Effective Date: December 2019
Kendo Holdings, Inc. and our subsidiaries and affiliates (collectively, “Kendo”, “we”, “us” or “our”) care about the processing, confidentiality, and safety of your personal data.
- I. What is personal data?
The term “personal data” refers to any information about an identified physical person or a physical person that may be directly or indirectly identified.
- II. What personal data do we collect and when do we collect it?
We collect information about you in a variety ways depending on how you interact with us and our products and services, including through our websites, media channels, online and mobile applications, advertisements, and in selected stores.
The following provides examples of the type of personal data that we collect from you and how we use that information.
|Context||Information we collect||Primary Purpose for Collection and Use of Information|
|Create a customer account||If you create a customer account on one of our websites, apps, or in one of our stores, we collect your name, email address, and the month and day of your birthday, if you choose to provide it. Within your customer account, you can also store additional information such as mailing address, phone number, and payment methods. We also collect information relating to the actions that you perform while you are logged into your account||We have a legitimate interest in providing account related functionalities to our customers and managing access to customer accounts. Customer accounts can be used for faster and simpler checkout, to save your personal preferences and order history, and receive updates about your order details.|
|Order goods from our websites||If you place an order on one of our websites, we collect your name, email address, phone number, shipping address, billing address and payment details (payment card number, expiration date, CVV/CVC, etc)||We use your information to perform our contract with you to process your orders and to provide you with the products or services you have requested|
|Make purchases in our stores||If you make a purchase in one of our stores, we may collect your name, email address, billing address and payment details (payment card number, expiration date, CVV/CVC, etc).||We use your information to perform our contract with you to provide you with the products you have requested.|
|Sign up for our mailing list||When you sign up for one of our mailing lists, we collect your email address, phone number, or postal address, depending on your selection||We share information about our products, services, offers, news and events with those individuals that consent to receive such information. We also have a legitimate interest in sharing information about our products or services|
|Contact us||If you contact us, such as via our website, customer service center, or social network pages, we collect your name, contact information (email and/or phone number) as well as any other information you provide to us in order to reply.||We have a legitimate interest in managing customer relations with respect to any requests for information or complaints that we receive. We also have a legitimate interest in responding to inquiries related to support, employment opportunities, and other requests.|
|Report potential adverse reactions||If you contact us to notify us of an undesirable reaction concerning any of our products, we collect your name, contact information, as well as any other information you provide to us, including specific health data if you choose to provide it.||We have a legitimate interest in receiving, processing, following up, and responding to, your reports as part of our cosmetic vigilance obligations. In some jurisdictions, we are also required by law to record information related to product safety and adverse event reports. We have a legitimate interest in complying with all legal requirements to collect information in the countries in which we operate.|
|Interact with us on social networks||If you interact with us through our official page on social networks, or if you publish content on a social network or participate in online forums, we collect any content that you choose to provide, which may include your social media handle or account profile.||We have a legitimate interest in communicating with you, understanding your opinions, and providing tailored services and products.|
|Take part in an event||If you take part in an event, we may collect information about you including your name and contact information.||We have a legitimate interest in operating and managing participation in our events.|
|Apply for a job or become an employee||If you apply for a job with our company, or become an employee, we collect information necessary to process your application or to retain you as an employee. This may include, among other things, our name, contact details, curriculum vitae, application letter, and Social Security Number. Providing this information is required for employment.||We have a legitimate interest in using information about job applicants to manage applications as well as in anticipation of a contract of employment. We use information about current employees to perform our contract of employment. In some contexts, we are also required by law to collect information about our employees. We also have a legitimate interest in using your information to have efficient staffing and work force operations.|
We also use the following technologies to automatically collect personal data when you browse our websites, use our mobile applications, interact without our content, advertisements, and related features.
|Context||Information we collect||Primary Purpose for Collection and Use of Information|
|Cookies and first party tracking||“Cookies” are small pieces of information that a website sends to a computer’s hard drive while a website is viewed. For more information about cookies and to update your preferences, please click the “Cookie Settings” available on our websites’ cookie banners.||We have a legitimate interest in making our websites operate efficiently. We also have a legitimate interest in serving you targeted advertisements.
We will obtain your consent for the deployment of cookies on our websites.
|Cookies and Third Party Tracking||We participate in behavior-based advertising. This means that a third party uses technology (e.g., a cookie) to collect information about your use of our website so that they can provide advertising about products and services tailored to your interests on our website, or on other websites. For more information about cookies and to update your preferences, please click the “Cookie Settings” available on our website.||We have a legitimate interest in engaging in behavior-based advertising and capturing website analytics.
