 If you are an existing customer, we will only contact you by electronic means (e-mail) with information about goods and services similar to those which were the subject of a previous sale or negotiations of a sale to you. If you are a new customer, and where you have agreed that we may permit selected third parties to use your data for this purpose, we (or they) will contact you by electronic means only if you have consented to this.


2.5 If you do not want us to use your data in the ways described in this privacy policy, or to pass your details on to third parties for marketing purposes, you can refuse to provide us with your personal information or your consent, or withdraw a previously given consent. Please note that our processing of some of your data will be absolutely necessary to provide a service you have requested or wish to use (like a billing address when you purchase something from our site). If you refuse to provide such necessary data, we may not be able to provide the requested service.


3. Information We Collect by Automated Means


When you visit this site or our online advertisements, or use one of our social networking or mobile applications, we collect certain information by automated means, using technologies such as cookies, web server logs and web beacons. Information may include (i) technical information, such as the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone settings, language settings, browser type, domain, and other system settings operating system and platform, and (ii) information about your visit, including the full Uniform Resource Locators (URL) clickstream to, through and from our site, products you viewed or searched for, page response times, download errors, length of visits to certain pages, page interaction information, and methods used to browse away from the page and any phone number used to call our customer service number.


4. Technologies We Use


4.1 Cookies, Web Server Logs and Web Beacons. Cookies are small text files that websites send to your computer or other Internet-connected device to uniquely identify your browser or to store information or settings in your browser. Your browser may tell you how to be notified when you receive certain types of cookies and how to restrict or disable certain cookies. Please note, however, that without cookies you may not be able to use all of the features of our website. Read more about the different types of cookies we use and how to recognise and manage them here.


4.2 In conjunction with obtaining information through cookies, our web servers may log details such as your operating system type, browser type, domain, and other system settings, as well as the language your system uses and the country and time zone in which your device is located. The web server logs also may record information such as the address of the web page that linked you to our site and the IP address of the device you use to connect to the Internet.


4.3 To control which web servers collect this information, we may place tags on our web pages called "web beacons". These are computer instructions that link web pages to particular web servers and their cookies.


4.4 Third Party Web Analytics Services. We use third party web analytics services on this site, our social media platforms, or our social networking or mobile applications, as listed below. The service providers that administer these services use technologies such as cookies, web server logs and web beacons (over which we have no control) to help us analyse how visitors use the site. The information collected through these means (including IP address) is disclosed to these service providers, who use the information to evaluate use of the website. Some browsers indicate when a cookie is being sent and allow you to decline cookies on a case-by-case basis. The list of third party service providers below is merely illustrative and not comprehensive; for a complete list of all third party service providers, please contact us at info@jomalone.com. To learn more about each service, and exercise your choice with respect to their collection of information on this site:

• For Omniture (Adobe Analytics), please click here.

• To disable Google Analytics and the collection and use of data (cookies and IP address), please download and install the browser add-on for the deactivation of Google Analytics provided by Google at http://tools.google.com/dlpage/gaoptout?hl=en. To learn more about privacy and Google Analytics please consult the Google Analytics overview provided by Google at: http://www.google.com/intl/en/analytics/privacyoverview.html.

• For Signal, please click here.


4.5 Targeted Advertising. We also may contract with third-party advertising networks that collect IP addresses and other information through the use of cookies, web server logs and web beacons on our websites and emails; on third-party websites and emails; and on our advertising placed on third-party websites (over which we have no control). They use this information to provide advertisements about products and services tailored to your interests (including for companies not affiliated with us). You may see these advertisements on our websites and other websites. This process also helps us manage and track the effectiveness of our marketing efforts. When you are visiting this site, such information will only be collected and further processed if you have chose the "targeting" setting in our cookie-consent-tool, available here. We use the following third party advertising networks (this list is merely illustrative and not comprehensive); for a complete list of all third party service providers, please contact us at info@jomalone.com.:

• For Google, click here.

• Double Click, click here.

To learn more about these and other advertising networks and their further opt-out instructions, click here.


4.6 Social Media & Customer Support. We may use cookies and similar technologies to help us provide you and others with social plugins for social sharing and other customized content and experiences, such as making suggestions to you and others or providing you with customer support. We use the following third party social media and customer support services (this list is merely illustrative and not comprehensive); for a complete list of all third party service providers, please contact us at info@jomalone.com. Learn more about each service, including any choices you may have:

• For Facebook, click here.

• For LivePerson, click here.


5. How We Use the Information Collected by Automated Means


We may use the information collected through automated means on this site to deliver personalised content, for market research, data analytics and system administration purposes, such as to determine whether you've visited us before or are new to the site, and for compliance with our legal obligations, policies and procedures, including compliance with relevant industry standards and the enforcement of our Website Terms of Use and our Terms and Conditions of Sale. We also may use the information in other ways for which specific notice is provided, and if necessary, consent is obtained, prior to collection.


