SECTION 1 – COLLECTION OF PERSONAL DATA
1.1 We may collect Personal Data from you through various means, including but not limited to instances when you
(1) Provide your Personal Data through our site for the purpose of registering for and creating an account
(2) Apply for a membership or account with our CYCPLUS Loyalty Program or access your existing membership status through the site
(3) Participate in a promotion or other website features;
(4) Request for a product or service information or to receive any marketing, promotional or other types of communications
(5) Provide your ratings and review of products as a customer
(6) Make purchases through our site
(7) Make inquiries or comments through our Customer Service Support through email or ticketing system or interact with our Sales Staff through email
1.2 In addition to the above, we may use the following technologies (elaborated below) to automatically collect information about your activities on the site, as the case may be (each a “Mobile Technology”): Cookies; Flash Cookies; Web beacons; clear pixels, or pixel tags; Analytical tags; Web server logs; Geo-location technologies. For more information about these Mobile Technologies and how they operate to collect information about you, you may refer to Section 9 of this Policy below.
1.3 You have no obligation to provide any of the Personal Data requested by us. However, depending on circumstances, it may be the case that if you do not provide the requested Personal Data, we may not be able to provide you with certain products and services or transact with you, that depend on the collection, use or disclosure of your Personal Data.
SECTION 2 - AGE OF CONSENT
2.1 By using this site, you represent that you are at least the age of majority in your state or province of residence, or that you are the age of majority in your state or province of residence and you have given us your consent to allow any of your minor dependents to use this site.
SECTION 3 – PURPOSES FOR COLLECTION, USE, DISCLOSURE AND PROCESSING OF PERSONAL DATA
3.1 CYCPLUS will/may collect, use, disclose and/or process your Personal Data for one or more of the following purposes or any other directly related purposes:
(1) Administering, facilitating, processing, and/or dealing in any matters relating to your use or access to the site. Without limiting the generality of the foregoing, if you gain access to or sign in to the site, using your login credentials of a Social Networking site, or use any features of a Social Networking site such as its widgets, plug-ins and browser push notifications, made available to you on our site, it may result in information or your Personal Data is collected or shared between us and the third party. For example, if you use Facebook’s “Like” feature, Facebook may register the fact that you “liked” a product and may post that information on Facebook. (“Social Networking Site” refers to an online or digital platform owned or operated by a third party, that is used by people to build social networks or social relations, or to interact, with other people, such as but not limited to Facebook, Instagram, Twitter). By your proceeding pursuant to above, you consent to such collection, use or disclosure of your Personal Data;
(2) Monitoring, processing and/or tracking your use of the site in order to provide you with a seamless experience, facilitating or administering your use of the Site, and/or to assist us in improving your experience in using the site;
(3) Assessing and processing your request for the purchase of and/or subscription to our products and/or services;
(4) Registering you as a customer of CYCPLUS and/or to deal with, process and/or administer the account that you may open with us, including to facilitate your transactions or activities on the site, or your transactions or activities with us;
(5) Administering, facilitating, processing, and/or dealing with your relationship with us, any transactions or activities carried out by you on the site. This includes processing your application, orders, and payment transactions; implementing transactions, and the supply of products and/or services to you that you have requested. Without limiting the generality of the foregoing, should you make a purchase to be delivered to a third party recipient, you consent to us disclosing Personal Data that identifies you, to the said third party recipient (such as but not limited to your name). Further, you acknowledge and agree that delivery of your purchase could involve the disclosure of certain Personal Data about you to bring about delivery of the same such as your name and contact details, which may be disclosed on the cover of the parcel, on an envelope or a delivery related document, as the case may be, which could be seen by third parties who view such parcel, envelope or said document;
(6) Carrying out your instructions or responding to any enquiry given by (or purported to be given by) you or on your behalf including responding to your customer service inquiries and complaints, or responding to or dealing with your interactions with us;
(7) Contacting you or communicating with you via phone/voice call, text message and/or fax message, email and/or postal mail for the purposes of administering and/or managing your use of the site, your membership and/or account with us, your relationship with us or any transactions made by you with us. You acknowledge and agree that such communication by us could be by way of the mailing of correspondence, documents or notices to you, which could involve the disclosure of certain Personal Data about you to bring about delivery of the same as well as on the external cover of envelopes/mail packages;
(8) Providing services to you as our account holder, as our customer, as a member of our loyalty programs or when requested by you; dealing with or administering your participation in contests, gamification, social events organized by us;
(9) Sharing or disclosing (at our discretion) your suggestions, comments, feedback or content (including audio, video etc.) (collectively “Feedback”) that you provide through Social Networking Sites, to the site or to us, with other users of the site or with the public, for publicity and/or promotion purposes with a view to marketing or showcasing the business of CYCPLUS, and/or to acquiring customers, and/or for the purpose of providing the public with your Feedback which may be useful for the public’s purchasing decision or for the public’s information or otherwise. This includes us disclosing your name together with your Feedback. Without limiting the generality of the foregoing, in the above regard, your Feedback and name may/will be published or shared by us on public media platforms such as the newspaper, the Internet, in our (including our affiliates’) annual reports (if any) etc., and/or incorporated as part of CYCPLUS’s marketing collaterals/materials or corporate video to be disclosed to the public, and you hereby consent to the same. Do not provide us with Feedback if you do not wish for such Feedback to be disclosed to the public. If you wish to give us your Feedback without it being disclosed to the public, please separately email our Customer Service Support. And head the subject of your email with the word “Confidential”;
