PRIVACY POLICY

Last Updated: February 6th 2023

WHAT DOES THIS POLICY COVER?

This privacy policy ("Privacy Policy") describes the practices of MAKE UP FOR EVER LLC ("MAKE UP FOR EVER ", "we," "us" or “our”) regarding the collection, use, and disclosure (“Processing”) of personal information obtained from residents of Canada online at https://www.makeupforever.com/ca/en (the “Website”), in store, or by telephone. By “Personal Information” we mean information about an identifiable individual. By accessing or using the Website, you consent to the terms of this Privacy Policy. If you do not consent to the Processing of your Personal Information in accordance with this Privacy Policy, do not access or use the Website, or provide us with any Personal Information.

Your Personal Information may be Processed and stored in the United States or any other country in which we, or our service providers, maintain facilities. Any Personal Information that is Processed in countries outside of Canada may be subject to the laws of those countries (e.g. where a third party service provider operates internationally). As a result, Personal Information may be disclosed in response to valid demands or requests from government authorities, courts, or law enforcement officials in countries outside of Canada.

MAKE UP FOR EVER does not knowingly collect or use any personally identifiable information from individuals under the age of 13. If we become aware that any such information has been provided or submitted to us, we will delete the information as soon as possible.

WHAT PERSONAL INFORMATION IS COLLECTED?

A. Information you provide

Depending on how you use the Website or engage in the other services described below, we may ask you to share Personal Information with us.

B. Automated Information Collection

We also receive and store certain types of information, including Personal Information, when you interact with our Website and emails. We use a number of technologies to automatically collect information about your activities online (and may use other technologies in the future).

  • COOKIES AND FLASH COOKIES

We may use "cookies" or “flash cookies” to keep, and sometimes track, information about you. Cookies are small data files that are stored on your computer's hard drive and can be used to collect information about where you travel on our Website and what you look at on our Website. Flash cookies (also called Local Shared Objects) are data files similar to cookies except that they can store more complex data. Cookies and flash cookies may store your username and/or password, settings, preferences or your IP address. All of these purposes serve to improve and personalize your experience on our Website.

  • CLEAR GIFS

We may use "clear GIFs" (aka "Web beacons" or "pixel tags") or similar technologies, in the Website and/or in our communications with you to enable us to know whether you have visited a specific page on the Website or received/ opened a message. A clear GIF is typically a one-pixel, transparent image (although it can be a visible image as well), located on a Website page or in an e-mail that communicates to us whether you viewed an email that we sent you or visited a certain page on our Website. A clear GIF may enable us to relate your viewing or receipt of a Website page or message to other information about you, including your Personal Information.

  • IP ADDRESS AND CLICKSTREAM DATA

Our server automatically collects data about your server's Internet address when you visit the Website. This information, known as an Internet Protocol address, or IP Address, is a number that's automatically assigned to your computer by your Internet service provider whenever you're on the Internet. When you request pages from our Website, our servers may log your IP Address and sometimes your domain name. Our server may also record the referring page that linked you to our Website (e.g., another website or a search engine); the pages you visit on this Website; the website you visit after this Website; the ads you see and/or click on; other information about the type of Web browser, computer, platform, related software and settings you are using; any search terms you have entered on this Website or a referral site; and other Web usage activity and data logged by our Web servers. We use this information for internal system administration, to help diagnose problems with our server, and to administer our Website. Such information may also be used to gather broad demographic information, such as country of origin and internet service provider.

Any or all of these activities with regard to Website usage information may be performed on our behalf by our service providers.

  • MOBILE DEVICES

You may be visiting our Website from your mobile device. Certain mobile service providers uniquely identify mobile devices and we or our third-party service providers may receive such information if you access the Website through mobile devices. Some features of the Website may allow for the collection of mobile phone numbers and we may associate that phone number to mobile device identification information. Furthermore, some mobile phone service providers operate systems that pinpoint the physical location of devices that use their service. Depending on the provider, we or our third-party service providers may receive this information.

HOW IS THE PERSONAL INFORMATION USED?

We will use the Personal Information you provide to us, for example, to respond to your requests and to provide you with our product and service offerings. We may also use your Personal Information to maintain our internal record keeping, and contact your for account and promotional purposes. You may have the opportunity to sign up to receive communications from us (for example, in the form of e-mails, mailings, and the like), about products, services, companies and events, sponsored by us and by others, that we think might interest you. You may unsubscribe from these communications at any time by following the instructions in the How to Opt Out section below. You can also amend your contact information by following the instructions below.