6. Information We Share


6.1 We do not rent lists, sell or otherwise disclose personal information we collect about you, except as described here.


6.2 In addition to our local affiliates listed in clause 2.2 above, we may share your personal information with:

(a) any member of or brand owned by our corporate affiliates. For a complete list of our corporate affiliates who will receive your personal information, please see http://www.elcompanies.com. We may share your personal information, as described in Section 1, with our corporate affiliates for purposes consistent with our Privacy Policy.

(b) third party service providers who perform services on our behalf based on our instructions. We do not authorise these service providers to use or disclose the information except as necessary to perform services on our behalf or comply with legal requirements. Examples of these service providers include entities that: process credit card payments; fulfil orders; provide web hosting, site maintenance and marketing services; and provide data cleansing and analytics services; and

(c) other third parties with your prior consent (e.g., some of our Facebook applications may share information collected through those applications with your Facebook friends or other Facebook users).


6.3 In addition, we may disclose information about you to the extent absolutely necessary (i) if we are required to do so by law or legal process, (ii) to law enforcement authorities or other government officials due to applicable mandatory law, or (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity.


6.4 We also reserve the right to transfer personal information we have about you in the event that (i) we intend to sell any business or assets, in which case we may disclose your personal data to the prospective buyer of such business or assets (provided that any prospective buyer has agreed that it will keep the information strictly confidential and will not use the data for purposes other than its determination whether or not to purchase the respective business or asset), or (ii) we sell or transfer all or a portion of our business or assets to a third party. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use personal information you have provided to us in a manner that is consistent with our Privacy Policy subject to adequate advance notice to you, where required by applicable law. Following such a sale or transfer, you may contact the entity to which we transferred your personal information with any enquiries concerning the processing of that information.



BY ACCEPTING THIS PRIVACY POLICY, YOU AGREE AND CONSENT TO THE DATA TRANSFERS SET OUT IN THIS CLAUSE 6.


7. Your Rights and Choices


We offer you certain choices in connection with the personal information we collect from you, such as how we use the information and how we communicate with you. To update your preferences, ask us to remove your information from our mailing lists or submit a request, please contact us as specified below.


8. Email Opt-Out


You can at any time tell our affiliate(s) not to send you marketing communications (i) by email by clicking on the unsubscribe link within the marketing emails you receive from those affiliate(s). You also may opt out of receiving marketing emails by clicking here.


9. Postal Mail Opt-Out


You can ask our affiliate(s) to stop sending you marketing communications by postal mail by following the instructions that may be included in a particular promotion. You also can also opt-out of receiving marketing emails from us when you provide your email address to use for the first time (in the context of the purchase of goods or services) or request that our local affiliate(s) refrain from sending you promotional postal mail by contacting them at the addresses available here.


10. Social Networking Application Opt-Out


To remove or delete our apps from your social networking account, follow the instructions from the social network: Facebook: Link provided by the Facebook Help Center.


11. Geo-Location Information through Mobile Applications


When you use one of our mobile applications, you may be asked for your geo-location. You may choose not to share your geo-location details by adjusting your mobile device's location services settings. To decline from sharing your geo-location details, follow the instructions on your mobile device on changing the relevant settings; otherwise, please contact your service provider or device manufacturer.


12. Withdrawing Consent


You may withdraw any consent you previously provided to us, or object at any time to the processing of your personal information. If you want to withdraw consent previously given or object to the processing of your personal information, please contact us as specified here.

We will consider your request and, as required by applicable law, apply your preferences going forward, within a reasonable amount of time and without cost to you. Even where you withdraw your consent, we may still process your personal data for limited purposes, for example, to give effect to your request, or to safeguard our business. In some circumstances, withdrawing your consent to our use or disclosure of your personal information may mean that you will not have the opportunity to take advantage of some of our products or services.


13. Reviewing, Updating and Modifying Personal Information


Subject to applicable law, you may have the right to request access to and receive details about the personal information we maintain about you, update and correct inaccuracies in your personal data, and have the information blocked or deleted, as appropriate. The right to access personal information may be subject to local law requirements. You may request to review, change or delete your personal information by sending an email to info@jomalone.com.


14. Data Transfers Outside of the European Union


Subject to the terms of this Privacy Policy, we may transfer the personal information we collect about you to countries other than the country in which the information was originally collected (which may include countries outside the European Economic Area ("EEA") (including to the United States) where data protection laws differ and provide different protections). It may also be processed by staff operating outside the EEA who work for us or one of our suppliers. Such staff may be engaged in, among other things, the fulfilment of your order, the processing of your payment details and the provision of support services.