We will obtain your consent for the deployment of cookies on our websites
|Web beacons, clear pixels, or pixel tags||A “web beacon” (also called a pixel tag or a clear GIF) is a small graphic image placed on website pages, e-mails, advertising, and other marketing communications that can be used for such things as recording the pages and advertisements clicked on by users, or tracking the performance of e-mail marketing campaigns. This may also include information about your device or browser.||We have a legitimate interest in understanding how you interact with our websites to better improve them, and to understand your preferences and interests in order to select offerings that you might find most useful. We have a legitimate interest in understanding the effectiveness of our features and advertising, as well as interactions with our e-mail and advertising. We also have a legitimate interest in detecting and preventing fraud.|
|Web logs||We collect information, including your browser type, operating system, Internet Protocol (IP) address (a number that is automatically assigned to a computer when the Internet is used), domain name, click-activity, referring website, and/or a date/time stamp for visitors.||We have a legitimate interest in monitoring our networks and the visitors to our websites. Among other things, it helps us understand which of our services is the most popular.|
In addition to the information that we collect from you directly, we also receive information about you from other sources, including third parties, business partners, our affiliates, or publicly available sources. For example, if you submit a job application, or become an employee, we may conduct a background check.
- III. For what purpose is your personal data collected and used?
In addition to the purposes and uses described above, we use data in the following ways:
To identify you when you visit our websites or our stores.
To streamline the checkout process, to provide products and services, and to process returns.
To secure online transactions, prevent fraud and payment incidents, and manage debt collection (see our terms and conditions for more details).
To manage and optimize customer experience by improving our knowledge of our customers.
To propose appropriate, tailored services, particularly when we enhance our products and services.
To conduct statistical analyses to develop management, measuring and reporting tools in order to adjust and improve our sales, marketing and product manufacturing.
To send marketing and promotional materials, including information relating to our products, services, sales, or promotions.
To manage our relationships as well as for internal administrative purposes.
Although the sections above describe our primary purpose in collecting your personal data, in many situations we have more than one purpose. For example, if you complete an online purchase we collect your personal data to perform our contract with you, but we also collect your personal data as we have a legitimate interest in maintaining your information after your transaction is complete so that we can quickly and easily respond to any questions about your order. As a result, our collection and processing of your personal data is based in different contexts upon your consent, our need to perform a contract, our legal or regulator obligations, and/or our legitimate interest in conducting our business.
- IV. Who are the recipients of your personal data?
Affiliates. We share personal data with our corporate affiliates (e.g., parent company, sister companies, subsidiaries, joint ventures, or other companies under common control) including across our different brands and other entities in the LVMH Moët Hennessy-Louis Vuitton Group, with some of these entities acting as data processors.
Business Transaction. If another company acquires, or plans to acquire, our company, business, or our assets, we will share personal data with that company, including at the negotiation stage.
Other Disclosures without Your Consent. We may share personal data with third parties in response to subpoenas, warrants, court orders, or other requests from legal or regulatory authorities; in connection with any legal process; or to comply with relevant legal, regulatory or treaty obligations. We may also share your personal data in order to establish or exercise our rights, to defend against a legal claim, to investigate, prevent, or take action regarding possible illegal activities, suspected fraud, safety of person or property, or a violation of our policies. In addition, we may share your personal data to comply with your request for the shipment of products to or the provision of services by a third party intermediary.
Public Forums. Some of our websites provide the opportunity to post comments or reviews in a public forum. If you decide to submit information on these pages, that information may be publically available.
Service Providers. We share your personal data with service providers. Among other things, service providers help us to administer and maintain our websites, send communications, provide technology solutions at counters in our stores, conduct surveys, assist with customer service, provide technical support, process payments, provide ant-fraud services, manage regulatory alerts or notifications, provide marketing solutions, assist in order fulfillment, and organize events.
- V. International transfers of personal data
As a multi-national company we transmit information between and among our affiliates. As a result your personal data may be processed in a foreign country where privacy laws may be less stringent than the laws in your country. Nonetheless, where possible we take steps to treat personal data using the same privacy principles that apply pursuant to the law of the country in which we first received your information. By submitting your personal data to us you agree to the transfer, storage and processing of your information in a country other than your country of residence including, but not necessarily limited to, the United States.
All data transfers are subject to appropriate safeguards to ensure compliance with applicable regulations relating to the protection of personal data. For example, all transfers of personal data to our affiliates outside of the EEA are based on the EU Commission’s standard contractual clauses. If you would like more information concerning our attempts to apply the privacy principles applicable in one jurisdiction to data when it goes to another jurisdiction you can contact us using the contact information below.
- VI. How do we protect your personal data?
No method of transmission over the Internet, or method of electronic storage, is fully secure. While we use reasonable efforts to protect your personal data from unauthorized access, use, or disclosure, we cannot guarantee the security of your personal data. In the event that we are required by law to inform you of a breach to your personal data we may notify you electronically, in writing, or by telephone, if permitted to do so by law.
Some of our websites permit you to create an account. When you do you will be prompted to create a password. You are responsible for maintaining the confidentiality of your password, and you are responsible for any access to or use of your account by someone else that has obtained your password, whether or not such access or use has been authorized by you. You should notify us of any unauthorized use of your password or account.
- VII. What are your choices and how can you exercise them?
