Privacy Policy
This Policy tells you how you can access and update your personal data and make certain choices about how your personal data are used including a right to object to some of the processing (including personalised marketing) we carry out or where we rely on your consent, a right to withdraw this consent. More information about your preferences and rights is set out in Section 7 below.
This Policy covers our data collection activities, including personal data we collect through our various channels online (such as websites, apps, and social networks) and offline (such as at points of sale, customer service and events). It also explains how we collect information through the use of cookies and related technologies on our websites and apps. Certain sections may not be applicable to you depending on how you provide your personal data to us or interact with Luna MicroCare. Please note that we combine personal data that we collect via one channel (e.g. Luna MicroCare website) with personal data we collect via another channel (e.g. a Luna MicroCare point of sale or event-in-store) which can include combining personal data that were originally collected by different Luna MicroCare companies in different countries in order to provide you a personalised service adapted to your preferences and interests. More information about these activities is set out below.
If we change the way we handle your personal data, we will update this Policy and notify you or seek your consent as and when appropriate, usually by placing an updated Policy on our websites. If we make significant changes that materially alter our privacy practices, we may also notify you by other means, such as sending an email prior to the changes taking effect. We reserve the right to make changes to our practices and this Policy at any time. We invite you to check our websites from time to time for any updates or changes to this Policy.
We may also provide you with additional information when we collect personal data where we feel it would be helpful to provide relevant and timely information.
We obtain personal data from or about you from various online and offline sources, including when you:
(i) interact with our websites listed on lunamicrocare.com, mobile sites, applications or social media pages (together "the Digital Platforms"); (ii) create a Luna MicroCare account on our Digital Platforms or in "Points of Sale"; (iii) interact with us on our chat services, forums or blogs; (iv) visit one of our Points of Sale; (v) participate in our events and demonstrations, loyalty or other client programs, competitions, promotions or surveys; (vi) subscribe to our marketing communications; (vii) make physical, or distance purchases in our Digital Platforms or Points of Sale; (viii) subscribe to our marketing communications; (ix) participate in beauty consultations or treatments; or (x) interact with our beauty advisors and customer service.
Our products are sold through various authorised business partners. Unless otherwise indicated at the time that you provide your personal data, this Policy does not apply to any personal data that our authorised business partners independently collect from you.
We collect and process the following personal data:
The list below is provided to give you an overview of the type of personal data we may collect and process. However, the collection and processing of these data are not systematic: only personal data necessary to fulfil each purpose will be collected and used.
Personal data provided by you (for example, by creating a Luna MicroCare account, signing up to our loyalty or other client programmes, or by providing data about yourself to us in our Digital Platforms or Points of Sale):
- Contact information (such as your name, phone number (home and mobile), home address and email address);
- Identification information (such as your age, date of birth, gender, nationality, country of residence, image, and signature);
- Purchase history and interactions with us (such as order details, products bought and quantity, consultations, treatments, and visits to our Digital Platforms or Points of Sale);
- Social media account;
- Billing information (including delivery address and payment details). We reserve the right to request additional evidence or proof of billing information where, in our reasonable opinion, this is necessary. Please note we do not keep your payment card details on file. We use a third-party data controller to process payment details;
- Website registration credentials (including username and password). By creating a Luna MicroCare account, you can store and edit your delivery addresses and billing information and review your previous purchases and order history;
- Preferences (such as communication channels, preferred language, product preferences, and skincare wishes);
- Personal life information and inferences (such as life habits, interests, lifestyle, hobbies, and reactions to marketing campaigns);
- Skin type and health information in case you participate in our beauty consultations or treatments (such as allergies, medication, previous reactions) or you provide this information to our customer service;
- Information about your physical characteristics, skincare concerns and any other information obtained through the different interactions with us (such as a beauty consultation or treatments, a survey or when you visit our social media pages, blogs or forums or interact with customer service or our chat service);
- Correspondence and communication between you and us; and,
- Information or content you provide to us (such as photographs, videos, reviews, questions, survey response and comments).
We do not knowingly collect and process information about minors, nor do we knowingly sell or share personal data about individuals who are under the age of 16.
