Legal inventory


Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Interbrands Orbico may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communications might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time. e.g. unsubscribe email, website preferences upon login or sending a notice to our email address privacy.sp.ro@orbico.com .

Currently not used, but if personal data is intended to be used for automated decision-making, including profiling, information about the logic shall be provided as well as the significance and the envisaged consequences of such processing for the data subject.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Your information may also be processed in a destination outside of the European Economic Area Third parties are limited in their ability to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Interbrands Orbico, with its head office at Zagreb is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities, A.N.S.P.D.C.P. ,should contact for any questions you may have relating to the way our company uses your data.
For some services, we rely on specialized partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law. We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit www.dataprotection.ro. Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address Soseaua Viilor No. 14, Sector 5, Street code 050156, Bucharest, Romania. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may
(a) contact the Orbico Privacy Manager, Alina Arsene privacy.sp.ro@orbico.com , and/ or
(b) lodge a complaint with the supervisory authority, A.N.S.P.D.C.P.

Privacy - candidates


Cookie notice


Cookie Notice

In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Orbico or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Impressum


Company name: INTERBRANDS ORBICO SRL

Address: Street Sergent Nuțu Ion no. 44, Building A, floor 3, district 5 One Cotroceni Park, 050762, Bucharest

Delivery address: P3 Logistic Park, Warehouse Building 11, 10-11 Catinei Street, Domnesti Commune, Ilfov County, Romania ( Interbrands warehouse)

Reg. of Commerce No: J1993009571402

VAT code: RO3786280

Bank details

RAIFFEISEN BANK– SUC PIPERA

IBAN: RO15RZBR0000060007245150

BANCA TRANSILVANIA – SUC MARRIOTT

IBAN: RO42BTRLRONCRT0563206703

IBAN EUR: RO33RZBR0000060013583485

SWIFT: RZBRROBU

Impressum


Company name: Orbico Style LLC // Registered seat: Usievicha street 31A building 2, Russia, Moscow,
Court of registration: State register of Russian Federation // Registration no.: 1097746486386
Management Board: Irena Novinec
Bank: UniCredit Bank, Moscow // Account no.: 40702810700013929414
Share capital (paid in full): EUR 1.333.333,00

Impressum


Company name: Orbico d.o.o. // Registered seat: Lužansko polje 7, Sarajevo 71000, Bosnia & Herzegovina

Court of registration: 065-0-Reg-20-001697 // Registration number: 65-01-0634-08

Management Board: Marina Nevrt, Fedja Vuković

Bank: Raiffeisen Bank // Account no.: 1610000007720047

Share capital (paid in full): 1.259.800 BAM

Merger of companies


Merger plan (serbian)

Impressum


Company name: ORBICO SP. Z O.O. // Registered seat: 5 Wołoska Str, 02-675 Warsaw, Poland //
Court of registration: The Regional Court for the capital city of Warsaw, 13th Commercial Division of the National Court Register // Registration no.: KRS 0000046562 //
Number REGON/NIP: REGON: 277632751, NIP: 6462526337
Share capital (paid in full): PLN 40841450,00

Cookie notice


Cookie Notice

In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Orbico or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Privacy - general


INTRODUCTORY INFORMATION

Respecting the right to privacy of the persons who entrusted ORBICO Sp. z o.o. (hereinafter referred to as "Orbico") with their personal data, we would like to state that we process the collected data in accordance with national and European legal regulations and in conditions ensuring their safety. In order to ensure transparency of data processing, we present the rules of personal data protection applicable in Orbico, as laid down in the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)  (General Data Protection Regulation, hereinafter referred to as the "GDPR").

Data Controller

The controller, i.e. the entity deciding about the purposes and means of personal data processing is ORBICO Sp. z o.o. with its registered office in Warsaw 02-675 at ul. Wołoska 5, entered in the National Court Register by the District Court for the Capital City of  Warsaw in Warsaw, 13th Commercial Division under the number: KRS 0000046562, REGON: 277632751, NIP: 646-25-26-337, share capital PLN 40 841 450,00.

Orbico attaches considerable importance to the protection of personal data, which is why as a Controller it encourages you to contact in case of any doubts regarding the processing of your personal data at the e-mail address iod.no.pl@orbico.com

Obtaining personal data and the purpose of their processing

Orbico is a member of the Orbico Group, the largest distributor in Europe.  While running our business we process personal data for the following purposes:

Conclusion and performance of a contract  with a customer or a contractor
Art. 6, sec. 1b and f of the GDPR
For the term of the contract, and after its termination until the expiration of the claims resulting from it, as a rule - for 3 years (in the case of a sales contract within the scope of the business activity of the company - for 2 years), maximum: for 6 years.
In connection with actions taken in order to conclude a contract or in relation to its performance, the Data Controller shall contact the employees/co-operators of clients and contractors for a justified purpose. Moreover, the Controller may obtain from the contracting party the basic data of its employee/co-worker (name, surname, place of employment or cooperation, telephone number, e-mail adress and in specific situations the document number with a photo) in connection with the performance of the contract to which the data relate, from the entity with which the person is employed or cooperates.

Complaints handling
Art. 6, sec. 1b and f of the GDPR
For 1 year from the date of expiration of the warranty or complaint solution.
In connection with the processing of a complaint, the Controller shall contact the employees/workers of the clients for a justified purpose.

Assertion of claims or defense against claims
Art. 6, sec. 1f of the GDPR
For the duration of proceedings concerning the claims, i.e. until their final settlement, and in the case of enforcement proceedings until the final settlement of the claims being pursued.
In connection with assertion of claims or defending against claims, for a justified purpose the Controller may process the data of customers, contractors,  employees/co-operators of customers or contractors.

Filing the documents i.e. agreements and settlement documents
Art. 6, sec. 1c of the GDPR
For the periods specified by law and if, with regard to certain documents, they are not indicated, for the time when their storage is within the scope of the legally justified purpose of the Controller, depending on the time of claims assertion

Keeping statistics and analyses
Art. 6, sec. 1f of the GDPR
Until another processing purpose specified in this table is met.. We do not store personal data exclusively for statistical and analytical purposes.
Keeping statistics and analysis of activities allows the controller to improve the business.

Marketing activities without the use of electronic means of communication
Art. 6, sec. 1f of the GDPR
Until you object i.e. inform us in any form that you do not wish to be contacted by us and that you do not want to be informed of the actions we take.
Marketing activities promoting our business.

Marketing activities with the use of electronic means of communication
Art. 6, sec. 1a GDPR
Due to other applicable regulations, in particular, the Telecommunications Law and the Act on providing services by electronic means these activities are conducted on the basis of consents obtained.
Until you withdraw your consent, i.e. inform us in any form that you do not wish to be contacted by us and that you do not want to be informed of the actions we take. After withdrawal of your consent - in order to prove compliance of Orbico with its legal obligations and related claims (up to 6 years from the revocation of your consent).
Marketing activities promoting our business with the use of email addresses and telephone numbers.

Access control, including monitoring on the premises of the Data Controller for the purposes of improving the security of employees, protection of property and confidentiality of information 
Art. 6, sec. 1c and f of the GDPR
Until an objection is lodged (no longer than one year)
Image recordings shall only be processed for the purposes for which they were collected and shall be kept for a period not exceeding 3 months from the date of recording, unless the recording is an evidence in the proceedings, and then  - until the proceedings are finally terminated or until an objection is lodged.
Access control for persons staying on the territory of the Controller is its legitimate purpose, and in the case of employees it is specified in legal regulations (Article 222 of the Labour Code).
Moreover, the Controller may obtain the basic data of an employee/co-worker (name, surname, place of employment or cooperation, telephone number and in specific situations the document number with a photo) before the arrival of the data subject, from the entity with which the data subject is employed or with which it cooperates.

Recruitment process
Art. 6, sec. 1a, b, c and f of the GDPR
Up to 3 months from the end of the recruitment process, and in case of consent for further recruitment processes not longer than for 2 years.
Without additional consent of the data subject, the Controller may store the data of candidates for employment who have not been employed  for 3 months after the end of the recruitment process as a legitimate objective of the Controller, as the employed employee/co-operator may not prove himself/herself good at the position or may resign.

HR management  (employees and cooperators)
Art. 6, sec. 1a, b, c and f of the GDPR
Art. 9, sec. 2b of the GDPR
Pursuant to the binding provisions on archiving labour law documents, i.e. personal files for years and in some cases - for 10 years. The 10-year period for keeping records  related to employment relationship and employees' personal files shall apply to all employees employed after 1 January 2019. In the case of employees employed after 31 December 1998 and before 1 January 2019, records related to employment relationship and the employees' personal files shall be kept for 50 years from the date of termination or expiry of the employment relationship, unless the employer makes a statement of intent to provide reports concerning all employees and contractors employed during that period, and the employer actually submits such reports.
If the retention period of  selected documents is shorter, the Controller will follow this shorter retention period. Civil law contracts shall be stored until the expiration of the statute of limitations of the resulting claims.
Facial image may be used by the Controller only with the consent of the employee / cooperator.

Contact form at a website
Art. 6, sec. 1f of the GDPR
Until an objection is lodged (no longer than one year)
Providing answers to requests and enquiries made with the use of a contact form or in any other form, including storing sensitive requests and answers provided, with a view to maintaining the principle of accountability.

Adapting the content of websites to user's needs, optimizing the use of websites
Art. 6, sec. 1f of the GDPR
Personal data will be processed for the periods indicated in the Information on the use of "cookies" or until you object to the data being processed.
Expressing an objection can only occur by changing the settings of the end user's browser, which will prevent the collection of information using cookies.
The legitimate interest of the Controller, which is service of websites, website user's visits and analysis of website activity, as well as optimization of the use of websites.

If the time limits for pursuing potential claims are shorter than the time limits for storing settlement documents for tax purposes, we will store them for the time necessary for tax and settlement purposes, i.e. for 5 years from the end of the year in which the tax obligation has been updated.
We have collected your personal data from the following sources: 
- publicly accessible registers,
- directly from you
- from superiors, co-operators, employees and co-workers
- from another member of Orbico Group, which is a separate controller, but only for internal administrative purposes. To use your personal data for any other purpose we will ask you for your consent.


Data recipients

In connection with its business, Orbico will disclose your personal information to the following entities:

- state bodies or other entities qualified under the provisions of law,
- entities supporting us in conducting our business by our order, in particular: providers of external IT systems supporting our business, transport companies and providers of postal and courier services, entities auditing our operations, entities cooperating with Orbico in marketing campaigns, as well as providing consulting, legal and insurance services. Such entities, however, will process data on the basis of an agreement with Orbico and only in accordance with its instructions,
- banks in case of a need to conduct settlements,
- producers of goods for which Orbico is a distributor,
- other companies of Orbico Group.


Powers with regard to the processing of data and the voluntary nature of the provision of data

Each person whose data is processed by Orbico is entitled to:

- access their personal data
- rectify their personal data
- erase their personal data
- limit the processing of their personal data
- object against processing their personal data
- portability of their personal data

For more information on the rights of data subjects, see Articles 12-23 of the GDPR, the text of which can be found at the following address: https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679

Moreover, the person whose data is processed by Orbico has the right to lodge a complaint with the supervisory authority, i.e. the President of the Office for Personal Data Protection. More information at the following address: https://uodo.gov.pl/pl/p/skargi

Do you have to provide your personal data?

Providing data is necessary for concluding agreements, settlement of business transactions as well as for the fulfilment of legal requirements by Orbico. For the remaining purposes (in particular for the purpose of processing the data by Orbico for marketing purposes), the provision of the data is voluntary.

Transfer of data to third countries

In certain situations, data may be transferred to third countries. The transfer of personal data always takes place on the basis of legal regulations, including the basis of a decision of the European Commission stating the appropriate degree of protection of that third country or with the application of appropriate safeguards referred to in art. 46 of the GDPR or in special situations referred to in art. 49 of the GDPR. Further information on the transfer of data to third countries and the legal bases can be obtained by e-mail via the Data Protection Officer.

Processing of personal data by automated means 
Personal data will not be processed by automated means (including profiling) in such a way that such could result in making decisions or obtaining any legal effect or otherwise significantly affect our customers, business partners and their employees/co-workers.

Merger of companies


W związku z planowanym połączeniem Orbico Sp. z o.o., Orbico Supply Sp. z o.o., Orbico Salon Professional Sp. z o.o., Orbico Beauty Sp. z o.o., Orbico Style Sp. z o.o. Zarząd Spółki w trybie art. 500 § 2¹  Kodeksu spółek handlowych publikuje Plan połączenia z dnia 30 września 2020 r. wraz z załącznikami. Pliki zamieszczono w formacie PDF – możliwym do odczytania i wydrukowania za pomocą darmowego oprogramowania Adobe Reader lub podobnego:

Plan połączenia
Załącznik do Planu połączenia
Merger plan (english)

Adobe Reader

Privacy - candidates


Applicant Privacy Policy
Issuer: Orbico Beauty s.r.o. organizačná zložka
Published: 25 May 2018
Validity: 25 May 2018

1. General

1.1. This Applicant Privacy Policy (hereinafter referred to as “Applicant Privacy Policy”) governs the protection of your personal data, as well as your privacy if you applied to a job position in our Company, whether this job position was advertised or not (hereinafter referred to as “you”). This Applicant Privacy Policy is issued by Orbico Beauty s.r.o. organizačná zložka, Kutlíkova 17, Bratislava 5 - 851 02, Reg. No. 318 122 10 (hereinafter referred to as “Company” or “Us”). We act as the controller of your personal data.

1.2. Our range of activities is wide, that’s why we have more privacy policies. This one refers to you as an applicant, but other may apply to you as well (if applying to a job position is not the sole reason of our communication).

2. What personal data do we process?

2.1. We process your personal data which you provided us with in your job application, as well as your personal data that we collected in the recruitment process i.e. the following data:
2.1.1. Your identification data: Name, last name, address and citizenship;
2.1.2. Your contact data: Phone number, E-mail address;
2.1.3. Information about your education and title;
2.1.4. Information about your age and current and previous work experience;
2.1.5. Information about test results (if testing is done as a part of the recruitment process) and our interviews (summary relevant for the job position we are considering you);
2.1.6. Other data that may be relevant for a job position e.g. certificates and other skills.

