Definitions and interpretation
Collectively all information that you submit to VIL Skin Care Ltd. via the Website. This definition incorporates, where applicable, the definitions provided in the Data Protection Laws;
A small text file placed on your computer by this Website when you visit certain parts of the Website and/or when you use certain features of the Website. Details of the cookies used by this Website are set out in the clause below (Cookies);
Data Protection Laws
Any applicable law relating to the processing of personal Data, including but not limited to the Directive 96/46/EC (Data Protection Directive) or the GDPR, and any national implementing laws, regulations and secondary legislation, for as long as the GDPR is effective in the UK;
The General Data Protection Regulation (EU) 2016/679;
VIL Skin Care Ltd., or us
VIL Skin Care Ltd., a company incorporated in England and Wales with registered number 98 whose registered office is at Crawford Street, Marylebone, London, W1H 2HL;
UK and EU Cookie Law
The Privacy and Electronic Communications (EC Directive) Regulations 2003 as amended by the Privacy and Electronic Communications (EC Directive) (Amendment) Regulations 2011;
User or you
Any third party that accesses the Website and is not either (i) employed by VIL Skin Care Ltd. and acting in the course of their employment or (ii) engaged as a consultant or otherwise providing services to VIL Skin Care Ltd. and accessing the Website in connection with the provision of such services; and
The website that you are currently using, http://www.vilskincare.com, and any sub-domains of this site unless expressly excluded by their own terms and conditions.
- the singular includes the plural and vice versa;
- a reference to a person includes firms, companies, government entities, trusts and partnerships;
- "including" is understood to mean "including without limitation";
- reference to any statutory provision includes any modification or amendment of it;
- For purposes of the applicable Data Protection Laws, VIL Skin Care Ltd. is the "data controller". This means that VIL Skin Care Ltd. determines the purposes for which, and the manner in which, your Data is processed.
We may collect the following Data, which includes personal Data, from you:
- demographic information such as postcode, preferences, and interests;
- IP address (automatically collected);
- web browser type and version (automatically collected);
- operating system (automatically collected);
- internal URLs visited at vilskincare.com;
How we collect Data
We collect Data in the following ways:
- data is given to us by you; and
- data is collected automatically.
Data that is given to us by you
VIL Skin Care Ltd. will collect your Data in a number of ways, for example:
- when you contact us through the Website, by telephone, post, e-mail or through any other means;
- when you register with us and set up an account to receive our products/services;
- when you complete surveys that we use for research purposes (although you are not obliged to respond to them);
- when you enter a competition or promotion through a social media channel;
- when you make payments to us, through this Website or otherwise;
- when you elect to receive marketing communications from us;
Data that is collected automatically
To the extent that you access the Website, we will collect your Data automatically, for example:
- We automatically collect some information about your visit to the Website. This information helps us to make improvements to Website content and navigation and includes your IP address, the date, times and frequency with which you access the Website and the way you use and interact with its content.
- We will collect your Data automatically via cookies, in line with the cookie settings on your browser. For more information about cookies, and how we use them on the Website, see the section below, headed "Cookies".
Our use of Data
Any or all of the above Data may be required by us from time to time in order to provide you with the best possible service and experience when using our Website. Specifically, Data may be used by us for the following reasons:
- internal record keeping;
- improvement of our products/services;
- transmission by email of marketing materials that may be of interest to you;
We may use your Data for the above purposes if we deem it necessary to do so for our legitimate interests. If you are not satisfied with this, you have the right to object in certain circumstances (see the section headed "Your rights" below).
- For the delivery of direct marketing to you via e-mail, we'll need your consent, whether via an opt-in or soft-opt-in:
- soft opt-in consent is a specific type of consent which applies when you have previously engaged with us (for example, you contact us to ask us for more details about a particular product/service, and we are marketing similar products/services). Under "soft opt-in" consent, we will take your consent as given unless you opt-out.
- for other types of e-marketing, we are required to obtain your explicit consent; that is, you need to take positive and affirmative action when consenting by, for example, checking a tick box that we'll provide.
- if you are not satisfied about our approach to marketing, you have the right to withdraw consent at any time. To find out how to withdraw your consent, see the section headed "Your rights" below.
When you register with us and set up an account to receive our services, the legal basis for this processing is the performance of a contract between you and us and/or taking steps, at your request, to enter into such a contract.
We may use your Data to show you VIL Skin Care Ltd. adverts and other content on other websites. If you do not want us to use your data to show you VIL Skin Care Ltd. adverts and other content on other websites, please turn off the relevant cookies (please refer to the section headed "Cookies" below).
Who we share Data with
We may share your Data with the following groups of people for the following reasons:
Keeping Data secure
We will use technical and organisational measures to safeguard your Data, for example:
- Access to your account is controlled by a password and a user name that is unique to you.
