Privacy and Cookies Policy

If you are using or just visiting monrevecosmetics.com (the "Website") or buying from this Website, this Privacy and Cookies Policy (henceforth "Privacy Policy", "Policy") applies to you. This Policy contains information about the types of personal data we may collect, why we might collect them and how we might process them. Please study this Policy carefully prior to browsing our Website and before each transaction. By making any use (such as access, viewing, browsing, transmission, temporary or non-temporary storage, etc.) of our Website, the services or functions offered on it and making any transaction in our online store in any way, through any platform or device, you acknowledge and agree that you have read and understood this Policy.

Our Role

If you are using our website to:
a. access information relevant to our products, services and brand
b. buy our products on our online shop (e-shop) and add products to your wishlist
c. create an account on our Website
d. access information on stores and online stores that sell our products
e. share our products on social media (facebook, twitter and Pinterest)
f. contact us for any matter via contact form or find information on how to contact us by other means in order to make enquiries
g. find links to our social media pages (facebook and Instagram); find a link to the team that designed and developed our Website
h. subscribe to our newsletter

or you are just visiting or browsing our website, we act as the data controller" of personal data. This means we determine why and how your data are processed. For these purposes the data controller is HELLENICA COSMETIC PRODUCTS EXPLOITATION S.A. ("HELLENICA COSMETICS S.A."), a company incorporated under the Laws of the Hellenic Republic (Greece), with registered offices at 7 Chimaras street, Marousi, P.O. 15125, Attica, GREECE, VAT number EL094004232, business registry number (Γ.Ε.ΜΗ.) 249101000, tel. +30 211 8804000, fax +30 210 6198840-9, e-mail monreve-sales@hellenica.gr (hereinafter referred to as monrevecosmetics.com”, Mon Rêve”, "Hellenica Cosmetics S.A.", Company”, "us", "we" or "our").

If you provide us with personal information about other people, or if others give us your information, we will only use that information for the specific purpose for which it was provided to us. By submitting any information, you confirm that you have the right to authorise us to process it on your behalf in accordance with this Privacy Policy.

If you have any questions regarding this Privacy and Cookies Policy and the way that Hellenica Cosmetics S.A. collects and processes your personal data, please contact our Data Protection Officer at dpo@hellenica.gr.

Types of Data We Collect

1. Data relevant to your order
When you place an order to buy our products from our online shop, we collect your first name, last name, street address, city, state/county (optional), postcode/zip-code, country of residence, phone number, email address, method of payment (card or PayPal) and any message you include in your order for the courier. We require these essential data for the fulfilment of your order. We do not collect or store in any way your card or PayPal details, so you need to re-submit them each time you use your card for transactions on our Website.

2. Data relevant to your account on our Website
When you create an account on our Website we collect your email address, your first name (optional) and last name (optional). Additionally, if you add an address to your account address book, we collect your first name, last name, street address, city, state/county (optional), postcode/zip-code, country of residence and phone number. We also collect your order history and wishlist. We require these data in order to provide you with the services associated with creating an account on our Website, such as order tracking, easier checkout process etc.

3. Data relevant to your inquiries
When you contact us for any matter via email, we collect your email and the content of your message. When you contact us for any matter via contact form, we collect your name, email and the content of your comments. In addition, if you contact us for any matter via telephone, we will collect your telephone number and any information you give us. We require these data in order to address your comments and inquiries.

4. Data relevant to our newsletter
When you subscribe to our newsletter, we collect your email in order to send you our newsletter. You can unsubscribe at any time, by following the dedicated link at the end of each newsletter.[ΕΚ1] [LF2]

5. Data relevant to your identity online and your location
Your Internet Protocol (IP) address, browser type and version, browser plug-in types, time zone setting, geolocation information about where you might be, the speed of the connection, basic connection information to the server, information about the software programs installed on your computer and your operating system type and version.

6. Data relevant to your use of our Website
Your URL clickstreams (the path you take through our site), locations and/or services viewed, page response times, cookie preferences, download errors, the web pages you visited immediately before and after your visit to our Website, how long you stay on our pages, what you do on those pages, how often and other actions.We do not however relate this information to a specific user, email or IP.