3. What are the purposes for which we process your personal data?

3.1. We process your personal data for the following purposes:
3.1.1. If you applied for a job position, we process your data to find out if you are the right candidate. In such case, the basis for processing your personal data is our legitimate interest;
3.1.2. If we think you might be the right candidate, we process your data in order to make you an offer and enter into the relevant contract. In such case, the basis for processing your personal data is processing necessary for entering into a contract;
3.1.3. If you applied for a job position, but we have not made you an offer or you rejected our offer, we might process your data for future job positions in our Company. In such case we will separately notify you about such processing and you will be given the opportunity to object. If you do not object, the basis for our processing of your personal data is our legitimate interest;
3.1.4. We might process your personal data for other purposes such as confirming whether the recruitment process was managed fairly and transparently, confirming whether the information you gave us was true, in order to answer to your request or in order to protect our interest in a court or other proceeding. In such case, the basis for our processing of your personal data is our legitimate interest.

4. How do we protect personal data?

4.1. All our personnel accessing your personal data must comply with the internal rules and processes in relation to the processing of personal data to protect them and ensure their confidentiality. They are also required to follow all technical and organisational security measures put in place to protect your personal data.

4.2. We have also implemented adequate technical and organisational measures to protect your personal data against unauthorized, accidental or unlawful destruction, loss, alteration, misuse, disclosure or access and against all other unlawful forms of processing. These security measures have been implemented taking into account the state of the art of the technology, their cost of implementation, the risks presented by the processing and the nature of the personal data, with particular care for sensitive data.

5. Who has the access to your personal data?

5.1. Within the Orbico Group
5.1.1. In limited and necessary instances, we may provide access to personal data by other Orbico companies, to complete the purposes indicated in section above. Access to personal data will only be given to authorised individuals, such as HR managers or IT administrators. Certain executives, managers and employees at other Orbico companies may also have access to certain personal data, only on a need to know basis and if there is a legitimate business purpose.

5.2. Outside the Orbico Group

5.2.1. We may also consider it necessary to transfer personal data to third parties outside the Orbico Group to complete the purposes listed in section above, or as may be required by law, including:
• third party service providers, such as our IT systems providers, our hosting providers, cloud service providers, database providers, consultants (including lawyers, tax accountants, labour consultants) and third parties who carry out pre-employment or preengagement checks on prospective employees - each of these service providers has signed contracts to protect your personal information and are obligated to only use personal data for the specific purposes stated by Orbico;
• any national and/or international regulatory, enforcement or exchange body or court where we are required to do so by applicable law or regulation or at their request.

5.3. Is my personal data transferred to third countries?
5.3.1. If we transfer your personal data to a third country (outside the EEA or other jurisdiction NOT recognized by the EU Commission as providing the adequate level of protection), we previously request your explicit consent to do so or we sign a contract with a specific party that guarantees the same level of protection, i.e. it contains and applies contractual clauses approved by the EU Commission.

6. How long do we keep your personal data?

6.1. Personal data we process based on our legitimate interests are kept as long as there is a legitimate interest and we delete them in a period of one year from when our legitimate interest ceased to exist.

6.2. Personal data that we process based on your consent, we keep as long as we have your consent. In the event of withdrawal of your consent, we will delete your personal data in the shortest possible time. If consent is given for a specific period of time, after the expiration of that period, your data will be deleted as soon as possible, within a reasonable time.

7. Your rights

7.1. You can exercise your rights (see below) by submitting your request to privacy.orbicobeautysk@orbico.com. Please make sure that you (1) enter "Request of the data subject" as the title of the message and in the text tell us (2) who you are so that we can identify  you and (3) what right you want to exercise. Upon receipt of the message, we will send you a confirmation that we have received your request.

7.2. You can exercise your rights free of charge. However, if you frequently request (for example, if you requested to exercise your rights less than 6 months ago) or excessively request (for example, you are looking for all your personal information in writing) access or transfer of your personal data, we have the right to ask you to settle our costs before carrying out such actions.

7.3. Access to your personal data
You have the right to ask for a confirmation that we process your personal data, as well as access to your personal data we process.

7.4. Rectification of inaccurate personal data
You have the right to request the rectification of your incorrect personal data, as well as the right to have incomplete personal data completed.

7.5. Data portability

You have the right to take over and request the transfer of your personal data (when we process your data based on your consent or for the purpose of entering into the contract).

7.6. An objection about the processing or handling your personal data
You have the right to object to the processing of your personal data, as well as our general manner of handling your personal data.

7.7. The right to withdraw the consent
You are entitled, at any time, to withdraw the consent for the further processing of your personal data – but for the personal data that we process based on your consent (and not when we have different legal basis). The withdrawal does not affect the processing carried out on the basis of the consent prior to its withdrawal.

7.8. The right to complaint to the authority
At any time, you have the right to complain to the competent body for the protection of personal data – Úrad na ochranu osobných údajov Slovenskej republiky, www.dataprotection.gov.sk, in relation with processing and protection of your personal data.

8. Changes to the Applicant Privacy Notice

8.1. The Applicant Privacy Notice may be subject to amendments (changes, additions or similar). Any future amendments to how we process your personal data described in the Applicant Privacy Notice will be communicated to you through an appropriate channel, depending on how we normally communicate with you. Be sure to check the actual version published on http://www.orbicobeauty.sk/.

9. Contact

9.1. If you have any questions regarding the processing of your personal data or if you believe your privacy rights have been violated, please address your request to the following address: privacy.orbicobeautysk@orbico.com
Orbico Beauty s.r.o. organizačná zložka, Kutlíkova 17, Bratislava 5 - 851 02

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA – ORBICO BEAUTY (SLOVAKIA)
Issuer: Orbico Beauty s.r.o., organizačná zložka
Published: 25 May 2018
Implementation: 25 May 2018

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we
collect it and what do we do with it in an easy and readable way. Personal data means any data from which we
are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil
local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover

This Notice covers how we process your data whenever you interact with us, e.g. when you
- visit any of our websites;
- use our social media channels;
- purchase and use our products and services, systems and applications;
- subscribe to our newsletters;
- provide to us your goods or services, systems or applications;
- contact our customer support;
- join our business events;
- participate to our contests;
- participate to our promotions;
- or otherwise interact with us

as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner, etc.) and how you interact with us (e.g. online, offline, phone, etc.) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

- Data you provide us directly us

Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded/ provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences 

- Data about your use of products and/ or services that we collect automatically - In addition to the information you provide to us directly (see above), we may collect information sent to us by your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites/ apps/ services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media
Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data
o Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services.

We may combine this information with other information we receive from you.

- Other

You may choose not to provide certain types of information to us but doing so may affect your ability to enable certain functionality of the products and/ or services.

In compliance with the law, we will not process data relating to
- racial or ethnic origins;
- political opinions;
- religion or beliefs;
- trade union membership;
- genetic features;
- health;
- sex life;
- criminal convictions or related security measures;
- biometric data;
- genetic data.

If we had to process this type of data, we would always request your prior consent.

4. How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data.
Please find below the overview.

Contract/agreements execution:
Billing and delivering products and/ or services that you have purchased;
Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest:
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests: 
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact center support;
Security and protection of our interests/assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communications might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time. e.g. unsubscribe email, website preferences upon login or sending a notice to our email address privacy.orbicobeautysk@orbico.com.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

When the data is transferred abroad?
Which countries, under which instrument

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:

- Service providers: e.g. outsourcing, we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as ICT service providers, consulting providers, shipping providers
- Business partners: they can provide you with the services you request
- Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
- Professional advisors such as auditors, lawyers, accountants, other professional advisors.
- Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).


Your information may also be processed in a destination outside of the European Economic Area. Third parties are limited in their ability to use your information for other purposes than providing services to us and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. 

We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”). Sometimes we might keep your data longer if required or permitted by law.

We determine the period based on the following criteria:
- How long is the data needed to provide you with our products or services or to operate our business?
- Do you have an account with us? Then we will keep your data while your account is active.
- Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include  mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.

8. Who is responsible for your data?

Orbico Beauty s.r.o., organizačná zložka with its head office at Kutlíkova 17, Bratislava 5 - 851 02 is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities, The Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, www.dataprotection.gov.sk) should contact for any questions you may have relating to the way our company uses your data.

For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law of Sweden. We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit www.dataprotection.gov.sk. Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address privacy.orbicobeautysk@orbico.com. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may
(a) contact the Entity Privacy Manager: privacy.orbicobeautysk@orbico.com
(b) lodge a complaint with the supervisory authority, The Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, www.dataprotection.gov.sk)

Impressum


Company: Orbico Trgovina i usluge d.o.o. Belgrade // Headquarters: Partizanske avijacije 4, 11070 New Belgrade // PIB: 105564523

Registered at: Business Registers Agency in Belgrade // MB: 20410060 // Authorized person: Ivo lelas

Bank: BANCA INTESA // Account number: 160-0000000493199-20 // Founding capital (paid in full): 559.059.520,69 RSD

Job Candidate Privacy Policy


Personal Data Protection Information for job candidates
Publisher: ORBICO TRGOVINA I USLUGE DOO BEOGRAD, Partizanske avijacije 4, registration number: 17321323
Use: 01.03.2020.

1. In general

1.1. These Job Candidate Privacy Policy(hereinafter „Candidate Privacy Policy“) governs the protection of your personal information, as well as your privacy, if you have applied for a job with the aim of employment in our company (hereinafter „You“). This Privacy Policy  of the candidate is issued by  Orbico Trgovina i usluge DOO, Partizanske avijacije 4, 11000 Beograd, registration number: 105564523  (hereinafter   „Company“ or „We“). In this sense, the company has the position of controller of the processing of your personal data.

1.2. The Company has the Rulebook on personal data protection which regulates the obligations of the Company and its employees regarding the collection and processing of personal data. These privacy rules further regulate the privacy and protection of your personal data as a job candidate , and provide you with information in accordance with Articles 23 and 24 of the  Law on Personal Data Protection(„ Official Gazette of RS“, No. 87/2018).

1.3. Please read this Candidate  Privacy Policy. If you do not agree with our actions, please do not provide us with your personal information.

1.4. The range of  activities of the Company  is wide and therefore there are several types of privacy rules. These apply to you as a job candidate , but other privacy policies may also apply to you (if applying for a particular job is not the only reason for our communication).

2. What personal data do we process?

2.1. We process your personal data that you provided to us as part of the job application, as well as your data that we collected during the hiring process. In this regard, we process your following personal data:

2.1.1. Your basic information: Name, surname, address and citizenship, age;
2.1.2. Your contact information: phone number,  e-mail address;
2.1.3. Academic and professional qualifications contained in the curriculum vitae and/or cover letter (level of education, titles, skills, work experience, knowledge of foreign languages, training, employment history, etc);
2.1.4. Data on test results (if testing is performed as part of the recruitment process) as well as interviews conducted (relevant resume for the position for which we are considering you);
2.1.5. Other data that may be relevant to the workplace , e.g. certificates and other skills.

3. For what purpose do we process your personal data?

3.1. We process your personal data for the following purposes:

3.1.1. If you have applied for a job, we process your information to find out if you are a suitable candidate. In that case , the basis for the processing of your personal data is our legitimate interest;
3.1.2. If we belive that you could be a suitable candidate, we process your personal data in order to give you an offer and enter into a relevant contract. In that case, the basis for the processing of your personal data is the processing necessary for the conclusion of the contract;
3.1.3. If you have  applied for a job, but we have not given you an offer or you have rejected the offer, we may process your personal data for future jobs in the Company. In that case, we will specifically inform you about such processing and you will be given the opportunity to object. If you do not object, the basis for the processing of your personal data is the legitimate interest of the Company. 
3.1.4. We may process your personal information for other purposes, such as verifying that the information you provided to us was true, in  order to respond  to your request, or to protect our interest in court or other proceedings. In that case, the basis for the processing of your personal data is the legitimate interest of the Company.

4. How do we protect your personal data?

4.1. All employees of the Company who have access to your personal data must comply with internal rules and and processes regarding the processing of personal data in order to protect and ensure the confidentiality of your personal data. Employees are also required to follow all technical and organizational security measures in place to protect your personal information. 

4.2. We have also implemented appropriate technical and organizational measures to protect your personal data from unauthorized , accidental or unlawful destruction, loss, alteration, misuse, disclosure or access as well as against all other unlawful forms of processing. These security measures shall be implemented taking into account the state of the art , their cost of implementation, the risks posed by the processing and the nature of personal data , with particular attention to sensitive data.

5. Who has access to your personal data?

5.1. Within the Orbico Group

5.1.1. If necessary, we may provide access to the personal data of other Orbico companies to serve the purpose stated in the previous section. Access to personal data will be provided only to authorized persons, such as HR managers or IT administrators. Certain executives , managers and employees of other Orbico companies may also have access to certain personal information, only if necessary and if there is a legitimate business purpose. 

5.2. Outside the Orbico Group

5.2.1. We may also consider it necessary to transfer pesonal data to third parties outside the Orbico Group in order to fulfill the purposes set out in the previous section or which may be  required by law including:
• Third party service providers, such as our Company`s  IT service providers, our Company`s  hosting service providers, cloud service providers, database providers, consultants (including lawyers, accountants, employment consultants) and third parties performing pre-employment or pre-employment checks potential employees-each listed service provider has signed contracts to protect your personal data and is obliged to use personal data only for certain purposes specified by the Company. 
• Is my personal data transferred to other countries?
5.2.2. We do not transfer your personal data to other countries.

6. How long do we keep your personal data?

6.1. Personal data that we process on the basis of the existence of a legitimate interest, we keep as long as there is legitimate interest and we delete them within one year from the termination of the same.

6.2. We store personal data that we process on the basis of your consent as long as your consent exists. In case of withdrawal of consent , we delete them as soon as posible. If the consent is given for a certain period of time, after the expiration of that period, we will delete your personal data as soon as possible, within a reasonable time. 

7. Your rights

7.1. If you choose to exercise one or more of your rights below , the Company has the right to verify your identity , all for the purpose of protecting personal information.