BY SUBMITTING YOUR PERSONAL DATA AND ACCEPTING THIS PRIVACY POLICY, YOU AGREE TO THE TRANSFER, STORING OR PROCESSING OF SUCH DATA OUTSIDE OF THE EUROPEAN UNION.

We will take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and applicable law.


15. How We Protect Personal Information


We maintain appropriate administrative, technical and physical safeguards designed to protect the personal information you provide against accidental, unlawful or unauthorised destruction, loss, alteration, access, disclosure or use.


16. Links To Other Websites


Our site may provide links to other websites for your convenience and information. These websites may operate independently from us. Linked sites may have their own privacy notices or policies, which we suggest you review if you visit any linked websites. To the extent any linked websites you visit are not owned or controlled by us, we are not responsible for those sites' content, any use of those sites, or the privacy practices of those sites.


17. Cookies




Most web browsers allow some control of most cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.


18. Updates To Our Privacy Policy


This Privacy Policy may be updated periodically and without prior notice to you to reflect changes in our personal information practices. We will post a prominent notice on our website to notify you of any significant changes to our Privacy Policy and indicate at the top of the Policy when it was most recently updated.


19. How To Contact Us and Access to Information


If you have any questions or comments about this Privacy Policy, or if you would like us to update information we have about you or your preferences, please contact us by email at info@jomalone.eu or telephone at 00800 91009299. For Italy customers call 800693078. You also may write to:

Customer Care Center
Estée Lauder Cosmetics Ltd
Constellation House
3 Kites Croft Business Park
Warsash Road
Fareham
PO14 4FL

 

The Data Protection Act 1998 gives you the right to access information held about you. Your right of access can be exercised in accordance with that Act. For any request, whether in writing or by telephone, we reserve the right to authenticate your identity and may require that you furnish a valid form of identification if you require information about our processing of your personal information and before we respond to your request.


20. Non-waiver


No failure to exercise and no delay on our part in exercising any of our rights, remedies, powers or privileges under these Terms & Conditions (of which this Privacy & Cookie Policy forms part) and no course of dealing between us shall be construed or operate as a waiver, nor shall any single or partial exercise of any right, remedy, power or privilege preclude any other or further exercise thereof or the exercise of any other right, remedy, power or privilege on our part.


21. Law, Jurisdiction And Language


This Site, any content contained herein and any contracts entered into as a result of usage of this Site by you are governed by English law and not by the laws of any other jurisdiction except where required by applicable law or where the law of a particular jurisdiction apply on a mandatory, non-waivable basis. You have come to England to access the Site and both you and we agree to submit to the jurisdiction of the courts of England and Wales to resolve any disputes. All contracts between you and us are concluded in English even where this page or any portion of the site has been translated into a different language for your convenience.


22. Local Country Disclosures


FOR RESIDENTS OF AUSTRIA:

Where you provide contact information for friends and other people, please make sure that you have obtained their prior consent that we collect this information and contact them regarding the respective offer or service. By providing to us contact information for friends and other people you confirm that you have obtained such required consent.


FOR RESIDENTS OF SPAIN:

As mentioned in section 2 of this Privacy Policy, if you live in Spain, the personal data that Estée Lauder Cosmetics may have collected about you will be disclosed to Estée Lauder S.A. located at Poligono Industrial Las Mercedes C/ Nanclares De Oca, 3 28022 Madrid Spain.


Your personal data will be included in a data file owned by Estée Lauder S.A. Estée Lauder S.A. will process your data in the terms and for the purposes mentioned in section 2.1 to 2.5 of this Privacy Policy. The processing of your personal data by Estée Lauder S.A. will be subject to Spanish Organic Law 15/1999, of December 13, on Personal Data Protection and its implementing regulations.


You may exercise your rights to access, modify, delete and cancel your personal data processed by Estée Lauder Cosmetics S.A. and to oppose to the processing of your data by contacting with Estée Lauder Cosmetics S.A in the address above mentioned. For any request, whether in writing or by telephone, we reserve the right to authenticate your identity and may require that you furnish a valid form of identification if you require information about our processing of your personal information and before we respond to your request


Estée Lauder Cosmetics S.A hereby informs that it has implemented all the technical and organizational security measures needed to prevent modification, loss, processing and/or unauthorized access to personal data, bearing in mind the state of the art in technology, the nature of the data stored and the risks associated therewith, whether as a result of human action or as a consequence of the physical or natural environment.


