PRIVACY notice
UNITED STATES/ENGLISH
To access the Privacy Notice in more regions / languages, please click here: https://privacy.coty.com/fr_fr/
Last Modified: 5 November 2024
Introduction
Your privacy is important to Coty Inc. and its affiliates and subsidiaries ("Coty", "us", "our") and we are committed to protecting your personal information. For the purposes of this Privacy Notice ("Notice"), personal information means any information that could be used to directly or indirectly identify a particular individual, or as may otherwise be similarly defined under applicable data privacy law. This Notice relates to our use of your personal information when you:
Interact with us through social media or adverts and content on third party websites (collectively “Coty Content");
- Use our:
- Websites, microsites, or mobile applications;
- Services delivered by via voice activated devices and/or new technologies, such as virtual reality and augmented reality;
- Visit our offices, sites, salons or stores ("Coty Locations");
- Purchase products or services directly from Coty, including from the Coty Sites and Coty Locations; or
- Otherwise engage with us, for example by contacting Customer Services or consumer affairs, attending an education event, tradeshow or other Coty event.
This Notice explains who we are; what information we collect about you; how we use it (including who we share that information with); our use of cookies; and your rights and choices regarding your personal information. Unless otherwise defined in this Notice, capitalized terms used in this Notice have the same meaning as in our Terms of Use.
The relevant Coty entity that is responsible for your personal information will be the Coty entity that collected your personal information. We may share your personal information within our group, and other Coty entities may also use your personal information in accordance with this Notice.
Coty is home to iconic global and regional brands. More information about our associated brands can be found here (the “Coty Brands"). In some instances, this Notice will not apply to a Coty Brand and the relevant Coty Site will display a brand specific privacy notice. For those Coty Brands, you should refer to that privacy notice for more information about how it uses your personal information.
If you have any questions or concerns about our use of your personal information, then please contact us using the contact details provided in section "How do I contact Coty?" of this Notice.
Click on the relevant link below to expand that section
We encourage you to take the time to review this Notice in full to make sure you are fully informed. However, if you only want to access a particular section of this Notice, then you can click on the relevant link below to expand that section:
Coty is a world leading beauty company, making cosmetic, skincare, fragrances, hair color and styling brands. Our three divisions – Luxury, Professional Beauty and Consumer Beauty – are home to iconic global brands and much loved regional brands. Luxury is focused on prestige fragrances and skincare; Professional Beauty is focused on servicing salon owners and professionals in both hair and nail; and Consumer Beauty is focused on mass color cosmetics, mass retail hair coloring and styling products, body care and mass fragrances.
The personal information that we may collect about you broadly falls into the following categories:
- Information that you provide directly
When you engage with Coty, either online or in person, we may ask you to provide us with personal information about you. For example, we may ask you to provide us with your contact details to register an account with us, to sign up to receive our newsletters or information about our products or events; and/or to submit enquiries to us. You may also provide us with your personal information in other ways, such as if you contact us in relation to employment opportunities; purchase products or request free samples from us; communicate with us through social media, consumer affairs or our customer services teams; join a loyalty scheme or reward program, participate in our promotions, or interact with us at tradeshows or our other events. The personal information that you are asked to provide, and the reasons why you are asked to provide it, will be made clear to you at the point when we ask you to provide it; however we may collect:
- Identification and demographic information, for example your first name, last name, email address, postal address, employer, job function/title or department, date of birth, phone number, gender, country of residence, lifestyle/interests, appearance, style, login name, password, answers to security questions;
- Transaction information, for example details regarding your transactions with us, including information about the purchases you (or your employer) made and the date and time that you made the purchase;
- Information in connection with the performance of a contract, for example right to work information, information obtained from credit reference agencies or other background checks which are required for us to perform a contract we have with you or your employer;
- Images and photographs, for example if you submit a picture to a competition, the Coty Sites or to social media and tag Coty or a Coty Brand, or when you engage with Coty via technologies such as AR, face evaluation or other tools;
- Health Information, with your explicit consent, for example information related to product usage and medical history (such as heart rate, skin condition and other features) which may be provided as part of voluntary consumer research, product development and trials;
- Information you provide when you visit us, for example information you give us when you visit our offices by signing in or when you are recorded on CCTV installed at Coty Locations; and/or
- Your opinions or other information, for example if you review the products you have purchased from us, provide information about products and/or cosmetic concerns, and the brands and products you use or if you provide us with your CV when exploring your employment prospects with us.
- Information that we collect automatically
When you visit the Coty Sites, engage with Coty Content or with us digitally, we may collect certain information automatically from your computer, tablet or mobile phone (a “Device") by using automated technologies such as cookies. In some countries, including countries in the European Economic Area, this information is personal information under applicable data protection laws.
Specifically, the information we collect from you automatically may include your IP address, Device type (i.e. make and model), unique device identification numbers, browser-type, time zone settings, broad geographic location (e.g. country or city-level location) and other technical information. You may change your preferences at any time by adjusting the settings on your Device.
We may also collect information about how your Device has interacted with us, including the pages accessed and links clicked, how you navigate to and from the Coty Sites and Coty Content (such as how you scroll over the Coty Sites and Coty Content, which parts you click and how long you spend on each page), your preferences, the products and/or services that you have viewed or searched for, crashes, download errors and response times and any phone number or social media handle used to call or contact our customer services or consumer affairs teams.