7.2. You exercise your rights for free. Exceptionally, if your request is obviously unfounded or excessive(e.g. you are asking for personal data that you have), and especially if the same request is repeated frequently (e.g. less than 6 months have passed since the last request), the Company has the right to charge necessary costs to act on your request or to refuse to act on your request.

7.3. Access to your personal data:
You have the right to ask us for information on whether we process your personal data, access to that data, as well as information on processing in accordance with Article 26 of the Law. Please send questions and requests , in writing and signed, to   privacy.orbicors@orbico.com.  We will respond to your request immediately, and within a month at the latest, unless the exceptional complexity of an individual case does not require an extension of the specified deadline. 

7.4. Correction of inaccuracies, additions, deletions, restrictions, on the use of personal data:
You have the right to request the correction of your inaccurate personal data , as well as the right to suplement , delete and limit the use of your personal data. Please send questions and requests, in writting and signed, to privacy.orbicors@orbico.com. We will respond to your request immediately , and at the latest within a month, unless the exceptional complexity of the individual case requires an extension of the specified deadline. 
Portability of personal data
You have the right to download and request the transfer of your personal data. Please send questions and requests, in writing and signed , to the adress privacy.orbicors@orbico.com. We will respond to your request immediately, and at the latest within a month, unless the exceptional complexity of the individual case requires an extension of the specified deadline.

7.5. The right to withdraw consent and forget
You have the right to withdraw your consent to the processing of personal data as well as to request that your personal data that we have processed on the basis of your consent be permanently deleted. Please send questions and requests , in writing and signed, to the adress privacy.orbicors@orbico.com.  We will respond to your request immediately, and at the latest within a month, unless the exceptional complexity of a particular case requires an extension of the specified deadline.

7.6. Complaint against the processing or handling of your personal data:
You have the right to object to the processing of your personal data as well as to our way of handling your personal data in general. Send your request by e-mail to the adress privacy.orbicors@orbico.com. Where in the title of the message you state the Objection against processing and in the message itself you explane the reason for the objection and your request. 
The right to complain to the Commissioner for Information of Public Importance and Personal Data Protection
As a Client, at any time you have the right to complain to the competent authority for personal data protection-the Commissioner for Information of Public Importance and Personal Data Protection ( https://www.poverenik.rs/

8. Changes in the Candidate Privacy Policy

8.1. The candidate`s privacy policy may be subject to change (amendments, additions or the like). You will be notified of any future changes in the way your personal information is described in the Candidates Privacy Policy through the appropriate channel, depending on how we normally communicate with you. 

9. Contact

9.1. If you have any questions regarding the processing of your personal data or if you belive that your privacy rights have been violated, please submit your request to the following address: privacy.orbicors@orbico.com.
Orbico Trgovina i Usluge DOO, Partizanske avijacije 4, 11000 Beograd.
 

General Privacy Policy


Personal Data Protection Information for Clients
Publisher: ORBICO TRGOVINA I USLUGE DOO BEOGRAD, Partizanske avijacije 4, matični broj: 105564523
Use: 01.03.2020

1. Important notes
These are the privacy rules (hereinafter: the "Privacy Policy") issued by ORBICO TRGOVINA I USLUGE DOO, 11000 Belgrade, Partizanske avijacije 4, registration number: 105564523 (hereinafter: the "Company"). In this sense, the company has the position of controller of the processing of your personal data.

1.1. These Privacy Policy apply to all individuals who interact with the Company in the role of consumers, customers, service users, those who are interested in becoming, business partners, suppliers, subcontractors, contractors or other persons who are with the Company in business relationship. (hereinafter: "Clients").

1.2. The company has a Rulebook on personal data protection which regulates the obligations of the Company and its employees regarding the collection and processing of personal data. These privacy rules further regulate the privacy and protection of your personal data as Clients, and you are provided with information in accordance with Articles 23 and 24 of the Law on Personal Data Protection ("Official Gazette of RS", No. 87/2018).

1.3. The privacy policy applies only to individuals or their personal data. Personal data is all data through which we can, directly or indirectly, identify you.

1.4. Please, read this Privacy Policy. If you do not agree with our actions, please do not provide us with your personal information

1.5. In case of any questions or requests regarding the handling or protection of your personal data, please contact us at privacy.orbicors@orbico.com

2. What is covered by the Privacy Policy?
• The Privacy Policy covers the ways in which your personal data is processed when you interact with us, e.g. when:
• You visit our websites
• Use our channels on social networks
• Purchase and use our products and services, systems and applications 
• Subscribe to our newsletter
• Provide your goods and services, systems or applications
• Contact our customer support
• Attend our business events
• Participate in our competitions
• Participate in our promotions
• Communicate with us in some other way in the role of you as a consumer, costumer, business partner, supplier, subcontractor, or other person who is in a business relationship with us

2.1. Processing of personal data is any action or set of actions performed on personal data, whether automated or non-automated means such as collecting, recording, organizing, structuring, storing, adapting or modifying, finding, restoring, discovering, using, and consulting related to personal data.

3. What personal data do we process?

3.1. We process the personal data that you have given us, either during the initial contact, or during later communication (eg through a phone call, e-mail, etc.) or those that resulted from our business cooperation.

3.2. We process the following personal information we have collected from you:

3.2.1. Your identification data: Name, surname, adress (street and house number, place, postal code, country, apartment, floor), JMBG; tax (registration) number;
3.2.2. Your contact data: Mobile phone, telephone, Fax, Email address; contact adress (street and house number, place, postal code, country, apartment, floor);
3.2.3. Your user data: user ID, password;
3.2.4. Additional information necessary for business needs: Company name, type of user(private or business); business atribute; Current account data (number and bank);
3.2.5. Data derived from our business relationship: Sales data, pictures from the point of sales
3.2.6. Change history of all listed data: Initially given data, their changes,as well as the change was made
3.2.7. Your other data: Data related to your household, your interests, your occupation;

3.3. We also process personal data related to your use of products and/or services, which are collected automatically.

3.4. We process the following personal information we have collected automatically:

3.4.1. Information obout your device: Device model ,unique device identifier, MAC address, IP address, operating system version, device settings you use to access websites, applications and services;
3.4.2. Your login details: The time and duration of use of our digital channel or product;
3.4.3. Your location information: The actual location(derived from the IP adress or other location-based technologies) that we may collect when you provide us with this through product or location-related settings;
3.4.4. Your other data: The applications you use, the websites you visit, the links you click within our advertising email;

3.5. We process the personal information we receive about you from publicly available sources(within the legal framework) such as public databases , as well as those we receive from our marketing partners or social networking platforms when you choose to use such services. We may combine the information obtained in this way with other information we have received from you.

3.6. You are not obligated to provide us with certain types of information, but this may affect the functionality  of the product or service we offer.

3.7. In accordance with the law, we will not process data related to:
• Racial or ethnic origin;
• Political opinion;
• Religious or philosophical beliefs;
• Trade union membership;
• Genetic functions;
• Health;
• Sex life;
• Criminal convictions or related security measures;
• Biometric data;
• Genetic data.
If there is a need to process some of the above personal data we will always need your explicit consent.

4. Why we process your personal data?

4.1. We process your personal data because you are our customer or user of our services or you are interested  in becoming one(e.g. you have subscribed to our newsletter or sent us certain questions). 

4.2. We process your personal data for the following purposes: 

4.2.1. Conclusion and implementation of contracts
We process your personal data  that we need in order to process, accept and fulfill some of your inquiries, orders, purchases or other mutual agreements.
4.2.2. Fulfilling our legal duties 
We process your personal informations in order to fulfill our legal duties. For example, disclosure of information to state institutions or supervisory bodies related to reporting obligations , compliance audits, tax deductions, mandatory records, conducting inspections and compliance with requirements by state bodies or other public bodies.In that case, the basis for processing your personal requests is the fulfillment of our legal duties. 
4.2.3. Information on orders and requests
We process your personal data in order to inform you about the status of an individual request, the execution of a service or the like, all for the purpose of your full information. In that case, the basis for the processing of your personal data is our legitimate interest.
4.2.4. Sending a newsletter
We process your personal data in order to inform you about interesting events, our services and products, all the for the purpose of your full information. In that case,  the basis for the processing of your personal data is our legitimate  interest or your consent, depending  on the specific case.
4.2.5. Other cases
In order to protect our legitimate interests as a company(eg. When it is necessary to ensure an adequate level of protection). In that case, the basis for processing your personal requests is our legitimate interest.

5. Who has access to your personal data?

5.1. We consider your personal data to be a business secret and as such we protect them in accordance with applicable legal regulations and best practice. 

5.2. We will process your personal data ourselves, as well as the entities within Orbico group. Third parties have the right to access and process your personal data only in the situations described below:

5.2.1. Legal entities with which we cooperate in business and which enable or assist us in regular business. These are e.g. individuals who develop and maintain the IT solutions we use. In that case, these legal entities process your personal data exclusively for our needs;
5.2.2. Persons with whom we cooperate in business, when we assess that it is necessary for the protection of certain of our justified interests. For example tax advisors, accountants, lawyers and other advisors. In that case, these persons process your personal data exclusively for our needs; 
5.2.3. Competent bodies in conducting supervision over the legality of business and actions , as well as other legal entities when it is necessary for the performance of some of our legal duties , e.g. auditor. In that case, these legal entities process your personal data for the purpose assigned to them by law;
5.2.4. Other parties in connection with business transactions such as e.g. sale  of the company or part of the company, reorganization, merger, joint venture, or any other type of disposal of our company, property or stocks) including bankruptcy or similar proceedings).

5.3. Third parties are limited in their ability to use your personal information for any purpose  other than those listed, and are required to protect and process your personal information in accordance with  legal, regulatory and contractual obligations.

6. Is my personal data transferred to other countries?

6.1. In order to realize the legitimate interests of the Company and the implementation of loyalty programs to Clients, your personal data may be transferred to other countries, specifically certain EU countries in which the Orbico group has entities, and the Company always complies with legal regulations relating to such transfer.  

7. How do we protect your personal data?

7.1. The protection of your personal data is extremely important to us. Some of the protection measures we implement are the following: 

7.1.1. Implement database pseudonymization whenever possible;
7.1.2. Application of modern methods of protection and control access to data resources containing  personal data;
7.1.3. Continuous monitoring  of all resources (physical spaces where your data is stored) that are used to process personal data.

7.2. The purpose of implementing these measures is to prevent the risk of destruction , loss, alteration, unauthorized disclosure or access to your personal data.

7.3. We also request the use of appropriate protection measures , in relation to your personal data, from third parties who have the right to access and process your personal data , as stated in Article 5, paragraph 5.2.

8. In what period do  we keep your personal data?

8.1. For data where there is a statutory retention period, we store your data in that period and delete them for an additional period of one year.  

8.2. We keep your personal data as our Clients , for which there is no defined legal retention period, for the entire duration of the contract we have concluded with you. Upon termination of the contract , we delete your data within an additional period of 6 years from the termination of the contract (statute of limitations of 5 years , increased by 1 year period for deletion).

8.3. Personal data that we process based on our legitimate interest, we store as long as our legitimate interest exists, and we delete it within a period od 2 years from the termination of our legitimate interest. 

8.4. We store personal data that we process on the basis of your consent as long as we have your consent. In case of withdrawal of consent , we delete them as soon as possible.

8.5. The above periods of storage of your personal data are defined based on the following criteria:
• The period during which we need your personal data in order to be able to provide you with our services , products or manage your business;
• If you have registered account with us, then we process your personal data as long as you are an active user of the account;
• Whether there is a legal, contractual or similar obligation to retain your personal data.

9. What regulations apply?

9.1. The protection of your personal data is regulated by the Law on Personal Data Protection(„Official Gazette of RS“, No.87/2018).

10. Your rights

10.1. If you choose to exercise one or more of your rights below, the Company  has the right to verify your identity , all for the purpose  of protecting personal information.
10.2. You exercise your rights for free. 
Exceptionally, if your request is obviously unfounded or excessive (e.g. you are asking  for personal data that you have), and especially if the same request is repeated frequently (e.g. less than 6 months have passed since the last request), the Company has  the right to charge  necessary costs to act on your request or to refuse to act on your request.  

10.3. Access to your personal data:
You have the right to ask us for information on whether we process  your personal data , access to that data, as well as information on processing in accordance with Article 26 of the Law. Please send questions and requests, in writing and signed , to privacy.orbicors@orbico.com. We will respond  to your request immediately , and within a month at the latest, unless the exceptional complexity  of an individual case  does not require an extension of the specified deadline.

10.4. Correction  of inaccuracies, additions, deletions, restrictions on the use of personal data:
You have the right to request the correction of your inaccurate personal data, as well as the right to supplement, delete  and limit the use of your personal data. Please send questions and requests, in writing and signed, to privacy.orbicors@orbico.com.   We will respond to your request immediately, and at the latest within a month, unless the exceptional complexity of the individual case requires an extension of the specified deadline. 

10.5. Portability of personal data
You have the right to download and request the transfer of your personal data. Please send questions and requests, in writing and signed, to the adress
privacy.orbicors@orbico.com. We will respond to your request immediately, and at the latest within a month, unless the exceptional complexity of the individual case requires an extension of the specified deadline. 

10.6. The right to withdraw consent and forget 
You have the right to withdraw your consent to the processing of personal data as well as to request that your personal data that we have processed on the basis of your consent be permanently deleted. Please send the question and requests, in writing and signed, to the adress 
privacy.orbicors@orbico.com. We will respond to your request immediately, and at the latest within a month, unless the exceptional complexity of a particular case requires an extension of the specified deadline.

10.7. Complaint against the processing or handling of your personal data:
You have the right to object to the processing of your personal data as well as to our way of handling your  personal in general. Your request to us is privacy.orbicors@orbico.com  send by e-mail to to the adress, where in the title of  the message you state the Objection against processing and in the message itself you explain the reason for the objection and your request.

10.8. The right to complain to the Commissioner for Information of Public Importance and Personal Data Protection
As a Client, at any time you have the right to complain to the competent authority for personal data protection-the Commissioner for Information of Public Importance and Personal Data Protection (https://www.poverenik.rs/) .
 

Cookie notice


In this guide, we use the term „cookies“ in relation to cookies and other similar technologies covered by Article 12, paragraph 1, item 6 of the Law on Personal Data Protection (legitimate interest) on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website you are visiting, that contain data. They are stored on the visitor`s computer to allow the user to access various functions.

