Our Privacy Policy Statement
Including for California Residents
This U.S. state privacy notice (“U.S. State Notice”) supplements the information contained in our privacy policy statement above and applies to visitors, users, and others who are residents of certain states with generally applicable privacy laws (“consumers” or “you”), namely, California, Colorado, Connecticut, Utah, and Virginia. Consumers in these states have certain privacy rights as specified under state law, and this U.S. State Notice describes state-specific requirements. Any terms defined in the applicable state privacy laws that we use here have the same meaning when used in this U.S. State Notice. When we use the term "personal data,” in this U.S. State Notice we are also including “personal information” as that term is defined under applicable state privacy laws. Information We Collect As more fully described above under the Personal Data Processed section above, we collect (and have collected within the last twelve (12) months) the following categories of personal data: Identifiers, including name, alias, email, phone number, physical/shipping address, unique personal identifier, online identifier (including social network usernames), IP address, or other similar identifiers. Customer records, including contact information, customer numbers, purchase order numbers, and purchase history. Commercial information, including records of products purchased, obtained, or considered. Internet or other electronic network activity, including browsing history, clickstream data, search history, and information regarding interactions with our website, interactions with our advertisements or emails, and other usage data related to your use of our website, or any services offered through the website. Geolocation data, including general location information about a particular individual or device. Audio, electronic, visual, or similar information, including information collected via call recordings if you call our customer service department or if you otherwise call us on a recorded line. Inferences, including inferences drawn from any of the information described in this section about a consumer (e.g., reflecting the consumer’s preferences, characteristics, and behaviors). Protected classification characteristics under state or federal law, including your gender, age, and date of birth. Sensitive Personal Data, including precise geolocation information. For purposes of this U.S. State Notice, personal data may not include: Publicly available information lawfully made available from government records, or information that we have a reasonable basis to believe was made publicly available by you and not restricted to a specific audience.
Information otherwise excluded from the scope of various state privacy laws. Disclosure of Personal data to Third Parties and Other Recipients The categories of personal data we may have disclosed for a business purpose in the preceding 12 months include: Identifiers; Customer records; Commercial information; Internet or other network activity information; Geolocation data; Audio, electronic, visual, or similar information; Inferences; Protected classifications; and Sensitive personal data.
The categories of third parties and other recipients to whom we may have disclosed personal data for a business purpose may include: affiliates and subsidiaries; business partners; service providers; data analytics and marketing providers; Internet service providers; and operating systems and platforms. Sources of Personal data We generally collect personal data from the following categories of sources:
Directly or indirectly from you; Affiliates and subsidiaries; Business partners; Internet service providers; Operating systems and platforms; and Vendors and service providers. Purposes of Collecting and Disclosing Personal data. As more fully described in the Purpose Of The Processing in the table above, in general we collect and process personal data for the following business or commercial purposes:
Providing, supporting, developing, and improving our website and products; Conducting analytics; Opening and managing user accounts; Communicating with you; Marketing and promotions; Research and surveys; Planning and managing events; Security, fraud detection, and protection of our and others rights; Compliance and legal process; Auditing, reporting, and other internal operations; and General business and operational support, including engaging in business sales or acquisitions. Sensitive Personal Data We do not collect, use, or disclose sensitive personal data beyond the purposes authorized by applicable state privacy laws. Retention of Personal Information We retain your personal information for as long as needed or permitted, based on the reason we obtained it (consistent with applicable law). When deciding how long to keep your personal information, we consider whether we are subject to any legal obligations (e.g., any laws that require us to keep records for a certain period before we can delete them) or whether we have taken any legal positions (e.g., issued any legal holds or otherwise need to preserve the information). Rather than delete your data, we may also deidentify it by removing identifying details. Where we have committed to maintaining and using personal information in a deidentified form, we agree not to reidentify deidentified data except as permitted by applicable law. Sales and Sharing of Personal Data; Use for Targeted Advertising Certain state laws, including the California Consumer Privacy Act, define "sale" as disclosing or making available personal data to a third-party in exchange for monetary or other valuable consideration, and “sharing” or “targeted advertising” as disclosing or making available personal data to a third-party for purposes of cross-contextual behavioral advertising. While we do not disclose personal data to third parties in exchange for monetary compensation, we may “sell” or “share” or use for targeted advertising the following categories of personal data: identifiers, and Internet or other electronic network activity information. We disclose these categories to third-party advertising networks, analytics providers, and social networks for purposes of marketing and advertising. We do not sell or share or use for targeted advertising personal data about individuals we know are under age 16. Your Privacy Rights and Choices Residents of California, Colorado, Connecticut, Utah, and Virginia may have the following rights regarding their personal data, subject to certain