(10) Where you have provided your consent to us, whether such consent was obtained through the site, or otherwise, sharing your Beauty Profile Personal Data with or disclosing your Beauty Profile Personal Data to other users of the site or with/to the public, through the Site or any other media (whether print, online or otherwise) or communication platform as we so choose, at our discretion, such as but not limited to as part of CYCPLUS’s marketing collaterals/materials or corporate video. “Beauty Profile Personal Data” includes your name, skin type/ concerns, eye color, hair color and type and other information which you provide;
(11) Carrying out due diligence or other screening activities (including background checks) in accordance with legal or regulatory obligations (whether Hong Kong or foreign country) applicable to us or our affiliates/associated companies, the requirements or guidelines of governmental authorities (whether Hong Kong or foreign country) which we determine are applicable to us or our affiliates/associated companies, and/or our risk management procedures that may be required by law (whether Hong Kong or foreign country) or that may have been put in place by us or our affiliates/associated companies;
(12) To prevent or investigate any fraud, unlawful activity or omission or misconduct, whether or not there is any suspicion of the aforementioned; dealing with and/or investigating complaints;
(13) Complying with or as required by any applicable law, court order, order of a regulatory body, governmental or regulatory requirements of any jurisdiction applicable to us or our affiliates/associated companies, including meeting the requirements to make disclosure under the requirements of any law binding on us or our affiliates/associated companies, and/or for the purposes of any guidelines issued by regulatory or other authorities (whether of Hong Kong or foreign country), with which we or our affiliates/associated companies are expected to comply;
(14) Complying with or as required by any request or direction of any governmental authority (whether Hong Kong or foreign country) which we are expected to comply with; or responding to requests for information from public agencies, ministries, statutory boards or other similar authorities (including but not limited to Hong Kong Customs and Ministry of Health) (whether Hong Kong or foreign country). For the avoidance of doubt, this means that we may/will disclose your Personal Data to such parties upon their request or direction;
(15) Conducting research (including customer research), surveys, market surveys, analysis and/or development activities (including but not limited to data analytics, surveys and/or profiling) to improve our services and facilities, or to improve our understanding of your interests, concerns, and preferences, in order to enhance any continued interaction between yourself and us connected or in relation to the site, or improve any of our products or services. Without limiting the generality of the foregoing, we may/will in this regard send you surveys or request a face to face interview survey, by way of email or postal mail;
(16) Storing, hosting, backing up (whether for disaster recovery or otherwise) of your Personal Data, whether within or outside Hong Kong;
(17) Facilitating, dealing with and/or administering external audit(s) or internal audit(s) of the business of CYCLUS or that of its affiliates/related corporations;
(18) For marketing purpose and in this regard, we would be providing you with marketing, advertising, and promotional information, materials and/or documents relating to products, contests, services and/or events(including those of third party organizations whom CYCPLUS may collaborate with as set out in paragraph 4.1 below) that CYCPLUS (including its affiliates/related corporations) or such third party organizations set out in paragraph 4.1 below may be selling, marketing, offering, organizing, involved in or promoting, whether such products, services and/or events exist now or are created in the future: (i) by way of postal mail, electronic transmission to your email address, push notifications, other forms of in-app/ site notifications or harnessing other technologies (such as geo-location technology) on your mobile device(s) or other technologies on your computers, and/or through other modes of communication that is not the 3 DNC Modes, in compliance with the Privacy Act. You may opt-out of this or withdraw from this at any time by sending an email to our Customer Service Support.; and/or (ii) if you have separately expressly consented to one or more of the following 3 DNC Modes, by way of the 3 modes of communications of voice calls, text messages or faxes (the “3 DNC Modes”) to your telephone number, in compliance with the requirements of the Privacy Act. For the avoidance of doubt, this subparagraph is without prejudice to subparagraph (o) above for which you have hereby consented to us contacting you for a survey, which you may subsequently opt-out of by sending our Customer Service Support notice;
(19) Dealing with and/or facilitating a business asset transaction or a potential business asset transaction, where such transaction involves CYCPLUS as a participant or involves only a related corporation or affiliated company of CYCPLUS as a participant or involves CYCPLUS and/or anyone or more of CYCPLUS related corporations or affiliated companies as participant(s), and there may be other third party organizations who are participants in such transaction. “business asset transaction” means the purchase, sale, lease, merger or amalgamation or any other acquisition, disposal or financing of an organization or a portion of an organization or of any of the business or assets of an organization;
(20) To implement and maintain our information technology systems, including to store and process Personal Data in computer databases and servers located within and outside Hong Kong;
(21) Anonymization of your Personal Data. In this regard, you acknowledge that Personal Data that has been anonymized to the extent that your identity could not be practicably revealed directly or indirectly is no longer Personal Data and the requirements of the Privacy Act would no longer apply to such anonymized data. In this connection, we will not attempt to re-identify any individuals from anonymized data or to use the information or any individuals even if re-identification is possible;
(22) Record-keeping purposes and producing statistics and research for internal and/or statutory reporting and/or record-keeping requirements, of CYCPLUS or of its affiliates/related corporations; and
(23) CYCPLUS reporting on business performance
The purposes set out in this paragraph 2.1 above shall be collectively referred to as the “Purposes”.
