This document called Privacy Policy is intended to help you understand the information we collect when you visit the site viorica.md (referred to as the “Site”), whether or not you are registered, and describes how we use this information.
If applicable, this Privacy Policy also describes how we process the information you provide or collect about you when you visit our stores directly administered by us (“stores”) or in the context of any other contacts you may have with us. This policy is complementary to any other information provided in other circumstances.
This Site is a site with a general audience; however, our services are intended for people 16 years of age or older. We do not request, collect, use or disclose personal data provided by a person under the age of 16 both online and in our stores. If we learn that we have collected personal data from a child, we will delete this information.
If you are under 16, please do not register or proceed with your online purchase and ask an adult (one of your parents or legal guardian) to continue the necessary procedures.
Who are we?
Viorica-Cosmetic JSC is a joint-stock company, duly established and operating in accordance with the laws of Republic of Moldova, with Registered office located in Chisinau, Mesager street no. 1, registered on 22.02.1996, tax code 1002600033793.
This document gives you important information about the following:
- PERSONAL DATA OPERATOR
- PERSONAL DATA STORAGE
- WHO HAS ACCESS TO PERSONAL DATA
- WHAT IS THE LEGAL BASIS FOR PROCESSING PERSONAL DATA
- CLIENT’S RIGHTS AND THEIR EXERCISE
- PERSONAL DATA PROCESSING
- COLLECTION OF PERSONAL DATA
- HOW WE USE PERSONAL DATA
- SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
- THE RIGHT TO SUBMIT A COMPLAINT WITH A SUPERVISORY AUTHORITY
- UPDATING THE PRIVACY POLICY
By visiting our website, by using the services, or otherwise interacting with us via our stores, news platforms or other websites, you acknowledge that you have read and understood this Privacy Policy and you acknowledge and agree that we may collect, use, transmit and disclose your personal information that we collect through the websites, and Stores, in accordance with this Privacy Policy. If you have not already registered, we may ask you to register if we consider it appropriate to protect your rights or if this is required by applicable laws. If you do not agree to the terms of this Privacy Policy, please do not access this Site, create an account, and use or submit personal data on this Site or sign up when this option is provided to you in accordance with applicable laws.
1. PERSONAL DATA OPERATOR
Viorica-Cosmetic JSC is the operator of the personal data you transmit to us and is responsible for your personal data in accordance with applicable data protection legislation (collectively referred to as Viorica-Cosmetic, “We”, “us” or “our” in this Privacy Policy).
Our contact details are:
Viorica-Cosmetic JSC
mun. Chisinau, Rep. Moldova
Mesager street no. 1
E-mail: onlinemagazin@viorica.md
2. PERSONAL DATA STORAGE
The data we collect from you are stored on Viorica-Cosmetic JSC servers.
3. WHO HAS ACCESS TO PERSONAL DATA
We do not transmit, sell or transfer your data to third parties for marketing purposes outside Viorica-Cosmetic JSC. Data transmitted to third parties is only used to provide you with our services. You will find the third party categories within each specific process below.
Part of the collected data will be transferred to a third party for:
- Delivering orders – in this case we transfer your contact details to the courier companies and the Post Office of Moldova that deliver the orders and collect the payment on our behalf;
- Sending advertising messages – to send them effectively, we use the services of the email marketing platform Mailchimp-the Rocket Science Group LLC, based in Atlanta, Georgia, USA. Mailchimp is EU-US Privacy Shield certified and complies with EU regulation 679/2016.
These third parties have made a contractual commitment to provide adequate safeguards for your personal data, which means that it will be protected in accordance with the legal requirements of the European Union.
4. WHAT IS THE LEGAL BASIS FOR PROCESSING PERSONAL DATA
Depending on the purpose for which the data are used, fundamentally legal for the processing of your data may be:
- Your consent;
- Our legitimate interest, which could be:
- Improve our products and services: specifically, our business interests to help us better understand your needs and expectations and therefore improve our services, websites / apps/ devices, products and brands for the benefit of our consumers;
- Fraud Prevention: to ensure that payment is complete and fraud less;
- Securing our tools: keeping the tools used by you (our websites / apps / devices) safe and ensuring that they are working properly and continuously improving.
- Contract fulfilment: specifically to perform the services you request from us;
- Legal reasons in which data processing is required by law.
For each specific processing of personal data we collect from you, we will inform you whether the provision of personal data is required by regulations or is necessary to conclude a contract, whether it is mandatory for you to provide us with personal data and what are the possible consequences if you refuse.
