Privacy Policy

ARTICLE 1 – PERSONAL INFORMATION COLLECTED

This privacy policy applies to the processing of your personal data, carried out in particular via the website (hereinafter the "Site") accessible at the following address: https://www.madamedalexis.com/.

COSMO, as data controller, ensures that your personal data is processed in accordance with applicable regulations, including the amended French Data Protection Act of January 6, 1978, and European Regulation No. 2016/679/EU of April 26, 2016 (GDPR).
The purpose of this privacy policy is to inform you about the processing operations processing operations carried out on your personal data and your rights.

Ordering & navigating our website:

When you make a purchase or create a customer account on our site, as part of our buying and selling process, we collect the personal information you provide that is necessary to prepare and deliver your package, such as your name, address, email address, mailing address, and phone number.

This order data is sent to our logistics providers, who prepare and transport the package to your home. They are strictly prohibited from using your data for any purpose other than processing your order and must delete this data from their computer systems after processing. If you choose to have your order delivered outside Europe, your data, such as your postal address, will necessarily be transmitted to the logistics services of the carrier who will deliver to you in that country.

When you browse our website, we automatically receive your computer's Internet Protocol (IP) address, which allows us to obtain more details about the browser and operating system you are using. In addition, data may be stored in or retrieved from your browser, usually in the form of cookies. These collect information about you, your preferences, or your device and browser. They are usually set in response to actions you have taken that constitute a request for services.

Emails:

If you have decided to follow COSMO by email (via the form on our website or by checking the corresponding box during the purchase process), we will use your email address to send you news about Madame d'Alexis (new products, tips, and advice) by email to contact@madamedalexis.com hair beauty, etc.) or to send you information about your purchase history or browsing history on our website. Please note that if you no longer wish to receive these emails, you can unsubscribe at any time by clicking on the "Unsubscribe" link at the bottom of the emails or by contacting us by email at contact@madamedalexis.com . This will take effect immediately.

The emailing tool we use is French. Furthermore, as a "processor," this emailing tool is required to comply with the legal requirements of the General Data Protection Regulation (GDPR).

Audience measurement:

We use audience analysis tools (such as Google Analytics) to help us better understand activity on our site and how you interact with it, and to improve our site's performance so that it best meets your needs. To this end, we provide these tools with data about your browsing history on our site and information about the products you have ordered. All data processed for statistical purposes outside Europe is completely anonymized.

Product reviews:

Your email address, first and last name, and order reference number are sent to our partner, who will email you a review form. Your email address is not published on our website when your review is published. This data is not shared with any other company and is used solely for the purpose of evaluating your experience with our products.

Advertisement:

Advertising cookies are placed when you visit our site to display targeted advertising messages when you browse other sites. The data collected is anonymous and is only used for advertising purposes.

How long will my personal data be stored?

The length of time we retain personal data depends on our business needs and legal obligations.

When you purchase products, we store your data for as long as it is necessary for the purposes for which it was collected and for any other related purposes, such as monitoring our inventory, while complying with applicable data security and storage legislation.

If you agree to receive emails from CSOMO to follow our adventure, your data will be stored until you request to unsubscribe or delete your personal data, or after a certain period of inactivity (for a maximum of 3 years from the last contact).

If you create a customer account, your data will be stored until you send a request to delete it or after a period of inactivity on your part (for a maximum of 3 years from the end of the commercial relationship (e.g., last order) or the last contact (e.g., click on one of our emails).

When you contact us to obtain information about our products or our brand, or when you apply for a job, the data is only kept for three years from the date of collection or the last contact initiated by you.

ARTICLE 2 - IDENTITY AND CONTACT DETAILS OF THE DATA CONTROLLER 

Your personal information is collected and processed by COSMO, whose registered office is located at 46 – 66 avenue des Champs Elysées, PARIS (75008). You can contact us at contact@madamedalexis.com

ARTICLE 3 - COLLECTION OF PERSONAL DATA 

A. Categories of personal data

COSMO may process your personal data, including your identification data (last name, first name, email address, postal address, etc.), your connection data (IP addresses, logs, device identifiers, cookies, etc.), your customer profile data (consumption habits, hair information, opinions and comments, etc.), and your economic and financial data (bank details, purchase data, etc.). COSMO also processes data about the devices you use to access the Site, such as data from cookies, trackers, and browsing and audience measurement data. To learn more about the purposes for which we collect and use this data, please see our detailed Cookie Management Policy below.