3.2 For the avoidance of doubt, you acknowledge and consent to CYCPLUS sharing anonymized information such as but not limited to in the following circumstances: (i) Aggregate information. We may share anonymized aggregate information about our customers with advertisers and marketing partners; (ii) Behavioural-based advertising. A third party may use technology to collect anonymized information about your use of Site so that they can provide advertising about products and services tailored to your interest. That advertising may appear either when you are using the Site or using the Internet or your mobile device to visit other websites.
SECTION 4 – SHARING AND DISCLOSURE OF PERSONAL INFORMATION
4.1 CYCPLUS may/will need to disclose your Personal Data to third parties, whether located within or outside Hong Kong, for one or more of the above Purposes, as such third parties, would be processing your Personal Data for one or more of the above Purposes. In this regard, you hereby acknowledge, agree and consent that we are permitted to disclose your Personal Data to such third parties (whether located within or outside Hong Kong) for one or more of the above Purposes and for the said third parties to subsequently collect, use, disclose and/or process your Personal Data for one or more of the above Purposes. Without limiting the generality of the foregoing or of paragraph 3, such third parties include:
(1) Our related corporations and affiliates either in Hong Kong or overseas
(2) Any of our agents, contractors or third-party service providers that process or will be processing your Personal Data on our behalf or otherwise, including but not limited to those which provide administrative or other services to us such as mailing houses, call centers, telecommunication companies, logistics companies, information technology companies and data centers;
(3) Our business partners including those in skincare, body care, cosmetics, entertainment, leisure and sports, health and wellness, food and beverage, telecommunications, media and public relations, information technology, property, banking, financial, transportation, travel and tourism industries;
(4) Any other person to whom such disclosure is required by law or regulatory requirement or pursuant to a court order.
4.2 We will provide our preferred service providers with the information they need to perform their services and work with them to respect and protect your Personal Data. We require our service providers to adhere to strict privacy guidelines and not to use your Personal Data for unauthorized purposes.
SECTION 5 – PROVISION OF THIRD PARTY PERSONAL DATA BY YOU
5.1 To the extent permitted under the applicable laws, should you provide CYCPLUS with Personal Data of individual(s) other than yourself, you represent and warrant to CYCPLUS and you hereby confirm that:
(1) Prior to disclosing such Personal Data to us, you would have notified all the terms and conditions of this Privacy Notice to, and had obtained consent from the individuals whose Personal Data are being disclosed to us, to:
(i) Permit you to disclose the individuals’ Personal Data to SEPHORA for the Purposes; and
(ii) Permit CYCPLUS to collect, use, disclose and/or process the individuals’ Personal Data for the Purposes, as set out in paragraph 2 in this Policy above;
(2) Any Personal Data of individuals that you disclose to us is accurate; and
(3) You are validly acting on behalf of such individuals and that you have the authority of such individuals to provide their Personal Data to CYCPLUS and for CYCPLUS to collect, use, disclose and process such Personal Data for the Purposes.
SECTION 6 – REQUEST FOR ACCESS AND/OR CORRECTION OF PERSONAL DATA
6.1 You may request to access and/or correct your Personal Data currently in our possession or control by submitting a written request to us. We will need enough information from you in order to ascertain your identity as well as the nature of your request, or to deal with your request. Please submit your written request to firstname.lastname@example.org.
6.2 For a request to correct Personal Data, once we have sufficient information from you to deal with the request, we will deal with your request and correct your Personal Data within 30 days.
