PERSONAL DATA AND COOKIES PAGE

The CAUDALIE Company respects your concerns regarding the protection of your privacy and your personal data.

Your personal data collected is mainly processed by the CAUDALIE SAS Company, and possibly its foreign entities, in its capacity as data controller.

CAUDALIE SAS, 6 Place de Narvik, 75008 PARIS, FRANCE

RCS Paris: 398 360 123

This charter explains how CAUDALIE uses your personal information, collected when you use the www.caudalie.com website (hereinafter the “Website”), including the mobile and tablet versions, when shopping in our stores, with one of our authorized distributors or more generally, when you interact with us.

This charter allows you to find out more about the use of the browsing information collected using Cookies, as well as the means at your disposal for exercising your rights against this data collection.

This charter applies to all the pages of the Website, applications and services offered by the CAUDALIE Company, designated under the terms “CAUDALIE”, “Us”, “Our”, referring to this charter and complements the "General Terms and Conditions of Sale" of the Website (as well as any document or information leaflet referring to this charter).

By using our Website, you accept the terms of this charter and consent to us collecting and processing your personal data in accordance with our data privacy policy. In case of disagreement with the terms of the charter, please do not use our Website or contact us.

Amendments to the charter

We may modify and update this charter.
We invite you to read it as soon as you interact with us in order to stay informed about our practices regarding the protection of personal data and your rights.

CHARTER BASICS

1. Personal data collected and processed – Cookies deposited and activated

Personal data is any information that identifies you, directly or indirectly. This may include identifying information such as your last name, first name, email, date of birth, postal address, IP address, purchase habits or preferences. To find out more, click here. (Link 1 .1)

“Cookies" are alphanumeric identifiers placed on your computer, cell phone or digital tablet through your Internet browser; they are used to recognize your browser and propose personalized services. We use cookies when you browse on our Website in order to memorize your preferences, provide you with a more enjoyable customer experience and optimize our Website by supplying content in line with your needs.

Session cookie

(Una sesión) (A session) These cookies are used to ensure that visitors browse easily on the website; they do not keep any personal information. They guarantee the proper operation of certain basic functionalities such as account connection, browsing or adding a product to the shopping cart. Their duration is limited to the user session and does not persist over time.

Caudalie cookie

CaudCountry (3 months): memorizes the visitor's preferred language
CaudIsSubscriber (30 months): keeps the newsletter subscription pop-in from displaying again
CaudPush (24 hours): identifies a visitor browsing on the Caudalie.com website from a specific marketing campaign in order to display the corresponding offer

Analytics cookie (Google Analytics)

We use software to analyze certain visitor information, such as traffic on the Caudalie.com Website, browser use, the number of new visitors, marketing activity and orders placed. This information helps us improve our Website and the shopping experience, as well as our campaigns. Data stored by this cookie can be seen only by the pertinent teams at Caudalie; the cookie does not record any confidential information.

Store locater cookie

(1 session) Caudalie.com uses Google Maps to search for Caudalie points of sale and spas. Google privacy policy https://www.google.fr/intl/fr/policies/privacy/

Third-party cookie

Google, Facebook, Bing, Yahoo, Zanox, Splio, Yzance Caudalie.com accepts that partner companies may use cookies in the context of delivering targeted advertisements. They help us follow visitors who clicked on advertising and interact with them. Each company uses its own tracking cookies and the data extracted are not interchangeable. No confidential information is recorded. (From 1 session to 3 years)

Sharing tools

Caudalie.com uses the "share" function for contents via social networks like Facebook. Caudalie has no control over the distribution of these cookies; we suggest you consult these third-party Websites for more information on their cookies. Facebook Privacy Policy: http://www.facebook.com/policy.php YouTube privacy policy: https://www.google.fr/intl/fr/policies/privacy/

Cookie Configuration

Most Internet browsers automatically accept cookies by default. However, you can configure your browser to avoid the placement of cookies on your computer or an associated device. Some browsers propose a mode where cookies are always removed after a visit. The Help section on the toolbar of most browsers tells you how to refuse new cookies, how to be notified when new cookies have been received and how to deactivate them. You can also choose to deactivate or remove cookies used by your browser's accessory software by modifying the configuration of this software or by visiting the software editor's Website.

