shoppingBagNoDot

storeLocatorICON

STORE LOCATOR

wishlistICON

WISHLIST

shoppingBagNoDot

SHOPPING BAG

CONTACT

Your comments and questions are important to us. If your inquiry cannot be answered by the FAQ's, please contact us using the Contact Form or call us on +41 800 11 33 66.

 
Privacy Policy

Kanebo Cosmetics (Europe) Ltd. ("Kanebo" or "we" or "our") and each of its affiliates and subsidiaries in the EMEA region (collectively, the "Kao Group") takes data privacy seriously. This Privacy Policy informs the users of https://www.sensai-cosmetics.com/gb/en and any other Kanebo-owned websites or mobile applications on which this Privacy Policy is displayed ("Website”) how we, as controller within the meaning of the General Data Protection Regulation ("GDPR") collect and process any information relating to you ("personal data", e.g. your name and E-Mail address)in connection with their usage of the Website.  
If you have any questions regarding the processing of your personal data, please contact us dataprivacy.emea@kao.com.  
Note that other websites or mobile apps of Kanebo or its affiliates may be governed by other privacy policies.    
Last revised February 2021 

Summary 

This Privacy Policy includes information on the following:

  • 1.  Categories of Personal Data and Processing Purposes - What personal data do we process about you and why? / Processing Basis and Consequences - What  is the legal justification for processing your personal data and what happens if you choose not to provide it?
  • 2.  Categories of Recipients - Who do we transfer your personal data to?
  • 3.  International Data Transfer - Where do we transfer your Personal Data to?
  • 4.  Retention Period - How long do we keep your personal data?
  • 5.  Your Rights - What rights do you have and how can you assert your rights?
  • 6.  Cookies and other tracking technologies
  • 7.  Questions and Contact Information
  • 8.  Changes to this Privacy Policy

1.  Categories of Personal Data and Processing Purposes - What personal data do we process about you and why? / Processing Basis and Consequences - What is the legal justification for processing your personal data and what happens if you choose not to provide it? 

We base the processing of your personal data depending on the respective activity identified in detail below on the following legal basis:

  •   You have provided your consent to the processing, Art. 6 (1)(a) GDPR ("your consent");
  •   The processing is necessary for the performance of a contract with us, to which you are a party of, Art. 6 (1)(b) GDPR ("Performance of a contract");
  •   The processing is necessary for the fulfilment of a legal obligation that we are subject to, Art. 6 (1)(c) GDPR ("Legal obligation");
  •   The processing is necessary for the purpose of the legitimate interest pursued by us or a third party, except where such interest is overridden by your interest or fundamental rights and freedoms which require the protection of personal data, Art, 6 (1)(f) GDPR ("Legitimate interest").  
In the following you will find a detailed description of the data collected for the respective processing activity and the legal basis that the processing is based on

1.1  Metadata 

  • 1.1.1  When you visit the Website certain necessary data will be collected automatically. Without the collection of such data the use of the Website is not possible.
  • 1.1.2  In this case, we will collect the following metadata: browser type and version, operating system and interface, website from which you are visiting us (referrer URL), webpage(s) you are visiting on our Website date and time of accessing our Website, and internet protocol (IP) address. Such data may be linked to you indirectly.
  • 1.1.3  Your IP address will be used to enable your access to our Website. We do not store this data after your access any further. The metadata will be used to improve the quality and services of our Website by analysing the usage behaviour of our users.
  • 1.1.4  The legal basis for the processing is legitimate interest as the use of our Website is not possible without the collection of the data.

1.2  Newsletter  

  • 1.2.1  You can sign up to our E-Mail newsletter via our newsletter banner on our websites, when you create an account or during the checkout process.
  • 1.2.2  If you request to receive our E-Mail newsletter, we process the following personal data about you: E-Mail address as well as the request to receive the E-Mail newsletter; country and language will be pre-populated due to your location. We process such personal data for purposes of providing the newsletter to the extent permitted by applicable law and analysing your interests for marketing purposes.
  • 1.2.3  The legal basis for the processing of your personal data is your consent, where required, or our legitimate interest.

1.3  Contact form  

  • 1.3.1  On our website, we offer you the opportunity to contact us via a contact form.
  • 1.3.2  For this we need the following personal data from you: title, first and last name, E-Mail and content of the message; if you are signed into your user account your name and E-Mail address will be pre-populated.
  • 1.3.3  The personal data that you provide to us in the context of this contact request will only be used to answer your enquiry/contact request and for the associated technical administration.
  • 1.3.4  The legal basis for the processing of your personal data is our legitimate interest as the processing of your Personal Data is necessary to respond to your request.