Special categories of data and children's data
We do not collect any data about you revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning sex life or sexual orientation, except when we have your explicit consent, or when we have to comply with the law.

We offer services directed to and intended for use only by those who are 18 years of age or over. We do not target monrevecosmetics.com at children, and we do not knowingly collect any personal data from any person under 16 years of age. In any case, if we find that we have collected any personal information from a minor under 16 without a verifiable parental consent, we will delete this information from our database as soon as possible. If you believe we may have collected information from a minor under the age of 16, please contact the Data Protection Officer of Hellenica Cosmetics S.A. at dpo@hellenica.gr.

Our Legal Bases for Processing Your Personal Data

In order to collect and/or use your personal data we have at least one of the following legal bases:

▪ Consent. You have given us clear and explicit consent to process your personal data for one or more specific purposes. If you have previously given consent to processing your data, you can withdraw such consent at any time. You can do this by emailing us dpo@hellenica.gr. If you do withdraw your consent, and if we do not have another legal basis for processing your information, then we will stop processing your personal data. If we do have another legal basis for processing your information, then we may continue to do so, subject to your legal rights.

▪ Contract. Processing your data is necessary for a contract you have with us (for the sale of our products or otherwise), or because providing such data is necessary to take specific steps before entering into that contract (e.g. placing an order or making a product-related inquiry).

▪ Legitimate interests. Processing your data is necessary for our legitimate interests or the legitimate interests of a third party, provided those interests are not outweighed by your legal rights and interests. These legitimate interests are:
o delivering, developing and improving our products and services
o determining whether marketing campaigns are effective
o improving data security
o gaining insights from your behaviour on our website and assessing the website’s function and performance.

In each case, these legitimate interests are only valid if they are not outweighed by your legal rights and interests.

▪ Legal obligation. Processing of your data is necessary for compliance with a legal obligation to which we are subject (e.g. providing you with an invoice or when required by law enforcement).

Any personal data collected by us is intended to be used exclusively for the fulfilment of your orders and our services and for the dispatch to you by email of marketing material relating to our brand and products. Such processing is performed in accordance with the relevant Greek and EU law.

Why do we collect your personal data and how do we use them?

We use your personal data for the following reasons: 1. Providing you the products you order and the services you request (legal bases: contract, consent and legitimate interest). Managing and processing your orders (legal basis: contract). Managing your account on our Website (legal bases: contract and consent). Managing your inquiries (legal bases: contract and consent). Managing hosting and back-end infrastructure (legal basis: legitimate interest).

2. Marketing purposes, promotional emails and newsletter. Mon Rêve may send promotional emails and newsletters containing information about our products, offers/discounts etc and news and information about our brand. We will only send you such informational and promotional emails if one of two conditions applies:

o You are an existing customer and we believe you might be interested in receiving information about our products and offers (legal basis: legitimate interest).
o You have subscribed to our newsletter (legal basis: consent).

You can always elect not to receive such promotional content upon creating an account or unsubscribe from our newsletter by following the dedicated link at the end of each promotional email or newsletter and the procedure described therein or by emailing us your request at dpo@hellenica.gr.

3. Customer support (legal bases: contract and legitimate interest). Notifying you of any changes to or any problems with your orders or our services, solving issues via email or phone support including any bug fixing.

4. Improving our services and the performance of the website (legal bases: consent and legitimate interest). Testing features, managing landing pages, heat mapping our site, traffic optimization and data analysis and research. Please find out more about these functions in our cookie policy.

5. To support our legal rights and claims or defend against third party claims in court or state authorities (legal basis: legitimate interests)

How We Protect Your Data

The security of your personal data is our ultimate commitment. The website monrevecosmetics.com is operated according to applicable EU and Greek legislation and it stores your personal data with safety. We have physical and electronic procedures (technical and organisational measures) to secure and protect the information we collect and process. We check the response and sufficiency of these procedures at regular intervals.

However, please keep in mind that no data transmission is guaranteed to be 100% secure. If you believe your privacy has been breached, please contact us without delay by sending us an email at dpo@hellenica.gr.