Information is automatically collected and processed from us or from your use of our Digital Platforms, your visits to our Points of Sale or your interaction with our online adverts.
We automatically collect and process the following information:
- technical information, including your device’s IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system, unique device identifiers and advertising identifiers;
- information about your visit to our Digital Platforms, including the URL clickstream to, through and from our Digital Platforms (including date and time); products you viewed or searched for; the content (and any ads) that you view or interact with, page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), and methods used to browse away from the page.
- online activity, such as your internet and other electronic network activity information, including, but not limited to, browsing history, search history, and information regarding your interaction with our websites or third-parties websites such as social media, applications or advertisements and other technical information or personal information shared by the service provider you are using;
- social media data – the use of our Digital Platforms does not generally involve processing data in relation to third party media platforms and/or social networks, such as Facebook or Instagram. However, if you accept the targeting cookies or if you use the share button to share our content through those platforms, those third parties may collect and process your data in order to provide you with personalised advertising. To find out more about how those third parties process your data and your data protection rights, please check their respective privacy policies;
- CCTV security camera data (such as your image) when you visit one of our Points of Sale that has a CCTV camera used to view and record individuals 24 hours per day, 7 days per week for security reasons. When a CCTV camera is in use at our boutiques, we will make sure that signs are displayed at the entrance of the surveillance zone to inform employees, clients and contractors. Other activities might be conducted at our boutiques, such as measurement and analysis of client’s movements and demographics in an aggregated and anonymous way. If they involve the processing of your personal data, additional and specific notice will be available at our boutiques and your consent will be requested if required by applicable laws;
- Information necessary to fight counterfeiting and infringements of Luna MicroCare’s intellectual property rights, such as identification and contact details and any other information and documents related to counterfeit and infringing activities. This information may be collected directly by Luna MicroCare or one of its vendors on its behalf and provided to Luna MicroCare by external parties;
- Information necessary to manage Luna MicroCare’s selective distribution system in order to protect Luna MicroCare brand and identify unauthorised resellers. This will include profiling activities on client’s purchase behaviours (such as products bought, quantities, frequency and other transaction details) based on objective criteria but it does not imply automated decision making.
Some of this information is collected using cookies and related technologies. To learn more, please see Section 6 on "Cookies and related technologies".
Information collected and processed from third party sources
- From time to time (where permitted by applicable law), we collect information such as your preferences, interests and other demographic data from trusted third party sources (e.g. business and retail partners, payment and delivery services, social media networks, advertising networks, analytics providers, market research organisations, our affiliates, event partners, public authorities and search information providers) for example, when you have given consent to such third party to share your information with us. We may also instruct such third-party partners to provide their own information about you to external platforms. This information will be used for the purposes outlined in this Policy and in particular, to enrich your Luna MicroCare profile. The privacy and cookie policies of those third parties will apply to their processing of your personal data.
- Location information when you visit our Digital Platforms in order to direct you to the appropriate domain (internet location) or when you request location services provided by us, for example in order to find the nearest sale point to you or to provide more precise location based content.
- When you pay for your products, we may get information from our payment processing service provider who will carry out credit and antifraud checks on you and the payment method you provide in order to verify your identity, to validate your credit or debit card, to obtain an initial credit or debit card authorization and/or to authorize individual purchases.
Profiling
In order to ensure data accuracy and to offer you a better and personalised client experience no matter where and how you interact with us, we link or combine the information that we collect from the different sources and channels outlined above to provide personalised services, content, targeted communications and advertising and for analytics purposes (e.g. we combine data about your purchases in our Digital Platforms with information gathered at our Points of Sales such as details from a beauty consultation so that we can provide you with personalised service, offers and skincare recommendations). This includes combining personal data also collected by different Luna MicroCare companies. All the information that Luna MicroCare processes about you (including information provided by you or collected by us or by third parties) will be linked to your Luna MicroCare profile. We also may draw inferences from any of your information and interactions with us to enrich and supplement such profile, reflecting your preferences, characteristics, trends, predispositions, aptitudes and attitudes. We will use your identification data such as email address or phone number to link the information to your profile. The above may also apply when checking out as a guest on our Digital Platforms and if you are a prospective client.