1.4  Account 

  • 1.4.1  If you create an account for our “Webshop”, you will be asked to provide the following personal data about you: E-Mail address, selected password for your account.
  • 1.4.2  We process such personal data for purposes of account administration, answering your queries or information requests, analysing your interests for marketing purposes, improving our “Webshop” according to usage patterns, and for technical administration or other purposes to which you have agreed.
  • 1.4.3  The legal basis for the processing of your personal data is your consent, the Performance of a contract and/or our legitimate interest in the pursuing the above-mentioned purposes.

1.5  Product Orders 

  • 1.5.1  If you order a product via our “Webshop”, we collect and process the following personal data about you: title, first and last name, E-Mail address, telephone number, invoicing and delivery address, and products ordered, to provide desired products or services and related information.
  • 1.5.2  Such personal data will be added to your personal data stored relating to your account.
  • 1.5.3  We process such personal data for purposes of carrying out the contractual relationship and the product order, compliance with legal obligations, defending, establishing and exercising legal claims, and analysing your interests for marketing purposes.
  • 1.5.4  The processing of your personal data is based on one of the following legal basis: Your consent (if required), performance of a contract, legal obligation, and/or legitimate interest as we have an interest in pursuing the purposes listed in 1.5.3.

1.6  Payment  

  • 1.6.1  We process your personal data for the documentation and processing of payment transaction undertaken by you on our Website.
  • 1.6.2  The following categories of personal data are processed: name, information on the third-party payment provider used, confirmation of payment, address.
  • 1.6.3  We base the processing your personal data on the following legal basis: Performance of a contract, Legal obligation, legitimate interest in order to protect our business and legal rights.

1.7  Rating & Reviews  

  • 1.7.1  You can provide feedback on our goods and services in the form of product ratings and reviews and such feedback will be posted on our Website to be visible to other users.
  • 1.7.2  We process the following personal data: name/username, rating, content of the review, type of product.
  • 1.7.3  The legal basis for the processing is our legitimate interest in the processing and publishing of your feedback and/or consent (if required).

1.8  Virtual Make-up  

  • 1.8.1  Our Virtual Make-up Tool allows you to virtually test our make-up products.
  • 1.8.2  We will collect and process the following data categories: picture/real-time video. 
  • 1.8.3  The processing of your personal data is based on our legitimate interest as the processing is required to offer the respective service to you as requested by you.
For the sole purpose of visiting our website, the provision of your personal data is not required by a statutory or contractual obligation. The provision of your personal data, however, is necessary if you want to receive our services/s or if you want to buy products.
Not providing your personal data may result in disadvantages for you, for example, we may not be able to answer your request or to provide you with products you request, or you may not be able to fully experience the website (cookies). However, unless otherwise specified, not providing your personal data will not result in legal consequences for you.

2.  Categories of Recipients - Who do we transfer your personal data to? 

We may transfer your personal data to third parties for the processing purposes described above as follows:

  • 2.1  Within the Kao Group: Members of the Kao Group may receive your personal data as necessary for the processing purposes described above. Depending on the categories of personal data and the purposes for which the personal data has been collected, different internal departments within the Kao Group may receive your personal data. 
  •  
  • 2.2  With data processors: Certain third parties, whether affiliated or unaffiliated, may receive your personal data to process such data under appropriate instructions ("Processors") as necessary for the processing purposes described above, such as Website service providers, order fulfilment providers, payment providers, customer care providers, marketing service providers, IT support service providers, and other service providers who support us in maintaining our commercial relationship with you. The Processors will be subject to contractual obligations to implement appropriate technical and organisational security measures to safeguard the personal data, and to process the personal data only as instructed.
  •  
  • 2.3  Other recipients: We may transfer, in compliance with applicable data protection law, personal data to law enforcement agencies, governmental authorities, judicial authorities, legal counsel, external consultants, or business partners. In case of a corporate merger or acquisition, personal data may be transferred to third parties involved in the merger or acquisition.
  •  
  • 2.4  We will not disclose your personal data to third parties for advertising or marketing purposes or for any other purposes without your consent. Any access to your personal data is restricted to those individuals that have a need-to-know in order to fulfil their job responsibilities.

3.  International Data Transfer - Where do we transfer your Personal Data to? 

  • 3.1  We may transfer your personal data to countries outside of the European Union ("EU")/European Economic Area (“EEA”) which do not provide for a data protection level as provided in the EU/EEA.
  •  
  • 3.2  Some recipients located outside of the EU/EEA and identified in section 2 are located in countries for which the EU Commission has issued an adequacy decision, such as in Switzerland and Japan. The transfer does therefore not require any additional safeguards as provided in Art. 45 GDPR.
  •  
  • 3.3  We have implemented appropriate safeguards with regard to transfers of your personal data to any other third countries (such as the U.S.) by putting in place data transfer agreements based on the standard contractual clauses (EU Commission decision 2010/87/EU and/or 2004/915/EC) as referred to in Art. 46 (2)(c) GDPR and/or by relying on binding corporate rules of the recipient (Art. 46 (2)(b) GDPR).

