This data protection policy is part of Bexley’s transparency process. This document describes BEXLEY's practices regarding the collection, use and confidentiality of your personal data, so as to inform you about the conditions under which BEXLEY, as data controller, processes your data.
This data protection policy is in addition to the information which is provided to you when you send us your data by completing a form on our website www.bexley.fr (for example: visiting our website, subscribing to our newsletter, creating a customer account, online ordering), in a store or over the phone, whether you are a customer or prospect.
Should you have any questions about this document or about the way BEXLEY processes and protects your data, then contact our Data Protection Officer (DPO) at the following address: firstname.lastname@example.org
1. WHAT IS PERSONAL DATA ?
According to the General Data Protection Regulation, "personal data" means any information relating to an identified or identifiable natural person; is deemed to be an "identifiable natural person" a natural person who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.
2. WHY DOES BEXLEY COLLECT YOUR DATA ?
The information collected about you allows us to manage, facilitate, record and execute your orders, to know you better in order to send you targeted offers and thus to improve and personalize our services, to process your requests and your claims, and to provide after-sales service.
We use your personal data for specified, explicit and legitimate purposes, which are based on one of the following legal basis:
- Performance under the contract of sale relating to BEXLEY products: processing your data in order to (i) identify you, (ii) perform under our contractual relationship when you buy BEXLEY products in store or online: order, delivery, billing, tracking customer relations, exchanges, returns, refunds, credits, fidelity checks, claims;
- Your consent: processing your data in order to (i) communicate with you, send you newsletters, promotional offers, loyalty benefits (ii) to communicate some of your personal data to our business partners;
- Our legitimate interests: processing your data for (i) accounting purposes, litigation management; (ii) prevention and fight against fraud; (ii) performance of loyalty actions, commercial offers, commercial prospecting for products similar to those already purchased, study, survey, product test and promotion, (iii) organization of contests, lotteries and any promotional operation, (iv) development of business statistics, marketing analysis, statistics and volumes of use and use of our website and our shops;
- Compliance with a legal obligation: processing your data in order to (i) manage the exercise of one or more of your rights in accordance with the paragraph below, (ii) retain the elements of the sales contract in accordance with the legal limitation.
3. WILL YOU BE RECEIVING ADVERTISMENT FROM BEXLEY?
BEXLEY carries out advertising campaigns by email, SMS, postal mail, relating to BEXLEY products.
If you are a BEXLEY customer, and unless you object, we can send you information about BEXLEY products and offers, by email, SMS, postal mail. This objection can be made simply, free of charge, at any time and without cause (more information here)
If you are a prospect (and therefore have never bought BEXLEY products online or in stores), and if you agree, we can send you information about BEXLEY products and offers, by email, SMS, postal mail.
When you consent to the collection of your data, we will also process the postal mail information for transmission to our business partners, for direct marketing purposes of their own, to allow you to discover their products, services, special offers, promotions, tips, etc.
4. WHAT ARE THE DATA TYPES COLLECTED BY BEXLEY?
- When shopping in a store
We collect the data you provide to the Bexley seller when creating a customer account in the shop:
- Last name and first name
- Email address
- Phone number
- When shopping on line
We collect the data you provide when you:
- Browse and visit www.bexley.com and www.bexley.com;
- Create a customer account;
- Add products to your shopping cart;
- Make an order or a return request on our sites;
- Sign up for BEXLEY newsletters;
- Contact our customer service ;
- Take part in a quiz;
- Fill in a questionnaire or answer a survey.
In this context, we collect and process data relating to your identity: name, surname, civility, date of birth, country of delivery, delivery address, and we associate to the above an internal customer number and a loyalty card number related to the customer account.
We also collect commercial information relating to the transactions performed: transaction number, purchase details, payment terms, discounts granted, receipts, outstanding balances, purchase history, loyalty account, return of products, and / or telephone exchanges with you and our after-sales service.
Your bank details are collected and processed directly by our banking service provider and BEXLEY is never in possession of such data.
We collect information about your preferences in terms of communications: selection of authorized communication channels.
Through cookies, we are also led to collect and process personal data relating to your browsing and your behavior on the BEXLEY website, which includes technical data such as your IP address, pages visited, products that you are interested in, purchases made, language used, etc.
Subject to your agreement and the configuration of your navigation terminal (computer, tablet, smartphone), BEXLEY may also collect and process all or part of the following personal data: type of terminal, operating system, access provider Internet (ISP), browser, network.