You may have the following choices regarding your personal data:
Access to Your Personal Data. You may request access to your personal data by contacting us at the address described below. If required by law, upon request, we will grant you reasonable access to the personal data that we have about you.
Changes to Your Personal Data. We rely on you to update and correct your personal data. Most of our websites allow you to modify or delete your account profile. Note that we may keep historical information in our backup files as permitted by law. If our website does not permit you to update or correct certain personal data, you may contact us at the address described below.
Objection to Certain Processing. You may object to our use or disclosure of your personal data by contacting us at the address described below.
Revocation of Consent. If you revoke your consent for the processing of personal data then we may no longer be able to provide you services. In some cases, we may limit or deny your request to revoke consent if the law permits or requires us to do so, or if we are unable to adequately verify your identity. You may revoke consent to processing (where such processing is based upon consent) by contacting us at the address described below.
Online Tracking. We do not currently recognize or respond to automated browser signals regarding tracking mechanisms, which may include “Do Not Track” instructions.
Promotional Emails. If, at any time, you no longer wish to receive details of our offers, news and events, you can unsubscribe using the hypertext link provided for this purpose in each mail we send you. You can also contact us at the address described below. If you decide not to receive promotional emails, we may still send you service related communications.
Promotional Text Messages. If you receive a text message from us that contains promotional information you can opt-out of receiving future text messages by replying “STOP.”
- VIII. Contact Details
You can exercise any of the rights described above in the “What are your choices and how can you exercise them?” section above directly with Kendo by sending an email to email@example.com or by mailing a non-registered letter with a document proving your identity to the below address:
Kendo Holdings, Inc.
Legal Department, Privacy
425 Market Street, 19th Floor
San Francisco, CA 94105
1 844 500 2438
For all questions relating to the collection and processing of your data by Kendo, you can contact our Data Protection Officer at firstname.lastname@example.org. If you are not satisfied with our response and are in the European Union, you may have a right to lodge a complaint with your local supervisory authority.
- IX. Information for California Residents
California Civil Code Sections 1798.115(c), 1798.130(a)(5)(c), 1798.130(c), and 1798.140 indicate that organizations should disclose whether certain categories of personal data are collected, “sold” or transferred for an organization’s “business purpose”(as those terms are defined under California law). You can find a list of the categories of information that we collect and share about online visitors and customers here. Please note that because this list is comprehensive it may refer to types of information that we share about people other than yourself. If you would like more information concerning the categories of personal data (if any) we share with third parties or affiliates for those parties to use for direct marketing, please contact us using the information in the “Contact Details” section above. We do not discriminate against California consumers who exercise any of their rights described in this policy.
- X. Miscellaneous
The following additional information relates to our privacy practices:
Third Party Applications/Websites. We have no control over the privacy practices of websites or applications that we do not own.
California Information Sharing Disclosure
California Civil Code Sections 1798.115(c), 1798.130(a)(5)(c), 1798.130(c), and 1798.140 indicate that organizations should disclose whether the following categories of personal data are collected, transferred for “valuable consideration,” or transferred for an organization’s “business purpose” (as those terms are defined under California law). The table below indicates the categories of personal data we collect and transfer in a variety of contexts. Please note that because this list is comprehensive, it may refer to types of information that we collect and share about people other than yourself. For example, while we transfer credit card or debit card numbers for our business purpose in order to process payments for orders placed with us, we do not collect or transfer credit card or debit card numbers of individuals that submit questions through our website’s “contact us” page.
|Category of Personal Information||Is information collected by us?||Is information transferred for valuable consideration?||Is information transferred for business purposes?|
|Audio, electronic, visual, thermal, olfactory, or similar information (e.g., for customer service call recordings)||✔||☐||✔|
|Bank account number||✔||☐||✔|
|Characteristics of protected classifications (e.g., age, sex, race,
ethnicity, physical or mental handicap, etc.)(e.g., from our employees)
|Commercial information (e.g., products or services purchased, or other
purchasing or consuming histories or tendencies)
|Credit card number||✔||☐||✔|
|Debit card number||✔||☐||✔|
|Driver’s License Number / State ID (e.g., from our employees)||✔||☐||✔|
|Education (e.g., from our employees)||✔||☐||✔|
|Electronic network activity (e.g., browsing history)||✔||☐||✔|
|Employment (e.g., from our employees)||✔||☐||✔|
|Employment history (e.g., from our employees)||✔||☐||✔|
|Health insurance information (e.g., from our employees)||✔||☐||✔|
|Identifiers (e.g., name or alias)||✔||☐||✔|
|Insurance Policy Number (e.g., from our employees)||✔||☐||✔|
|Medical information (e.g., from our employees)||✔||☐||✔|
|Online identifier (e.g. IP address)||✔||☐||✔|
|Other financial information||✔||☐||✔|
|Passport Number (e.g., from our employees)||✔||☐||✔|
|Signature (e.g., from our employees)||✔||☐||✔|
|Social Security Number (e.g., from our employees)||✔||☐||✔|