Both session cookies and non-session cookies are used on our site.

The session cookie is temporarily stored in computer`s memory while the visitor browses the website. This cookie is deleted when the user closes his web browser or after the certain time (which means after the session expires).

A cookie without a session remains on the visitor`s computer until it is deleted.

Why do we use cookies?

We use cookies to learn more about how visitors interact with the content of our websites and to help us improve their experience when visiting our website.

Function and content of the website

The sharing feature is used by visitors to recommend our websites and content on social networks such as Facebook. Cookies store information about  how visitors use the sharing feature –though not on an individual level- so that the website can be improved. If you do not accept cookies, the data is not saved.

We use third-party services for some of the features on our websites , for example, when you visit a page with  videos embedded or linked  to You Tube . These videos or links (as well as some third-party content) may contain third-party cookies, and information on the use of such cookies can be found in the policies on third-party websites.

Web analytics

This website uses Google Analytics which uses cookies. On a common level, cookies store information about how visitors use the website, including the number of pages displayed, where visitors come from, as well as the number of visits , in order to improve the website and ensure a good user experience. If you do not accept cookies, the data is not saved.

How do I refuse and delete cookies?

We will not use cookies to collect personal visitor information.

However, you may refuse or block cookies provided by Orbico Beauty d.o.o. or websites of any third parties set up, by changing the settings of your browsers – see the „Help function“ in your browser for futher details.

Keep in mind that most browsers automatically accept cookies, so if you do not want to use them, you may need to actively delete or block cookies.

For information on the use of cookies in mobile phone or browsers and details on how to refuse or delete such cookies, see the manual for your mobile phone.

Please note that if you refuse to use cookies, you will still be able to visit our websites, but some features may not work properly.

Privacy - general 2


Privacy Policy


INTRODUCTORY INFORMATION

Respecting the right to privacy of the persons who entrusted ORBICO Sp. z o.o. (hereinafter referred to as "Orbico") with their personal data, we would like to state that we process the collected data in accordance with national and European legal regulations and in conditions ensuring their safety. In order to ensure transparency of data processing, we present the rules of personal data protection applicable in Orbico, as laid down in the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)  (General Data Protection Regulation, hereinafter referred to as the "GDPR").

Data Controller

The controller, i.e. the entity deciding about the purposes and means of personal data processing is ORBICO Sp. z o.o. with its registered office in Warsaw 02-675 at ul. Wołoska 5, entered in the National Court Register by the District Court for the Capital City of  Warsaw in Warsaw, 13th Commercial Division under the number: KRS 0000046562, REGON: 277632751, NIP: 646-25-26-337, share capital PLN 40 841 450,00.

Orbico attaches considerable importance to the protection of personal data, which is why as a Controller it encourages you to contact in case of any doubts regarding the processing of your personal data at the e-mail address iod.no.pl@orbico.com

Obtaining personal data and the purpose of their processing

Orbico is a member of the Orbico Group, the largest distributor in Europe.  While running our business we process personal data for the following purposes:

Conclusion and performance of a contract  with a customer or a contractor
Art. 6, sec. 1b and f of the GDPR
For the term of the contract, and after its termination until the expiration of the claims resulting from it, as a rule - for 3 years (in the case of a sales contract within the scope of the business activity of the company - for 2 years), maximum: for 6 years.
In connection with actions taken in order to conclude a contract or in relation to its performance, the Data Controller shall contact the employees/co-operators of clients and contractors for a justified purpose. Moreover, the Controller may obtain from the contracting party the basic data of its employee/co-worker (name, surname, place of employment or cooperation, telephone number, e-mail adress and in specific situations the document number with a photo) in connection with the performance of the contract to which the data relate, from the entity with which the person is employed or cooperates.

Complaints handling
Art. 6, sec. 1b and f of the GDPR
For 1 year from the date of expiration of the warranty or complaint solution.
In connection with the processing of a complaint, the Controller shall contact the employees/workers of the clients for a justified purpose.

Assertion of claims or defense against claims
Art. 6, sec. 1f of the GDPR
For the duration of proceedings concerning the claims, i.e. until their final settlement, and in the case of enforcement proceedings until the final settlement of the claims being pursued.
In connection with assertion of claims or defending against claims, for a justified purpose the Controller may process the data of customers, contractors,  employees/co-operators of customers or contractors.

Filing the documents i.e. agreements and settlement documents
Art. 6, sec. 1c of the GDPR
For the periods specified by law and if, with regard to certain documents, they are not indicated, for the time when their storage is within the scope of the legally justified purpose of the Controller, depending on the time of claims assertion

Keeping statistics and analyses
Art. 6, sec. 1f of the GDPR
Until another processing purpose specified in this table is met.. We do not store personal data exclusively for statistical and analytical purposes.
Keeping statistics and analysis of activities allows the controller to improve the business.

Marketing activities without the use of electronic means of communication
Art. 6, sec. 1f of the GDPR
Until you object i.e. inform us in any form that you do not wish to be contacted by us and that you do not want to be informed of the actions we take.
Marketing activities promoting our business.

Marketing activities with the use of electronic means of communication
Art. 6, sec. 1a GDPR
Due to other applicable regulations, in particular, the Telecommunications Law and the Act on providing services by electronic means these activities are conducted on the basis of consents obtained.
Until you withdraw your consent, i.e. inform us in any form that you do not wish to be contacted by us and that you do not want to be informed of the actions we take. After withdrawal of your consent - in order to prove compliance of Orbico with its legal obligations and related claims (up to 6 years from the revocation of your consent).
Marketing activities promoting our business with the use of email addresses and telephone numbers.

Access control, including monitoring on the premises of the Data Controller for the purposes of improving the security of employees, protection of property and confidentiality of information 
Art. 6, sec. 1c and f of the GDPR
Until an objection is lodged (no longer than one year)
Image recordings shall only be processed for the purposes for which they were collected and shall be kept for a period not exceeding 3 months from the date of recording, unless the recording is an evidence in the proceedings, and then  - until the proceedings are finally terminated or until an objection is lodged.
Access control for persons staying on the territory of the Controller is its legitimate purpose, and in the case of employees it is specified in legal regulations (Article 222 of the Labour Code).
Moreover, the Controller may obtain the basic data of an employee/co-worker (name, surname, place of employment or cooperation, telephone number and in specific situations the document number with a photo) before the arrival of the data subject, from the entity with which the data subject is employed or with which it cooperates.

Recruitment process
Art. 6, sec. 1a, b, c and f of the GDPR
Up to 3 months from the end of the recruitment process, and in case of consent for further recruitment processes not longer than for 2 years.
Without additional consent of the data subject, the Controller may store the data of candidates for employment who have not been employed  for 3 months after the end of the recruitment process as a legitimate objective of the Controller, as the employed employee/co-operator may not prove himself/herself good at the position or may resign.

HR management  (employees and cooperators)
Art. 6, sec. 1a, b, c and f of the GDPR
Art. 9, sec. 2b of the GDPR
Pursuant to the binding provisions on archiving labour law documents, i.e. personal files for years and in some cases - for 10 years. The 10-year period for keeping records  related to employment relationship and employees' personal files shall apply to all employees employed after 1 January 2019. In the case of employees employed after 31 December 1998 and before 1 January 2019, records related to employment relationship and the employees' personal files shall be kept for 50 years from the date of termination or expiry of the employment relationship, unless the employer makes a statement of intent to provide reports concerning all employees and contractors employed during that period, and the employer actually submits such reports.
If the retention period of  selected documents is shorter, the Controller will follow this shorter retention period. Civil law contracts shall be stored until the expiration of the statute of limitations of the resulting claims.
Facial image may be used by the Controller only with the consent of the employee / cooperator.

Contact form at a website
Art. 6, sec. 1f of the GDPR
Until an objection is lodged (no longer than one year)
Providing answers to requests and enquiries made with the use of a contact form or in any other form, including storing sensitive requests and answers provided, with a view to maintaining the principle of accountability.

Adapting the content of websites to user's needs, optimizing the use of websites
Art. 6, sec. 1f of the GDPR
Personal data will be processed for the periods indicated in the Information on the use of "cookies" or until you object to the data being processed.
Expressing an objection can only occur by changing the settings of the end user's browser, which will prevent the collection of information using cookies.
The legitimate interest of the Controller, which is service of websites, website user's visits and analysis of website activity, as well as optimization of the use of websites.

If the time limits for pursuing potential claims are shorter than the time limits for storing settlement documents for tax purposes, we will store them for the time necessary for tax and settlement purposes, i.e. for 5 years from the end of the year in which the tax obligation has been updated.
We have collected your personal data from the following sources: 
- publicly accessible registers,
- directly from you
- from superiors, co-operators, employees and co-workers
- from another member of Orbico Group, which is a separate controller, but only for internal administrative purposes. To use your personal data for any other purpose we will ask you for your consent.


Data recipients

In connection with its business, Orbico will disclose your personal information to the following entities:

- state bodies or other entities qualified under the provisions of law,
- entities supporting us in conducting our business by our order, in particular: providers of external IT systems supporting our business, transport companies and providers of postal and courier services, entities auditing our operations, entities cooperating with Orbico in marketing campaigns, as well as providing consulting, legal and insurance services. Such entities, however, will process data on the basis of an agreement with Orbico and only in accordance with its instructions,
- banks in case of a need to conduct settlements,
- producers of goods for which Orbico is a distributor,
- other companies of Orbico Group.


Powers with regard to the processing of data and the voluntary nature of the provision of data

Each person whose data is processed by Orbico is entitled to:

- access their personal data
- rectify their personal data
- erase their personal data
- limit the processing of their personal data
- object against processing their personal data
- portability of their personal data

For more information on the rights of data subjects, see Articles 12-23 of the GDPR, the text of which can be found at the following address: https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679

Moreover, the person whose data is processed by Orbico has the right to lodge a complaint with the supervisory authority, i.e. the President of the Office for Personal Data Protection. More information at the following address: https://uodo.gov.pl/pl/p/skargi

Do you have to provide your personal data?

Providing data is necessary for concluding agreements, settlement of business transactions as well as for the fulfilment of legal requirements by Orbico. For the remaining purposes (in particular for the purpose of processing the data by Orbico for marketing purposes), the provision of the data is voluntary.

Transfer of data to third countries

In certain situations, data may be transferred to third countries. The transfer of personal data always takes place on the basis of legal regulations, including the basis of a decision of the European Commission stating the appropriate degree of protection of that third country or with the application of appropriate safeguards referred to in art. 46 of the GDPR or in special situations referred to in art. 49 of the GDPR. Further information on the transfer of data to third countries and the legal bases can be obtained by e-mail via the Data Protection Officer.

Processing of personal data by automated means 
Personal data will not be processed by automated means (including profiling) in such a way that such could result in making decisions or obtaining any legal effect or otherwise significantly affect our customers, business partners and their employees/co-workers.

Privacy - general


INTRODUCTORY INFORMATION

Respecting the right to privacy of the persons who entrusted ORBICO Sp. z o.o. (hereinafter referred to as "Orbico") with their personal data, we would like to state that we process the collected data in accordance with national and European legal regulations and in conditions ensuring their safety. In order to ensure transparency of data processing, we present the rules of personal data protection applicable in Orbico, as laid down in the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)  (General Data Protection Regulation, hereinafter referred to as the "GDPR").

Data Controller

The controller, i.e. the entity deciding about the purposes and means of personal data processing is ORBICO Sp. z o.o. with its registered office in Warsaw 02-675 at ul. Wołoska 5, entered in the National Court Register by the District Court for the Capital City of  Warsaw in Warsaw, 13th Commercial Division under the number: KRS 0000046562, REGON: 277632751, NIP: 646-25-26-337, share capital PLN 40 841 450,00.

Orbico attaches considerable importance to the protection of personal data, which is why as a Controller it encourages you to contact in case of any doubts regarding the processing of your personal data at the e-mail address iod.no.pl@orbico.com

Obtaining personal data and the purpose of their processing

Orbico is a member of the Orbico Group, the largest distributor in Europe.  While running our business we process personal data for the following purposes:

Conclusion and performance of a contract  with a customer or a contractor
Art. 6, sec. 1b and f of the GDPR
For the term of the contract, and after its termination until the expiration of the claims resulting from it, as a rule - for 3 years (in the case of a sales contract within the scope of the business activity of the company - for 2 years), maximum: for 6 years.
In connection with actions taken in order to conclude a contract or in relation to its performance, the Data Controller shall contact the employees/co-operators of clients and contractors for a justified purpose. Moreover, the Controller may obtain from the contracting party the basic data of its employee/co-worker (name, surname, place of employment or cooperation, telephone number, e-mail adress and in specific situations the document number with a photo) in connection with the performance of the contract to which the data relate, from the entity with which the person is employed or cooperates.

Complaints handling
Art. 6, sec. 1b and f of the GDPR
For 1 year from the date of expiration of the warranty or complaint solution.
In connection with the processing of a complaint, the Controller shall contact the employees/workers of the clients for a justified purpose.

Assertion of claims or defense against claims
Art. 6, sec. 1f of the GDPR
For the duration of proceedings concerning the claims, i.e. until their final settlement, and in the case of enforcement proceedings until the final settlement of the claims being pursued.
In connection with assertion of claims or defending against claims, for a justified purpose the Controller may process the data of customers, contractors,  employees/co-operators of customers or contractors.

Filing the documents i.e. agreements and settlement documents
Art. 6, sec. 1c of the GDPR
For the periods specified by law and if, with regard to certain documents, they are not indicated, for the time when their storage is within the scope of the legally justified purpose of the Controller, depending on the time of claims assertion

Keeping statistics and analyses
Art. 6, sec. 1f of the GDPR
Until another processing purpose specified in this table is met.. We do not store personal data exclusively for statistical and analytical purposes.
Keeping statistics and analysis of activities allows the controller to improve the business.

Marketing activities without the use of electronic means of communication
Art. 6, sec. 1f of the GDPR
Until you object i.e. inform us in any form that you do not wish to be contacted by us and that you do not want to be informed of the actions we take.
Marketing activities promoting our business.