You do not have to provide personal data to us to purchase our products in the Points of Sale or access our Digital Platforms but certain functionalities and services (such as being able to buy our products via the website) will not otherwise be available to you. You may however choose whether or not to receive personalised marketing communications from us and we will only send you such communications where we have the appropriate consent to do so. For more information on your rights and preferences regarding how we use your personal data, please Section 7 below.
You must not provide to us information about anyone else unless you have their permission to do so.
We process your personal data for the reasons set out below:
Purpose |
Legal basis |
To provide you with the products and services you have purchased or requested in our Digital Platforms or Points of Sale. This includes for example the processing of your payment, credit card checks and fraud prevention activities, delivery and return management. |
|
To send you service-related communications. This includes communications related to your purchases, your beauty consultations, appointments or events you have registered to. |
|
To set up and manage your Luna MicroCare profile and provide you with personalised services. All personal data we process about you will be linked and combined to create a profile about you and provide you with personalised services adapted to your interests and preferences. More details can be found in Section 2under "Profiling". |
|
To communicate with you for marketing-related purposes if agreed by you. This includes communications about our products, services, promotions and events by telephone, post, SMS, e-mail, social media, chat or via our applications or to send you samples, gifts and rewards in accordance with your communications preferences and to the extent permitted by applicable laws. These communications can be conducted by our beauty advisors or by any of our group companies (please see Section 7 below about how you can control your preferences and opt-out from these communications); |
|
To enrich your Luna MicroCare profile. This includes supplementing your Luna MicroCare profile with information related to your activities on social media and your browsing activity across different websites and devices through the use of cookies and similar technologies by us or third parties (such as social media - WeChat, WhatsApp, Baidu, Kakao Talk, Twitter, Facebook, Instagram or other online platforms). The privacy and cookie policies of these third parties will apply to their use of your personal data. |
|
To allow you to participate in the interactive features of the website and to place cookies and related technologies in accordance with Section 6 below. |
|
To ask your opinion or to take part in market research or client studies. |
|
To provide you with personalized advertising both on our Digital Platforms and other selected partner websites. |
|
To create lookalike campaigns that enable us to reach people who are likely to be interested in our products because they are similar to you. We may use cookies or other technologies that may rely on third parties (such as Facebook, Instagram, WeChat and other online platforms). You may have provided your consent to those third parties and their respective privacy policies would apply. |
|
To monitor your account to prevent, investigate and/or report fraud, terrorism, misrepresentation, security incidents or crime in accordance with applicable law. |
|
To investigate any complaints or answer any inquiry received from you or from others about our Digital Platforms, Points of Sale or our products and services. |
|
To monitor the use of our Digital Platforms and Points of Sale and use your information to help us monitor, improve and protect our products, brand, content, services and Digital Platforms and Points of Sale, both online and offline and your experiences with us including via research and demographic studies; analytics and data cleansing and measuring the effectiveness of our advertising campaigns. |
|
To use personal data in connection with legal claims, compliance, regulatory and investigative purposes as necessary (including disclosure of such personal data in connection with legal process or litigation) or to enforce or apply our Terms of Use or any other agreements, our selective distribution system or to protect the rights, property, or safety of Luna MicroCare, our customers, or others. |
|
For our internal corporate reporting purposes. |
|
In response to requests by government or law enforcement authorities conducting an investigation. |
|
In addition to the Luna MicroCare companies mentioned in the Data Controllers & Contact section below, we may share your personal data: (where permitted in accordance with applicable privacy laws) with the following third parties for the purposes outlined above:
- companies in our group. A full list of our group companies can be found www.Imperial Bioscience.co.uk
- banks and our payment services provider for the purpose of transaction processing;
- third parties, where we have your permission to do so (e.g. social networks providers, concierge service or our authorised retail partners). Your personal data will become subject to the privacy policies of those third parties when your personal data is shared with them;
- prospective or eventual buyers of our business (if we or substantially all of our assets are acquired by or merged with a third party including through bankruptcy);
- any law enforcement agency, court, regulatory, government authority or other third party where in our reasonable opinion this is necessary to comply with a legal or regulatory obligations or otherwise to enforce or apply our Terms of Use or any other agreements and our selective distribution system; or to protect the rights, brand, property, or safety of Luna MicroCare, our customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction; or
- our third-party service providers (as well as group companies and authorised retail partners) who perform services on our behalf based on our instructions. We do not authorize these parties to use or disclose the information except as necessary to perform services on our behalf or to comply with legal requirements. Examples of these parties include employees of our authorised retailers partners that serve you in the sale points, IT support service providers, companies that fulfil orders and manage refunds, and provide data hosting and support, content personalization, advertising and marketing services (including digital and personalized advertising) and data cleansing, management, segmentation and analysis.