Location of Processing and Storage of Data

The personal data we collect are stored and processed at our offices in Greece and the EU and in any data processing facilities operated by[ΕΚ3] [LF4] the third parties identified below.

You agree to the transfer, storing or processing of your data by us, by submitting your personal data to us. If your information is transferred or stored outside of the EU or the EEA in this way, we will take steps to ensure that your privacy rights continue to be protected as outlined in this Privacy Policy.

Any personal data stored by us will be deleted within five (5) years of its collection. Some of the data stored in cookies and similar technologies can be retained for even shorter periods of time. We may however keep your personal data longer in order to exercise or defend a legal claim or in case we are obliged by a legal provision to do so.
With regard to the email addresses kept for promotional purposes we may keep them for longer periods but you can unsubscribe anytime, in which case we will continue to hold such information only for the purpose of not sending you undesired communications.

Please note that while the above retention policy applies to personal data collected or stored by us, it may not apply to third parties who may have access to your personal data. You can learn more about third parties bellow, in the section “Third Parties and Sharing Your Information”.

Your Rights

1. You have the right to access information we hold about you. You can contact us and we shall inform you about:
· the categories of data we’re processing
· the purposes of data processing
· the categories of third parties to whom the data may be disclosed
· how long the data will be stored (or the criteria used to determine that period)
· other rights you have regarding our use of your data

We can also send you a copy of these information, if you wish.

2. You have the right to ask us to correct personal data about you if they are inaccurate or incomplete.

3. You can object to us using your data for profiling you or making automated decisions about you. We can deny your request if such processing is necessary for us and you to enter into a contract or perform our obligations arising out of such contract, or when such processing is authorized in law or when you have provided explicit consent to such processing. Please note that exercising this right does not equal to an obligation on our behalf to not show advertisements at all. Currently, we do not have such functions installed at our website.

4. You have the right to ask us to directly transfer your data to another service, as long as it is technically feasible or to provide you a copy in a common machine-readable format.
Please note that if such data also contain personal data about another person, we may not choose to include such data in our deliverables.

5. You have the right to request to be ‘forgotten’ (i.e. that we erase your personal data)
All you have to do is ask and we will delete your data unless we have another legal reason to retain your personal data or continue to process them without restriction (such as a legal claim or a regulatory requirement).

6. You can ask us not to use your data for direct marketing purposes or when we process your personal data for our legitimate interests or for statistical purposes. With the exception of direct marketing we can however reject your request if we have strong reasons to continue processing your data which override your objection (ex. exercise a legal claim).

7. You have the right to request that we restrict the processing of your personal data in the following circumstances:
a. When you are contesting the accuracy of your personal data and while we are verifying the accuracy of the data;
b. When you believe that your data has been unlawfully processed and you oppose their erasure;
c. When we would no longer need the personal data but you need us to keep them so that you can exercise or defend a legal claim; or
d. When you have objected to the processing of your data and while we are considering whether your legitimate grounds override those of the individual.
8. You can file a complaint regarding our use of your data to the Hellenic Data Protection Authority.

Please tell us first and we would be happy to address your concerns. If you insist on contacting the Hellenic Data Protection Authority, you can find out how to reach them and exercise your rights at their website (www.dpa.gr)

You can exercise all the aforementioned rights (with the exception of 8.) by contacting our Data Protection Officer via email at dpo@hellenica.gr. We may need to verify you before processing your request and thus require your ID or other appropriate documentation. We shall address your request within thirty (30) days of its receival, unless it is too complicated or we are dealing simultaneously with too many such requests. In the latter case it may take us up to two (2) additional months to address your request, but we will let you know so within thirty (30) days of reception of your initial request.

Third Parties and Sharing Your Information [ΕΚ5] [LF6]

As with most websites and e-shops, we often have to use the services of third parties in order to be able to keep monrevecosmetics.com up and running, to provide our Website’s services and in order to be able to perform all its functions already explained above.

These third parties help us manage our database, maintain our services, process data, distribute email and text messages, analyse the performance of our Website, gain valuable insights, improve our marketing practices, facilitate the fulfilment of your orders and make it easier for you to share our content on social media, etc.