Some of this information may be collected using cookies and similar tracking technology, as further explained under section "Does Coty use cookies and other similar technologies?" below.
- Information that we obtain from third party sources
From time to time, we may receive information about you from third party sources, but only where we have checked that these third parties either have your consent or are otherwise legally permitted or required to disclose your personal information to us.
The types of information we collect from third parties includes:
- Our social media partners, for example if you ‘log-in’ to our Coty Sites using a Social Site (as defined in the "What if I access or use a social network or public forum through a Coty Site?" section of this Notice), use the social plug-ins, such as “like” or “share”, that Social Site may pass information to us, including: the user ID for that third party site, the name, email address and location associated with the user ID and any other information permitted under the privacy policy for that website. We may also share information about you to that social networking site regarding your login. More information about accessing or using a Social Site can be found in the section "What if I access or use a social network or public forum through a Coty Site?"
- Our retailers, distributors and third party brand partners, for example where permitted by applicable data protection law and if applicable where you have specifically consented, may pass information to us including your first name, last name, email address, postal address, phone number, gender, browsing patterns, geo-location and device identifiers, click through and other cookie data, demographic information including information about your appearance (including hair color, hair characteristics; and hair-care routine) and information in relation to products purchased at their stores (whether on the high-street or online through their own website or a dedicated microsite) and services requested using their websites and/or applications.
- Our technology partners and market research organizations, for example where permitted by applicable data protection law and if applicable where you have specifically consented, may share information with us, including your browsing patterns, geo-location and device identifiers.
- Information that you provide directly
We will use your personal information for the purposes set out in this Notice, which will include:
- To provide you with the products and services that you (or your employer) have requested, to administer our relationship with you (or your employer) and to carry out our obligations arising from the relationship, including internal accounting and administration purposes, to process payment for purchases or other services and to create and manage the account.
- To verify your identity, for example we may use your date of birth to determine that you are old enough to use our services, or your email address to determine if you already have an account with the relevant Coty Site, or your job title and employer to confirm you are authorised to purchase any products or services on their behalf.
- To provide a personalized service, for example we use your information to provide you with personalized recommendations for our products that we think you might like, tailor Coty Content to better suit your interests or, at your request and where available, to offer personalized and customized products. We will also use your personal information across the Coty Sites to provide a seamless user experience.
- For analytics purposes, for example we may analyze your information including your location, products and/or services requested, age, time zone, IP address and URL visited, against our wider customer base for internal business purposes, such as generating statistics and developing marketing plans, to improve our services and products, the Coty Sites and Coty Content. We may also aggregate and de-identify your information to create customer segments and share with our licensees and partners.
- To provide you with marketing communications that you might be interested in, for example, if you choose to receive marketing communications from us, we may use your information to keep you up to date with our latest products, services, surveys, announcements, upcoming events, sweepstakes, contests and other promotions and competitions via our newsletters, emails, or other communications. If you no longer wish to receive these marketing communications, details of how to opt out are described in the section “How do I stop receiving marketing communications?"
- For tailored advertising, for example we, or with third party vendors, may use your information to provide you with tailored advertising on third party sites, including Social Sites. These advertisements are either: (i) “contextual" (meaning they are presented due to the webpage that you are viewing); or (ii) “behavioral advertising" or “interest based advertising" (i.e. where advertisements are shown to you based upon your interests which we have inferred from your information including demographic, geographic and interest-based data). We may use tailored advertising to specifically include or exclude individuals who have registered for our products and services to ensure that you are provided with information about those products or services that are most relevant to you. To do this, we may track your browsing activity across different websites, different Devices and/or different applications. We may match your browsing activity on one Device, such as your mobile phone, with your browsing activity on another device, such as your tablet, to ensure our advertising is tailored to you. If you no longer wish to see tailored advertising, you may be able to amend your cookie preferences (see: section: "Does Coty use cookies and other similar technologies?"). In addition, some third party sites allow you to stop seeing advertisements from specific advertisers on that site, so you should also check your preferences on those websites.
- For non-marketing communications, for example we may use your personal information to communicate with you important information in relation to your account, the products or services you (or your employer) have requested or purchased from us or other non-marketing communications. This includes: (i) emailing you to verify your identity when you sign-up; (ii) emailing you where you have requested a password and/or username reset; (iii) notifying you that a particular service has been suspended for maintenance or terminated; (iv) letting you know that we have updated this Notice or our Terms of Use; or (v) providing details about or updates to any products or services that you have requested or purchased. We will never contact you to ask for your password. Please be careful if you receive any communications from people requesting this information.
- To provide the best service to our customers and consumers, for example, we may use your personal information to process and respond to your questions and/or inquiries.
- For site optimization and management, for example we may use your personal information provided to us to:
- administer the Coty Sites, Coty Content and our other digital offerings, including the services and products offered through those Coty Sites;
- ensure the security of our networks and of your information;
- customize your future visits to the Coty Sites and our other digital offerings based on your interests to ensure the most user-friendly online navigation experience;
- improve the Coty Sites and our other digital offerings (including to fix operational problems such as pages crashing and software bugs); and
- provide services to our partners such as tools, analyses, data and insights to see how their website or mobile applications are used.
- For product development and business development purposes, for example we will use information we collect from you to improve and develop new products and services.
- For fraud prevention and detection purposes and to protect and defend the rights and property of Coty, our employees and our business partners.