Marketing activities with the use of electronic means of communication
Art. 6, sec. 1a GDPR
Due to other applicable regulations, in particular, the Telecommunications Law and the Act on providing services by electronic means these activities are conducted on the basis of consents obtained.
Until you withdraw your consent, i.e. inform us in any form that you do not wish to be contacted by us and that you do not want to be informed of the actions we take. After withdrawal of your consent - in order to prove compliance of Orbico with its legal obligations and related claims (up to 6 years from the revocation of your consent).
Marketing activities promoting our business with the use of email addresses and telephone numbers.

Access control, including monitoring on the premises of the Data Controller for the purposes of improving the security of employees, protection of property and confidentiality of information 
Art. 6, sec. 1c and f of the GDPR
Until an objection is lodged (no longer than one year)
Image recordings shall only be processed for the purposes for which they were collected and shall be kept for a period not exceeding 3 months from the date of recording, unless the recording is an evidence in the proceedings, and then  - until the proceedings are finally terminated or until an objection is lodged.
Access control for persons staying on the territory of the Controller is its legitimate purpose, and in the case of employees it is specified in legal regulations (Article 222 of the Labour Code).
Moreover, the Controller may obtain the basic data of an employee/co-worker (name, surname, place of employment or cooperation, telephone number and in specific situations the document number with a photo) before the arrival of the data subject, from the entity with which the data subject is employed or with which it cooperates.

Recruitment process
Art. 6, sec. 1a, b, c and f of the GDPR
Up to 3 months from the end of the recruitment process, and in case of consent for further recruitment processes not longer than for 2 years.
Without additional consent of the data subject, the Controller may store the data of candidates for employment who have not been employed  for 3 months after the end of the recruitment process as a legitimate objective of the Controller, as the employed employee/co-operator may not prove himself/herself good at the position or may resign.

HR management  (employees and cooperators)
Art. 6, sec. 1a, b, c and f of the GDPR
Art. 9, sec. 2b of the GDPR
Pursuant to the binding provisions on archiving labour law documents, i.e. personal files for years and in some cases - for 10 years. The 10-year period for keeping records  related to employment relationship and employees' personal files shall apply to all employees employed after 1 January 2019. In the case of employees employed after 31 December 1998 and before 1 January 2019, records related to employment relationship and the employees' personal files shall be kept for 50 years from the date of termination or expiry of the employment relationship, unless the employer makes a statement of intent to provide reports concerning all employees and contractors employed during that period, and the employer actually submits such reports.
If the retention period of  selected documents is shorter, the Controller will follow this shorter retention period. Civil law contracts shall be stored until the expiration of the statute of limitations of the resulting claims.
Facial image may be used by the Controller only with the consent of the employee / cooperator.

Contact form at a website
Art. 6, sec. 1f of the GDPR
Until an objection is lodged (no longer than one year)
Providing answers to requests and enquiries made with the use of a contact form or in any other form, including storing sensitive requests and answers provided, with a view to maintaining the principle of accountability.

Adapting the content of websites to user's needs, optimizing the use of websites
Art. 6, sec. 1f of the GDPR
Personal data will be processed for the periods indicated in the Information on the use of "cookies" or until you object to the data being processed.
Expressing an objection can only occur by changing the settings of the end user's browser, which will prevent the collection of information using cookies.
The legitimate interest of the Controller, which is service of websites, website user's visits and analysis of website activity, as well as optimization of the use of websites.

If the time limits for pursuing potential claims are shorter than the time limits for storing settlement documents for tax purposes, we will store them for the time necessary for tax and settlement purposes, i.e. for 5 years from the end of the year in which the tax obligation has been updated.
We have collected your personal data from the following sources: 
- publicly accessible registers,
- directly from you
- from superiors, co-operators, employees and co-workers
- from another member of Orbico Group, which is a separate controller, but only for internal administrative purposes. To use your personal data for any other purpose we will ask you for your consent.


Data recipients

In connection with its business, Orbico will disclose your personal information to the following entities:

- state bodies or other entities qualified under the provisions of law,
- entities supporting us in conducting our business by our order, in particular: providers of external IT systems supporting our business, transport companies and providers of postal and courier services, entities auditing our operations, entities cooperating with Orbico in marketing campaigns, as well as providing consulting, legal and insurance services. Such entities, however, will process data on the basis of an agreement with Orbico and only in accordance with its instructions,
- banks in case of a need to conduct settlements,
- producers of goods for which Orbico is a distributor,
- other companies of Orbico Group.


Powers with regard to the processing of data and the voluntary nature of the provision of data

Each person whose data is processed by Orbico is entitled to:

- access their personal data
- rectify their personal data
- erase their personal data
- limit the processing of their personal data
- object against processing their personal data
- portability of their personal data

For more information on the rights of data subjects, see Articles 12-23 of the GDPR, the text of which can be found at the following address: https://eur-lex.europa.eu/legal-content/PL/TXT/?uri=CELEX%3A32016R0679

Moreover, the person whose data is processed by Orbico has the right to lodge a complaint with the supervisory authority, i.e. the President of the Office for Personal Data Protection. More information at the following address: https://uodo.gov.pl/pl/p/skargi

Do you have to provide your personal data?

Providing data is necessary for concluding agreements, settlement of business transactions as well as for the fulfilment of legal requirements by Orbico. For the remaining purposes (in particular for the purpose of processing the data by Orbico for marketing purposes), the provision of the data is voluntary.

Transfer of data to third countries

In certain situations, data may be transferred to third countries. The transfer of personal data always takes place on the basis of legal regulations, including the basis of a decision of the European Commission stating the appropriate degree of protection of that third country or with the application of appropriate safeguards referred to in art. 46 of the GDPR or in special situations referred to in art. 49 of the GDPR. Further information on the transfer of data to third countries and the legal bases can be obtained by e-mail via the Data Protection Officer.

Processing of personal data by automated means 
Personal data will not be processed by automated means (including profiling) in such a way that such could result in making decisions or obtaining any legal effect or otherwise significantly affect our customers, business partners and their employees/co-workers.

Privacy - general


ORBICO Beauty Kft., 1138 Budapest, Dunavirág utca 2-6 Gateway Office Park 3. 3.emelet
EU VAT: HU23953253
Issued 25th May 2018.

DATA PRIVACY AND PROTECTION OF YOUR DATA

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.
This Privacy notice is valid as of 25th May 2018. It is published on www.orbicobeauty.hu
If case of any questions or demands regarding data privacy and data protection of your data, please kindly send us an email to email address privacy.orbicobeautyhu@orbico.com.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico Beauty may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communications might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any timeby sending a notice to our e-mail address: privacy.orbicobeautybg@orbico.com or according to the information posted on our website.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Your information may also be processed in a destination outside of the European Economic Area Third parties are limited in their ability to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Hungary Kft , with its head office at 1138 Budapest, Dunavirág utca 2-6 Gateway Office Park 3. 3.emelet is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities privacy.orbicobeautyhu@orbico.com should contact for any questions you may have relating to the way our company uses your data.

For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law of Hungary.
We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit www.naih.hu.
Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address privacy.orbicobeautyhu@orbico.com . We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may
(a) contact the [Entity Privacy Manager]: privacy.orbicobeautyhu@orbico.com, and/ or
(b) lodge a complaint with the supervisory authority, www.naih.hu

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico Beauty may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communications might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any timeby sending a notice to our e-mail address: privacy.orbicobeautybg@orbico.com or according to the information posted on our website.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Your information may also be processed in a destination outside of the European Economic Area Third parties are limited in their ability to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Beauty, with its head office at Sofia, 18 Mile Popyordanov Str. is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities Republic of Bulgaria, Commission for personal data protection, should contact for any questions you may have relating to the way our company uses your data.
For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law. We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit https://www.cpdp.bg/. Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address Sofia, 18 Mile Popyordanov Str. or on на e-mail: privacy.orbicobeautybg@orbico.com. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may

(a) contact the Entity Privacy Manager: Sofia, 18 Mile Popyordanov Str., privacy.orbicobeautybg@orbico.com ,
and/ or (b) lodge a complaint with the supervisory authority, Commission for personal data protection - https://www.cpdp.bg/

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

Issuer: Orbico Beauty s.r.o.
Published: 25 May 2018
Implementation: 25 May 2018

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico Beauty may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communications might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time. e.g. unsubscribe email, website preferences upon login or sending a notice to our email address privacy.orbicobeautycz@orbico.com.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Your information may also be processed in a destination outside of the European Economic Area Third parties are limited in their ability to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

For the purposes of marketing campaigns or sending notifications, we may use the services of The Rocket Science Group LLC d / b / a MailChimp based in the United States (you can read more about how it processes your personal data through the Mailchimp Privacy Policy available here). In these cases, your personal data may be stored in the United States.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Beauty s.r.o., with its head office at Vinohradská 1597/174, Praha 3, 130 00 is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities The Office for Personal Data Protection (Úřad pro ochranu osobních údajů, www.uoou.cz) should contact for any questions you may have relating to the way our company uses your data.
For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law. We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit www.uoou.cz. Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address privacy.orbicobeautycz@orbico.com. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may
(a) contact the Entity Privacy Manager: privacy.orbicobeautycz@orbico.com
(b) lodge a complaint with the supervisory authority, The Office for Personal Data Protection (Úřad pro ochranu osobních údajů, www.uoou.cz )

Privacy notice


This Privacy Notice (further as: Notice) describes the way trading company INTERBRANDS Orbico S.R.L. with headquarters in One Cotroceni Park, Building A, 3rd floor, Str. Nutu Ion 44, Sector 5, Bucharest, Romania, VAT nr.: RO 3786280 (hereinafter: "Orbico") processes your personal data. 

This Notice is harmonized in line with respect to Regulation (EU) 2016/679 of the European Parliament and of the Council of April 27, 2016 on the protection of individuals in connection with processing of personal data and on the free movement of such data and on the repeal of Directive 95/46/EC (General Data Protection Regulation) (hereinafter: „GDPR“).

To help better understand (or remind) you what processing and personal data mean in the sense of GDPR, please see below table. 

Personal data
Any information relating to an identified or identifiable natural person (‘data subject’); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person.

Personal data processing
any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

1. Scope

This Notice governs the general way Orbico processes personal data. In this sense, Orbico is the so-called Data controller with regard to the personal data it processes. Also, this Notice applies to Orbico and does not apply to the services of other companies within the group to which Orbico belongs, nor to companies managed by third parties. 

Note that for processsing of personal data in specyfic cases, for example purchase of our goods, a separate privacy policy is applicable, which you can access on the respective webpage.

2. Purposes and legal bases for data processing

Administrative communication
communication with you about Orbico services and any inquiries you may have when contacting us, either using the contact form on this page or any other means of communication (such as our profile on various social media platforms).
Processing purpose: Responding to your inquiries.
Legal basis: Orbico’s legitimate interest to respond to your inquiry – GDPR Article 6. Par 1 (f).

Prize games/Award winning contests
we process personal information you provide us when registering to such an event. If you won any of the main prizes, and invited to the award ceremony. That event may be recorded and the recording published publicly.    
Processing purpose: To facilitate participation in prize game/award winning contest and organize distribution of awards for winners.
Legal basis: Your consent to participate in the prize game/award winning contest – Article 6. par. 1 (a) GDPR.

Cookies 
Orbico only stores cookies you selected upon opening this website. You can read more about those cookies in our cookie policy
Processing purpose: Provision of the website, analytical tools for improving the website and user experience. 
Legal basis: Your consent to accept the cookies – Article 6. par. 1 (a) GDPR.

In any case, Orbico does not carry out automated decision-making based on your personal data, nor does Orbico create profiles of data subjects for this purpose.

3. Transfer and disclosure of your personal data

Depending on the type of process within which we process your personal data, some data may be transferred to third parties. In these cases the subject entities are acting as processors and are processing data in accordance with our instructions. These parties are required by contract to safeguard any personal data they receive from us and are prohibited from using them contrary to our instructions. 

These third parties may refer to:
• Companies within the Group of which Orbico belongs to;
• Third party service providers which process your personal data on behalf of Orbico and which are obliged to preserve the confidentiality of your personal data. (e.g.  IT support providers,  logistical support providers, etc.);
• Public authorities, regulatory agencies  for the purpose of complying with applicable legislation;
• Professional advisers – persons which provide to us certain consultancy services may have access to your personal data if this is required for providing the subject service. 

Your personal data are processed and transferred within the territory of the European Union. 

If personal data would be transferred to other countries outside the European Union (third countries) Orbico shall rely on  Standard Contractual Clauses, i.e. Commission Implementing Decision (EU) 2021/914 of June 4, 2021 on standard contractual clauses for the transfer of personal data to third countries in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council. 

The transfer of data based on the aforementioned mechanism is envisaged in Article 46 of the GDPR in those situations where the European Commission has not issued a Decision on Adequacy for the third country to which personal data is to be transferred.

4. Your personal data storage period

The storage period of your personal data will primarily depend on the purpose for which it was collected, or the reason for which we process your personal data. In this sense, we guarantee that we will not store your data longer than is absolutely necessary to fulfill the purpose for which it was collected.
If the processing is based on consent , we retain your personal data for the period your consent was given, or until you withdraw your consent.
If the procssing is based on our legitimate interest, we retain your personal data as long as our legitimate interest exists.
If the processing is based on our legal obligation, we retain your personal data as long as we are required by law which is the basis for such processing. 

5. Your rights

You can exercise your rights regarding your personal data by contacting us through privacy.orbicobeautyro@orbico.com. You can use our Data Subject Request Form to exercise your rights available on our web site. Please note that you can only exercise your rights regarding your personal data.

With respect to you personal data you have the following rights: 

Access to your personal data
You have the right to ask us to confirm whether we process your personal data, as well as access to your personal data that we process.

Rectification of personal data
You have the right to ask us to correct your inaccurate personal data, as well as the right to supplement your personal data.

The right to withdraw consent
You have the right to withdraw your consent for further processing of personal data at any time. The withdrawal of consent does not affect processing performed on the basis of consent prior to its withdrawal.

Deletion of personal data (the right to be forgotten)
If you withdraw your consent to the processing of your personal data or when the legal basis for the processing of your personal data ceases or in other cases provided by the General Data Protection Regulation, you have the right to ask us to delete your personal data.