- In all cases
BEXLEY may also be the recipient of personal data from its business partners who entrust it with their databases for commercial prospecting purposes. In such a case, you have given your consent to this data controller in order for its partners, such as BEXLEY, to contact you for business development purposes. In this context, BEXLEY ensures contractually that you have given your consent to this partner so that your data is transmitted to us for this purpose. Your data is then processed by BEXLEY as controller, to enable us to inform you about our offers, to conduct studies, surveys and product tests. The categories of data processed by BEXLEY are the following: postal mailing address, email address, mobile number, last name, first name, age, socio-professional category.
BEXLEY does not collect or process personal data that reveal racial or ethnic origin, political opinions, religion or philosophical beliefs, trade union membership, genetic data, health data or data, sexual life or data relating to criminal convictions and offenses, or related measures.
For each processing, BEXLEY only processes the relevant and necessary data in relation to the purpose for which the same was collected.
For each processing, BEXLEY only processes adequate, relevant and limited data to what is necessary in relation to the purposes for which they are processed.
5. WHAT HAPPENS IF YOU DO NOT COMMUNICATE YOUR DATA?
Some information requested in the forms is mandatory and is marked with an asterisk. The collection of the same is essential to the processing of your request. Therefore, in the absence of a response, we will not be able to respond to your request (example: postal mailing address for delivery).
6. WHO IS THE DATA CONTROLLER FOR PROCESSING YOUR DATA ?
The data controller is BEXLEY S.A.S, a company having its registered office 19 rue Louis Guérin, 69100 Villeurbanne France, registered with the Lyon, trade registrar under the number 344 434 253 00078.
7. WHO IS YOUR DATA COMMUNICATED TO?
The recipients of all or part of your data are:
- Within BEXLEY: the department in charge of the administrative and technical management of orders and returns, the department in charge of the management of marketing campaigns.
- Outside the BEXLEY group: the processors to whom BEXLEY entrusts certain processing operations and who process your data on our behalf, according to our instructions, such as: service providers in charge of hosting services and management of the hosting service, service providers in charge of the management and routing of our marketing campaigns, service providers in charge of monitoring and audience measurement of our marketing campaigns, service providers in charge of logistics, transport and delivery services.
BEXLEY ensures to select processors providing sufficient guarantees regarding the protection of personal data. The transmission of your data to our processors is contractually regulated so as to guarantee the security of your data.
When you agree to your data being sent to BEXLEY's business partners for business development purposes, each of these companies becomes responsible for the processing of your data. Each company that sends you business prospection must identify itself in any communication with you, which allows you to contact them directly.
BEXLEY may also share anonymous or aggregated data with third parties other than those identified above, for statistical purposes, without it being possible for these third parties to identify you in any way.
The data may also be transmitted to the competent authorities at their request, or in order to comply with legal obligations.
Data on email addresses and mobile phone numbers may be used anonymously as part of profiling.
8. WHAT ARE YOUR RIGHTS?
You enjoy many rights over your data. These rights can be exercised directly from your customer area, or by sending a letter together with a proof of identity to:
To the attention of the Data Protection Officer
19 rue Louis Guerin, 69100 Villeurbanne France
Or by email at: email@example.com
If BEXLEY has reasonable doubts as to the identity of the natural person making the claim relating to its rights as described below, BEXLEY may request additional information necessary to confirm the identity of such person (copy of the identity card for example).
We inform you that no payment is required to exercise your rights as described below.
However, where a given person's requests are manifestly unfounded or excessive, in particular because of their repetitive nature, BEXLEY may
- charge a reasonable fee taking into account the administrative costs of providing the information or communication or taking the action requested; or
- refuse to act on the request.
We will respond to your request within one month of receiving your request. Depending on the complexity and the number of requests, this period may be extended by two further months. BEXLEY will inform you of such extension within one month of receipt of the request, together with the reasons for the delay.
Right to object to processing of personal data
BEXLEY makes sure that you can always buy the products it offers for sale without this being conditional upon receiving direct marketing messages from BEXLEY or its partners.
This possibility is available on the account creation page, and on the page "My account / My registrations" of the BEXLEY site and by the setting of the cookies. And if you have accepted to receive direct marketing messages from BEXLEY and / or its partners, you will always be able to change your mind afterwards, and to object the reception of future messages, free of charge and without reason. If you have accepted the deposit of cookies on your terminal, you can also object it later, always for free and without reason.
If you object to processing for direct marketing purposes, BEXLEY will no longer process your data for business purposes. However, we draw your attention to the fact that if you exercise your right to object to receive for the future of the commercial prospecting from BEXLEY, you will continue however to receive emails from us relating to:
- the orders you could make (confirmation, follow-up, satisfaction questionnaire);
- your fidelity checks (supply of fidelity checks which and reminder on fidelity checks you did not use);
- your promotional code for your birthday.