- For employment application purposes, for example, if you contact us in relation to your employment prospects we will use your personal information to consider you for current and future employment opportunities and to contact you with respect to employment opportunities at Coty that you have expressed interest in.
We are required to satisfy one or more of the reasons set out by applicable data privacy law before we can collect and use your personal information.
Generally, our legal basis for collecting and using the personal information described above will depend on the personal information concerned and the specific context in which we collect it. However, we will normally rely on the following reasons, where permitted by data privacy laws to collect and use your personal information:
What are the legal grounds?
What are they?
Performance of a contract
Using your information may be necessary for us to perform our obligations under a contract with you or with a view to entering into such a contract. For example, where you have: (i) requested services and/or products from us, we will need to use your information to provide those services and/or products that you have requested; or (ii) approached us in relation to employment opportunities, the collection and use of your personal information is necessary to enable us to offer you the job role, process your acceptance of the offer, on-board you as an employee and fulfil our obligations as an employer.
Compliance with our legal obligations
The collection and use of your personal information may be necessary to enable us to meet our legal obligations. For example, if you are a business customer we need to process your information to verify your identity and undertake necessary due diligence checks.
Pursuing our legitimate interests
Where such processing is not overridden by your rights and applicable to your location, we are permitted to use your personal information to pursue our legitimate interests, for example to operate the Coty Sites and our other digital offerings, to improve our products and services, the Coty Sites, Coty Content and our other digital offerings or to undertake marketing. We may have other legitimate interests and if appropriate we will make this clear to you at the relevant time.
Consent
We may rely on your consent to collect and use your personal information. For example, we may rely on consent where you have approached us in relation to employment opportunities and have provided us with sensitive personal information, such as information in relation to your racial and ethnic origin, sexual orientation, religion, physical and mental health, disabilities or trade union membership.
If we rely on consent, this will be made clear to you at the time we request your information. You can withdraw your consent at any point by using the mechanism provided at the time, or by contacting us using the contact details provided in the section “How do I contact Coty?” of this Notice.
Vital interests
In some instances, we may need to use your personal information to protect your vital interests or those of another person, if this legal basis is applicable to your location.
You may not always be required to provide the personal information that we have requested. However, if you choose not to provide certain information, you may not be able to take advantage of some of our services. Any information that is so required is clearly marked as mandatory. If you would prefer that we do not collect certain personal information from you, please do not provide us with any such information, or opt out of providing this information where applicable.
If we ask you to provide personal information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your personal information is mandatory or not (as well as of the possible consequences if you do not provide your personal information).
If we collect and use your personal information in reliance on our legitimate interests (or those of any third party), these interests will normally be as set out in this Notice; however, if this changes we will make clear to you at the relevant time what those legitimate interests are.
If you have any questions or need further information concerning the legal basis on which we collect and use your personal information, please contact our Data Protection Team. Details for how to contact our Data Protection Team can be found in the section “How do I contact Coty?"
When you access the Coty Sites, view or interact with Coty Content or otherwise communicate with us digitally, Coty and our partners may place small data files on your Device, known as "cookies", to collect and use personal information about you, including to serve interest-based advertising. In order to opt out of interest-based advertising, please visit optout.networkadvertising.org and the DAA WebChoices Tool (for mobile apps). To learn more about cookies and other similar technologies, including how to amend your cookie settings, please refer to our Cookie Notice. Please also note that we do not respond to or honor “do not track" (a/k/a/ dnt) signals or similar mechanisms transmitted by web browsers.
When you: (i) sign-in to our Coty Sites using a Social Site or other websites; (ii) access Social Sites using the Coty Sites or other websites; and/or (iii) submit content to Social Sites or other websites using a Coty Site, that Social Site or other website may use cookies and similar technologies to collect data about user behavior for their own purposes. This use of cookies is in line with that third party’s own cookie policy, over which we have no control.
Please see section “What if I access or use a social network or public forum through a Coty Site?" for further information.
During the past 12 months, we may have disclosed the categories of personal information listed in the section marked “What information does Coty collect about me?” to the following categories of recipients listed below:
- Within the Coty Group: We may make your personal information available to other entities within the Coty Group, including those entities listed on our website, to allow us to provide our services to you, for the purposes described in this Notice, or as notified to you when we collect your personal information.
- With third parties for marketing purposes: Certain promotions and events run by third parties and sponsored by Coty may offer you the opportunity to consent to receive marketing communications from Coty’s business partners such as Coty’s licensors or promotion co-sponsors. If you have given your consent, your personal information may be used by such third party for the purposes stated at the point you enter the event and/or sign-up to receive the promotional updates.
- With our service providers: Coty engages third party service providers to perform functions on Coty’s behalf (for example, to support the delivery of our products, or the Coty Sites). This includes but is not limited to sharing information with the following types of service providers:
- advertising providers – including companies that provide: (i) advertising space for Coty; (ii) the provision of advertising related services, including agencies instructed to make advertising purchases on behalf of Coty, providers of ad-exchanges (a digital marketplace to buy and sell advertising space) and providers of a demand-side platform (software used to purchase advertising in an automated fashion), such as DoubleClick from Google;
- providers of marketing and customer relationship management databases and data management platforms – that enable Coty to manage your information in a safe and efficient manner;
- data analyses firms – that provide insights and help us to analyze trends using the data that we and they hold;
- customer support specialists – that provide customer support services on our behalf for Coty’s products and services;
- fulfillment companies – this includes companies that coordinate email campaigns, sweepstakes, contests or promotions on our behalf;
- application development and web-hosting companies – to enable the Coty Sites to be hosted on the internet;
- information technology and related infrastructure providers;
- email delivery providers;
- credit reference agencies - for the purpose of assessing your or your employer’s credit score whether this is in the context of us entering into a contract with you or the person that you work for;
- payment processing providers - who provide secure processing services; and
- audit and professional service providers.