We also may analyze user behavior as a measure of interest in, and use of, our Website and e-mails, both on an individual basis and in the aggregate, to improve our offers. Finally, we may use your Personal Information for other legitimate business purposes, including to detect and prevent fraud, to collect amounts owing to us and to maintain our business records.

MAKE UP FOR EVER retains the Personal Information collected from you until you elect to no longer receive emails or information from us, otherwise terminate your account with us or when MAKE UP FOR EVER concludes it no longer requires that Personal Information for the purposes for which it was collected. Upon expiry of the applicable retention period, we will securely destroy your Personal Information in accordance with applicable laws and regulations

DO WE SHARE PERSONAL INFORMATION AND WEBSITE USAGE INFORMATION?

MAKE UP FOR EVER does not sell or rent personal information to third parties for the purpose of allowing those parties to directly market to you, but we may share information with third parties as noted below.

  • SERVICE PROVIDERS

We may use third-party partners to help operate our Website and to respond to your inquiries, such as Website or database hosting companies, address list hosting companies, e-mail service providers, analytics companies, distribution companies, fulfillment companies, and other similar service providers that use such information on our behalf.

  • AGGREGATE STATISTICS

We may disclose aggregate statistics regarding user behavior as a measure of interest in, and use of, our Website and e-mails to third parties like advertising and marketing partners in the form of aggregate data, such as overall patterns or demographic reports that do not describe or identify any individual user.

  • LEGALLY COMPELLED DISCLOSURES

We may disclose user information to government authorities, and to other third parties when compelled to do so by government authorities or otherwise as required or permitted by law, including but not limited to in response to court orders and subpoenas. We also may disclose user information when we have reason to believe that someone is causing injury to or interference with our rights or property, other users of the Website, or anyone else that could be harmed by such activities. Additionally, we cooperate with law enforcement inquiries and other third parties to enforce laws, intellectual property rights and other rights.

  • BUSINESS TRANSFER OR TRANSITION

In the event that we are acquired by one or more other parties as a result of an acquisition, merger, sale, reorganization, consolidation or liquidation, or if we sell or otherwise transfer our assets or operations, Personal Information may be one of the transferred assets. We may also disclose Personal Information to prospective purchasers to evaluate a proposed transaction with us. Our successors and assigns may collect and use your information for substantially similar purposes as described in this Privacy Policy.

  • SOCIAL NETWORKS, WIDGETS AND PLUG-INS

If you use any features made available to you on our Website by a third party it may result in information being collected or shared between us and the third party. For example, if you use Facebook’s “Like” feature Facebook may register the fact that you “liked” a product and may post that information on Facebook. As another example, if you are posting images to Instagram using hashtags that directly correlate with our campaigns, that gives us permission to dynamically pull this content into our Website. Note that information you post to third party sites is governed by the policies of such third party websites.

  • PUBLIC AND INTERACTIVE AREAS

We may from time to time provide interactive services on our Website, including, without limitation, blogs, chat rooms, bulletin boards and discussion groups. Personal Information that you post on or through the public areas of any Website is generally accessible to, and may be collected and used by, others and may result in unsolicited messages or other contact from others. You should not provide Personal Information about yourself in public or interactive areas of the Website. If posted, such Personal Information is not covered under this Privacy Policy.

HOW DO WE PROTECT YOUR INFORMATION?

While MAKE UP FOR EVER will take reasonable measures to protect the security, confidentiality, integrity, and access of your Personal Information, due to the inherent nature of the Internet as an open global communications vehicle, we cannot guarantee that information, during transmission through the Internet or while stored on our system or otherwise in our care, will be absolutely safe from intrusion by others, such as hackers.

We do maintain physical, electronic and procedural safeguards to protect your personal information. We use industry-standard Secure Sockets Layer ("SSL") authentication for online transactions made on our site. SSL authentication and encryption of the information that you send to us over the Internet helps protect your online transaction information from third party interception.

Unfortunately, despite our efforts, there is always a risk that third parties may unlawfully intercept transmissions. This reality is true of all Internet use. As a result, we cannot ensure the security of any information you transmit, and you transmit all information at your own risk. We will not be liable for disclosure of your information due to errors or unauthorized acts of third parties during or after transmission.

