top of page

Data Protection 

1. General Statement

We take your privacy very seriously and we are committed to protecting it. We believe that you should easily know what personal data we collect and use, as well as to understand your rights in respect of your personal data.

This privacy policy (“Privacy Policy”) explains our policies and practices regarding how we collect, use, and disclose the personal data that we collect through our Digital Platforms, our stores or during our events.

We recommend that you read this Privacy Policy carefully as it provides important information about your personal data.

This Privacy Policy is designed so that you can easily reach the section you are interested in.

You can print the complete text of our Privacy Policy. 

Do not hesitate to contact us should you have any questions or remarks about this Privacy Policy: 00 33 666250654 or contact@lesac.store.

​

2. Who we are? 

​

“Le Sac”, "we" "us" and “our” refer to Le Sac company as the controllers of your personal data, except otherwise stated in this Privacy Policy.

Le Sac is a French limited is a French business. 

​

3. What personal data do we collect and how is it collected?

​

Personal data is information relating to an identified or identifiable natural person. For example, it may include an individual’s name, address and gender.

We may collect personal data either directly from you (for example when you purchase a product in a store) or indirectly (for example from your electronic devices that interact with our websites, electronic forms or mobile applications (“Digital Platforms”)).

​

3.1.     Information you provide directly to us

​

You may provide us with information:
-    When you create an account online or in our stores; 
-    When you subscribe to our newsletter;
-    When you use our Digital Platforms;
-    When you purchase products or services on our Digital Platforms or in our stores;
-    When you visit our stores;
-    When you participate in one of our events;
-    When you contact our customer-services. 

​

3.2. Depending on what you provide us with, such information may include:


-    Your identity (including your first name, last name, gender, image, nationality);
-    Your contact details (including your postal address(es), email address(es), phone number(s));
-    Your personal status (including your title);
-    Your purchases and repairs (including purchase history, order details);
-    Your preferences (including your size);
-    Certain payment information (including billing information, payment type or method, charge or credit card number);
-    Other information you may provide by filling forms or by contacting us (including your feedbacks, or other communications with us which may include health data relating to possible adverse reactions to our cosmetic products). 

We will inform you when your information is required in order to process your request, to respond to your queries or to provide you with our products and services. If you do not provide this information, then it may delay or prevent us from processing your request, responding to your query or providing products or services to you. 

We hope to ensure that the personal data we possess are accurate at all times and therefore we encourage you to update your information in case any changes have occurred. We also may ask you to update your information from time to time.

We recommend that you only provide the data requested or necessary for your query, with the exception of any sensitive information related to racial or ethnic origin, political opinions, religious or philosophical beliefs, data concerning health, sex life or sexual orientation. 

​

3.3.    Information indirectly collected

​

We may collect information when you use our Digital Platforms, such as your IP address or other browsing information (including browser, operating system, device model), through cookies or similar technologies placed on your device. Some cookies are required for the proper functioning of our Digital Platforms and other are used for analytics purposes which help us to provide you with more personalized and customized services and a better digital experience. For more information about cookies and to know how you can edit your preferences, please read our Cookie Policy.

We may also collect information about you from third parties, such as a spouse who contacts us on your behalf or from your friends who provide us with your information in order to invite you to events you may be interested in.

If you provide personal data to us about someone else, you must ensure that you are entitled to disclose that information to us and that, without us taking any further steps required by data protection laws, we may collect, use and disclose such information for the purposes described in our Privacy Policy. For example, you should ensure the individual concerned is aware of the various matters detailed in our Privacy Policy. The individual must also provide the consents set out in this Privacy Policy in respect of how we will deal with their personal information.

​

3.4.    Minimum age


We remind you that we do not collect, directly or indirectly, personal data from persons under the age of 16, without prejudice to any local law setting a different minimum age. We therefore ask you not to provide us with personal data of persons who do not meet this requirement.

​

4. Why do we collect your personal data and how do we use it?

​

We collect and use your personal data based on one or many of the following legal basis:

  • we have obtained your prior consent (for example, when you subscribe to our newsletter). Please note that for this specific legal basis, you have the right to withdraw your consent at any time (see below “What rights do you have on your personal data?”);

  • the processing is necessary in connection with any contract between Hermès and you (for example, when you make a purchase);

  • we have a legitimate interest in carrying out the processing and that legitimate interest is not overridden by your interests, fundamental rights, or freedoms (for example, to prevent payment fraud);

  •  we have to process your personal data to comply with applicable laws and regulations.

 

Depending on the context, we may use your personal data in order to: 

​

  • provide you with the products or services you requested;

  • conduct checks to identify you and verify your identity;

  • send you Promotional Communications - with your prior consent (see section “Promotional Communications”);

  • provide you after-sale services and manage refunds;

  • respond to your queries, suggestions and requests, including your data subjects’ rights exercises;;

  • manage complaints and litigation;

  • manage the events you registered and/or participated in;

  • to detect, prevent and fight against any fraudulent or illegal activity, including to protect your transactions from payment fraud, to act against counterfeiting and against the resale of our products in violation of our terms and conditions of sale and/or outside our distribution network

  • protect you, employees and other individuals in our stores as well as our property;

  • manage the stock of certain types of rare products to allow a fair allocation of the products we sell;

  • monitor and improve our Digital Platforms;

  • conduct statistical analysis, in particular to adapt our product offer (including the use of your nationality after anonymization);

  • improve our products and services;

  • respect our legal obligations, including providing information to regulatory bodies when legally required, in particular to comply with our legal obligations in terms of cosmetovigilance, prevention and the fight against fraud, money laundering and the financing of terrorism.