- As part of a business transfer: Coty may disclose your personal information to an actual or potential buyer (and its agents and advisers) in relation to any actual or proposed divestiture, merger, acquisition, joint venture, bankruptcy, dissolution, reorganization, or any other similar transaction or proceeding. If in connection with any business transfer Coty sells all or substantially all of its assets to a third party, any personal information held by us will be one of the transferred assets.
- To comply with laws: Coty may disclose your personal information to any competent law enforcement body, regulatory, government agency, court or other third party where we believe disclosure is necessary (i) as a matter of applicable law or regulation, (ii) to exercise, establish or defend our legal rights, or (iii) to protect your vital interests or those of any other person.
- To any other person with your consent to the disclosure.
Depending on where you live and subject to applicable data protection law, you may also have the following rights:
- The right to request access to personal information that we collect, use, disclose and sell, which enables you to receive confirmation as to whether or not we are processing your personal information and access to such personal information.
- The right to change and/or correct inaccurate personal information;
- The right to request that we delete your personal information in certain circumstances;
- The right to block or suppress the processing of your personal information;
- The right to object to our processing of your personal information (including any processing for direct marketing purposes). More information on how to stop receiving direct marketing can be found in the section marked, “How do I stop receiving marketing communications?"
- The right to request portability of your personal information;
- The right to withdraw your consent, if applicable. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your personal information conducted in reliance on lawful processing grounds other than consent; and
If you exercise any of your data protection rights detailed in this section, we will not discriminate against you and we will not deny you goods or services, charge you a different price, or provide you with a lesser quality of goods or services.
We have a strict policy where we do not rent or sell your personal information. We can confirm that we have not sold any California residents’ personal information to third parties in the preceding 12 months.
You can exercise these rights by contacting us using any of the methods provided in the section “How do I contact Coty?" of this Notice. We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable data protection laws. In order to verify your identity and so that we can locate your personal information in our systems, we may require you to provide us with a copy of either your passport or driver’s licence when you make a request. In some circumstances, we may require additional documentation to verify your identity such as a utility bill to confirm proof of address and/or a customer reference number relating to your purchase and/or product you used.
You can exercise these rights yourself or designate an agent (such as a solicitor) to make a request on your behalf by executing a notarized power of attorney to enable that person to act on your behalf.
If you have any questions or concerns about how we use your personal information, please do not hesitate to let us know. You also have the right to lodge any complaints with a relevant supervisory authority.
We will only send you marketing communications if you have agreed to this, or if we are otherwise permitted by law. If at any time you decide that you no longer wish to receive marketing communications from us, you may opt out by clicking on the relevant ‘unsubscribe’ link in the email you receive, by sending us an email, or by contacting us using the contact details in section "How do I contact Coty?" of this Notice. Please Note, whilst we will honor your request to stop receiving marketing communications, we will continue to send you service-related communications such as emails confirming purchases through the Coty Sites and keep your information for record keeping purposes.
We will retain your information where we have an ongoing legitimate business need to do so (for example, to provide you with access to the Coty Sites or other digital offerings, to provide you with a product you have purchased, or to comply with applicable legal, tax, or accounting requirements).
When we have no ongoing legitimate business need to process your personal information, we will either delete or anonymize it or, if this is not possible (for example, because your personal information has been stored in backup archives), then we will securely store your personal information and isolate it from any further processing until deletion is possible.
As an international entity, in order to provide our services we may need to transfer and process your personal information internationally (including to destinations outside the European Economic Area (the “EEA") and the UK), notably throughout the Coty Group and to the jurisdictions in which those entities are based listed on our website. This means that when we process your personal information we may process it in any of these countries.
As a result, your information may be transferred to and/or processed in countries which may not guarantee the same level of protection for personal information as the country in which you reside. However, we have taken appropriate safeguards to ensure that your personal information will remain protected in accordance with this Notice. This includes implementing the European Commission's Standard Contractual Clauses for transfers of your personal information between our group companies, which require all group companies to protect personal information that they process from the EEA in accordance with European Union data protection law.
Further information can be provided on request: please contact us using the details found in the section “How do I contact Coty?" We have also implemented similar appropriate safeguards with our third party service providers and partners and further details can be provided upon request.
We understand that you care how your personal information is used and/or shared with others, and we value your trust and seek to safeguard your personal information.
We implement appropriate technical and organizational security measures, including physical, administrative and technical safeguards to protect your personal information from loss, theft, unauthorized access, use, copying, modification or disclosure. To ensure the security of your personal information, we communicate our privacy and security guidelines to all Coty employees and enforce privacy safeguards within our company.
The measures we use to protect your personal information are designed to provide a level of security appropriate to the risk of processing your personal information. However, please be aware that no electronic transmission of information can be entirely secure. We cannot guarantee that the security measures that we have in place to safeguard personal information will never be defeated or fail, or that those measures will always be sufficient or effective.