To that extent, sometimes it is necessary for us to share your data with them in order to get these services to work well.

Below you can find our main third-party service providers with which we may be sharing your personal information. Please note that the countries mentioned bellow are relevant to services provided by them in the EU or the EEA.

Payment Processors
In order for your orders to be fulfilled, your payment is processed by appropriate payment processors. Currently these are Alpha e-Commerce by Alpha Bank (Greece), Masterpass by Mastercard (Belgium) and PayPal (Luxemburg). By using these payment service providers you explicitly agree to their terms for using these services.

You can learn more about the manner in which they shall process personal data, and what data they collect or we share with them, here:
https://www.alpha.gr/en/business/myalpha/e-commerce-e-payments/alpha-e-commerce (Alpha e-Commerce)
https://www.mastercard.us/en-us/about-mastercard/what-we-do/privacy.html (Masterpass by Mastercard)
https://www.paypal.com/gr/webapps/mpp/ua/privacy-full (PayPal)

Shipping/Delivery companies, DHL - Germany
In order to effectively fulfil and deliver your orders to you, we use the services of shipping and delivery companies such as DHL, a package delivery and supply chain management company.

You can learn more about the manner in which they shall process personal data, and what data they collect or we may share with them, here:
https://www.dhl.com/global-en/home/footer/global-privacy-notice.html

Servers/ Cloud Storage
In order to keep the website up and running we do need to co-operate with providers of server/ cloud storage mechanisms. We make sure that such providers are always located in the EU.

Social Media: Facebook and Instagram - Ireland
We use some of Facebook’s and Instagram’s services so that you can share our products on Facebook and connect with our Facebook and Instagram pages more easily. Please note that Instagram is owned by Facebook.

You can learn more about how they process personal data and what data they collect or we may share with them at the following websites:
www.facebook.com/about/privacy (Facebook)
https://help.instagram.com/519522125107875 (Instagram)

You can find their Cookie Policies here:
https://www.facebook.com/policies/cookies (Facebook)
https://www.facebook.com/help/instagram/1896641480634370 (Instagram)

Twitter - Ireland
We use some of Twitter’s services so that you that you can share our products on Twitter more easily.
You can learn more about how Twitter processes personal data and what data it collects or we may share with Twitter at the following website:
https://twitter.com/en/privacy

Pinterest - Ireland
We use some of Pinterest’s services so that you that you can share our products on Pinterest more easily.
You can learn more about how Pinterest processes personal data and what data it collects or we may share with Pinterest at the following website:
https://policy.pinterest.com/en/privacy-policy

Google (Analytics, Marketing Platform) - Ireland
We use Google Analytics in order to collect aggregated anonymized information about the use and performance of our website and Google Marketing Platform, which is a unified advertising and analytics platform, in order to achieve better and smarter results in marketing.

You can learn more about the manner in which they shall process personal data, and what data they collect or we share with them, here:
https://www.google.com/analytics/terms/us.html and here:
https://marketingplatform.google.com/about/.

You can find Google's general Terms here: https://policies.google.com/terms and you can also find out how Google in general processes personal data it may collect here:
https://policies.google.com/privacy.
You can always opt out from Google analytics by use of this tool https://tools.google.com/dlpage/gaoptout.

Newsletters: Moosend – United Kingdom
In order to be able to send our newsletters and informational emails to you, we make use of the services of Moosend, an email marketing platform.
You can find more information about Moosend here:
https://moosend.com/terms/

You can learn more about the manner by which Moosend shall processes personal data, and what data they collect or we share with them, here: https://moosend.com/privacy-policy/

If you disagree with the processing of personal data performed by any of the aforementioned third parties, we urge to refrain from using our website.

Your information and countries outside the EU or the EEA

Some of your information, as specified above (third parties and sharing your information), may be processed, transferred or stored outside of the EU or the EEA. To that extent, we take steps to ensure that your privacy rights continue to be protected as outlined in this Privacy Policy. We always elect to cooperate with best-in-field third parties, which might also have appropriate accreditation in relation to personal data protection. We also ask any third parties outside the EU or the EEA that have access to your personal data to provide us withappropriate safeguards for your information.