B. Methods of collecting personal data

COSMO may collect your personal data in various ways,
including:

  • When you browse the Site;
  • When you create a customer account;
  • When you place an order and use our online payment applications 
  • When you subscribe to the newsletter;
  • When you use our services, particularly our after-sales service;
  • When you leave reviews and respond to our satisfaction surveys;
  • During your exchanges with Madame d'Alexis, of whatever nature, via the contact form on the Website, but also by email, post, telephone, or on social media; This personal data may be collected directly by a positive action on your part or automatically by our systems, through the placement of necessary and functional cookies on your device.


C. Mandatory information and necessity of personal data collection

COSMO will indicate when the provision of information is mandatory (in particular due to a legal, regulatory, or contractual obligation, or simply in order to process your request or respond to you). If you do not provide this "mandatory" information, COSMO may be unable to provide you with certain services or respond to the request or form in question. Fields on a form that are not marked as mandatory are left to your discretion. It is up to you to decide whether or not to fill them in.

ARTICLE 4 - PURPOSES AND LEGAL BASIS FOR THE PROCESSING OF YOUR PERSONAL DATA

COSMO processes your personal data only if the purposes pursued require it. Any data processing carried out by COSMO is based on a legal basis that justifies it.

 Purposes of processing


Relevant legal bases

Site management

Technical administration in conjunction with our service providers (Shopify), security management

Our legitimate interest in operating
operate and improve the Website
website

Administration of personal accounts created by
users, management of creations and deletion requests

Our legitimate interest in ensuring
the user a good
ordering experience and
proper management of their
personal data

Order processing, delivery and returns, receipt of
checks, issuing invoices, after-sales service,
contact for feedback and complaints

1. Our legitimate interest in
improve our products (for
contacting you for feedback)
2. Performance of the contract (for
other sub-purposes)

Receipt and processing of requests received via our
contact form, via the diagnostic form, by email
or by phone

1. Our legitimate interest in
process requests
made by our
users.
2. Consent (for the
diagnostic form)

Loyalty program management

Consent

Newsletter management
Subscriptions, mailings, and unsubscriptions

Consent

Sales prospecting
Advertising, promotion

1. Our legitimate interest in promoting
promote our business and
our products 2. Consent (in
other cases)

Management of cookie data
Operations necessary for the functioning of the Site, Audience measurement statistics
audience measurement, content personalization, provision
personalized advertising, sharing on social networks

1. Our legitimate interest in
operate and improve the
Website 2. Consent (for
other sub-purposes)

Financial analysis, management control, social security and tax returns
and tax returns

Compliance with a legal obligation

Management of requests to exercise rights



Compliance with a legal obligation


ARTICLE 5 - RETENTION PERIODS FOR PERSONAL DATA

From a general perspective, COSMO takes the following criteria into account when determining how long to retain your personal data: The time required to fulfill the purposes for which it was collected;

The existence of a legal or regulatory obligation to which COSMO is subject. Once these periods have expired, COSMO archives your personal data for the applicable limitation period.

More specifically, COSMO retains:

  • Your data relating to our business relationship with you for as long as we are bound by a contract (before archiving it).
  • Your data relating to your newsletter subscription for as long as you remain subscribed (before archiving).
  • Your data relating to commercial prospecting will be kept for the duration of our commercial relationship with you and then for three years from our last contact with you (before being archived).
  • Your account data until you delete it (before archiving it). However, if you have not used your account for 3 years, we will notify you and delete it if you do not respond within the following month or for a period of 3 years in the event of inactivity on your personal account.
  • Your data relating to a message you sent us while we were processing your request (before archiving it);
  • Your personal data from cookies is stored for 30 days.

ARTICLE 6 - RECIPIENTS OF PERSONAL DATA 

  • Access to your personal data is strictly limited. However, COSMO may be required to disclose your personal data to certain third parties:
  • To COSMO teams subject to a confidentiality obligation, responsible for the processing identified above in the performance of their duties;
  • To external service providers, such as IT service providers managing the Website (hubteam), the host (Shopify), the data collection form manager (Typeform), the cookie manager (Shopify), payment managers (Shopify, PayPal, Stripe, Apple Pay, Shop), delivery and returns manager (COSMO), and development agency (hubteam).
  • To other third parties if such disclosure is required by law, a regulatory provision, or a court order, or to respond to any complaints or protect the security of your personal data. If you click on a social media button on the Site, you are informed that we will share your social media information with that social media platform.
    or court order, or to respond to any complaints or protect the security of your personal data. If you click on a social media button on the Site, you are informed that we will transmit some of your personal data to that social media platform.
    We ensure that these various service providers offer sufficient guarantees to ensure the security of the processing and the confidentiality of your personal data. To this end, we have entered into the relevant subcontracting agreements with these service providers in order to define the rights and obligations incumbent on each party and thus ensure their compliance with personal data protection regulations.
  •  PayPal transactions.
    Please note that PayPal transactions are subject to PayPal's Privacy Policy, which you can view at the time of payment. 
    By using the solutions provided by PayPal to execute a transaction on the Site, you guarantee that you have read the corresponding Policies and accepted them without reservation.