As described above, the Coty Sites may contain links to and from other third-party websites and services (collectively, “Third Party Sites") that are not controlled and operated by us.
Please be aware, we have no control over the content, policies or actions of these Third Party Sites. Your use of these Third Party Sites is at your own risk and we do not accept any responsibility or liability for the privacy practices of these Third Party Sites. We encourage you to read the privacy policies and terms of use of each Third Party Site to which you link from the Coty Sites.
The Coty Sites may facilitate easy access to certain social networking Third Party Sites and other websites or services with user-generated content features, such as Facebook, Instagram and Twitter (“Social Sites"). You understand that we do not control such services and are not liable for the manner in which they operate. Please review the Social Sites’ privacy policies if you would like more information about how they collect, use and share your data, your privacy rights and how to change your privacy settings.
The Coty Sites may enable you to:
- Access Social Sites: this may include: access to websites such as a Coty Brand’s YouTube video; or activation of third party websites when you make a ‘comment’, ‘share’ or ‘like’ something on the Coty Sites using a third party social network plug-in. In each instance, such third party’s privacy policy will apply to your interaction with that website or service;
- Submit content to Social Sites: for reviews, discussion forums, message boards, photographs and other public features (“Public Forums"). We do not restrict the distribution of personal information that you voluntarily disclose in these Public Forums, so please be aware that any information you disclose there may be collected and used by Coty and others. For this reason, we encourage you to refrain from providing or sharing personal information about yourself in the Public Forums. Coty cannot prevent third parties from using such information in a way that may violate this Notice or applicable law;
- Accept certain cookies from the Coty Sites (for example “Facebook Pixels”): These types of cookies help us understand your activity including the Coty Content you see, whether or not you have a Social Site account and if you are logged into that account. This information helps us to show you Coty Content you might be interested in on the Social Sites and measure the effectiveness of the Coty Content.
- Sign-in to the Coty Site using a Social Site: for example, for a harmonized user experience. Signing-in using a Social Site or other third-party account may allow us to access information that you have given the Social Site permission to share. The sign-in feature may also transfer information to the Social Site or third party, such as your username or social media handle, to authenticate you. The Social Site or third party may also automatically collect information such as your IP address, information about your browser and device, and the web page address of the Coty Site. The sign-in feature may also place and read cookies from that third party that may contain a unique identifier the Social Site or other third party assigns to you. The functionality of and your use of the sign-in is governed by the privacy policy and terms of the Social Site.
We may also use any personal information you provide us with on our Sites, apps and/or devices (e.g. your name, email address, gender and phone number) to identify you on Social Sites in order to show you ads that are more relevant for you. While doing this, the Social Sites will not share your personal information with other parties and will delete the information promptly after the matching process is complete.
Our use of your personal information in relation to the Social Sites will be as set out in this Notice or as otherwise notified to you. Again, please note that Third Party Sites (including the Social Sites) may be under the control of a third party and we encourage you to familiarize yourself with the privacy policies and terms of use of each Third Party Site.
Coty and its preferred third party service providers or business partners may offer sweepstakes, contests, promotions and surveys (each, a “Promotion") through a Coty Site.
Where we do this, we will use your personal information as set out in this Notice, or as otherwise notified to you. However, in certain cases, a third party’s privacy policy may apply to any personal information that you provide in connection with such Promotion. Before entering any Promotion, we encourage you to check who is operating the Promotion in question, and the terms, conditions, policies and rules that apply to it.
To learn more about the terms and conditions that apply to Promotions being run by Coty, please refer to our Promotion Terms and Conditions.
You must be aged 13 or over to use the Coty Sites and our other digital offerings, or the applicable age in your country when you can legally consent to the use of your personal data.
We take your privacy very seriously and we understand the importance of taking extra precautions to protect the privacy and safety of children who use Coty’s products and services. We do not solicit or knowingly collect personal information from children under the age of 13 or applicable age for your country when you can legally consent to the use of your personal data. If we are made aware that we have received such information, or any information in violation of our policy, we will use reasonable efforts to locate and remove that information from our records.
Specific provisions apply to Salon Owners that use our Coty Sites and our other digital offerings– these are described below.
Each time you submit information relating to a ‘new client’, ‘member of staff’ or other personal information, please make sure that the relevant individual: (i) is over the age of 13; (ii) is aware and if required, consented that you will be sharing their details with us and our processing in accordance with this Notice; and (iii) has, if applicable, consented to receiving marketing communications from us and our affiliates.
You may only share these details with us when using a Coty Site and/or our other digital offerings where you have made those individuals aware of our Notice and how we will use their personal information. If we become aware that you have submitted personal information to a Coty Site and/or any of our other digital offerings without permission, we will delete the information from our records.
We have Coty offices, warehouses, factories, salons and stores (“Coty Locations”) in many countries. If you visit a Coty Location we will collect your personal information for the following purposes:
- Visitor Information: For health and safety and security reasons, we maintain a register of visitors to Coty Locations, including your first and last name, your contact details including mobile number, your employer and your vehicle license plate number. We ask all our visitors to sign in and out at reception and may ask our visitors to show a form of identification which is used for verification purposes only and will not be recorded.
- CCTV System: Closed Circuit Television (CCTV) is installed at the entrances, exits and at other strategic locations at the Coty Locations. This is part of Coty’s commitment to ensuring a safe and secure environment for our employees and visitors. We may also use the footage to prevent and investigate crime. The images may be recorded and viewed by authorised individuals. The CCTV recorded data is stored for no longer than 90 days. We may retain it for longer if we have a legitimate reason to do so, for example where a crime is being investigated by police or law enforcement agencies.