You are also informed that you can register for free on the BLOCTEL list of opposition to phone marketing. For further information, visit, please www.bloctel.gouv.fr
Apart from processing your data for commercial purposes, you may also object, for legitimate reasons, to the processing of your personal by BEXLEY. In the event of exercise of this right of opposition, BEXLEY will no longer process your personal data, unless there are legitimate and compelling reasons for the processing which override your interests, rights and freedoms (examples: keeping your data for the purpose of finding, exercising or defending legal rights).
Right of access to your data
You have the right to obtain from BEXLEY confirmation as to whether or not your personal data are being processed, and, where that is the case, access to the personal data. To exercise your right of access, you must prove your identity by providing proof.
The exercise of your right of access may not affect the rights and freedoms of others.
Right to rectification
You may request the rectification of your data if the information held by BEXLEY is inaccurate. You also have the right to have the incomplete personal data completed, including by providing a supplementary statement.
You can rectify and update some of your data, directly on the page "My account / My information" of the BEXLEY website.
When you exercise of this right, BEXLEY will communicate any rectification to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
Right to erasure (Right to be forgotten)
You have the right to obtain from BEXLEY the erasure of your data for a reason which is provided by law, such as for example: personal data are no longer necessary in relation to the purposes for which they were collected or otherwise processed or the withdrawal of your consent for processing based on such a ground, if you object to processing for prospecting purposes, or if you object to processing for another purpose while there is no compelling legitimate reason for the processing.
When you exercise of this right, BEXLEY will communicate any erasure to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
However, BEXLEY may retain some of your data in the form of intermediate archives, for the time necessary to meet, in particular, its legal, accounting and tax obligations.
Right to restriction of processing
You have the right to obtain from BEXLEY restriction of processing when one of the following applies:
- If you dispute the accuracy of your data, for a period of time allowing us to verify it;
- If the processing is illegal and you object the erasure of the data and require instead the limitation of their use;
- If BEXLEY does not need your data for processing anymore, but you still need it for the purposes of finding, exercising or defending legal rights;
- If you have objected to processing based on the legitimate interest of the data controller, during the verification as whether the legitimate grounds pursued by the data controller take precedence over yours.
When you exercise of this right, BEXLEY will communicate any restriction of processing to each recipient to whom the personal data have been disclosed, unless this proves impossible or involves disproportionate effort.
Right to data portability
You have the right to request the portability of your data. This allows you to receive the data in a digital format. This right applies only to the case where the processing is carried out by automated means and is based on your consent or on a contract.
Right to withdraw your consent for direct marketing purposes
You have the right to withdraw your consent for direct marketing purposes from us at any time, free of charge and without cause. Just click on the "unsubscribe" link in any email sent by BEXLEY or write to us at firstname.lastname@example.org, or send STOP via SMS to 36608. In this case, your data will not be processed anymore for direct marketing purposes.
You can also manage your subscription preferences to our communications directly from your customer account.
To stop receiving direct marketing from our partners, we suggest you to refer to their conditions for more information. In any case, you can directly exercise with them your various rights, including rights of access, rectification and right to object. In case of difficulty or in order not to receive direct marketing from our partners, you can always write to us at email@example.com.
Automated decision-making and profiling
BEXLEY does not make any decision about you based solely on automated processing, which has legal effects on you, or which may affect you significantly.
The only "profiling" which is performed by BEXLEY lies in the analysis of your data concerning your personal preferences or interests, your localization. This information can be taken into account in order to automatically address personalized communications, for example based on gender, age group or postal code. You can still object this profiling.
Right to give instructions relating to your data in the event of death
You have the right to set general or specific directives for the retention, erasure and disclosure of your data after your death, and to specify how you intend these rights to be exercised. These directives may appoint a person responsible for their execution, failing which, your heirs will be appointed. You can provide BEXLEY with your specific directives. In the absence of any direction, your heirs may contact BEXLEY's DPO at firstname.lastname@example.org
When such directives are general and concern all of your personal data, they may be registered with a digital trusted third party certified by the French data protection authority (CNIL).
Right to lodge a complaint with a supervisory authority
You have the right to lodge a complaint with a supervisory authority, such as the French data protection authority (CNIL) .
9. ARE YOUR DATA TRANSFERRED TO A COUNTRY WHICH DOES NOT BELONG TO THE EUROPEAN UNION?
BEXLEY don’t transfer your personal data outside European Union or European Economical Area. Thus all your data are processed and hosted on the territory of the European Union.