5. CLIENT’S RIGHTS AND THEIR EXERCISE
The right of access means that you have the right to obtain confirmation from Viorica-Cosmetic JSC that we process your data or not, and if so, to provide you with access to this data and information about how it is processed.
Right to rectification means that you have the right to request rectification of your personal data if they are incorrect, including the right to complete incomplete personal data. If you have a Viorica-Cosmetic account, you can edit your personal data from your account.
The right to delete the data means that you have the right to obtain at any time the deletion of the personal data being processed by Viorica-Cosmetic JSC , in any or more of the following situations: the data are no longer required for the fulfilment of the purposes for which they were collected or otherwise processed; you decided to withdraw your consent and there is no other legal basis for data processing; you refuse data processing; the data have been processed illegally; the data needs to be erased for compliance with a legal obligation or a collection has been made in connection with the provision of services of the information society.
However, your data will be kept for the completion of the following situations:
- you have an unresolved customer service request;
- you have an open order that has not yet been delivered or has been partially delivered;
- you have an unpaid debt to Viorica-Cosmetic JSC , regardless of the method of payment;
- if you have made a purchase, we will retain your personal data in connection with your transaction in accordance with the accounting legislation.
The right to processing restriction means that you have the right to obtain restriction of processing in the following situations:
- if you dispute the accuracy of the data, for a period that allows Viorica-Cosmetic JSC to verify the accuracy of the data;
- if the processing is illegal and you object the deletion of personal data, requesting instead to restriction of their use;
- if you have objected the processing, for the time period during which it is verified whether the legitimate rights of Viorica-Cosmetic JSC prevail over those of yours;
- if Viorica-Cosmetic JSC no longer needs your personal data, but they are necessary to defend your rights in court.
The right to portability refers to the fact that you have the right to obtain personal data in a structured, commonly used and automatically readable format and you have the right to transmit these data to another operator.
The right to object means that you have the right to object the processing of your personal data based on the legitimate interest of Viorica-Cosmetic JSC . Viorica-Cosmetic JSC will not continue to process your personal data unless we can demonstrate a legitimate reason for the processing that prevails over your interests and rights or if the processing is carried out on the basis of legal proceedings.
The right to refuse automated decision-making process means that you have the right not to be the subject of a decision based solely on automated processing, including profiling, if you have not explicitly consented to it or if automated processing is not necessary for the conclusion or performance of a contract.
Your right to oppose direct marketing:
- You have the right to object the direct marketing, including Profile Analysis for direct marketing purposes.
- You may unsubscribe from direct marketing by following the instructions in each marketing email or by sending a letter through any of the contact details mentioned herein.
How can you exercise your rights?
We attach particular importance to the protection of personal data and our staff is always at your disposal at onlinemagazin@viorica.md.
6. PERSONAL DATA PROCESSING
- “Personal data” means any information relating to an identified or identifiable natural person (“data subject”); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an identification of one or more specific factors of his or her physical, physiological, genetic, mental, economic, cultural, and social identity;
- “Processing” means any operation or set of operations performed upon the personal data or sets of personal data, either with or without the use of any automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or making available in any other way, alignment or combination, restriction, erasure or destructio;
- “Operator” means the natural or legal person, public authority, agency or any other entity which alone or jointly with others determines the purposes and means of the processing of personal data; where the purposes and means of processing are determined by Union law or by national law, the controller or the specific criteria for its nomination may be consulted in European Union law or national law;
When we use the term “personal data” in the table of contents of this Privacy Policy, we mean any information that will allow us to identify you, or any third party whose personal information you provide to us, either directly or indirectly, and including any information relating to the purchase of goods or services, or the information you choose to provide to or share with us or with third parties, while you use our website or our Stores.
We will process personal data in accordance with regulation (EU) 2016/679 “GDPR regulation” and the legislation of Republic of Moldova. We reserve the right to conduct further processing in accordance with the law as part of a criminal investigation or other investigation or proceeding.