CCTV outside some of the Coty Locations and in some public areas, for example reception areas, may not be operated by us and will be under the control of the relevant building landlord. Please consult their privacy notices for more information.
- Guest Wi-Fi: We have guest Wi-Fi available at many of the Coty Locations for the use of visitors. Where guest Wi-Fi is available we will provide you with a username and a password to log-in. We record the device address and will automatically allocate you an IP address whilst on site. We also log your traffic information including the sites you visited, duration and date sent/received. When you join our guest Wi-Fi we ask you to agree to Coty’s terms to use it responsibly and not to visit inappropriate websites. The purpose for processing this information is to provide you with access to the Internet whilst visiting the Coty Locations. We process this personal information when necessary for the purpose of our legitimate interest.
- Access Control System: As a visitor or contractor, we may issue you with an ID card to access the Coty Location. If we do issue you with an ID card then we will collect your first and last name, your address, your contact details and a photograph. We collect this personal information for the purposes of recording and controlling access in and out of our office and for security purposes.
- Accidents and Incidents: Coty will collect personal information from anyone injured or suffering from ill health whilst visiting a Coty Location. We may collect name, address, age, next of kin and details of the incident including any relevant medical history. We collect this data as we have a legal duty to document workplace incidents/accidents and to report certain types of accidents, injuries and dangerous occurrences arising out of work activities to the relevant enforcing authority. We will use the personal information collected to investigate and improve our health and safety procedures, and to support any legal claims arising from the incident.
We may update or modify this Notice from time to time in response to changing legal, technical or business developments. We will obtain your consent to any material Notice changes if and where this is required by applicable data protection laws. The date of the most recent version of this Notice will appear at the top of the page.
When we update our Notice, we will take appropriate measures to inform you, consistent with the significance of the changes we make. For example, we will notify you of any changes to this Notice by posting a new Notice and updating the “last modified" date at the top of this page or by sending the new Notice to you via email, where appropriate.
These supplementary terms describe how Coty collects and uses your personal information whilst using the Virtual Try-On or Shade-Finder service (“the Service”).
- What personal information do we collect and for what purpose?
With your consent, Coty may process your personal information through your use of the Services.
Some of that personal information may be considered biometric information, biometric identifiers, or biometric data in some jurisdictions.
The method by which Coty processes biometric information, the biometric information that is processed, and the purpose of processing depends on the type of Service you are using:
Hand Scan: The Nail Virtual Try On service uses a camera to collect an image of your hand for the purpose of applying virtual shades and/or colors to the users hand via augmented reality.
Face Scan: The Make Virtual Try On & Foundation Shade Finder service uses a camera to take a photograph of your face for purposes of applying virtual shades and/or colors to the users face via augmented reality.
Skin Tone Scan: The Skin Diagnostic service uses a camera to collect an image of your skin for the purpose of detecting skin concerns and giving recommendations to address said concerns with products via augmented reality.
Once an image is taken by the Hand Scan, Face Scan, or Skin Tone Scan, the Service uses the information to apply the shade of the product you have selected and demonstrate the product application. The resulting images are illustrative only and actual product results will vary.
Personal information collected and its purpose depends on the channel of the Service being used (if available for your region) and is detailed in the following table:Purpose
Legal Basis
Categories of Data
Data Controller
Retention Period
Provision of the augmented reality service
Necessity for the performance of the services and consent from users
Hand/Face/Skin Tone scan taken by the users
Coty Inc.
Image is deleted once the application has closed on customer’s device
Sending the image
Necessity for the performance of the services and consent from users
Image taken by the users
Email address and full name of the users
Coty Inc.
30 days
User’s Email address for marketing and communications
Consent
Email address and full name
Coty Inc
3 years
- Who will process your personal information?
Coty will securely process your personal data, along with its other service providers, located within and outside of the European Economic Area or the United Kingdom. - For what purposes is your personal data processed?
The scan and any other images will be used to apply the shade/color to demonstrate the product result. Please note the images are indicative only and actual product results will vary. Email address will be used for marketing purposes at the consent of the user. - How long does Coty retain biometric information?
The information collected from the Hand Scan, Face Scan, or Skin Tone Scan shall be retained on the customer device until the application has been closed. - Will Coty share biometric information about me
With your consent, Coty and Coty’s service provider, Perfect Corp, may process the biometric information we collect in connection with your use of the Services. Coty and Perfect Corp may also disclose biometric information where required by applicable law or is in response to subpoenas, court orders, or other legal processes. Perfect Corp, Coty and other Coty service providers (on behalf of Coty) may also process personal information about you that is not considered biometric information. - What are my rights and how can I withdraw my consent?
You may have the right to withdraw your consent for our processing of biometric information about you.
If Coty is unable to fulfill your request to delete biometric information about you, you may appeal the decision through our contact is form available at https://coty.cotyconsumeraffairs.com/. Please include the words “Deletion Request Appeal” in the subject heading of your request. More information regarding the appeal process will be provide in our correspondence with you regarding the denial of your request. - Where can I find out more information and contact Coty with any questions?
Please see the ‘How do I Contact Coty?’ section.
- What personal information do we collect and for what purpose?