Please note that the third parties listed above may be located in a country outside of your country of residence, including outside the European Economic Area or United Kingdom . When these third parties process your data on our behalf, we implement appropriate contractual arrangements with them that include strong data protection obligations. More details about international data transfers can be found below under "Data Transfers."
We also share information with third parties including social media and search engine partners:
We aggregate your personal data with the information of other customers, creating a dataset of information about the usage of our platforms, purchase of our products, and other general, grouped information about our customers. Although this dataset is aggregated and anonymised, meaning it cannot directly identify you as an individual, it provides a valuable insight into the use of our Digital Platforms and Points of Sale and we will share it with select third parties. These parties include our group companies.
We also transfer information about you to ad technology providers and our social media and search engine partners (including Meta, Google and Twitter) so that they may recognize your devices and deliver interest based content and advertisements. The information can include your name, postal address, email, device ID, or other identifier in encrypted form. The providers often process the information in hashed or de-identified form. These providers can collect additional information from you, such as your IP address and information about your browser or operating system; combine information about you with information from other companies in data sharing cooperatives in which we participate; and may place or recognize their own unique cookie on your browser. The third parties that generate these cookies have their own privacy policies that will apply.
In this regard, we have concluded a corresponding agreement with Meta for joint controllership, which can be accessed here: https://www.facebook.com/legal/controller_addendum. This agreement defines the respective responsibilities for fulfilling the obligation under the applicable laws with regard to joint controllership. The contact details of the controller and the data protection officer of Meta can be found here: https://www.facebook.com/about/privacy. Without prejudice to this, the jurisdiction of the Rights of Data Subjects is not limited. We have agreed with Meta that Meta can be used as a contact point for the exercise of data subject rights (see Section 7).
Further information on how Meta processes personal data, including its legal basis and further information on the rights of data subjects can be found here: https://www.facebook.com/about/privacy. We transfer the data within the scope of joint controllership based on the legitimate interest.
Information on the data security conditions can be found here. https://www.facebook.com/legal/terms/data_security_terms and on processing on the basis of standard contractual clauses can be found here:
Data Transfers
Your personal data is stored mainly on servers in the United Kingdom. However, we operate globally and may transfer your personal information to other companies within the Luna MicroCare group, third party service providers or to authorised retail partners in locations around the world, including countries that do not provide an adequate level of data protection. We want you to have the best service and client experience no matter how and where you interact with us, whether in our Digital Platforms or our Points of Sale all over the world. For this purpose, we may have to share your personal information outside the country where you have first shared it with us, always for the purposes described in this Policy and where we are satisfied with the levels of protection and security implemented by the third party in compliance with applicable laws. This sharing of your personal information is necessary to enable us to offer you a global and personalised client experience and services.
Where your personal data is transferred to countries outside the European Union or United Kingdom and to countries that do not offer an adequate level of data protection in accordance with the European Commission and British authorities, we will take steps to ensure your information is adequately protected by entering into the EU Commission and British approved standard contractual clauses pursuant to Art. 46 (2) of the GDPR or put in place other measures under applicable laws to ensure that such transfer provides adequate safeguards. More information about this topic is published here: https://commission.europa.eu/law/law-topic/data-protection/international-dimension-data-protection_en
A copy of the relevant mechanism can be obtained for your review on request by using the contact details provided in Section 8.