7. PERSONAL DATA COLLECTION
Data source
We collect personal data from you only when you voluntarily provide us with information such as:
- Viorica.md website: when you place an order through the Website, as a Customer, when you register for an account or change your account; when you create a wishlist of products, when you participate in a contest, a lottery, or promotion; when you are looking for any information on the Website, when you contact us with a comment or a question; when you sign-up to receive our newsletter;
- Our stores: when you fill out the form for issuing the loyalty card, during informal discussions when you visit the boutiques or points of sale, when you participate in a contest, lottery or promotion within the stores; when you purchase goods;
- Events: when you participate in our events, surveys and market research and other promotions, also online (e.g. actions we perform on third-party social networks, such as Facebook);
- Our customer services: when you request assistance, special services or services before or after sale;
- E-mail, text and other electronic messages: when we communicate between you and us;
If you provide us with personal information of third parties (e.g. family members, other third parties), you must ensure that these third parties are informed and authorized about the use of their data as described in this Privacy Policy.
Data types
We may collect and use different types of personal data depending on the purpose we have, as described below:
- personal data such as name, surname, gender, age / date of birth, country of origin and other personal details (hair and complexion type etc.) as permitted by applicable law;
- contact details such as address, e-mail address, telephone number, mobile number and other contact details as applicable;
- payment details such as payment instrument (credit card, debit card)
- sales information such as products or services provided, location of purchase, product codes, amount, total sales, complaints, returns, refunds and other sales-related information, as applicable;
- habits and profiles, such as data on your purchases. (purchase history, including where the sale takes place, type, quantity and price of products purchased by you), information on customer relationship management activities, purchase habits and preferences (wish list, favorite product categories, how you learned about our brands, quality marks on products purchased, special habits or needs declared by you), other information (job, education, hobby and lifestyle information), as per applicable laws;
8. HOW WE USE PERSONAL DATA
Personal data may be used for the following purposes, depending on the specific circumstances in which you interact with us.
When you use our website
When you use our Site to search for our products and services and to view the information we provide, a number of cookies are used by us and third parties to enable the site to operate, to collect useful information about visitors and to help you have the best user experience.
Some of the cookies we use are strictly necessary for our site to work and we do not require your consent to place them on your device. in addition to the cookies we use, various third parties place others on the device with your consent.
When you submit a request through our website
When you submit a request through our website, depending on the information that is of interest to you, we may need the following information: your first and last name, contact phone number, email address, postal address, gender and age.
We use this information to answer your question, including to provide you with the requested information about our products and services. We may also send you several emails after you have made a request and to ensure that we have answered your question. We will do so based on our legitimate interest in providing accurate information prior to the sale.
We do not use the information you provide to make automatic decisions that may affect you.
When you purchase a product on our website
When you buy products from us online, we ask you for contact information such as: your first and last name, address, contact phone number, email address and credit card information (when the order is paid online). We also record the IP address (Internet Protocol), which is the address of your device on the Internet.
We use this information to manage your online purchases on viorica.md, to process your order and to deliver your products. We will e-mail you an order confirmation as well as a product delivery confirmation and, if applicable, we will use your phone number to contact you in connection with your purchase, also we will use your data to process product claims and warranties. We use your personal data to identify and confirm your legal age for online shopping and to confirm your address to external partners.
We request this information in order to process your payment, to deliver your products and to fulfill your contract. The card data is processed through Victoriabank payment system and Viorica-Cosmetic JSC does not store any customer card details. We record your IP address to demonstrate that the sale has been properly charged, an obligation that we have under the legal provisions.
Your personal data transmitted to third parties is only used to provide you with the above-mentioned services, for operations performed by storage and distribution service providers in connection with the delivery of your order, for the processing of payments by payment processing service providers.
We do not use the information you provide to make automatic decisions that may affect you.
When you sign up to receive our newsletter
You can sign up for the newsletter through the following ways:
- On our website, by filling out the email address in the application form;
- When registering a new account;
- In the checkout page upon completion of the order.
We will ask for your consent to use this data to send you an e-mail newsletter containing information about our products and other information that we believe may be of interest to you.
You may withdraw your consent at any time by following the instructions in each newsletter, and we will immediately cease sending you these notices.
In order to send newsletters, your name and email address are transferred to a third party. Thus, to effectively transmit them, we use the services of the email marketing platform Mailchimp-the Rocket Science Group LLC, based in Atlanta, Georgia, USA. Mailchimp is EU-US Privacy Shield certified and complies with the rules of EU regulation 679/2016 and has made a contractual commitment to provide adequate safeguards for your personal data, which means that it will be protected in accordance with the legal requirements of the European Union.
We do not use the information you provide to make automatic decisions that may affect you.
When you create a customer account
When you create a customer account, we ask you for the following categories of personal data: first and last name, email address and password.
We will process the following categories of personal data if you make a purchase:
- order history;
- delivery information (postal address and contact phone);
- payment history.