Portability of personal data
If we process your personal data based on your consent or based on our contract, you have the right to request us to transfer your personal data in an appropriate manner.

Objection to the processing of personal data
If we process your personal data for the purposes of direct marketing or based on our legitimate interest, you have the right to object to further processing of your personal data.

Limitation of processing
If you dispute the accuracy of your personal data or in other situations provided for in the General Data Protection Regulation, you have the right to ask us to limit the processing of your personal data until such a situation is resolved.

The right to complain to the Personal Data Protection Agency
At any time, you have the right to complain before the personal data protection authority relevant for your respective country (https://edpb.europa.eu/about-edpb/about-edpb/members_en) regarding the processing and protection of your personal data.

You exercise your rights without cost. However, if you frequently or excessively (for example, requesting all your personal information in writing) request access to or transfer of your personal information, we have the right to ask you to bear our costs before carrying out such an action.

6. Data safety

We also inform you that Orbico uses a wide range of data security measures to ensure the confidentiality and integrity of your personal data. 
However, given the nature of the Internet, we would like to draw your attention to the fact that there may be security flaws in the transmission of data via the Internet (e.g. communication via e-mail) and that complete protection of data from access by third parties is not possible. However, as we have stated, Orbico pays great attention to the protection of your personal data and in this sense, considering the described nature of this medium, has organized and is conducting significant technical and security measures.

7. Changes in the Policy

We reserve the right to change this Notice at any time. 

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

Issuer: Orbico Beauty s.r.o., organizačná zložka
Published: 25 May 2018
Implementation: 25 May 2018

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communications might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time. e.g. unsubscribe email, website preferences upon login or sending a notice to our email address privacy.orbicobeautysk@orbico.com.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Your information may also be processed in a destination outside of the European Economic Area Third parties are limited in their ability to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Beauty s.r.o., organizačná zložka with its head office at Kutlíkova 17, Bratislava 5 - 851 02 is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities, The Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, www.dataprotection.gov.sk) should contact for any questions you may have relating to the way our company uses your data.

For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law. We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit www.dataprotection.gov.sk. Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address privacy.orbicobeautysk@orbico.com. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may
(a) contact the Entity Privacy Manager: privacy.orbicobeautysk@orbico.com
(b) lodge a complaint with the supervisory authority, The Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky, www.dataprotection.gov.sk).

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

ORBICO BEAUTY d.o.o., Verovškova 72, 1000 Ljubljana
Issued 25th May 2018.

1. Introduction

Your privacy is important to us, Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Since Orbico Group is a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.
This Privacy notice is valid as of 25th May 2018. It is published on www.orbico.si.
If case of any questions or demands regarding data privacy and data protection of your data, please kindly send us an email to email address privacy.orbicobeautyslo@orbico.com .

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore these communication might be tailored to you preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in out emails).

When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time, e.g. unsubscribe email, website preferences upon login or sending a notice to our email address privacy.orbicobeautycro@orbico.com.

Currently not used, but if personal data is intended to be used for automated decision-making, including profiling, information about the logic shall be provided as well as the significance and the envisaged consequences of such processing for the data subject.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Your information may also be processed in a destination outside of the European Economic Area Third parties are limited in their ability to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Beauty d.o.o. , with its head office at Verovškova, 72 Ljubljana is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities privacy.orbicobeautyslo@orbico.com should contact for any questions you may have relating to the way our company uses your data.

For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation and applicable national data protection law of Slovenia.
We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit www.azop.hr.
Being Orbico a multinational company, this Notice may be replaced or supplemented in order to fulfil local requirements.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent and/ or request any erroneous data to be corrected. Please make your enquiries and requests in writing, sign and send your letter to the address privacy.orbicobeautyslo@orbico.com .We will respond promptly and no later than within a month,unless extraordinary complexity would require an extension of the time to respond.

If you have any issues exercising your rights regarding personal data you may
(a) contact the [EntityPrivacyManager]: privacy.orbicobeautyslo@orbico.com, and/or
(b) lodge a complaint with the supervisory authority, www.azop.hr

Privacy - general


Privacy Policy | ORBICO d.o.o.

1. General

1.1. This Privacy Policy is issued by Orbico d.o.o., with registered seat in Zagreb, Koturaška Cesta 69, PIN: 85611744662 (hereinafter „Orbico“ or „We“) provides you with information about the processing of your personal data when Orbico is acting as a data controller.
1.2. For some of our products or services, the protection of personal data of the users is regulated by separate privacy policies, which regulate the processing of personal data in more detail. This Privacy Policy applies to and regulates other situations in which personal data is processed, and where Orbico acts as a data controller or the person determining the purpose and manner of the processing of your personal data.
1.3. In case of any questions or requests regarding the handling or protection of your personal data, please contact us at privacy.orbicocro@orbico.com or by post at the address of the company's registered seat Data Protection Officer, Orbico d.o.o., Zagreb, Koturaška Cesta 69 
1.4. This version of the Privacy Policy applies from the date indicated above. The previous version from 25 May 2018, is amended with this version. The amendments include in particular more clear regulation of situations in which Orbico processes personal data of data subjects.
1.5. Special notice due to the Covid-19 pandemic: For the duration of the pandemic, we may ask you to confirm that you have no symptoms of the disease as well as ask that we measure your temperature. We do not record or further process such data, but we prohibit potentially infected persons from entering our premises or participating in our events, all for the protection of our employees, other visitors, and participants.

2. Orbico website and social networks visitors

2.1. If you are a visitor of website www.orbico.com or a website on a local (national) domain operated by Orbico, Orbico only stores your cookies, i.e. cookies you selected upon opening the website. You can read more about the cookies, the purpose for which they are used and the possible choices on our website.
2.2. You can contact us via contact form available on Orbico website. In that case, we collect the data you provided to us in the form. These are the following data: name and surname, e-mail address and the IP address from which you accessed our website.
2.3. If you are a Facebook user and have visited our Orbico Facebook page, Facebook Ireland Ltd (4 Grand Canal Square, Grand Canal Harbor, Dublin 2 Ireland) and Orbico are joint controllers. You can read more about the processing of your personal data via Facebook at https://hr-hr.facebook.com/privacy/explanation
2.4. If you are a user of other social networks and you have contacted us through them (Instagram, Linkedin, etc.), we process your personal data listed there only to get back to you. We are solely responsible for all our posts and messages via Orbico social networks (Facebook, Instagram, Linkedin, etc.) and the owners of these social networks do not necessarily share our views and vision.

3. Visitors

3.1. If you have visited one of our business premises (office premises, logistics centers, etc.), we process the personal data you provided us with at the entrance to the premises as well as a video recording of your entry / exit from the premises. These are the following data: name and surname, ID number, purpose of your arrival, time of arrival, contact person in Orbico and your video recording. Please note that not all our business premises are under video surveillance. Before entering our business premises, you will be appropriately warned that our business premises are under video surveillance.
3.2. If you have visited one of our retail locations, we are processing a video recording of your entry / exit. At some retail locations we may offer to sign up to receive our newsletters. In this case, for more information see point 6 of this Privacy Policy - Orbico Newsletter recipients.

4. Participants in the events we organized

4.1. If you participated in an event organized by us, we process the personal data you provided to us when applying for the event as well as upon arrival at the event.
4.2. Our events can be recorded (video recording and photographs). In such case, we will separately inform you in the invitation as well as at the entrance to the premises where the event takes place. The purpose of the recording is to promote the event and Orbico and the recordings are published.
4.3. If you are a panelist, speaker or host, we can publish your name and surname, your profession, position and experience when announcing you as well when reporting about the event (along with recordings from the event).

5. Participants in our prize games

5.1. If you have participated in one of our promotional or prize games, we process the personal data you have provided us with when registering and during participation in the prize game. The results of our promotional and prize games, i.e. the names and surnames of the winners, together with the information on the prize, are published publicly.
5.2. If you have won one of the main prizes and are invited to the award ceremony, such an event can be recorded (video recording and photographs). Video recordings and photographs are published publicly to promote the event and Orbico. Your recording is published only if you have given us separate consent.

6. Orbico Newsletter recepients

6.1. If you have subscribed to Orbico Newsletter, we process the personal data you provided us with on the application form (usually only your e-mail address). In addition, you can also receive Orbico Newsletter if you have made purchases of our products through our web shops (in case we believe you might be interested in our offer).
6.2. If you no longer wish to receive Orbico Newsletter, you can always simply unsubscribe from the list of recipients using the instructions provided in each Orbico Newsletter.

7. Submitting proposals, questions or complaints

7.1. If you have submitted a proposal, question or complaint in person, by e-mail or through our web form, we process your personal data you provided us with in order to respond to your proposal, question or complaint.
7.2. In case of a complaint about a product or service you purchased at Orbico retail stores (product defect claim, withdrawal request, etc.), we may contact you (usually by phone) to verify all relevant circumstances of your complaint and collect information about your health (such as your skin’s reaction to a particular product) so we are able to file a complete report to the manufacturer. In such cases, we are guided primarily by manufacturer’s instructions who uses the collected information to provide you with adequate feedback and advice, as well as to identify possible product defects.

8. Our business contacts (suppliers, customers, media and promoters)

8.1. If you are identified as a supplier or as a contact person of a supplier we work with, we process your personal data provided by you or your employer, which is necessary for the following: ordering goods / services, delivery and collection, payment or in case of complaint. These are the following data: name and surname, supplier`s name, supplier`s address, your position, e-mail address, and phone number.
8.2. If you are identified as a customer or contact person of a customer we work with, we process your personal data provided by you or your employer, which is necessary for the following: sale of goods / services, delivery and collection or payment of goods / services. These are the following data: name and surname, customer`s name, customer`s address, your position, e-mail address and phone number. Exceptionally, in case of sale of IQOS products, we additionally collect customer’s date of birth and gender for the needs of Philip Morris International as a manufacturer of IQOS products. You can find out more about how Philip Morris International handles your personal data (as separate data controller or as a joint controller with Orbico) at https://pmiprivacy.com/en/consumer
8.3. In order to minimize the amount of personal data we process, we always separately inform our suppliers and customers to use only business addresses, business e-mails and business phone numbers as contact information of their contact persons. In this case, your personal data may not be processed at all.
8.4. If you work for media with which we regularly cooperate and you are our contact person in that media, or if we work directly with you for the purpose of publishing business information, we process your personal data to contact you for various business publications. These are the following data: name and surname, media / platform / profile name, your position, e-mail address and phone number.

9. Legal basis for processing your personal data

9.1. We process your personal data only when we have a valid legal basis. The legal basis depends on the purpose for which we process your personal data:
9.1.1. if you have contacted us (by post, telephone, e-mail, via social network, via a web form), we process your personal data to reply to you. In that case, the legal basis for the processing is our legitimate interest in responding to your message;
9.1.2. if you have requested to receive Orbico newsletter, we process your personal data to send you Orbico newsletter. In that case, the legal basis for the processing is our legitimate interest as a provider of that service;
9.1.3. if you have visited any of our business or retail premises, we process your personal data for the purpose of protecting our employees and property. In that case, the legal basis for the processing is our legitimate interest as an employer and property owner;
9.1.4. if you participated in one of our events, we process your personal data for the purposes of (a) organizing that event - in which case, the legal basis for processing is our legitimate interest as the organizer of the event you applied for; (b organizing our future events - in which case, the legal basis for the processing is our legitimate interest as the organizer of the event in which you have previously expressed an interest; (c) promoting that event and Orbico - in which case, the legal basis for the processing is our legitimate interest as the organizer of the event in which you participated;
9.1.5. if you are a panelist, speaker or host of our event, we process your personal data for the purpose of (a) organizing the event and (b) promoting the event and Orbico - in both cases, the legal basis for processing is our legitimate interest as the organizer of the event;
9.1.6. if you have visited Orbico social networks and contacted us, we process your personal data to reply to you. In that case, the legal basis for processing is our legitimate interest in responding to your message. We do not store your information privately. Exceptionally in case of Facebook, Facebook processes your personal data in the manner described at https://hr-hr.facebook.com/privacy/explanation, while we affect the same processing only by identifying groups of users to whom we want to send certain information (for example by age, gender or similar). We receive user data from Facebook exclusively on a statistical, for us anonymized, basis;
9.1.7. if you have participated in one of our promotional or prize games, we process your personal data for the purpose of (a) organizing a promotional / prize game and awarding a prize - in which case, the legal basis for the processing is our legitimate interest as the organizer of the game; (b) promoting of the event and Orbico - in which case, the legal basis for the processing is our legitimate interest as the organizer of the game and your separate consent if we wish to publish recordings of you from the participation in the game or receipt of the prize;
9.1.8. if you have filed a complaint (product defect, withdrawal request, etc.) about the purchased goods or services, we process your personal data for the purposes of (a) verifying the nature of your request - in which case, the legal basis for processing is our legitimate interest as the seller of the goods or services for which you filed a complaint; (b) forwarding your request to the manufacturer of the product / service - in which case, the legal basis for the processing is our legitimate interest as the seller of the goods or services to contact the manufacturer for its contracted warranties; (c) acting on your request - in which case, the legal basis for processing is our legal obligation to you as a consumer;
9.1.9. if you have submitted an open job application or applied for our job advertisement, we process your personal data for the purpose of (a) conducting the selection process and recruitment - in which case, the legal basis for processing is our legitimate interest as an employer based on your job application; (b) conducting future selection procedures - in which case, the legal basis for processing is your separate consent or our legitimate interest if you have submitted an open job application; (c) verification of your previous work experience or verification of your education or training - in which case, the legal basis for processing is your separate consent to contact the relevant persons;
9.1.10. if you are identified as a supplier, customer, other business partner or as a contact person of one of them, we process your personal data for the purposes of (a) purchase and sale of goods and services (ordering goods / services, delivery, collection, payment, complaints, sending or preparation offers) - in that case, the legal basis for the processing of your personal data is our sales contract or legitimate interest in case you are an employee of our supplier or customer, based on business cooperation with your employer; (b) fulfillment of another contract we have entered into - in which case, the legal basis for processing is our contract or a legitimate interest in the event that you are an employee of our business partner, based on business cooperation with your employer; (c) checking the satisfaction with our business cooperation - in which case, the legal basis for processing is our legitimate interest as your business partner;
9.1.11. if you work for the media or act as a separate reporter, we process your personal data for various business publications. In that case, the legal basis for the processing is our legitimate interest based on our business cooperation;
9.1.12. if you have submitted a data subject request, we process your personal data for the purpose of responding to your request. In that case, the legal basis for the processing is our legal obligation to enable you to exercise your rights regarding your personal data;
9.1.13. if you fall into any of the previous categories, (a) in the case of a security incident or suspicion of such incident, we process your personal data for the purpose of investigating the incident, taking appropriate action and being able to report the incident - in which case the legal basis for processing is our legitimate interest in protecting your data and our legal duty to notify you in the event of a data breach; (b) in the event of an audit of our business or our handling of personal data, we process your personal data for the purposes of such an audit - in which case, the legal basis for the processing is our legitimate interest in proving the lawfulness of our conduct; (c) in the event of a dispute or other proceeding before a competent authority, we process your personal data for the purpose of conducting such proceedings - in which case, the legal basis for the processing is our legitimate interest as a party to such proceedings; (d) we process your personal data for internal analysis and reporting purposes - in which case, the legal basis for the processing is our legitimate interest as a business entity;

9.2. In any case, Orbico does not carry out automated decision-making based on your personal data, nor does Orbico create profiles of data subjects for this purpose.