ARTICLE 7 - TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION 


COSMO carries out some of this processing through service providers based outside the European Union, in particular our hosting provider Shopify, or due to the presence of social media sharing buttons on the Website and the placement of Google Analytics cookies on your device.
In the event of data transfers outside the European Union, COSMO undertakes to guarantee an adequate level of protection and to take all appropriate safeguards.

ARTICLE 8 - EXERCISE OF RIGHTS OVER PERSONAL DATA

In accordance with the amended French Data Protection Act of January 6, 1978, and European Regulation No. 2016/679/EU of April 26, 2016, you have the following rights regarding your personal data:

  • Right of access to know exactly what data is processed by COSMO.
  • Right to rectify in order to modify incorrect or outdated data.
  • Right to erasure if you want COSMO to stop processing all or part of your personal data.
  • Right to portability if you wish to retrieve your personal data or have it retrieved by a third party.
  • Right to restriction if you wish to have the processing of your personal data suspended.
  • Right to define guidelines on the fate of your personal data after your death. 
  • You have the right to object if you no longer want COSMO to process your personal data. In this case, you must provide "reasons relating to your particular situation."


However, with regard to the processing of data for commercial or advertising purposes, or for profiling, you may object at any time and without reason. You also have the right to withdraw any consent given to COSMO. Please note: Some of the above rights are subject to conditions and are not automatic or absolute. Depending on the right invoked and the circumstances, we may request information and/or supporting documents in order to investigate your request and, in any event, we will not necessarily be able to respond favorably to it.
If COSMO collects telephone data, you have the right, pursuant to Article L. 223-2 of the French Consumer Code, to register on the list of people who do not wish to receive telephone marketing calls (Bloctel).

You can exercise these rights by contacting COSMO using the contact details provided in the Preamble. Finally, you have the option of submitting a complaint to the CNIL online or by mail at the following address: 3 Place Fontenoy – TSA 80715 – 75334 Paris Cedex 07. For more information, please visit the following link: https://www.cnil.fr/fr/cnil-direct/question/adresser-une-reclamation-plainte-la-cnil-quelles-conditions-et-comment

ARTICLE 9 - CONSENT

When you provide us with your personal information to complete a transaction, verify your credit card, place an order, schedule a delivery, or return a purchase, we assume that you consent to our collecting your information and using it for that specific reason only.

If we ask you to provide us with your personal information for another reason, such as for marketing purposes, we will ask you directly for your explicit consent, or we will give you the option to decline.

If, after giving us your consent, you change your mind and no longer consent to us contacting you, collecting your information, or disclosing it, you can notify us by emailing us at contact@madamedalexis.com  or by mail at: COSMO Bureau 46 – 66 avenue des Champs Elysées, Paris (75008).

ARTICLE 10 – COOKIES

When you browse our website or place an order, data may be stored in or retrieved from your browser, usually in the form of cookies. A cookie is a small text file stored by the browser on your computer, tablet, or smartphone that allows user data to be stored in order to facilitate browsing and enable certain other features.

We use first-party cookies, placed by COSMO, to ensure the proper functioning of our website. Most of these cookies cannot be disabled in our systems. They enable us to store the information you enter in forms on our website so that you do not have to re-enter it when using the site, and also to manage and secure access to your account or shopping cart.

Here is a non-exhaustive list of cookies related to the functioning of our site:

- session_id: unique session identifier, allows Shopify to store information about your session (referrer, landing page, etc.).

- shopify_visit: no data retained, persists for 30 minutes since the last visit. Used by our website provider's internal statistics tracking system to record the number of visits.

- shopify_uniq: no data retained, expires at midnight (based on visitor location) the following day. Calculates the number of visits to a store by a unique customer.

- cart: unique identifier, persists for 2 weeks, stores information related to your shopping cart.

- secure_session_id: unique session identifier

- storefront_digest: unique identifier, undefined if the store has a password; it is used to determine whether the current visitor has access.

- More information here: https://fr.shopify.com/legal/cookies

We also use third-party cookies placed by our partners. These third-party cookies are managed directly by the companies that issue them, which must also comply with data protection regulations.

- Audience measurement cookies: to evaluate website traffic (number of visits, page views, shopping cart abandonment, etc.) and improve our performance.