For California residents
If you are a resident of the state of California, this section addresses your rights under the California consumer privacy act of 2018 (“CCPA”). Any terms defined in the CCPA have the same meaning when used in this policy.
Use of personal information
We may use or disclose the personal information we collect for one or more of the business purposes indicated in this policy.
We will not collect additional categories of personal information or use the personal information we collected for materially different, unrelated, or incompatible purposes without providing you notice.
Share and/or Sale of personal information
For more information on how we share personal information, including the categories of third-parties with which we share personal information, please see the “Does Coty share my personal information with anyone?” section.
Under California law, we are required to tell you if we "sell" information. while we do not believe we engage in “selling” information, it is possible that certain of our sharing activities (as described above) may be viewed as a sale. you can opt out of this activity by referring to the “How do I contact Coty” section below.
We do not knowingly sell information of Californians under 16.
Your rights and choices
The CCPA provides consumers (California residents) with specific rights regarding their personal information. this section describes your CCPA rights and explains how to exercise those rights.
a. Right to access specific information and data portability rights
You have the right to request that we disclose certain information to you about our collection and use of your personal information over the past twelve (12) months. once we receive and confirm your verifiable consumer request, we will disclose to you:
- The categories of personal information we collected about you.
- The categories of sources for the personal information we collected about you.
- Our business or commercial purpose for collecting or selling that personal information.
- The categories of third parties with whom we share that personal information.
- The specific pieces of personal information we collected about you (also called a data portability request).
- If we disclosed your personal information for a business purpose, the business purpose for which personal information was disclosed, and the personal information categories that each category of recipient obtained.
b. Right to delete
You have the right to request that we delete any of your personal information that we collected from you and retained, subject to certain exceptions. Once we receive and confirm your verifiable consumer request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies.
c. Exercising your rights
To exercise the access, data portability, and deletion rights described above, please submit a verifiable consumer request to us by either:
- calling us at the appropriate number referenced in the “How do I contact Coty” section below
- By submitting your request via the contact us form at https://coty.cotyconsumeraffairs.com/
Only you, or a person registered with the California secretary of state that you authorize to act on your behalf, may make a verifiable consumer request related to your personal information. you may also make a verifiable consumer request on behalf of your minor child.
You may only make such a request for access or data portability twice within a 12-month period. the verifiable consumer request must provide sufficient information that allows us to reasonably verify you are the person about whom we collected personal information or an authorized representative, and describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it. if you are submitting on someone else’s behalf, we may ask for additional verification. this may include providing a signed letter verifying your right to make this request.
We cannot respond to your request or provide you with personal information if we cannot verify your identity or authority to make the request and confirm the personal information relates to you. Making a verifiable consumer request does not require you to create an account with us. We will only use personal information provided in a verifiable consumer request to verify the requestor’s identity or authority to make the request.
We endeavor to respond to a verifiable consumer request within forty-five (45) days of its receipt. if we require more time (up to 90 days), we will inform you of the reason and extension period in writing. We will deliver our written response electronically. any disclosures we provide will only cover the 12-month period preceding the verifiable consumer request’s receipt. the response we provide will also explain the reasons we cannot comply with a request, if applicable. For data portability requests, we will select a format to provide your personal information that is readily useable and should allow you to transmit the information from one entity to another entity without hindrance.
We do not charge a fee to process or respond to your verifiable consumer request unless it is excessive, repetitive, or manifestly unfounded. if we determine that the request warrants a fee, we will tell you why we made that decision and provide you with a cost estimate before completing your request.
Non-discrimination
We will not discriminate against you for exercising any of your CCPA rights.
California shine the light law
California civil code section 1798.83 permits users who are California residents to obtain from us once a year, free of charge, a list of third parties to whom we have disclosed personal information (if any) for direct marketing purposes in the preceding calendar year. If you are a California resident and you wish to make such a request, please refer to the or write us at: Coty DTC Holdings, LLC, attn: privacy issues, 350 5th avenue, 19th floor, New York, NY 10118-0110.
Notice at Collection
Categories of Service Providers or Third Parties
Personal Information Category
Business Purpose Disclosures
Sales
Sharing and Disclosure
Identifiers
Payment processing, marketing, delivery services, customer relationship management, web hosting, or data storage
None
Application Service Providers, Financial Service Providers, Website Hosting and/or IT Consultancy Service Providers, Marketing and promotion service providers, Data analysis service providers, Security Service Providers
Account information
Marketing, customer relationship management, or data storage
None
Application Service Providers, Financial Service Providers, Website Hosting and/or IT Consultancy Service Providers, Marketing and promotion service providers, Data analysis service providers, Security Service Providers
Protected Classification Characteristics and Sensitive personal information
Include but are not limited to race, age, marital status, religion, sexual orientation, gender identity and military or veteran status
None
Financial service providers, such as independent agents, brokerage firms, and insurance companies
Website hosting or information technology consulting service providers
Marketing and promotion service providers
Data analysis service providers
Legal service providers
Accounting service providers
Administrative service providers
Security service providers
Application service providers
Communications
Customer relationship management, or data storage
None
Financial service providers, such as independent agents, brokerage firms, and insurance companies
Website hosting or information technology consulting service providers
Marketing and promotion service providers
Data analysis service providers
Legal service providers
Accounting service providers
Administrative service providers
Security service providers
Application service providers
Internet network activity
Marketing, delivery services, customer relationship management, web hosting, or data storage
Remarketing, retargeting, and advertising providers
Application service providers,
Website hosting or information technology consulting service providers,
Marketing and promotion service providers,
Data analysis service providers,
Legal service providers,
Accounting service providers,
Administrative service providers,
Security service providers
Geolocation information
Marketing, customer relationship management, web hosting, or data storage
Remarketing, retargeting, and advertising providers
Application Service Providers, Accounting Service Providers, Financial Service Providers, Website or Hosting Service Providers, Marketing and promotion service providers, Data analysis service providers.