- We store your Data on secure servers.
- We are certified to HIPAA compliant software. This family of standards helps us manage your Data and keep it secure.
- Technical and organisational measures include measures to deal with any suspected data breach. If you suspect any misuse or loss or unauthorised access to your Data, please let us know immediately by contacting us via this e-mail address: email@example.com.
- If you want detailed information from Get Safe Online on how to protect your information and your computers and devices against fraud, identity theft, viruses and many other online problems, please visit www.getsafeonline.org. Get Safe Online is supported by HM Government and leading businesses.
- Even if we delete your Data, it may persist on backup or archival media for legal, tax or regulatory purposes.
You have the following rights in relation to your Data:
- Right to access - the right to request (i) copies of the information we hold about you at any time, or (ii) that we modify, update or delete such information. If we provide you with access to the information we hold about you, we will not charge you for this, unless your request is "manifestly unfounded or excessive." Where we are legally permitted to do so, we may refuse your request. If we refuse your request, we will tell you the reasons why.
- Right to correct - the right to have your Data rectified if it is inaccurate or incomplete.
- Right to erase - the right to request that we delete or remove your Data from our systems.
- Right to restrict our use of your Data - the right to "block" us from using your Data or limit the way in which we can use it.
- Right to data portability - the right to request that we move, copy or transfer your Data.
- Right to object - the right to object to our use of your Data including where we use it for our legitimate interests.
To make enquiries, exercise any of your rights set out above, or withdraw your consent to the processing of your Data (where consent is our legal basis for processing your Data), please contact us via this e-mail address: firstname.lastname@example.org.
If you are not satisfied with the way a complaint you make in relation to your Data is handled by us, you may be able to refer your complaint to the relevant data protection authority. For the UK, this is the Information Commissioner's Office (ICO). The ICO's contact details can be found on their website at https://ico.org.uk/.
It is important that the Data we hold about you is accurate and current. Please keep us informed if your Data changes during the period for which we hold it.
Transfers outside the European Economic Area
- Data which we collect from you may be stored and processed in and transferred to countries outside of the European Economic Area (EEA). For example, this could occur if our servers are located in a country outside the EEA or one of our service providers is situated in a country outside the EEA.
- We will only transfer Data outside the EEA where it is compliant with data protection legislation and the means of transfer provides adequate safeguards in relation to your data, eg by way of data transfer agreement, incorporating the current standard contractual clauses adopted by the European Commission, or by signing up to the EU-US Privacy Shield Framework, in the event that the organisation in receipt of the Data is based in the United States of America.
- To ensure that your Data receives an adequate level of protection, we have put in place appropriate safeguards and procedures with the third parties we share your Data with. This ensures your Data is treated by those third parties in a way that is consistent with the Data Protection Laws.
Links to other websites
Changes of business ownership and control
- We may also disclose Data to a prospective purchaser of our business or any part of it.
- In the above instances, we will take steps with the aim of ensuring your privacy is protected.
- All Cookies used by this Website are used in accordance with current UK and EU Cookie Law.
- Before the Website places Cookies on your computer, you will be presented with a message bar requesting your consent to set those Cookies. By giving your consent to the placing of Cookies, you are enabling VIL Skin Care Ltd. to provide a better experience and service to you. You may, if you wish, deny consent to the placing of Cookies; however certain features of the Website may not function fully or as intended.
This Website may place the following Cookies:
Type of Cookie
These allow us to recognise and count the number of visitors and to see how visitors move around our website when they are using it. This helps us to improve the way our website works, for example, by ensuring that users are finding what they are looking for easily.
These cookies record your visit to our website, the pages you have visited and the links you have followed. We will use this information to make our website and the advertising displayed on it more relevant to your interests. We may also share this information with third parties for this purpose.
- You can find a list of Cookies that we use in the Cookies Schedule.
- You can choose to enable or disable Cookies in your internet browser. By default, most internet browsers accept Cookies but this can be changed. For further details, please consult the help menu in your internet browser.
- You can choose to delete Cookies at any time; however you may lose any information that enables you to access the Website more quickly and efficiently including, but not limited to, personalisation settings.
- It is recommended that you ensure that your internet browser is up-to-date and that you consult the help and guidance provided by the developer of your internet browser if you are unsure about adjusting your privacy settings.
- For more information generally on cookies, including how to disable them, please refer to aboutcookies.org. You will also find details on how to delete cookies from your computer.
- Unless otherwise agreed, no delay, act or omission by a party in exercising any right or remedy will be deemed a waiver of that, or any other, right or remedy.
- This Agreement will be governed by and interpreted according to the law of England and Wales. All disputes arising under the Agreement will be subject to the exclusive jurisdiction of the English and Welsh courts.