- Advertising cookies: to provide you with advertising content related to your interest in the Respire brand, products, and adventure.

Opposing cookies:

You can configure your browser to notify you of the existence of these cookies or to block them. If you choose to block these cookies, certain features of our site may be affected (such as keeping items in your shopping cart). If you wish to delete cookies from your web browser, you can follow these instructions:

Chrome:
http://support.google.com/chrome/bin/answer.py?hl=fr&hlrm=en&answer=95647

Firefox:
https://support.mozilla.org/fr/kb/protection-renforcee-contre-pistage-firefox-ordinateur?redirectlocale=fr&redirectslug=Activer+et+d%C3%A9sactiver+les+cookies

Internet Explorer:
http://windows.microsoft.com/fr-FR/windows-vista/Block-or-allow-cookies

Safari:
https://support.apple.com/fr-fr/guide/safari/sfri11471/mac

Most of these cookies expire when you end your visit to our sites. Others have a longer lifespan, which does not exceed 12 months, in accordance with current regulations. However, certain trackers are exempt from obtaining this consent (this is the case for trackers that last longer than 12 months).

You can also block third-party cookies:

- More information here: https://www.cnil.fr/fr/cookies-les-outils-pour-les-maitriser

- If you no longer wish to see our advertisements on social media, we recommend that you go to the "settings" section and then "advertising preferences."

- There are also platforms for opting out of advertising cookies, such as http://optout.networkadvertising.org/ or http://www.youronlinechoices.com/ or via the blue AdChoices icon.

- More information about Google cookies: https://policies.google.com/privacy

COSMO uses the following cookies to operate the Website, optimize
your browsing experience, and get to know you in order to improve your experience:

 Category of
cookies

Cookie name

Purpose

Duration of
shelf life

Cookies
necessary/functional
functional


Manage cookies

6 months

Functionality cookies
and
third-party service cookies

Shopify

Enable the collection,
display, and management
customer reviews on the website.

13 months

Cookies
statistical /
measurement
audience

Google Ads
Google Analytics

They enable us to measure
the performance of our
advertising campaigns
.

13 months for
the cookie and 25
months for
data
collected via
the cookie

Cookies
technical
management
ballistic

Google Tag Manager

Load and manage other
tags or scripts used
for tracking and analysis
on the website.

Duration of the
session or
a few days
depending on
needs
requirements.

Cookie
advertising

Google ads

Track user interactions
with
Google Ads and
measure the effectiveness of
advertising campaigns.

Up to 13
months

Cookies from
social networks

Facebook Pixels

Instagram Pinterest_sess

TIKTOK pixels (_ttp and _pangle)


It allows you to identify
visitors coming from
a Facebook post
.
It allows you to identify
visitors coming from
from Instagram. The same applies to Pinterest and TIKTOK. 

13 months

Cookies
or
performance

Cloudflare CDN

Speed up the loading
of web pages and
optimizing
performance via a
content delivery network
content

13 months

 

COSMO requests your consent to store these cookies. If you agree to their storage, we will be able to obtain information about your visits to the website. If you refuse their storage, this will not affect your visit to the website in any way.

ARTICLE 11 – DISCLOSURE

We will disclose your personal information if we are required to do so by law or if you violate our terms and conditions of sale and use, or to protect our rights, property, or safety, as well as those of third parties.

We have taken the necessary precautions to comply with the General Data Protection Regulation (GDPR). We will therefore not share your personal information with third parties without your prior consent (except as provided above). As explained above, your information may be shared with trusted third parties who assist us in the administration and proper functioning of our site, provided that these partners agree to keep this information confidential. Only data that does not directly identify you (e.g., cookies) may be shared with our partners for marketing or advertising purposes. You may, of course, choose to opt out of this.

ARTICLE 12 – SHOPIFY

Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our services and products to you.

Your data is stored in Shopify's data storage system and databases, and in Shopify's general application. Your data is stored on a secure server protected by a firewall.

Payment:

If you make your purchase through a direct payment gateway, Shopify will store your credit card information. This information is encrypted in accordance with the data security standard established by the payment card industry (PCI-DSS). Information relating to your purchase transaction is retained for as long as necessary to complete your order. Once your order is complete, the information relating to the purchase transaction is deleted.

All direct payment gateways comply with the PCI-DSS standard, managed by the PCI Security Standards Council, which is the result of a joint effort by companies such as Visa, MasterCard, American Express, and Discover.

The PCI-DSS requirements ensure that credit card data is processed securely by our store and its service providers.

For more information, please see Shopify's Terms of Service here or Privacy Policy here.