4.  Retention Period - How long do we keep your personal data?

Your personal data will be retained as long as necessary to pursue the above-mentioned purposes. For example, certain personal data, such as order and invoicing data, will typically be retained for about 11 years due to statutory retention requirements for tax purposes, personal data which are required to establish, defend or exercise a claim may be retained for as long as necessary to pursue this purpose and certain personal data may be retained to comply with applicable laws. If you delete your account or did not access your account for a period of two years, we will delete your personal data from our systems and/or take steps to properly anonymise it so that you can no longer be identified from it (except those that must be retained for a longer period as stated before).

To the extent possible, we will restrict the processing of your personal data for such limited purposes after the termination of the contractual relationship.

5.  Your Rights - What rights do you have and how can you assert your rights? 

  • 5.1  Right to withdraw your consent: If you have declared your consent regarding certain collecting, processing and use of your personal data (in particular, regarding the receipt of the E-Mail newsletter) you can withdraw this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal. Please contact us as stated in Section 7 below to withdraw your consent.

  • 5.2  Additional data privacy rights: Pursuant to applicable data protection law, you may have the right to: (i) request access to your personal data; (ii) request rectification of your personal data; (iii) request erasure of your personal data; (iv) request restriction of processing of your personal data; (v) request data portability; and/or (vi) object to the processing of your personal data (including objection to profiling). Please note that these aforementioned rights might be limited and/or subject to additional conditions under applicable data protection law. Below please find further information on your rights: 
  •  

  • 5.2.1  Right to request access to your personal data: You have the right to obtain from us confirmation as to whether or not personal data concerning you is being processed, and, where that is the case, to request access to the personal data. This access information includes – inter alia – the purposes of the processing, the categories of personal data concerned, the recipients or categories of recipient to whom the personal data have been or will be disclosed, and a copy of the personal data undergoing processing. However, this is not an absolute right and the interests of other individuals may restrict your right of access.

  • 5.2.2  Right to request rectification: You have the right to obtain from us the rectification of inaccurate personal data concerning you. Depending on the purposes of the processing, you have the right to have incomplete personal data completed, including by means of providing a supplementary statement.

  • 5.2.3  Right to request erasure (right to be forgotten):  In certain circumstances, you have the right to obtain from us the erasure of personal data concerning you and we are obliged to erase such personal data.

  • 5.2.4  Right to request restriction of processing: In certain circumstances, you have the right to obtain from us restriction of processing your personal data. In such case, the respective data may be processed only in certain cases.

  • 5.2.5   Right to request data portability: In certain circumstances, you have the right to receive the personal data concerning you, which you have provided to us, in a structured, commonly used and machine-readable format and you may have the right to transmit those data to another entity without hindrance from us.

  • 5.2.6   Right to object:  Under certain circumstances, you have the right to object, on grounds relating to your particular situation, at any time to the processing of your personal data by us where the processing is necessary for our legitimate interest (Art. 6 (1)(f) GDPR), including profiling, and we can be required to no longer process your personal data, unless we demonstrate compelling legitimate grounds for the processing or for the establishment, exercise or defence of legal claims. Where we process your personal data for marketing purposes, including marketing-related profiling, you have the right to object at any time and your personal data will not be processed any longer for such purposes.

    You may exercise this right by contacting us as stated in Section 7 below.

    Such a right to object may, in particular, not exist if the processing of your personal data is necessary to take steps prior to entering into a contract or to perform a contract already concluded.

    If you have given your consent to certain processing (such as the receipt of our E-Mail newsletter), you will need to withdraw your consent (e.g., by unsubscribing via the link in each E-Mail newsletter) as stated in section 5.1 in order to stop the receipt of such E-Mail newsletters.

  • 5.2.7  For other statutory rights, please go to www.kao.com/global/en/EU-Data-Subject-Request

  • 5.2.8  To exercise your rights, please contact us as stated under Section 7 below.

  • 5.3  Right to lodge a complaint: You also have the right to lodge a complaint with the competent data protection supervisory authority. You can find the contact details of the data protection supervisory authorities in the EU via this link: https://edpb.europa.eu/about-edpb/board/members_en.

6.  Cookies and other tracking technologies 

This Website uses cookies and other tracking technologies. For further information, please visit our Cookie Policy.

7.   Questions and Contact Information 

If you have any questions about this Privacy Policy or if you want to exercise your rights as stated above in Section 5, please contact us at www.kao.com/global/en/EU-Data-Subject-Request.
Kanebo's Data Protection Officer can be contacted at: dataprivacy.emea@kao.com.

8.  Changes to this Privacy Policy 

We may update this Privacy Policy from time to time in response to changing legal, regulatory or operational requirements. We will notify you of any such changes, including when they will take effect, by updating the "Last revised" date above and publishing the updated version here https://www.sensai-cosmetics.com/gb/en/privacy or as otherwise required by applicable law.  

Page Top