Below is a list of analytical, performance and targeting cookies that we use. We have tried to ensure this is complete and up to date, but if you think that we have missed a cookie or there is any discrepancy, please let us know.
We use the following analytical/performance cookies:
Description of Cookie
To help us analyse how our visitors interact with vilskincare.com.
To directly communicate with our visitors and provide recommendations in line with their geographic locales and real-time URL browsing activities.
The above privacy and cookie policies are revised as of the 25th May 2018.
SECTION 1 - What do we do with your information?
- When you purchase something from our website, as part of the buying and selling process, we collect the personal information you give us such as your name, address and email address.
- When you browse our website, we also automatically receive your computer’s internet protocol (IP) address in order to provide us with information that helps us learn about your browser and operating system.
- Email marketing (if applicable): With your permission, we may send you emails about our website, new products and other updates.
SECTION 2 - Consent
How do you get my consent?
- When you provide us with personal information to complete a transaction, verify your credit card, place an order, arrange for a delivery or return a purchase, we imply that you consent to our collecting it and using it for that specific reason only.
- If we ask for your personal information for a secondary reason, like marketing, we will either ask you directly for your expressed consent, providing you the opportunity to opt-out.
How do I withdraw my consent?
- If after you opt-in you change your mind, you may withdraw your consent for us to contact you for the continued collection, use or disclosure of your information at anytime, by contacting us at email@example.com or mailing us at: VIL Skin Care, 98 Crawford Street, London, W1H 2HL, United Kingdom.
SECTION 3 - Disclosure
We may disclose your personal information if we are required by law to do so or if you violate our Terms of Service
SECTION 4 - Shopify
- Our store is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell our products and services to you.
- Your data is stored through Shopify’s data storage, databases and the general Shopify application. They store your data on a secure server behind a firewall.
- If you choose a direct payment gateway to complete your purchase, then Shopify stores your credit card data. It is encrypted through the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction data is stored only as long as is necessary to complete your purchase transaction. After that is complete, your purchase transaction information is deleted.
- All direct payment gateways adhere to the standards set by PCI-DSS as managed by the PCI Security Standards Council, which is a joint effort of brands like Visa, MasterCard, American Express and Discover.
- PCI-DSS requirements help ensure the secure handling of credit card information by our store and its service providers.
SECTION 5 - Third-Party Services
- In general, the third-party providers used by us will only collect, use and disclose your information to the extent necessary to allow them to perform the services they provide to us.
- However, certain third-party service providers, such as payment gateways and other payment transaction processors, have their own privacy policies in respect to the information we are required to provide to them for your purchase-related transactions.
- For these providers, we recommend that you read their privacy policies so you can understand the manner in which your personal information will be handled by these providers.
- In particular, remember that certain providers may be located in or have facilities that are located a different jurisdiction than either you or us. So if you elect to proceed with a transaction that involves the services of a third-party service provider, then your information may become subject to the laws of the jurisdiction(s) in which that service provider or its facilities are located.
- As an example, if you are located in Canada and your transaction is processed by a payment gateway located in the United States, then your personal information used in completing that transaction may be subject to disclosure under United States legislation, including the Patriot Act.
When you click on links on our store, they may direct you away from our site. We are not responsible for the privacy practices of other sites and encourage you to read their privacy statements.
SECTION 6 - Security
- To protect your personal information, we take reasonable precautions and follow industry best practices to make sure it is not inappropriately lost, misused, accessed, disclosed, altered or destroyed.
- If you provide us with your credit card information, the information is encrypted using secure socket layer technology (SSL) and stored with a AES-256 encryption. Although no method of transmission over the Internet or electronic storage is 100% secure, we follow all PCI-DSS requirements and implement additional generally accepted industry standards.
Here is a list of cookies that we use. We’ve listed them here so you that you can choose if you want to opt-out of cookies or not.
- _session_id, unique token, sessional, Allows Shopify to store information about your session (referrer, landing page, etc).
- _shopify_visit, no data held, Persistent for 30 minutes from the last visit, Used by our website provider’s internal stats tracker to record the number of visits
- _shopify_uniq, no data held, expires midnight (relative to the visitor) of the next day, Counts the number of visits to a store by a single customer. cart, unique token, persistent for 2 weeks, Stores information about the contents of your cart.
- _secure_session_id, unique token, sessional
- storefront_digest, unique token, indefinite If the shop has a password, this is used to determine if the current visitor has access.
SECTION 7 - Age of consent
By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
- If our store is acquired or merged with another company, your information may be transferred to the new owners so that we may continue to sell products to you.
If you would like to access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact our Privacy Compliance Officer at firstname.lastname@example.org or by mail at the following address:
VIL Skin Care, 98 Crawford Street, London, W1H 2HL United Kingdom.