ARTICLE 13 – SERVICES PROVIDED BY THIRD PARTIES

In general, the third-party providers we use will only collect, use, and disclose your information to the extent necessary to perform the services they provide to us.

However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies with respect to the information we are required to provide to them for your purchase transactions.

With regard to these providers, we recommend that you carefully read their privacy policies so that you can understand how they will handle your personal information.

It is important to remember that some suppliers may be located or have facilities located in a jurisdiction other than yours or ours. Therefore, if you decide to proceed with a transaction that requires the services of a third-party supplier, your information may be governed by the laws of the jurisdiction in which that supplier is located or those of the jurisdiction in which its facilities are located.

For example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, your information used to complete the transaction may be disclosed under U.S. law, including the Patriot Act.

Once you leave our store's website or are redirected to a third-party website or application, you are no longer governed by this Privacy Policy or our website's Terms and Conditions of Sale and Use.

Links:

You may leave our website by clicking on certain links on our site. We assume no responsibility for the privacy practices of these other sites and recommend that you carefully read their privacy policies.

ARTICLE 14 – SECURITY

To protect your personal data, we take reasonable precautions and follow industry best practices to ensure that it is not lost, misused, accessed, disclosed, altered, or destroyed inappropriately.

If you provide us with your credit card information, it will be encrypted using SSL security protocol and stored with AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional standards generally recognized by the industry.

Finally, we recommend that you take the following security measures to improve your online security:

- When creating an account, use at least 8 characters for your password, combining letters (upper and lower case) and numbers. Do not use your name or other personal information that can be easily obtained.

- Keep your passwords confidential and avoid using the same password for multiple accounts.

ARTICLE 15 – AGE OF CONSENT

By using this site, you represent that you are at least the age of majority in your state or province of residence, and that you have given us your consent to allow any of your minor dependents to use this website.

ARTICLE 16 – CHANGES TO THIS PRIVACY POLICY

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately after they are posted on the website. If we make changes to the content of this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances we disclose it, if any.

If our store is acquired by or merged with another company, your information may be transferred to the new owners so that we can continue to sell products to you.

QUESTIONS AND CONTACT INFORMATION

In accordance with the General Data Protection Regulation (GDPR), if you wish to: access, correct, modify, restrict, contest the accuracy of, or delete any personal information we hold about you, file a complaint, object to the processing of your data, unsubscribe from our emails, exercise your right to transparency and portability of your personal data, or if you simply wish to obtain more information on these topics, please contact our privacy standards officer by email at contact@madamedalexis.com  or by mail at COSMO – Office 46 – 66 avenue des Champs Elysées in PARIS (75008). To exercise these rights, simply provide us with your first and last name, address, email address, and proof of identity.

ARTICLE 17 - LEGAL NOTICES

The website www.madamedalexis.com (hereinafter referred to as the "Site") is published by COSMO, a simplified joint stock company with a share capital of €851, registered in the Paris Trade and Companies Register under number 902 960 889, with intra-community VAT number FR54902960889.
Its registered office is located at Bureau 46 – 66 avenue des Champs Elysées, PARIS (75008).
Its unique identification number for the REP (Extended Producer Responsibility) for household packaging and graphic paper with ADEME (
) is FR429003_01REVZ.

The Director of Publication is Mr. Timothée TABARY, in his capacity as President of La COSMO. The Website is hosted by Shopify International Limited, whose registered office is located at 2nd Floor, 1-2 Victoria Buildings, Haddington Road, Dublin 4, D04 XN32 Ireland. The Website is an e-commerce site offering hair care products for sale. Any purchase made via the Website and/or any creation of a personal account on the Website is governed by the General Terms and Conditions of Sale and Use, which can be accessed via the following link: https://www.madamedalexis.com/pages/conditions-generales-de-vente

Cookies

When you visit the Website, COSMO uses cookies to operate the Website and optimize your browsing experience. You can change or withdraw your consent at any time while browsing the Website from the preference management center at the bottom left of your screen or by clicking on the "Cookie Management" tab at the bottom of the page.

Personal information

Your personal data is processed by COSMO as data controller, in particular for the following purposes: Management of the Website, contact requests, newsletters, orders, personal accounts, and reviews left on the Website. 

You have the following rights regarding your personal data: access, rectification, erasure, portability, and restriction. You also have the right to object, which may be exercised under certain conditions.

Contact

If you have any questions about the features offered by the Website, you can contact COSMO by mail at the address mentioned at the top of these Legal Notices or via the contact form accessible via the following link: https://www.madamedalexis.com/pages/contact