If you contact us by e-mail or through a "contact us" link or similar feature on our Website, you should be aware that your transmission might not be secure. A third party could view information you send by these methods in transit.

If you choose to set up an account, you are responsible for maintaining the strict confidentiality of your account password, and you shall be responsible for any access to or use of the Website by you or any person or entity using your password, whether or not such access or use has been authorized by or on behalf of you, and whether or not such person or entity is your employee or agent. You agree to (a) immediately notify MAKE UP FOR EVER of any unauthorized use of your password or account or any other breach of security, and (b) ensure that you exit from your account at the end of each session (especially if you are using a public computer or a shared computer). It is your responsibility to control the dissemination and use of your password, control access to and use of your account, and notify MAKE UP FOR EVER when you desire to cancel your account. We are not responsible or liable for any loss or damage arising from your failure to comply with this provision.

In the unlikely event that we believe that the security of your Personal Information in our possession or control may have been compromised, we may seek to notify you of that development. If a notification is appropriate, we would endeavor to do so as promptly as possible under the circumstances, and, to the extent we have your e-mail address, we may notify you by e-mail. You consent to our use of e-mail as a means of such notification.

HOW DO WE ENSURE YOUR PERSONAL INFORMATION IS ACCURATE?

We use reasonable efforts to ensure that your Personal Information is kept as accurate, complete, and up to date as possible. We do not routinely update your Personal Information, unless such an update is necessary. In order to help us maintain and ensure that your Personal Information is accurate and up to date, you must inform us, without delay, of any change in the information you provide to us.

WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL INFORMATION?

Depending upon the province in which you reside, you may have some or all of the following rights with respect to our Processing of your Personal Information:
- Access: You have the right to request whether we hold Personal Information on you and to request a copy of such information. There are exceptions to this right, so that access may be denied if, for example, making the information available to you would reveal Personal Information about another person, or if we are legally prevented from disclosing such information.

- Accuracy: We aim to keep your Personal Information accurate, current, and complete. We encourage you to contact us at dpo@makeupforever.fr to let us know if any Personal Information is not accurate or changes, so that we can update your Personal Information.

- Cessation of Dissemination: You have the right to request that we cease disseminating your Personal Information if the dissemination is contrary to the law or a court order.
You also have the right to request that we cease disseminating your Personal Information where the following conditions are met:
- the dissemination of the information causes you serious injury in relation to your right to have your reputation or privacy respected;
- the injury is clearly greater than the public’s interest in knowing the information or the interest of any person’s right to express themselves freely; and
- the cessation of dissemination requested does not exceed what is necessary for preventing the perpetuation of the injury.

- De-indexation: You have the right to request that we de-index any hyperlink attached to your name that provides access to information by a technological means if the dissemination is contrary to the law or a court order.
You have the right to request that we de-index a link providing access to information where the following conditions are met:
- the dissemination of the information causes you serious injury in relation to your right to have your reputation or privacy respected;
- the injury is clearly greater than the public’s interest in knowing the information or the interest of any person’s right to express themselves freely; and
- the cessation of dissemination requested does not exceed what is necessary for preventing the perpetuation of the injury.

- Re-indexation: You have the right to request that we re-index a link providing access to information where the following conditions are met:
- a failure to do so causes you serious injury in relation to your right to have your reputation or privacy respected;
- the injury caused by a failure to re-index is greater than the public’s interest in knowing the information or the interest of any person’s right to express themselves freely; and
- the re-indexation requested does not exceed what is necessary for preventing the perpetuation of the injury.

- Mobility: You have the right to request that computerized Personal Information collected from you be communicated to you in a commonly used technological format as well as to any person or body authorized by law to collect such information. This right does not extend to information that was created or inferred from your Personal Information and we are under no obligation to communicate such information if doing so raises serious practical difficulties.

- Complaints: If you believe that your Personal Information protection rights may have been violated, you have the right to lodge a complaint with the applicable supervisory authority, or to seek a remedy thought the courts.

HOW TO EXERCISE YOUR RIGHTS

You may enquire about your Personal Information by contacting our Data Protection Officer (“DPO”) at dpo@makeupforever.fr.

We will generally respond to all access requests within 30 days of the receipt of all necessary information. In circumstances where we are not able to provide access, or if additional time is required to fulfill a request, we will advise you in writing.