Your personal data will be retained for a certain period of time based on the following criteria: (i) as long as necessary to fulfil the purposes outlined in this Policy; (ii) any applicable legal requirements; or (iii) any request for deletion from you in applicable situations.
- In relation to our clients, your data is stored for the duration of the contractual relationship and for 7 years afterwards.
- In relation to our prospects: your data is stored for 3 years from your last interaction with us.
Please note that we may be required by law (e.g. tax, accounting or legal obligations) to store certain data for a longer period of time. For more information, please contact us using the details in Section 8.
What are cookies?
Cookies are small text files that websites send to your computer, mobile device or other Internet-connected device to uniquely identify your browser or to store information or settings in your browser.
We use and allow third party service providers to use cookies, web beacons and other similar technologies on our platforms, social media pages and communications. We do this to understand your use of our services, improve your user experience and enable personalized features and content; optimize our advertising and marketing and to enable third party advertising companies to assist us in serving ads specific to your interests across the Internet. View a full list of cookies and update your preferences in the Cookie Settings.
The cookies that we use can be categorised as follows:
- Strictly necessary cookies
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the website will not then work. These cookies do not store any personally identifiable information.
- Analytical / Performance cookies
These cookies allow us to count visits and traffic sources, so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. Whenever technically possible, all information these cookies collect is aggregated and therefore anonymous.
[If you do not allow these cookies, we will not know when you have visited our site. Upon your consent, we use Google Analytics, run by Google Inc for this purpose. To opt out of being tracked by Google Analytics, you can visit the Cookie Settings or visit https://tools.google.com/dlpage/gaoptout.
- Functional cookies
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third-party providers whose services we have added to our pages. If you do not allow these cookies, some or all of these services may not function properly.
- Targeting/advertising cookies
These cookies may be set through our website by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly identifying personal information but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
Web server logs and web beacons
In conjunction with obtaining information through cookies, our web servers may log details such as your operating system type, browser type, domain, and other system settings, as well as the language your system uses and the country and time zone in which your device is located. The web server logs also may record information such as the address of the web page that linked you to our website and the IP address of the device you use to connect to the Internet. This information helps us to troubleshoot errors, improve performance and maintain the security of our Digital Platforms. To control which web servers collect this information, we may place tags on our web pages called “web beacons”. These are computer instructions that link web pages to particular web servers and their cookies. We may also use cookies and similar technologies (such as web beacons) to allow us to tell if an email we have sent to you has been opened and acted upon and whether our mailing tools are working correctly or, to measure performance and to provide content and ads that are more relevant to you.
Can I opt out of cookies and similar technologies?
You have the option to accept or reject our cookies at any time in the Cookie Settings.
By rejecting or disabling cookies, certain website content or functionality may not be available to you.
Because web beacons are the same as any other content request included in the recipe for a web page, you cannot opt out or refuse them. However, you may be able to disable web beacons in email messages by not downloading images contained in messages you receive (this feature varies depending on the email software used on your personal computer). However, doing this may not always disable a web beacon or other similar technologies in the email message due to specific email software capabilities. For more information about this, please refer to the information provided by your email software or service provider. Web beacons may also be rendered ineffective in some circumstances by opting out of cookies or amending your cookie settings in your browser.
We are committed to protecting the personal data we collect and keeping your personal data secure is very important to us. We take steps to ensure that your personal data is protected against unauthorized or unlawful processing and against accidental loss, damage or destruction or disclosure and we limit access to your personal data to persons who reasonably need access to it, to provide products or services to you. However, no set of security measures is completely effective against all security threats.
Our Digital platforms may contain links to and from third party websites. If you follow a link to any of these websites, please note that these websites have their own privacy policies and that we do not accept any responsibility or liability for these policies or how those third parties may use your personal data. Please check these policies before you submit any personal data to those websites.
If you create an online account with us, you will be asked to provide an account username and password as part of our security procedures. You must treat such information as confidential and you must not disclose it to any third party.