FOR RESIDENTS OF PORTUGAL:

As mentioned in Section 2 of this Privacy Policy, if you live in Portugal, the personal data that Estée Lauder Cosmetics Limited may have collected about you will be disclosed to Socosmet - Sociedade de Cosmética, LDA. located at Amoreiras Square, Rua CarlosAlberto da Mota Pinto, 17, 3.º A, 1070-313 Lisboa, Portugal.


Your personal data will be included in a data file whose data controller is Socosmet - Sociedade de Cosmética, LDA, which shall process your data under the terms and for the purposes indicated in sections 2.1 to 2.5. of this Privacy Policy. The processing of your personal data by Socosmet - Sociedade de Cosmética, LDA shall be subject to and made in accordance with the Portuguese data protection legislation, notably, the Data Protection Law (Law no. 67/98, of 26 October).


You may exercise your rights to access, modify, delete and cancel your personal data processed by Socosmet - Sociedade de Cosmética, LDA and to oppose to the processing of your data by contacting with Socosmet - Sociedade de Cosmética, LDA in the address above mentioned.


Socosmet - Sociedade de Cosmética, LDA hereby informs that it has implemented all the technical and organizational security measures needed to prevent destruction, accidental or unlawful, accidental loss, modification, unauthorized disclosure or access, in order to ensure an adequate level of security with respect to the risks associated with the processing of data and the nature of the data to protect, having into account the state of the art in technology and the costs arising out of its application. Socosmet - Sociedade de Cosmética, LDA further informs that any data processor it may appoint shall offer sufficient guarantees in relation to the technical security and organizational measures in the processing of the personal data.


FOR RESIDENTS OF ITALY:

This Privacy Policy is applicable also in Italy with the unique specifications below:


For the purposes of the Italian Data Protection Code (Italian Legislative Decree No. 196 of 2003), the data controller is Estée Lauder S.r.l. (a company registered in Italy whose registered office is located at Via Turati 3, Milan, Italy).


If you have any questions or comments about this Privacy Policy, or if you would like us to update information we have about you or your preferences, please contact us by email at customerService@cs.jomalone.eu or telephone at 00800 91009299. For Italy customers call 800693078. You also may write to:
Estee Lauder S.R.L.
Via Turati, 3
Milano 20121
Italy.


The Italian Data Protection Code gives you the right to access information held about you. Your right to access can be exercised in accordance with Section 7 of the Italian Data Protection Code, in particular you shall have the right:

(1) To obtain confirmation as to whether or not personal data concerning you exist, regardless of their being already recorded, and communication of such data in intelligible form;

(2) to be informed of the source of the personal data, the purposes and methods of the processing, the logic applied to the processing, if the latter is carried out with the help of electronic means; the identification data concerning data controller, data processors and the representative designated as per Section 5, paragraph 2, of the Italian Data Protection Code; the entities or categories of entity to whom or which the personal data may be communicated and who or which may get to know said data in their capacity as designated representative/s in the State’s territory, data processor/s or person/s in charge of the processing;

(3) To obtain updating, rectification or, where interested therein, integration of the data, erasure, anonymization or blocking of data that have been processed unlawfully, including data whose retention is unnecessary for the purposes for which they have been collected or subsequently processed, certification to the effect that the operations above have been notified, as also related to their contents, to the entities to whom or which the data were communicated or disseminated, unless this requirement proves impossible or involves a manifestly disproportionate effort compared with the right that is to be protected;

(4) To object, in whole or in part on legitimate grounds, to the processing of personal data concerning him/her, even though they are relevant to the purpose of the collection,

(5) To the processing of personal data concerning you, where it is carried out for the purpose of sending advertising materials or direct selling or else for the performance of market or commercial communication surveys.


This Site, any content contained herein and any contracts entered into as a result of usage of this Site by you are governed by Italian law and not be the laws of the jurisdiction. You have come to Italy to access the Site and both you and we agree to submit to the exclusive jurisdiction of the courts of your address domicile in Italy to resolve any disputes. All contracts between you and us are concluded in Italian even where this page or any portion of the site has been translated into a different language for your convenience.


FOR RESIDENTS OF BELGIUM:

Under Belgian law, you have the right to object to the processing of your personal data for marketing purposes without being deprived of the right to purchase products or obtain services or to participate in special offers from us or from our Belgian affiliate.


Subject to proof of your identity, you have the right to access and correct or modify information or data maintained by us or by our Belgian affiliate pursuant to a signed and dated request personally delivered, sent by post or sent by email. The request should be submitted to either us or our Belgian affiliate. If the request is personally delivered, we or our Belgian affiliate, as applicable, will provide a dated and signed receipt.


Belgian residents are permitted to commence proceedings before the Belgian courts and request the application of the mandatory (contractual and extra-contractual) provisions of Belgian law.