9.3. Orbico does not process specific categories of your personal data - those that reveal racial or ethnic origin, political opinions, religious or philosophical beliefs or union membership, and the processing of genetic data, biometric data for unique identification, health data or data about sexual life or sexual orientation of the individual. Exceptions are health-related information in case of your complaint about a purchased product such as your skin reaction to the product.

10. Third party access to your personal data

10.1. Third parties may gain access to your personal data in the situations listed below. When these third parties act as a data processor, they process your personal data in accordance with our instructions. When these third parties act as a separate data controller, we have no influence on their conduct. We regularly check our business partners to make sure that your rights are properly respected.
10.1.1. Service providers: Third party service providers who provide us with services and products necessary for our regular business may have access to your personal data if this is necessary to provide us with the contracted service (e.g. security service, delivery, maintenance and development of various IT systems and applications, web design and maintenance, advertising). Then they act in accordance with our instructions as our data processors except when their conduct is determined by law or the rules of the profession in which case they have the position of a separate data controller;
10.1.2. Related parties: Our affiliates, who are part of the Orbico Group, may have access to your personal data if required to report or provide services for the Orbico Group. Then they act in accordance with our instructions as our data processors;
10.1.3. Professional advisors: Third party service providers who provide us with consulting services may have access to your personal data if it is necessary to provide us with the contracted service (e.g. tax and legal advice, financial and business consulting, accounting, auditing). Then they act in accordance with our instructions as our data processors except when their conduct is determined by law or the rules of the profession in which case they have the position of a separate data controller;
10.1.4. Competent authorities: Different authorities may gain access to your personal data for the purpose of supervising our business or for the protection of our rights (e.g. customs administration, tax administration, personal data protection agency, police, state attorney's office, court). In that case, they process your personal data in accordance with their legal powers and they have the position of a separate data controller.

11. Transfer of personal data to third countries

11.1. Your personal data is retained in the European Union. Your personal data is only exceptionally transferred to third countries (third countries do not include other European Union countries). In this case, we transfer your personal data based on an adequacy decision of the European Commission or only after the data importer from a third country undertakes to comply with the applicable standard contractual clauses approved by the European Commission.
11.2. For the purposes of conducting marketing campaigns or sending notifications, we may use the services of The Rocket Science Group LLC d / b / a MailChimp based in the United States (you can read more about how they process your personal information in their Privacy Policy available ovdje). We only send them your e-mail address information.
11.3. Also, members of the Orbico Group operating in third countries may have access to your personal data (depending on the specific case).

12. Storage period of your personal data

12.1. We retain your personal data for the period we need to fulfill the purpose for which we collected them, and the additional reasonable period required to delete them. The retention period depends on the purpose of the processing, the sensitivity of that data, our legal obligations (for example due to statute of limitations) and our legal basis. So:
12.1.1. In the case of processing based on your consent, we retain your personal data for the period for which consent was given or until the withdrawal of the consent (we delete them within 90 days from the date of withdrawal);
12.1.2. In the case of processing based on our contract, we retain your personal data for the period of the contract and an additional limitation period of five years (we delete them within one year from the expiration of the limitation period);
12.1.3. In the case of processing based on our legal obligation, we retain your personal data during that mandatory period (we delete them after the expiration of the mandatory period, in an additional period of one year);
12.1.4. In the case of processing based on a legitimate interest, we retain your personal data as long as our legitimate interest exists - we check the existence of a legitimate interest on an annual basis (we delete the data within one year after the expiry of legitimate interest).

13. Your rights

13.1. Your rights with regard to personal data are prescribed by the General Data Protection Regulation (“Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)”).
13.2. You can exercise your rights regarding your personal data by contacting us through privacy.orbicocro@orbico.com. You can use our Data Subject Request Form to exercise your rights available on our web site. Please note that you can only exercise your rights regarding your personal data.
13.2.1. Access to personal data
You have the right to ask us to confirm whether we process your personal data, as well as access to your personal data that we process.
13.2.2. Rectification of personal data:
You have the right to ask us to correct your inaccurate personal data, as well as the right to supplement your personal data.
13.2.3. The right to withdraw consent
You have the right to withdraw your consent for further processing of personal data at any time. The withdrawal of consent does not affect processing performed on the basis of consent prior to its withdrawal.
13.2.4. Deletion of personal data (the right to be forgotten)
If you withdraw your consent to the processing of your personal data or when the legal basis for the processing of your personal data ceases or in other cases provided by the General Data Protection Regulation, you have the right to ask us to delete your personal data.
13.2.5. Portability of personal data
If we process your personal data based on your consent or based on our contract, you have the right to request us to transfer your personal data in an appropriate manner.
13.2.6. Objection to the processing of personal data
If we process your personal data for the purposes of direct marketing or based on our legitimate interest, you have the right to object to further processing of your personal data.
13.2.7. Limitation of processing
If you dispute the accuracy of your personal data or in other situations provided for in the General Data Protection Regulation, you have the right to ask us to limit the processing of your personal data until such a situation is resolved.
13.2.8. The right to complain to the Personal Data Protection Agency
At any time, you have the right to complain before the personal data protection authority - Agencija za zaštitu osobnih podataka (www.azop.hr), regarding the processing and protection of your personal data.
13.3. You exercise your rights without cost. However, if you frequently (for example, less than 6 months have passed since your previous request) or excessively (for example, requesting all your personal information in writing) request access to or transfer of your personal information, we have the right to ask you to bear our costs before carrying out such an action.
 

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

1. Introduction

Your privacy is important to us, both Orbico Beauty GmbH and Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore this communication might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in our emails).
When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time. You may use different options to withdraw the consent, e.g. unsubscribe email, website preferences upon login, email note, written letter.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Third parties are not allowed to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as it is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Beauty GmbH, with its registered office at Ludwigstraße 180A, D-63067 Offenbach am Main, is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities (Data Security Officials at Federal and Federal State Authorities) should contact for any questions you may have relating to the way our company uses your data.

For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation (GDPR) and applicable national data protection law of Germany (EU-DSVGO und BDSG). We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit https://dsgvo-gesetz.de/.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent using and storing data. You are also entitled request any erroneous data to be corrected, request any data to be deleted and request any data to be used only in a restricted way. You are entitled to lodge a complaint with supervisory authority.

Please make your enquiries and requests in writing, sign and send your letter to the address Orbico Beauty GmbH, Ludwigstraße 180A, D-63067 Offenbach am Main. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond. Of course, you may also get in touch with us using email to privacy.orbicobeautyde@orbico.com.

If you have any issues exercising your rights regarding personal data you may

(a)  contact the Entity Privacy Manager
c/o Orbico Beauty GmbH, Ludwigstraße 180A, 63067 Offenbach am Main,
E-mail privacy.orbicobeautyde@orbico.com

(b)  contact the Group Privacy Manager
E-mail privacy.orbicogroup@orbico.com

(c)  lodge a complaint with the supervisory Federal State Authority
Der Hessische Beauftragte für Datenschutz und Informationsfreiheit, Postfach 3163, 65021 Wiesbaden, E-Mail poststelle@datenschutz.hessen.de, Telefon +49 611 1408 – 0, Telefax: +49 611 1408 - 611

Privacy - general


DATA PRIVACY AND PROTECTION OF YOUR DATA

1. Introduction

Your privacy is important to us, both Orbico Beauty GmbH and Orbico Group.

In this Privacy Notice, we would like to explain who we are, what personal data we collect about you, why we collect it and what do we do with it in an easy and readable way. Personal data means any data from which we are able, directly or indirectly, to identify you.

Please take time to read this Notice. If you do not agree to it, please do not provide us with your data.

2. What does this Privacy Notice cover?

This Notice covers how we process your data whenever you interact with us, e.g. when you
• visit any of our websites;
• use our social media channels;
• purchase and use our products and services, systems and applications;
• subscribe to our newsletters;
• provide to us your goods or services, systems or applications;
• contact our customer support;
• join our business events;
• participate to our contests;
• participate to our promotions;
• or otherwise interact with us
as consumer, business customer, partner, (sub) supplier, contractor or other person with a business relationship with us.

"Processing" means any operation performed on personal data, which includes collection, recording, storage, modification or update, retrieval, consultation, use, disclosure by manual and/or automated means.

3. What is the data that we collect about you?

Depending on who you are (e.g. customer, consumer, supplier, business partner) and how you interact with us (e.g. online, offline, phone, mail, letter) we may process different data about you.

In this notice we cover all possible personal data that we collect from you.

Data you provide us directly
Personal identification: Name, last name, title, date of birth
Contact information: Email, phone number, address, country
User login data: UserID, password
Images: Pictures uploaded / provided to us
Financial data: Credit card data, bank account information
Other information: Household information, interests, profession, preferences

Data about your use of products and / or services that we collect automatically
In addition to the information you provide to us directly (see above), we may collect information sent to us by
your computer, mobile phone or other access device. For example, we may collect:

Device information: Device model, unique device identifier, MAC address, IP-address, operating system version, and settings of the device you use to access, e.g. the websites / apps / services
Log information: Time and duration of your use of our digital channel or product
Location information: Your actual location (derived from your IP address or other location-based technologies), that may be collected when you enable location-based products or features such as through social media

Other information: Apps you use or websites you visit, links you click within our advertising e-mail, motion sensors data

Information from third-party sources
We may receive information about you from publicly available sources (as permitted by law) such as public databases, our marketing partners, or social media platforms when you choose to connect to such services. We may combine this information with other information we receive from you.

Other
You may choose not to provide certain types of information to us, but doing so may affect your ability to enable
certain functionality of the products and / or services.

In compliance with the law, we will not process data relating to

• racial or ethnic origins; political opinions; religion or beliefs;
• trade union membership; genetic features;
• health;
• sex life;
• criminal convictions or related security measures;
• biometric data;
• genetic data.
If we had to process this type of data, we would always request your prior consent.

4.How do we use your data?

We may process your data for different purposes, but only for those which have a legal basis to process the data. Please find below the overview:

Contract / agreements execution
Billing and delivering products and / or services that you have purchased; Enabling us to reach you for delivering you our products;
Registration to mobile applications or websites;
Service account management.

Compliance with legal obligations and Public interest
Disclosing data to government institutions or supervisory authorities as applicable in all countries in which we operate, such as reporting obligations, compliance audits, tax deductions, record-keeping and reporting obligations, compliance with government inspections and other requests from government or other public authorities;
Establish, exercise, or defend ourselves from legal claims.

Legitimate interests
Administrative communications, such as order confirmations, notifications about your account activities, and other important notices;
Providing support upon your request via communication channels, such as customer or contact service center support;
Security and protection of our interests / assets, such as deploying and maintaining technical and organizational security measures, conducting internal audits and investigations, conducting assessments to verify conflict of interests;
Managing any internal complaints or claim.

Orbico may send you communication about our products, services, events and promotions. The communication is send via different channels: email, phone, SMS, post, social networks. We would like to provide you with the best experience, therefore this communication might be tailored to your preferences (for example, email as your preferred channel of communication with us – you can indicate it yourself or we can understand it based on the links you click in our emails).
When required by law, we will ask your consent before starting the above activities. To give your consent, you can, for example, tick the box for acceptance of receipt of news and promotions or usage of your data for general ecommerce industry trend analytics. We also give you the opportunity to opt-out and withdraw your consent at any time. You may use different options to withdraw the consent, e.g. unsubscribe email, website preferences upon login, email note, written letter.

If we ask you to provide us with your data, but you chose not to, in some cases we will not be able to provide you with the full functionality of our products, services, systems or applications. Also, we might not be able to respond to requests you might have.

5. When do we share your data?

To whom the data is disclosed: other Orbico entities, affiliates, service providers, business partners, public authorities, governmental authorities, contractors, others.

Your data will be processed by ourselves and other entities within the Orbico Group. In exceptional cases and only to fulfil the above described purposes described above, your data might be shared with following parties:
• Service providers: we may outsource certain data processing activities to trusted third party service providers to perform functions and provide services to us, such as IT service providers, consulting providers, packaging providers, shipping providers.
• Business partners: we also use business partners they can provide you with the services you request, such as media agencies, marketing agencies, communication agencies, suppliers, print shops.
• Public and governmental authorities: when required by law, or as necessary to protect our rights, we may share your data with entities that regulate or have jurisdiction over Orbico Group.
• Professional advisors such as auditors, lawyers, accountants, banks, other professional advisors.
• Other parties in connection with corporate transactions such as during a sale of a business or a part of a business to another company, or any reorganization, merger, joint venture, or other disposition of our business, assets, or stock (including in connection with any bankruptcy or similar proceeding).

Third parties are not allowed to use your information for other purposes than providing services to us, and are also required to protect and handle your information in accordance with legal, regulatory and contractual obligations. We take reasonable steps to ensure that we retain information about you only for so long as it is necessary for the purpose for which it was collected, or as required under any contract or by applicable law.

