PERSONAL DATA INFORMATION & PRIVACY POLICY

This privacy policy describes the processing of personal data carried out by BEAUTY LAB TWELVE, S.L. on its online store www.twelvebeauty.com (hereinafter, the “Website”) with personal data of users who browse and place orders through it (hereinafter, the “Users”).

1. WHO IS RESPONSIBLE FOR PROCESSING YOUR DATA?

The controller of the personal data collected and processed through the use of the Website is BEAUTY LAB TWELVE, S.L. (hereinafter, “BLT”), with Tax ID No. B-22850226. Users may contact BLT through the following means:

  • Postal address: Calle Santísima Trinidad, 8, 03760, Ondara, Alicante, Spain.
  • Email address: privacidad@pyd.es

2. WHAT TYPE OF PERSONAL INFORMATION DOES BLT PROCESS AND HOW IS THE DATA OBTAINED?

BLT collects data directly from Users, mainly the following data and/or categories of data:

  • identification and contact data (i.e. first name, last name, email address, postal address and postcode, telephone number);
  • Website usage and browsing data in accordance with the provisions of the Cookie Policy.

As a result, at the time of User registration, the personal data collected by BLT comes from the data subject themselves. If the aforementioned data is not provided, registration and/or the corresponding order cannot be completed.

3. FOR WHAT PURPOSE DO WE PROCESS YOUR PERSONAL DATA AND WHAT IS THE LEGAL BASIS?

Below are the different processing purposes for which BLT will process Users’ personal data, as well as the legal bases applicable to each of them:

a. BLT will process Users’ personal data as necessary for the performance of the Contract in relation to the following purposes:

    • managing User registration on the Website.
    • managing Users’ orders (i.e. processing and delivering the order and informing them of its status by email, SMS and/or any other channel available at any given time).
    • contacting the User if BLT needs to inform or ask them about any matter related to their order (e.g. shipment confirmation).
    • handling any queries the User may have regarding their order.
    • managing and issuing proof of purchase documents (e.g. electronic simplified invoice, sales invoice, Tax Free).

b. BLT will process Users’ personal data when they have given their express consent for the following purposes:

    • creating a commercial profile based on the User’s browsing on the Website. Such profile will be created by processing their personal data and browsing information (e.g. products viewed or added to the bag, Website sections visited, country from which they access the Website) in order to assess preferences and/or interests and offer content, offers, services and products suited to their profile.
    • sending commercial communications to Users via email related to our products or promotions.
    • the use of cookies and similar technologies in accordance with the Cookie Policy.

The data subject may withdraw the consent given at any time by sending a withdrawal request to privacidad@pyd.es.

c. BLT will process Users’ personal data whenever necessary to comply with applicable legal obligations.

d. BLT will process Users’ personal data for the purpose of ensuring that the Website is a secure site based on BLT’s legitimate interest

so that transactions and access to it do not pose a risk to Users’ privacy or any other rights and freedoms.

4. HOW LONG IS PERSONAL DATA RETAINED?

In order to ensure that personal data is adequate, relevant and limited to what is necessary for the purposes for which it is processed, BLT will retain personal data only for the period necessary to fulfil the purpose for which it was collected, taking into account the need to respond to issues that arise, resolve problems, make improvements, activate services and comply with applicable legal requirements.

Once the relationship between the User and BLT ends, personal data will be blocked in all BLT systems solely for the purpose of making it available to competent authorities to address potential administrative or judicial liabilities and the exercise or defence of claims. After the blocking period, the personal data will be permanently deleted.

For processing activities based on the User’s express consent, such data will be processed as long as the consent is not withdrawn and, following such withdrawal, the data will be retained in a duly blocked form in accordance with the previous paragraph.

5. WITH WHOM IS PERSONAL DATA SHARED?

Users’ personal data will be disclosed to third parties in compliance with applicable legal obligations, for example to Public Authorities and/or Bodies when required by tax, labour, Social Security or other applicable regulations, as well as for the performance of the contract to third parties providing transport services necessary for the delivery of purchased products.

BLT may also engage third parties who will have access to personal data as part of providing services. In such cases, BLT will have entered into the corresponding data processing agreement in accordance with applicable regulations. These third parties operate in the technology services sector.

6. HOW DOES BLT PROTECT PERSONAL DATA?

BLT’s Website uses information security techniques such as firewalls, automated anti-attack systems, access control procedures and cryptographic mechanisms, all with the aim of preventing unauthorised access to data and ensuring confidentiality. Periodic security audits are also carried out to assess risks and implement regular controls.

BLT states that it has adopted all necessary technical and organisational measures to guarantee the security and integrity of the personal data it processes, as well as to prevent its loss, alteration and/or access by unauthorised third parties.

7. WHAT ARE USERS’ RIGHTS IN RELATION TO THEIR PERSONAL DATA?

Users have the rights detailed below. They may exercise them by contacting email privacidad@pyd.es. In case of reasonable doubts regarding the identity of the person exercising the right, BLT may request additional documentation to verify identity.