Reconfiguration may modify the conditions of access to our services requiring the use of cookies.

If your browser is configured to refuse all cookies, you will not be able to make purchases or take advantage of the essential functions of our Website, such as putting items in your shopping cart or receiving personalized recommendations. So that the cookies will enable meeting your expectations, we suggest you configure your browser to accept them.

You can deactivate the cookies by following the instructions below:

If you use the Internet Explorer browser

In Internet Explorer, click on the Tools button, then on Internet Options. Under the General tab, under Browsing History, click on Configuration, then on the Display Files button.

Next, click on the Name column header to sort the files in alphabetical order, then go down the list to the files starting with the Cookie prefix (all cookies have this prefix and normally contain the name of the Website that created the cookie).

Select the cookie(s) with the name Caudalie and remove them.

Close the window that contains the list of files, then double click on OK to return to Internet Explorer.

In the window that displays, choose Privacy and click on Display Cookies.

Locate the files that contain the name Caudalie then select them and delete them. If you use the Safari browser

In your browser, choose the Edit menu > Preferences.

Click on Security, then on Display Cookies.

Select the cookies containing the name Caudalie and click on Remove or Remove All.

After removing the cookies, click on Done.

If you use the Google Chrome browser

Click on the Tools menu icon and choose Options.

Click on the Advanced Options tab and access the Privacy section.

Click on the Display Cookies button.

Locate the files containing the name Caudalie, select them and remove them.

Click on Close to return to your browser.

For further information in French on cookies, see the CNIL Website: http://www.cnil.fr/vos-droits/vos-traces/les-cookies/

CONSEQUENCES OF BLOCKING COOKIES

Your choices regarding cookies

Your browser may allow you to choose to disable all or part of the Cookies, either systematically or depending on the issuer. You can also configure your browser software to accept or reject cookies (case by case or entirely). We remind you, however, that disabling all Cookies will prevent you from using our Website under normal conditions, except for basic functions.

2. Contact us

For any question or complaint concerning this charter, you can contact us by letter addressed to:

Caudalie Consumer Service

6 place de Narvik 75008 Paris

or by email: europe@caudalie.com

2 .1 WHAT INFORMATION DO WE COLLECT?

Caudalie collects several types of personal data about you:

Information you provide directly to us

We collect information that you communicate to us directly when you use our Website and interact with us. This is particularly the case when you:

- Create an online account.

- Subscribe to our loyalty program,

- Make purchases or book a service in our Stores or on our Website,

- Call us on the phone,

- Subscribe to receive our emails,

- Take part in a draw, competition, promotion or survey,

- Contact us through third-party social networks,

- Ask for customer support,

- Receive a beauty scan in a Store or with an authorized distributor

- Contact us in any other way.

Communicating your personal information is voluntary. However, if you do not provide some or all of the requested information, we may not be able to provide you with certain products, services or information. The categories of information we collect include:

- The identification and contact information (such as last name, first name, date of birth, postal address, contact details) necessary for your identification when you use one of our Services (e.g. creation of an online account),

- Transaction information needed to process your order (selected items, shipping and billing address, phone number and email address, phone number, payment method).

- Information about your preferences (such as your online Love List)

- Socio-demographic information (such as your age, profession, gender etc., mentioned when you post a review or create an account)

- Information about your skin type when you received the beauty scan or diagnosis

- The historical data of your contacts with us (We also keep the history of your contacts when you contact Customer Service or when you enter a claim)

- The reviews you write about the products

- The data we request from you and which is essential to answering your requests is identified by an asterisk or equivalent process on the collection forms or specified as such orally at the time of collection. In our authorized sales outlets or at the events we organize, we may collect additional personal data in the conditions and for the purposes for which you are specifically notified.

Information we collect automatically

We automatically collect certain information about you when you access the Website, browse or make a purchase, including:

- Connection data: We collect information about the device to which you are connecting and your use of the Website (such as the operating system, the type of browser used, the use or non-use of a proxy, the location of the device deduced from your IP address to identify your computer, access times, pages visited, and the link that allowed you to access our Website).