Cookie Policy

Like any other website, monrevecosmetics.com uses cookies. Cookies are small data files that are placed on your computer or mobile device when you visit a website. Cookies are unique to each web browser and are widely used to enable website functionality, efficiency or reporting. The information is used to optimize the users’ experience by customizing our web page content based on visitors’ browser type and/or other information. These may be "session" cookies, meaning they delete themselves when you leave monrevecosmetics.com, or "persistent" cookies, which do not delete themselves and help us recognise you when you return. They can be placed by the domain operating the website (first party) or by third parties. We use the following main types of cookies on monrevecosmetics.com:

▪ Necessary website cookies: these cookies are strictly necessary to provide you with services available through our Website and to use some of its features, such as access to secure areas.
▪ Security cookies: these cookies ensure our Website and services are protected from malicious activities.
▪ Site functionality cookies, which allow you to navigate our website and use features, such as placing an order on our online shop.
▪ Preference cookies, which will remember your preferences and details, so that your experience is more personal and streamlined (e.g. a cookie that enables us to remember your preferred language for our website).
▪ Website analytics cookies, which allow us to analyse how our customers use our site, in order to improve it (e.g. a Google analytics cookie of which you can always opt out via: https://tools.google.com/dlpage/gaoptout ).
▪ Targeting or advertising cookies: these cookies are used to deliver ads which might be relevant or useful to you.[ΕΚ7]

We can store cookies on your device, provided these are absolutely necessary for the operation of our Website. For all other types of cookies, we need your consent. You may change or withdraw your consent at any time through the relevant cookies tool on our Website.[ΕΚ8] [LF9] [ΕΚ10] Currently, the following cookies will be placed on your computer or mobile device when you visit our website:

FIRST PARTY COOKIES (placed by monrevecosmetics.com domain)[ΕΚ11] [LF12]

COOKIE NAME FUNCTION PURPOSE DURATION
cookieconsent_status Necessary Stores user’s permission to use cookies 1 year
csrftoken Security Protects against Cross Site forgery Attacks Session
sessionid Functional Stores session id 2 weeks
_cprid Functional Stores the country the user is located 6 months
oscar_history Functional Stores recently viewed product IDs 1 Week

THIRD PARTY COOKIES (placed by other domains)

COOKIE NAME FUNCTION PURPOSE DURATION THIRD PARTY
_ga Analytics (anonymous) Count and track pageviews 2 years Google Analytics
_gat_gtag_UA Analytics (anonymous) Store a unique ID 1 minute Google Analytics
_gid Analytics (anonymous) Count and track pageviews 1 day Google Analytics

By using monrevecosmetics.com, you agree to placing the aforementioned cookies on your device and accessing them when you visit the site in the future. However, you have the rights to accept, delete, block or reject cookies by modifying your browser settings accordingly. You can find out how by visiting websites such as http://www.allaboutcookies.org and https://cookies.insites.com/about-cookies/.

Managing the cookies of many companies used for online ads may be configured in the following websites.

Google Ads Settings:
https://www.google.com/ads/preferences/
Managing advertising companies' cookies for the EU:
https://www.youronlinechoices.com/
Managing advertising companies' cookies for the USA:
http://www.aboutads.info/choices

Please note that by deleting or disabling future cookies, your user experience may be affected and you might not be able to take advantage of certain functions of our website.

Information collected by third parties through links and their content

Our Website may include links to other websites and other content from third parties outside our control. We are not responsible for the security or privacy of the information collected by these third parties or the privacy practices of such third parties or the content on any third party website. We encourage you to review the privacy policies of these third parties if you visit their websites.

Will we update this privacy policy?

We may update this Policy from time to time in order to reflect changes in law, third party vendors, technologies we use etc.
Therefore, please re-visit this Policy regularly to stay informed.

Where can you get further information?

If you have any questions about our privacy policy, please email us at dpo@hellenica.gr or by post to:HELLENICA COSMETICS S.A., Digital Department, 7 Chimaras str., PO BOX 151 25, Marousi, Attica, GREECE (tel. +30 211 8804000, fax +30 210 6198840-9).