​

5. Promotional Communications (newsletter, invitations, etc.)

​

With your express prior consent (usually obtained by ticking a specific box in a form), you may receive information concerning offers, services, products or events sent by Le Sac and/or by other Le Sac  business partners companies (“Promotional Communications”). In such a case, you also accept that your contact information is shared with other Le Sac business Partners for this purpose. Please visit https://en.lesac.store/ for details about companies Le Sac business partners. 

​

We may ask you to confirm or update your preferences regarding Promotional Communications if you instruct us to provide further products and/or services in the future, or if there are changes in the law, regulation, or the structure of our business.

​

6. How long do we keep your personal data?

Your personal data are processed for the period necessary for the purposes for which they have been collected, to comply with legal and regulatory obligations and for the duration of any period necessary to establish, exercise or defend any legal rights.

In order to determine the most appropriate retention periods for your personal data, we have specifically considered the amount, nature and sensitivity of your personal data, the reasons for which we collected your personal data, the service you deserve and expect from us together with the applicable legal requirements. For example:

- With regard to our prospects (potential customers): your data is stored for three years from your last action and then deleted or archived to comply with legal retention obligations;
- With regard to our customers: your data is stored for the duration of our commercial relationship and for up to ten years and then deleted or archived to comply with legal retention obligations;
- With regard to the cookies used on Digital Platforms: they are stored for up to 13 months from the moment they were installed on your device.

​

7. How do we disclose and transfer your personal data?
​
We may disclose your personal data only to the parties indicated below and for the following reasons: 

We disclose your personal data to Le Sac employees that need to have access to your personal data and are authorized to process them in order to achieve the aforementioned purposes and who are committed to confidentiality. 

We may disclose your personal data to Le Sac company: departments in charge of customer relationship, retail, e-commerce, communication, legal affairs, finance, internal audit, IT management and security for the purposes set out in our Privacy Policy and to provide you with a consistent level of service across all Le Sac business. This may include providing you with the products and services that you have requested, improving the services provided and – with your consent – sending you Promotional Communications concerning offers, services, products or events (for such purpose, you may withdraw your consent at any time – see section “What rights do you have on your personal data?” below).

​

For the specific purpose of combating payment fraud, your personal data are communicated to Le Sac in order to process your order and to fight against online payment methods fraud attempts. As part of our legitimate interest to fight against fraud with payment methods, Le Sac , acting as data controller, can transmit your financial information to an external service provider with a fraud detection tool in order to authenticate a payment. Such service provider is committed to confidentiality.

 

 

The Le Sac company is located worldwide. As a result, personal data may be transferred outside the country where you are located. This includes transfers to countries outside the European Union (“EU”) and to countries that do not have laws that provide adequate protection for personal data according to the European Commission.  
To ensure lawful transfers of data, the Le Sec has implemented Binding Corporate Rules (“BCRs”) designed to allow Le Sec to transfer personal data from the European Economic Area (“EEA”) to other Le Sac located outside of the EEA in compliance with the European data protection law. These BCRs have been approved by the European data protection authorities. 

 

 

For countries where BCRs are not fully recognized as adequate mechanism, transfers are made on the basis of appropriate contractual clauses approved by the data protection authorities. To obtain a copy of the relevant adequate safeguards, you can send us your request (see below “How to contact us?”).
Please visit hhttps://en.lesac.store/ for more details.

We may also disclose personal data to third-party providers acting on behalf of Le Sac and approved by Le Sac.

All such processing is based on our prior instructions set out in a binding contract that is compliant with the requirements of applicable law.

 

 

Such disclosures are made for different purposes including:

  • IT development and support;

  • Hosting and carrying out marketing and business studies and marketing campaigns;

  • Verifying your information, authenticating payments and processing orders and payments, to third parties that provide credit reporting, payment or order fulfilment services;

  • Delivery services

  • Data quality management services (standardization, deduplication…)

​

These providers are committed to confidentiality and are not permitted to use your personal data for any other purposes. We also require them to use appropriate security measures to protect your personal data. 

Part of those service providers are located outside of your country, notably outside the EU. We have taken steps to ensure all personal data is provided with adequate protection and that all transfers of personal data, including outside the EU are done lawfully. Where we transfer personal data outside of the EU to a country not determined by the European Commission as providing an adequate level of protection for personal data, the transfers will be under an agreement which covers the EU requirements for the transfer of personal data outside the EU, such as the European Commission approved standard contractual clauses, or under other appropriate safeguards. 

To obtain a copy of the relevant adequate safeguards, you can send us your request using the details in Section

“How to contact us?”  Contact Us: 00 33 666250654 or contact@lesac.store

​

8. How do we protect your personal data?

​

All your personal data is strictly confidential and will only be accessible, on a need-to-know basis, to duly authorized personnel of Le Sac and third providers acting on our behalf with appropriate technical and organizational security safeguards.

​

The Le Sac has implemented security measures to protect your personal data against unauthorized access and use. We follow appropriate security procedures in the storage and disclosure of your personal data so as to prevent unauthorized access by third parties and to prevent your data being accidentally lost. We limit those who access your personal data to those who have a genuine business need to access it.  Those who do access your data will be subject to a duty of confidentiality towards Le Sac.

​

We also have procedures in place to deal with any suspected data security breach. We will notify you and any applicable regulator of a suspected data security breach where we are legally required to do so.

​

We also require those parties to whom we transfer your personal data to comply with the same. However, unfortunately, the transmission of information via the internet is not completely secure. So, we cannot ensure the security of your personal data transmitted by you to us via the internet. Any such transmission is at your own risk and you acknowledge and agree that we shall not be responsible for any unauthorized use, distribution, damage or destruction of Your Information, except to the extent we are required to accept such responsibility under the law. Once we have received your personal data, we will use the security measures abovementioned.

 

​

bottom of page