Your rights
In accordance with applicable law, you may have the following rights:
- Right of access and information: you have the right to be informed in a concise, transparent, intelligible and easily accessible form of the personal data we process about you and how we process it. You also have the right to obtain a confirmation from us on whether or not we process your personal data and if that is the case, access to such personal data and obtain a copy.
- Right to rectification: you have the right to rectify your personal data and to have it complete in case it is incomplete or inaccurate.
- Right to erasure: you have the right to ask us to delete your personal data. We will delete or anonymize your personal information, unless otherwise required by applicable data protection laws or if Luna MicroCare has a legitimate interest to keep it.
- Right to restriction of processing: in some cases, you have the right to obtain restriction of the processing of your personal data.
- Right to data portability: you have the right to receive your personal data, which you have provided to us, in a structured, commonly used and machine-readable format, and you have the right to transmit such personal data to another controller.
- Right to withdraw your consent: if you have given your consent to a data processing activity, you can withdraw this consent at any time as indicated under "Your preferences." Please note that the withdrawal of consent does not affect the lawfulness of processing based on consent before its withdrawal.
These rights may be limited in some situations – for example, where we can demonstrate that we have a legal requirement or contractual obligation to process your personal data. In some instances, this may mean that we are able to retain your personal data even if you withdraw your consent. In such a case, we will apply appropriate measures and safeguards to protect your personal data.
Right to object
You have the right to object to the processing of your personal data when such processing is based on legitimate interests. Nevertheless, we may have legitimate reasons to continue processing your personal data.
If you wish to exercise any of these rights, please contact us by using the details in Section 8.
Your preferences
We strive to provide you with choices regarding the personal data that you provide to us. The following mechanisms give you control over your personal data:
Advertising, marketing and personalization (offline and online): If you wish to be notified about our products and services, events, loyalty and other client programmes as well as other promotional activities, you can indicate your communication preferences through the relevant checkbox(es) on our Digital Platforms and Points of Sale or by answering the question(s) presented by our beauty advisors or sale representatives. Some of our activities and communications may be personalised to your specific interests and preferences (which will be done with your permission, if required by law).
If you wish to stop receiving our marketing communications (and/or you wish opt out of only some type of personalised marketing communications), simply let us know at any time by following the opt-out instructions in the relevant communication or using the details in Section 8. Please note that we send different types of personalised marketing communications (e.g. newsletters, beauty advisors’ emails, surveys, etc.) and you can decide to opt out of all of them or only some of them. Opting out of personalised marketing communications will not stop you from receiving service messages (i.e. non-marketing communications, such as e-mail updates on your order status or notifications about your account activities) from us.
Please note you may be asked about your preferred channel/s to receive our communications and you can change or update this at any time by contacting one of our beauty advisors or using the contact details in Section 8.
If you have a Luna MicroCare account on our Digital Platforms, you can withdraw your consent and/or update your communication preferences under your account profile while logged in.
Cookies/Similar Technologies and Interest Based Advertising: You can set your cookie preferences at any time in the Cookie Settings.
If you have any questions about this Policy or privacy matters generally or to make a complaint about our compliance with applicable privacy laws, please contact us using the Contact us page of our website and our customer services team will be happy to assist you.
You can also use this Contact us if you wish to exercise your preferences and rights as detailed above.
We will acknowledge and investigate any complaint you make (including a complaint that we have breached your rights under applicable privacy laws). We hope that we can satisfy queries.
However, you have the right to lodge a complaint with the relevant data protection authority, in particular in the Member State of your habitual residence or place of the alleged infringement.
DATA CONTROLLER RESPONSIBLE FOR ALL ACTIVITIES (BOTH ONLINE AND OFFLINE)
IMPERIAL BIOSCIENCE LTD
Building 3, Chiswick Business Park
566 Chiswick High Road W4 5YA.
London, United Kingdom
Phone number: +44 020 8899 7478
Contact Us form: Contact us
If indicated at the time you make a Luna MicroCare purchase in our Points of Sale or you provide your details to one of our in-store advisors or representatives, the Luna MicroCare group companies will also act as local data controllers. Please find here the list of companies and contact details: https://lunamicrocare.com