10. FOR HOW LONG ARE YOUR DATA STORED ?
The data retention period varies according to the purpose for which they are processed. In general, your data are stored for the duration of our commercial relationship, increased by a period of three years after the term of such relationship, then such data are archived to meet our legal obligations or for probative purposes or are made anonymous for the purposes of studies and statistics.
Your data will not be kept beyond the period strictly necessary for the purposes pursued as stated herein and in accordance with the law.
Data relating to your order(s) are kept for seven years from the last order.
Data relating to your customer are kept, for communication purposes, for a period of three years from your last activity on our website or on an electronic communication medium (in particular click on a hypertext link contained in one of our emails). At the end of this three-year period, BEXLEY will be able to contact you again to find out if you wish to continue receiving our commercial communications. In the absence of a positive and explicit answer from you, we will delete your data.
However, data enabling the establishment of proof of a right or a contract, or kept in compliance with a legal obligation, may be the subject of an intermediate archiving policy for a period not exceeding the duration necessary for the purposes for which they are kept, in accordance with the legal provisions in force, it being reminded that the general law time bar is five years (Article 2224 of the French Civil Code). In this context, we may retain certain data after the deletion of your account when such retention is provided by law, or when such retention is necessary to enable us to manage claims and disputes.
Likewise, if you have exercised your right of opposition to receive prospection materials by contacting a data controller, the information necessary for us to take into account your right to object will be kept for a minimum of three years from the date of exercise. In no case will these data be used for purposes other than the management of the right of opposition and only the data necessary to take into account the right of opposition will be retained.
11. OUR POLICY ON COOKIES?
"Cookie" refers, in the broad sense, to any tracer deposited and / or read during the consultation of a website or an email. A cookie may contain information such as the name of the server that dropped it, a unique number identifier, an expiration date.
Cookies are necessary in particular to enable you to benefit from certain features of our website. If you have chosen to disable cookies via your internet browser, access to the site may be altered.
Data collected using cookies is kept for a maximum of 13 months. Beyond this time, the data is deleted or made anonymous.
We share information about the use of our site, such as navigation and / or geolocation data, with our advertising and analytics partners, who may combine these with other information you have provided to them or that they collected during your use of their services.
You will find below the list of our cookies and the list of our partners authorized to place cookies on our sites, as well as a link to their privacy policies proposing and explaining the means to object to their services.
Name of the du cookies
Type of cookies
Purpose of the cookies
Lifetime of cookies
Type of raw data collected
Link to the partner’s Cookies policy
Analyze of the ser experience / Analyze of the web site performance
Analyze the performance of the keywords purchase campaigns
Analyze and optimize the performance of campaigns
Identification of the pages viewed / Analyze of the performance of campaigns
Measure the sales acquired through affiliation programs
Identification of the user’s origin and monitors the items added to cart
Measure interactions with the site: pages viewed, duration of the visit, test ID, date of first visit
How to enable / disable Cookies?
You can at any time manage, disable and authorize cookies by deleting cookies in your browser settings.
You can visit the site Youronlinechoices, proposed by digital advertising professionals grouped within the European association EDAA (European Digital Advertising Alliance). You will be able to know the companies registered on this platform and which offer the possibility of refusing or accepting Cookies used by these companies to adapt the cookies that may be placed on your terminal.
In addition, we invite you to consult the heading "Cookies: the tools to control them" on the CNIL website: www.cnil.fr
In case of difficulty to exercise your right of access or opposition to Cookies, you can contact BEXLEY: email@example.com
12. HOW DO WE ENSURE THE SAFETY OF YOUR DATA
BEXLEY implements the appropriate technical and organizational measures, taking into account the state of current knowledge, the costs of implementation and the nature, scope, context and purpose of the processing and the degree of probability and seriousness of the risks to the rights and freedoms of natural persons.
For example, our payment service provider integrates the SSL (Secure Socket Layer) security protocol. The confidential data: the credit card number, the expiry date and the cryptogram are encrypted and transmitted to the secure server of the bank. In no case these data transit or are stored on BEXLEY's servers.
BEXLEY also takes steps to ensure that its staff, processors and personnel who have access to your data do not process them except as instructed by the data controller, unless compelled to do so by of the law of the European Union or the law of a Member State.
The site hosting service provider conducts vulnerability tests on our servers twice a year to ensure the security of Bexley's infrastructure.
BEXLEY ensures that its processors provide sufficient safeguards for the implementation of appropriate technical and organizational measures to ensure that the processing best respects the protection of the rights of the data subject.