We will also process the following categories of personal data related to your cookies:
- click history;
- browsing and browsing history.
We will use your personal data to create and manage your Viorica-Cosmetic account and to provide you with a personalized and relevant experience on viorica.md.
We will record and manage the benefits offered to you in the customer account, we will send you information about your rewards such as discounts, tips, gifts and events.
We will provide you acces to your order history and order details and allow you to manage your account settings. We will also provide you with simple ways to correct and update your information, such as contact details and payment information.
If you have not refused direct marketing, we will use your personal data to send you marketing offers, information surveys and invitations through emails, text messages, phone calls and postal materials.
The processing of personal data for your account is based on your consent to the creation of your Viorica-Cosmetic account.
The processing of your personal data to provide you with relevant product information is based on our legitimate interest.
You have the right to delete your account at any time. If you choose to do so, your account will cease to exist and you will be considered inactive.
You have the right to object the processing of your personal data based on the legitimate interest of Viorica-Cosmetic JSC by contacting onlinemagazin@viorica.md, your account will then be deleted and we will not be able to offer you our services.
Direct Marketing
Based on your consent, we will process the following categories of personal data:
- contact information such as name, email address, phone number and zip code;
- products and offers that you clicked.
If you have a Viorica-Cosmetic account we will also process your personal data transmitted in connection with your account, such as: name; address; order history; how you navigated and what you clicked on the site.
We use personal data to send you marketing offers, information surveys and email invitations, text messages, phone calls and mail communications.
To optimize your Viorica-Cosmetic JSC experience, we will provide you with relevant information, product recommendations and send you personalized offers, invitations to contests, lotteries or promotions and other benefits for registered customers. All of these services are based on your previous orders, the items you clicked on and the information you sent.
Data transmitted to third parties is only used to provide you with the above-mentioned services, and those transmitted to media agencies and technical providers are aimed at the distribution of physical and digital direct marketing.
We do not transmit, sell or cede your data to third parties for marketing purposes.
The processing of personal data is based on your consent when you agree to direct marketing.
You have the right to withdraw your consent to the processing of personal data at any time.
When you do so, Viorica-Cosmetic JSC will cease to send you any other direct marketing offers or information based on your consent.
You can unsubscribe from direct marketing by following the instructions in each marketing message.
Storage period of your personal data
We will store your information as long as we are required by law. If there is no legal requirement, we will only store them for as long as necessary.
9. SECURITY AND CONFIDENTIALITY OF PERSONAL DATA
We have implemented appropriate measures to secure your personal data from accidental loss and prevent unauthorised access, use, modification and disclosure. For example, when providing information about a order, we use Secure Socket Layer (SSL) technology, an encryption tool that provides security while transmitting that information over the Internet. We also use firewall protection, password control and other technological and procedural safeguards to maintain this Site. Although we have implemented the above security measures for this Site, you should know that 100% security is not possible. Therefore, the provision of your personal data is at your own risk and to the fullest extent permitted by applicable law, so we will have no liability as a result of the disclosure of your personal information due to errors, omissions or unauthorised acts of third parties during or after its transmission to us. We recommend that you periodically update the software in order to protect the transmission of data over the network (for example, anti-virus software), and to make sure that the service provider for the provision of electronic communications services has adopted the proper means for the security of the transmission of the data via a network (e.g., firewalls and spam filters), (ii) to keep confidential and not to disclose to anyone your user name and password to access your account; (iii) change your password regularly; and (iv) the do not use the same password for all your accounts.
In the unlikely event that we find that the security of your personal information in our possession or control has been or may have been compromised, we will notify you of this situation, according to the applicable law, by using any of the methods described therein (providing us your e-mail address, you agree to receive this notice electronically, through the e-mail addresses).
10. THE RIGHT TO SUBMIT A COMPLAINT WITH A SUPERVISORY AUTHORITY
If you are of the opinion that Viorica-Cosmetic JSC processes your personal data incorrectly and you have a complaint about our use of your data, we would prefer you to contact us directly in the first instance, so that we can address your complaint.
You also have the right to lodge a complaint with a supervisory authority.
11. UPDATING THE PRIVACY POLICY
We regularly review and, where appropriate, periodically update this Privacy Policy as our services and use of personal data evolve. If we want to use your personal data in a way that we have not previously did, we will contact you to provide you with information about this and, if necessary, to request your consent.
We will update the version number and date of this document every time it is changed.
Applicable from 03.03.2020