6.3 We may also charge you a reasonable fee for the handling and processing of your requests to access your Personal Data. If so, we will provide you with a written estimate of the fee. Please note that we are not required to respond to or deal with your access request unless you have agreed to pay the fee.
SECTION 7 – REQUEST TO WITHDRAW CONSENT
7.1 You may withdraw your consent for the collection, use and/or disclosure of your Personal Data in our possession or under our control by submitting your request to email@example.com.
7.2 We will process your request within a reasonable time from such a request for withdrawal of consent being made, and will subsequently not collect, use and/or disclose your Personal Data in the manner stated in your request, unless the law or the Privacy Act allows us to.
7.3 However, your withdrawal of consent could result in certain legal consequences arising from such withdrawal. In this regard, depending on the extent of your withdrawal of consent for us to process your Personal Data, it may mean that we may not be able to fulfil the transaction you have entered into with us or continue with your relationship with us, or send you information that you have requested, as examples depending on the circumstances.
SECTION 8 – PROTECTING AND MANAGING YOUR PERSONAL DATA
8.1 We will endeavor to take all reasonable steps to ensure your Personal Data is kept confidential and secure, and to take appropriate technical and organizational measures to prevent unlawful or accidental destruction, accidental loss, unauthorized disclosure or access or other unlawful forms of processing. We will not rent, trade, distribute or sell any Personal Data that you give us to any third party unless we receive your prior consent or applicable law permits the same.
8.2 We will put in place reasonable security arrangements to ensure that your Personal Data is adequately protected and secured. Appropriate security arrangements will be taken to prevent any unauthorized access, collection, use, disclosure, copying, modification, leakage, loss, damage and/or alteration of your Personal Data. However, we cannot assume responsibility for any unauthorized use of your Personal Data by third parties which are wholly attributable to factors beyond our control.
8.3 We will take reasonable efforts to ensure that your Personal Data is accurate and complete, if your Personal Data is likely to be used by us to make a decision that affects you, or disclosed to another organization. However, this means that you must also update us of any changes in your Personal Data that you had initially provided us with. We will not be responsible for relying on inaccurate or incomplete Personal Data arising from you not updating us of any changes in your Personal Data that you had initially provided us with.
8.4 We will also put in place measures such that your Personal Data in our possession or under our control is destroyed and/or anonymized as soon as it is reasonable to assume that (i) the purpose for which that Personal Data was collected is no longer being served by the retention of such Personal Data; and (ii) retention is no longer necessary for any other legal or business purposes directly related to the Purposes.
SECTION 9 – COOKIES AND MOBILE TECHNOLOGY
9.2 Flash Cookies. "Flash Cookies" (also called Local Shared Objects or "LSOs") are data files similar to cookies, except that they can store more complex data. Flash Cookies are used to remember settings, preferences, and usage, particularly for video, interactive gaming, and other similar services.
9.3 Web Beacons. Web beacons are small graphic images on a web page or in an e-mail that can be used for such things as recording the pages and advertisements clicked on by users, or tracking the performance of e-mail marketing campaigns.
9.4 Analytics Tags. We use analytical tags to analysis what our clients like to do and the effectiveness of our features and advertising. They can also help us customize your browsing and shopping experience. We may use information collected through analytical tags or tracked links in combination with your Personal Data. We may also combine Personal Data you provide to us with other Personal Data (such as purchase history and demographic information). We often work with third-party companies to help us track, collect and analysis this information but they are prohibited from using this information for any other purpose.
9.5 Web Server Logs. Web server logs are records of activity created by the mobile device or computer that delivers the web pages you request to your browser. For example, a web server log may record the search term you entered or the link you clicked to bring you the web page. The Web server log also may record information about your browser, such as your IP address and the cookies set on your browser by the server.
9.6 Geo-Location Technologies. Geo-location technology refers to technologies that permit us to determine your location. We may ask you to manually provide location information (like your postal code), or to enable your mobile device to send us precise location information.
SECTION 10 – REGISTRATION INFOMRATION
10.1 Our Site contains areas where you can submit information to us (such as our registration service), and we also have features (such as cookies and performance tracking technology) that automatically collect information from the visitors to our Site. During the registration process, you must provide us with a password, your name, address and a valid email address, etc. It is your responsibility to keep your password strictly confidential.
SECTION 12 – TO UNSUBRIBE TO MARKETING PROMOTIONS
12.1 To close an account, please send your request by email to firstname.lastname@example.org. Your user account will be closed and all information removed from our server within 72 working hours.
SECTION 13 - QUESTIONS ABOUT PERSONAL DATA AND CONTACT INFORMATION
13.1 If you would like to: access, correct, amend or delete any personal information we have about you, register a complaint, or simply want more information contact us at
[Re: Privacy Compliance Officer]