6. How do we keep/retain your data?

We keep your data for the period necessary to fulfil the purposes for which it has been collected (see above section “How do we use your data?”).

Sometimes we might keep your data longer if required or permitted by law. We determine the period based on the following criteria:
• How long is the data needed to provide you with our products or services or to operate our business?
• Do you have an account with us? Then we will keep your data while your account is active.
• Are we subject to a legal, contractual, or similar obligation to retain your data? Examples can include mandatory data retention laws, government orders to retain data relevant to an investigation, or data that must be retained for the litigation purposes.

7. How do we secure your data?

To protect your data, we will take appropriate technical and organizational measures in line with the applicable data protection and data security laws, including requiring our service providers, business partners or professional advisors to use appropriate measures to protect the confidentiality and security of your data. We put in place measures to prevent risks such as destruction, loss, alteration, unauthorized disclosure of, or access to your data.


8. Who is responsible for your data?

Orbico Beauty GmbH, with its registered office at Liebermannstraße F06 402-1, A-2345 Brunn am Gebirge, is responsible for processing the personal data it deems necessary to process. We are therefore the party whom you, as well as the supervisory authorities (Data Security Officials at Federal Authorities) should contact for any questions you may have relating to the way our company uses your data.

For some services, we rely on specialised partners. They therefore have to follow our instructions and adhere to our policy on personal data protection. We ensure that our partners receive only the data that are strictly necessary to perform their contractual duties.

9. Which legislation applies?

The protection of your personal data is covered by the Regulation EU 2016/679, also known as the EU General Data Protection Regulation (GDPR) and applicable national data protection law of Austria (DSG). We undertake to comply with our obligations and respect your rights whenever we process your data. If you wish to learn more about this subject, we advise you to visit https://dsb.gv.at/.

10. Accessing your information

You are entitled to submit an inquiry to us and be advised about the data we process about you and how we process such data. You are also entitled at any time to withdraw your consent using and storing data. You are also entitled request any erroneous data to be corrected, request any data to be deleted and request any data to be used only in a restricted way. You are entitled to lodge a complaint with supervisory authority.

Please make your enquiries and requests in writing, sign and send your letter to the address Orbico Beauty GmbH, Liebermannstraße F06 402-1, A-2345 Brunn am Gebirge. We will respond promptly and no later than within a month, unless extraordinary complexity would require an extension of the time to respond. Of course, you may also get in touch with us using email to privacy.orbicobeautyat@orbico.com.

If you have any issues exercising your rights regarding personal data you may
(a) contact the Entity Privacy Manager
c/o Orbico Beauty GmbH, Liebermannstraße F06 402-1, A-2345 Brunn am Gebirge,
E-mail privacy.orbicobeautyat@orbico.com
(b) contact the Group Privacy Manager
E-mail privacy.orbicogroup@orbico.com
(c) lodge a complaint with the supervisory Federal Authority
Österreichische Datenschutzbehörde, Wickenburggasse 8, A-1080 Wien, Telefon +43 1 52 152 – 0, E-Mail dsb@dsb.gv.at
  

Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Privacy - candidates


Cookie notice


Cookie Notice

In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Orbico or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


Cookie Notice

In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Orbico or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


Cookie Notice

In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Orbico or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


Cookie Notice

In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Orbico or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Electrolux or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


1. What is a cookie?

Cookies are small text files, created by the website being visited, that contain data. They are stored on the visitor's computer in order to enable the user to access various functions. Cookies are useful for a number of reasons as they allow you to navigate between websites efficiently, remember your preferences and generally improve the user experience.
 
2. Why do we use cookies?

We use cookies to learn more about how visitors interact with the content of our websites and help us improve their experience when visiting our website.

3. What types of cookies do we use?
On our website we use:

a) Functional (necessary) cookies
Functional cookies enable the proper operation of the website and the visibility of the user's settings. By adding functional cookies, we also enable website ease of use (e.g. you don't have to type the same text again). This type of cookie is stored on your device without your consent. Below is a list of functional cookies we use:

Name: exp_tracker
Purpose: This cookie is used by the website's content management system. This cookie stores the last five pages viewed by a visitor to return a form or error message
Expiration time: When visitor closes the browser

Name: exp_csrf_token
Purpose : This cookie is used for the purpose of website security, i.e. preventing falsification of requests on different pages. It is used to identify trusted web traffic.
Expiration time: 2 hours

Name: PH_HPXY_CHECK
Purpose: This cookie is used to store information about the current session.
Expiration time: End of session

b) Analytical cookies

These cookies are used to track website statistics. Analytical cookies allow us to track the number and sources of visits so that we can measure and improve the performance of our website. This type of cookie helps us understand which sub-pages are most or least visited and how visitors navigate our website. If you refuse to save analytical cookies on your computer or smartphone, your visit will not be included in our statistics, but at the same time it will not restrict any functionality on our website for you.

The lower table provides more details on the analytical cookies we use.

Name: _ga
Purpose: Installed by Google Analytics, the _ga cookie calculates data about visitors, sessions and campaigns and also tracks the use of the site for a site analytics report. 
Expiration time: 1 year, 1 month, 4 days
The cookie stores information anonymously and assigns a randomly generated number to identify unique visitors.

Name: _gid
Purpose: Installed by Google Analytics, the _gid cookie stores information about how visitors use the website and also creates an analytical report on the performance of the website. 
Expiration time: 1 day
Some of the information collected includes the number of visitors, their source and the pages they visit anonymously.

Name: _gat
Purpose: This cookie is installed by Google Universal Analytics to limit the rate of requests and thereby limit data collection on high traffic pages.
Expiration time: 1 minute   

4. Other traffic information

Local storage technology allows us to use the website efficiently and is used to save data that was saved during the use of the website in a separate part of the browser's memory, after it is turned off. Only the website whose data is saved in the browser can access the data in the local storage.

Using the website implies sending a query to the server where the website is stored. Every query sent to the server is saved in the server logs. Logs include IP address, date and time, web browser and operating system information. The logs are saved and stored on the server. Data stored in server logs are not connected to individual users who use the website and were not used for identification purposes. Server logs are auxiliary material used to manage the website and their content is not disclosed to anyone except persons authorized to manage the server.

5. How to limit cookies?

Most web browsers allow some measure of control over most cookies through your browser settings. In order to view information about a particular browser (including its settings), the User should visit the website of that browser. Below is a list of guides for managing cookies for individual browsers:

Chrome - LINK 
Opera - LINK 
Mozilla - LINK 
Microsoft Edge - LINK 
Safari - LINK 

6. Consent management

When you visit our website for the first time, we will show you a pop-up with an explanation of cookies. By selecting "Accept all ", you agree to our use of all cookies described in the points above. By clicking on "Manage cookies" you can choose the type of cookies we use when you access our website. By selecting “Confirm settings” you will refuse use of analytical cookies. Please note that functional (necessary) cookies are required for proper use of the website and therefore cannot be refused. You can withdraw your consent at any time in the "Manage cookies" section.

You can also generally disable the use of cookies through your browser (see the point above "How to limit cookies"), but please note that then our website may not work in the most efficient way (because as we stated earlier, functional cookies are necessary for the proper operation of the website).

If you wish to change your cookie consent or wish to delete any cookies already stored on your device, you can do so by clearing the browsing history on your browser. This will remove all cookies from this website, and you will be asked again for cookie consent on your next visit. Please note that the loss of saved information is possible if you choose to do so (eg. saved login data, page preferences, etc.).

7. Changes in the Policy 

We reserve the right to change this cookie policy at any time. 

Cookie notice


In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Electrolux or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Electrolux or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Electrolux or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Electrolux or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Cookie notice


In this guideline, we use the term “cookies” to refer to cookies and other similar technologies covered by the EU Directive on privacy in electronic communications.

What is a cookie?

Cookies are small text files, created by the website visited, that contain data. They are stored on the visitor’s computer to give the user access to various functions.

Both session cookies and non-session cookies are used on our sites.

A session cookie is temporarily stored in the computer memory while the visitor is browsing the website. This cookie is erased when the user closes their web browser or after a certain time has passed (meaning that the session expires).

A non-session cookie remains on the visitor’s computer until it is deleted. Why do we use cookies?

We use cookies to learn more about the way visitors interact with our content and help us to improve the experience when visiting our website.

Site functionality and content

The share function is used by visitors to recommend our sites and content on social networks such as Facebook. Cookies store information on how visitors use the share function – although not at an individual level – so that the website can be improved. If you do not accept cookies, no information is stored.

For some of the functions within our websites we use third party suppliers, for example, when you visit a page with videos embedded from or links to YouTube. These videos or links (and any other content from third party suppliers) may contain third party cookies and you may wish to consult the policies of these third party websites for information regarding their use of cookies.

Web analytics

This website uses Google Analytics which use cookies. At the aggregate level, cookies store information on how visitors use the website, including the number of pages displayed, where the visitor comes from, and the number of visits, to improve the website and ensure a good user experience. If you do not accept cookies, no information is stored.

How do I reject and delete cookies?

We will not use cookies to collect personally identifiable information about a visitor.

However, you can choose to reject or block the cookies set by Electrolux or the websites of any third party suppliers by changing your browser settings – see the “Help function” within your browser for further details.

Please note that most browsers automatically accept cookies so if you do not wish cookies to be used, you may need to actively delete or block the cookies.

For information on the use of cookies in mobile phone browsers and for details on how to reject or delete such cookies, please refer to your mobile phone manual.

Note, however, that if you reject the use of cookies you will still be able to visit our websites but some of the functions may not work correctly.

Impressum


Company name: ORBICO SP. Z O.O. // Registered seat: 5 Wołoska Str, 02-675 Warsaw, Poland //
Court of registration: The Regional Court for the capital city of Warsaw, 13th Commercial Division of the National Court Register // Registration no.: KRS 0000046562 //
Number REGON/NIP: REGON: 277632751, NIP: 6462526337
Share capital (paid in full): PLN 40841450,00

Impressum


Company name: ORBICO SP. Z O.O. // Registered seat: 5 Wołoska Str, 02-675 Warsaw, Poland //
Court of registration: The Regional Court for the capital city of Warsaw, 13th Commercial Division of the National Court Register // Registration no.: KRS 0000046562 //
Number REGON/NIP: REGON: 277632751, NIP: 6462526337
Share capital (paid in full): PLN 40841450,00

Impressum


Company name: Orbico Beauty Kft. // Registered seat: Dunavirág utca 2-6, 1138 Budapest, Hungary

Court of registration: Fővárosi Törvényszék Cégbírósága // Registration no.: 01 09 986270 // Management Board: Tabár Andrea

Bank: OTP Bank Nyrt.,1051 Budapest, Nádor u. 16. // Account no.: HU91 11794008-24023177-00000000 // Share capital (paid in full): HUF 3,000,000

Impressum


Company name: ОРБИКО БЮТИ // Registered seat: ул. „Миле Попйорданов“ 18, ет. 2, 1619 София, България //

Court of registration: Business Registry at the Registry Agency // Registration no.: 121872387 // Management Board: Petya Stefanova //

Bank: UniCredit Bulbank, 1000 Sofia // Account no.: BG15UNCR96601018972800 // Share capital (paid in full): BGN 60,000.00

Impressum


Company name: Orbico s.r.o. // Registered seat: Vinohradská 1597/174, Praha 3, 130 00, Czech Republic

Court of registration: Městský soud v Praze // Registration number: 05 89 96 64

Management Board: Dušan Horvát, Radim Kratochvíl

Bank: Česká spořitelna a.s., 110 00 Praha 1 // Account no.: CZ90 0800 0000 0000 0129 2682

Share capital (paid in full): CZE 34,000,000.00

Impressum


Numele companiei: INTERBRANDS ORBICO SRL

CUI: 3786280

Reg. Comertului: J40/9571/1993

Director General: Marcel Mureșan

Banca: Raiffeisen Bank / Cont RO84RZBR0000060003474197

Impressum


Company name: Orbico s.r.o. // Registered seat: Vinohradská 1597/174, Praha 3, 130 00, Czech Republic

Court of registration: Městský soud v Praze // Registration number: 05 89 96 64

Management Board: Dušan Horvát, Radim Kratochvíl

Bank: Česká spořitelna a.s., 110 00 Praha 1 // Account no.: CZ90 0800 0000 0000 0129 2682

Share capital (paid in full): CZE 34,000,000.00

Impressum


Company name: Orbico Beauty d.o.o. // Registered seat: Verovškova ulica 72, 1000 Ljubljana, Slovenia //

Court of registration: Slovenian Business register and Court register // Registration no.: 5523800000 //

Management Board: Gordana Zvonarević 

Bank: SKB BANKA D.D. LJUBLJANA, 1000 Ljubljana // Account no.: SI56 0310 0100 8472 531

Share capital (paid in full) EUR 5.162.377,50

Impressum


Company name: ORBICO d.o.o. za trgovinu // Registered seat: Koturaška cesta 69, 10 000 Zagreb, Hrvatska // OIB: 85611744662

Court of registration:  Trgovački sud u Zagrebu // Registration no. (MBS): 080234144

Management Board: Mario Matić, Jurij Tršan, Romina Orešković Cvetanović, Vesna Rendulić

Bank: Zagrebačka banka d.d. 10000 Zagreb, IBAN: HR3023600001502908130                 

Share capital (paid in full): 176.718.000,00 kuna

Impressum


Company: Orbico Beauty GmbH // Adress of Record: Ludwigstrasse 180 A, D-63067 Offenbach am Main //
Management Board: Tina Dolinar Assefa
Registration: Amtsgericht Offenbach am Main, HRB 50173 // VAT No: DE815 273 968
Telefon:  +49 174 2199222 // E-Mail: beauty.de@orbico.com

Impressum


Company: Orbico Beauty GmbH // Adress of Record: Liebermannstraße F06 402-1, A-2345 Brunn am Gebirge //
Function: Distribution of beauty products // Professional law: Trade regulations, available on www.ris.bka.gv.at
Management Board: Tina Dolinar Assefa
Registration: Landgericht Wiener Neustadt, FN 362734 h // VAT No: ATU66 472 514
Telefon:  +43 1 8904 662 // Telefax:   +43 1 8904 662 30 // E-Mail: beauty.at@orbico.com