- Information about your browsing (whether you are logged in or not): We may use cookies and other tracking technologies to collect information about you when you interact with our Website or the emails we send you. This information allows us to deduce your preferences, your liking for this or that type of product, as well as analyze how you interact with certain content. This information is collected both when you are logged in and when you are not logged in and can be linked to each other, regardless of the terminal being used. The aim is to offer you the most personalized offers possible.

In addition, depending on the data already in our possession, some forms may be pre-filled.

Information we collect from our partners and other sources

We may also obtain information about you from other sources and link it to the information about you that we collect, such as:

- Information from the databases of local postal services to check and update mailing addresses;

- Data provided by third-party partners: this is information communicated to us by third-party partners with whom you have been in contact and for whom you have authorized sharing for the purposes of commercial prospecting or targeted advertising.

- Data communicated by social networks. For example, when you share your experience with Caudalie on a social network, you are sharing personal data about yourself with this social network and with Caudalie. These communications are governed by the personal data protection policies of these social networks to which we refer you and regarding which Caudalie disclaims any liability.

Information regarding third parties

In some cases, we may also collect information you provide about other people. For example, when you buy a gift card for a third-party, you may choose to send this gift card electronically to this third-party and must therefore send us the recipient's email address, which we use. We use such information only to respond to your requests and do not send marketing communications to your contacts without their consent.

2..2 WHAT ARE THE PURPOSES FOR WHICH WE COLLECT DATA?

The processing of your personal data and the use of cookies serve a specific, explicit and legitimate purpose. Any processing of personal data that would be not justified by a legitimate aim requires your consent. We strive to minimize the data collected.

Processing your personal data allows us to offer you services and maintain a secure environment through:

- The proper functioning of our Website

- The services and products offered;

- Prevent and detect fraud, malware (malicious software or malware) and manage security incidents;

- Carrying out all commercial operations (orders, payment, deliveries, invoices, accounting, satisfaction survey, consumer service, etc.);

- Analyzing and personalizing the online customer experience to ensure the highest quality of services (anonymously)

- Managing the loyalty program and the customer relationship via our CRM

- Optimizing our customer service (accessible by email, phone or chat)

- Managing any disputes.

Certain data is also kept to meet our legal obligations and to defend our interests in the event of disputes or legal action.

2..3 HOW LONG IS MY DATA BE KEPT?

Your data is kept for the duration of your relationship.In general, your personal data is kept for the duration of your relationship with us, increased by a period of three years after the end of our relationship, then archived to meet our legal obligations or for probative purposes or is anonymous for the purposes of studies and statistics.

However, we retain certain data after the deletion of your account where such retention is provided by law, or where such retention is necessary to enable us to handle litigation and disputes. In this case, the data necessary to resolve the problem or dispute will be kept as long as the dispute continues within the limits of the applicable rules on limitation. Other data may be retained after being processed to prevent reassignment to an identified person for study and statistical purposes

DESCRIPTION OF THE DATALENGTH OF TIME IT IS KEPT
>The personal data of the customer account
>Data concerning your use of the Website
Duration of three (3) years from your last activity on the Website (Purchase or modification of account)
>Data related to an order Duration of three (3) years from your last order (anonymization of the fields “last name, first name, email, phone, personal address” after 3 years of inactivity)
>Audience measurement and navigation statistics on the Website Duration of thirteen (13) months in terms of cookies.
>Prospect/customer data Duration of three (3) years from their collection or last contact, or last order.
>Data to establish proof of a right or contract, or retained for compliance with a legal obligation Archiving in accordance with the legislation in force

2.4 WHAT ARE MY OPTIONS WITH REGARD TO PROMOTIONAL COMMUNICATIONS?

You have the option to join our mailing lists and agree to receive marketing and promotional information from us. You can withdraw your consent at any time by clicking directly at the bottom of our emails or by contacting us: link to new Website contact page

In accordance with the provisions of the "Informatique et Libertés” (French Data Protection) law of 6 January 1978 as amended and Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016, you have the right of access, information, opposition, rectification, limitation, portability and deletion of your data. You also have the right to formulate and communicate guidelines regarding the fate of your data after your death. To exercise one or more of these rights, you must complete the Contact form.