Audio/Visual Images
Facilitating the uploading to social media sites
None
Application Service Providers and Website or Hosting Service Providers.
California Do Not Track Disclosures
“Do Not Track” is a privacy preference that users can set in their web browsers. When a user turns on a Do Not Track signal in their browser, the browser sends a message to websites requesting that they do not track the user. For information about Do Not Track, please visit www.allaboutdnt.org
Notice of Financial Incentive
For California residents, you have a right to receive this Notice of Financial Incentive, as defined in the California Consumer Privacy Act (CCPA) of 2018, Civil Code §1798.100. This Notice is to provide you with information regarding any financial incentive or “price or service difference” that we may provide in exchange for your personal information.
In order to participate in our loyalty rewards program, you may provide personal information from time to time, directly or indirectly, in exchange for cash, gift cards, or other financial incentive, or price or service difference, the amount or nature of which will be specified in each instance at the time the personal information is to be submitted.
You can opt into our loyalty rewards program by completing the form on the brand site that is running the program. If you subsequently wish to withdraw/opt-out of our loyalty rewards program, you can do so by sending an email to the published email address.
Each financial incentive or price or service difference related to submission and use of consumer personal information is based on our reasonable but sole determination of the estimated value of such information, which takes into consideration, without limitation, estimates regarding the revenue generated from such information, the participated expenses which might be incurred in the collection, storage and use of such information in operation of our business, and other relevant factors related to the estimated value of such information to our business, as permitted under the CCPA.
COLORADO
Colorado law provides Colorado residents with the rights listed below.
Right to Access
You have the right to know and see what personal data we have collected about you in a usable format.
Right to Delete
You have the right to request that we delete the personal data we have collected about you, subject to applicable legal exceptions.
Right to Correct
You have the right to request that we correct inaccurate personal data.
Right to Opt Out of Targeted Advertising and Sale of Personal Data
You have the right to “opt out” of “targeted advertising” and the “sale” of your “personal data” (as defined under Colorado law).
Exercising your Colorado Privacy Rights
Requesting Access, Deletion or Correction requests
To make an access, deletion or correction request please refer to the section “How do I contact Coty” section below.
CONNECTICUT
Connecticut law provides Connecticut residents with the rights listed below.
Right to Access
You have the right to know and see what personal data we have collected about you in a usable format.
Right to Delete
You have the right to request that we delete the personal data we have collected about you, subject to applicable legal exceptions.
Right to Correct
You have the right to request that we correct inaccurate personal data.
Right to Opt Out of Targeted Advertising and Sale of Personal Data
You have the right to “opt out” of “targeted advertising” and the “sale” of your “personal data” (as defined under Connecticut law).
Exercising your Connecticut Privacy Rights
Requesting Access, Deletion or Correction requests
To make an access, deletion or correction request please refer to the section “How do I contact Coty” section below.
UTAH
Utah law provides Utah residents with the rights listed below.
Right to Access
You have the right to know and see what personal data we have collected about you in a usable format.
Right to Delete
You have the right to request that we delete the personal data we have collected about you, subject to applicable legal exceptions.
Right to Opt Out of Targeted Advertising
You have the right to “opt out” of “targeted advertising” (as defined under Utah law). We do not “sell” personal data as defined under Utah law.
Exercising your Utah Privacy Rights
Requesting Access, Deletion or Correction requests
To make an access, deletion or correction request please refer to the section “How do I contact Coty” section below.
VIRGINIA
Virginia law provides Virginia residents with the rights listed below.
Right to Access
You have the right to know and see what personal data we have collected about you in a usable format.
Right to Delete
You have the right to request that we delete the personal data we have collected about you, subject to applicable legal exceptions.
Right to Correct
You have the right to request that we correct inaccurate personal data.
Right to Opt Out of Targeted Advertising
You have the right to “opt out” of “targeted advertising” (as defined under Virginia law). We do not “sell” personal data as defined under Virginia law.
Exercising your Virginia Privacy Rights
Requesting Access, Deletion or Correction requests
To make an access, deletion or correction request please refer to the section “How do I contact Coty” section below.
If you have any questions regarding our privacy practices, how we handle your personal information and/or would like to submit a privacy request, please contact our Data Protection Team by either:
By phone using one of the following toll-free numbers depending on your location:
- North America - +1 800 715 4023
- South America - +55 0800 702 9966
- Europe –
- UK - +44 800 028 4177
- Ireland - +353 800 535 909
- Germany - +49 800 935 5243
- France - +33 17 098 4953
- Italy - +39 0645 212 094
- Spain - +34 91 787 6484
- Asia -
- China - +86 400 898 1919
- Japan - +81 120 308 168
- Singapore - +65 800 120 6249
- Australia - +61 800 021 085
By submitting your question via the contact us form, found via this link on the Coty website - https://coty.cotyconsumeraffairs.com/
Thank you for taking the time to read this Notice.