exceptions and qualifications under their respective state laws. Access and Data Portability. You may have the right to request details about the personal data we have collected about you, such as whether we have collected personal data about you, the categories of sources, the purposes for which we have collected the personal data, the categories of recipients, and the specific pieces of personal data we have collected. You may also have the right to receive a copy of your personal data in a readily usable format. Correction. You may have the right to request we correct incorrect or inaccurate personal data, subject to restrictions regarding the determination of accuracy of the existing personal data. Deletion. You may have the right to request deletion of your data unless an exception applies. Opt-Out of Sale, Sharing, or Targeted Advertising. You have the right to opt-out of “sales” and “sharing” of your personal data, and to opt-out of the use of your personal data for “targeted advertising” as those terms are defined under applicable state privacy laws. To exercise these rights, please use Cookie Management link at the bottom of our website. You also have the right to opt-out of “sales” and “sharing” of your personal data or use for targeted advertising by using an opt-out preference signal. If our site detects that your browser or device is transmitting an opt-out preference signal, such as the “global privacy control”—or GPC — signal, we will opt that browser or device out of the use of cookies or other tools on our site that result in a “sale” or “sharing” or use for targeted advertising of your personal data. If you come to our site from a different device or from a different browser on the same device, or if you clear your cookies, you will need to opt-out again, or use an opt-out preference signal, for that browser and/or device as well.] Limit Use and Disclosure. We do not engage in uses of sensitive personal data that would trigger a right to limit use and disclosure of sensitive personal data under applicable state privacy law. Opt-Out of Profiling with Legal or Significant Effects. You may have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. However, as stated above, we do not engage in such activities as described under applicable state privacy law, so there is no need to exercise this right. Non-Discrimination. We will not discriminate against you in terms of price or service level for exercising any of the rights described in this section. Exercising Your Privacy Rights To exercise your privacy rights, please submit a request to us by emailing us at privacy@kikocosmetics.com or completing our webform here. You may designate someone as an authorized agent to submit requests and act on your behalf. For security purposes, authorized agents will be required to provide proof of their authorization in their first communication with us, and we may also require that the relevant consumer directly verify their identity and the authority of the authorized agent. Unless otherwise permitted by applicable state privacy law, you may only make a request for access or data portability twice within a 12-month period. The request must: Provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal data or an authorized representative. Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it. We cannot respond to your request or provide you with personal data if we cannot verify your identity or authority to make the request and confirm the personal data relates to you. Therefore, we will need your first and last name, email address, and, if applicable, customer number. In some cases, we may request additional information to verify your identity, or where necessary to process your request. If we are unable to verify your identity after a good faith attempt, we may deny the request and, if so, will explain the basis for the denial. Right to Appeal If we deny or reject your privacy rights request, you may have a right to appeal our decision if permitted by your state’s privacy law. To appeal our denial or rejection, please contact us at privacy @kikocosmetics.com and include in the subject line “Request to Appeal Privacy Right Request Decision.” Please provide us sufficient information to locate your privacy right request record, such as any unique number you were provided. Our privacy office will review your appeal request, our original determination, and will inform you of our decision on your appeal. KIKO ME Loyalty Program - Notice Of Financial Incentive We provide special offers and exclusive benefits to consumers participating in our KIKO ME loyalty program, and as part of this program you may have the opportunity to provide personal data in exchange for a financial incentive or price or service difference. Summary: As part of our loyalty program we may provide consumers discount codes, price reductions, periodic promotional discounts, and other giveaways. These incentives involve the collection of the following categories of personal data: identifiers; customer records; commercial information. How to Opt-In: Consumers may join online or in store. KIKO ME members earn points when they purchase certain products or services. If you request that we delete any of your personal data that is essential to providing you with KIKO ME loyalty program, we will not be able to provide you with the benefits of that program. How to Withdraw: To unsubscribe from the KIKO ME loyalty program, you can contact Customer Service through the Help Centre contact form on the website or by writing to the email address. privacy@kikocosmetics.com. Each financial incentive or price or service difference related to our use of consumer personal data is based upon our good faith estimate of the value of such information, which takes into consideration, without limitation, estimates regarding (i) the ways in which we may use such information currently or in the future, (ii) the anticipated revenue to KIKO which might be generated from the use of such information as part of the KIKO ME program, (iii) the anticipated expenses which might be incurred by operating the KIKO ME Program, including expenses of providing discounted products, and (iv) anticipated future economic and market conditions and other relevant factors related to the estimated potential value of such information to our business. This value will vary for each consumer depending on purchases made, where those purchases are made (in store or online), which offers a member takes advantage of, and many other factors. Last update: December 12, 2023.