We may not release certain types of information based upon exemptions specified in applicable laws. Where possible, we will sever the information that will not be disclosed and provide you with access to the remaining information. Should we be unable to provide access to or disclose Personal Information to you, we will provide you with an explanation, subject to restrictions.

In certain circumstances, such as where the request is excessive or unfounded, we may charge you an administration fee for access to your Personal Information. We may also charge for additional copies. We will advise you of any fees before proceeding with a request.

HOW TO WITHDRAW CONSENT

If you have provided your consent to the Processing of your Personal Information, you have the right to fully or partly withdraw your consent. To withdraw your consent please follow the opt-out links on any marketing message sent to you or contact the DPO at dpo@makeupforever.fr.

Once we have received notification that you have withdrawn your consent, we will no longer Process your information for the purpose(s) to which you originally consented unless there is another legal ground for the Processing. Withdrawal of consent to receive marketing communications will not affect the Processing of Personal Information for the provision of our services.

HOW TO OPT OUT FROM RECEIVING OUR PROMOTIONAL MATERIAL

If you would like to opt out of receiving promotional emails from us, our partners and/or affiliates, please follow the unsubscribe instructions located at the bottom of each email. If you would like to opt out of receiving direct mail or telephone marketing calls from us, please send your request, including your name, email, street address, city, province, and postal code, via email to contact@makeupforever.ca (please use the subject line: Privacy Opt-Out Request). You can also go online to your account page on the Site and change your email and marketing preferences at any time.

We are not responsible for notices that are not labeled or sent improperly, or do not have complete information. We will process your request within 10 business days of the date we receive your request, but you may, in the meantime, receive previously scheduled emails, mail or calls from us. We will not be responsible for any communications that you may receive from entities that received your Personal Information prior to such date following your request. In these cases, please contact that entity directly. Once you have opted out, you do not need to do so again. Please note that MAKE UP FOR EVER may still use your Personal Information (and may share your information with our service providers) to provide you with services, including sending you administrative and account-related emails.

HOW WILL YOUR CONCERNS BE RESOLVED?

Any report, concern, complaint or incident of which we become aware that involves conduct that may contravene the Privacy Policy will be treated confidentially to the extent possible. However, some disclosure may be necessary to adequately address issues raised, aid enquiry and implement solutions, as appropriate.

We take all potential or actual Personal Information breaches seriously.

You may report your concerns about the Processing of your Personal Information directly to our DPO.

The DPO will engage the appropriate levels of management to assist with resolution of the issue.

While we are committed to resolving all Personal Information matters internally, nothing in this Privacy Policy precludes you from contacting the appropriate federal or provincial privacy commissioner.

We will not retaliate against a Person who, in good faith and on the basis of reasonable belief, raises questions or concerns regarding their Personal Information.

WHO IS RESPONSIBLE FOR ENFORCING THIS PRIVACY POLICY?

MAKE UP FOR EVER is accountable for the Personal Information we Process. We are responsible for communicating this Privacy Policy and ensuring that employees fully comply with all relevant aspects of the Privacy Policy and the accompanying guidelines.

Our business or infrastructure units that Process Personal Information other than as required, are responsible for ensuring that these activities comply with the Privacy Policy.

The DPO is responsible for:
(a) developing our Personal Information protection strategy;
(b) developing and maintaining the Privacy Policy, accompanying guidelines and any other policy or procedure related to Personal Information and ensuring they comply with applicable law; and
(c) serving as the official liaison with the federal and provincial commissioners.

WILL THIS PRIVACY POLICY CHANGE?

MAKE UP FOR EVER reserves the right to change or update this Privacy Policy, or any other of our policies or practices, at any time, and will notify users of this Website by posting such changed or updated Privacy Policy on this page. Any changes or updates will be effective immediately upon posting to this Website. Under certain circumstances, we may also elect to notify you of changes or updates to our Privacy Policy by other means, such as posting a notice on the front page of our Website or by sending you an e-mail. We also will note the effective date of the latest version at the end of this Privacy Policy. You should review our Privacy Policy periodically so that you keep up-to-date on our most current practices.

HOW CAN YOU COMMUNICATE WITH US?

If you have any questions or comments regarding: (a) our privacy or security practices; (b) the data we maintain about you; (c) this Policy; or (d) how to review, edit or delete the information we maintain about you, you may contact us at dpo@makeupforever.fr.