We are committed to treating data privacy seriously. It is important that you know exactly what we do with your Personal Data.
WHO WE ARE:
Esskay Beauty Resource Private Limited is a company incorporated and registered under the provisions of the Companies Act, 2013 and having its registered office at Plot No. 31, Esskay House, near Passport Office, Phase IV, Sector 18, Gurugram, Haryana 122015. Esskay Beauty is engaged in the business of facilitating selling, marketing and retailing cosmetic and beauty products (“Business”) through the e-commerce websites and mobile applications (“App”) both developed and owned by Esskay Beauty and/or its parent company, and/or its affiliates (Website and App collectively referred to as “Platform”) or offline stores / events to conduct its Business.
DEFINITIONS AND KEY TERMS
Cookie: small amount of data generated by a website and saved by your web browser. It is used to identify your browser, provide analytics, remember information about you such as your language preference or login information
Country: where Esskay Beauty or the owners/founders of Esskay Beauty are based, in this case is India
Customer: refers to the company, organization or person that signs up to use the Esskay Beauty Service to manage the relationships with your consumers or service users
Device: any internet connected device such as a phone, tablet, computer or any other device that can be used to visit Ola Candy and use the services
Address: Every device connected to the Internet is assigned a number known as an Internet protocol (IP) address. These numbers are usually assigned in geographic blocks. An IP address can often be used to identify the location from which a device is connecting to the Internet
Personnel: refers to those individuals who are employed by Esskay Beauty or are under contract to perform a service on behalf of one of the parties.
Personal Data: any information that directly, indirectly, or in connection with other information — including a personal identification number — allows for the identification or identifiability of a natural person
Controller or controller responsible for the processing: Controller or controller responsible for the processing is the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data; where the purposes and means of such processing are determined by Union or Member State law, the controller or the specific criteria for its nomination may be provided for by Union or Member State law.
Recipient: Recipient is a natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not. However, public authorities which may receive personal data in the framework of a particular inquiry in accordance with Union or Member State law shall not be regarded as recipients; the processing of those data by those public authorities shall be in compliance with the applicable data protection rules according to the purposes of the processing.
Service: refers to the service provided by Esskay Beauty as described in the relative terms (if available) and on this platform.
Third-party service: refers to advertisers, contest sponsors, promotional and marketing partners, and others who provide our content or whose products or services we think may interest you.
Website: Ola Candy’s site, which can be accessed via this URL: www.olacandy.in
You: a person or entity that is registered with Esskay Beauty to use the Services.
ROLE WE PLAY
We play the role of a Data Controller when we collect and process Personal Data about you.
We play the role of a Data Processor when we collect and process Personal Data on behalf of another Data Controller
We commit to protecting your privacy and hence our Personal Data handling practices are continually reviewed to ensure compliance with the applicable Privacy laws and regulations
PERSONAL INFORMATION GATHERED BY ESSKAY BEAUTY
The information we learn and gather from you, personal or otherwise, is used to register you, verify your identity to permit you to use the app, undertake transactions (including to facilitate and process payments), communicate with you, convey any promotional offers, services or updates associated with Esskay Beauty, and generally maintain your accounts with us. We also use this information to customize your experience and improve Esskay Beauty.
INFORMATION YOU GIVE US
We receive and store any information you provide while using Esskay Beauty’s Website, or give us in any other way. You can choose not to provide certain information, but then you might not be able to use Our Website. We use the information that you provide for such purposes as opening your account, processing your transactions, responding to your requests, and communicating with you
INFORMATION WE COLLECT ABOUT YOU:
Esskay Beauty will collect personal information that you submit to us. We may also receive personal information about you from third parties as described above. We receive and store certain types of information whenever you interact with us. For example, like many websites, we use "cookies," and we obtain certain types of information when your web browser accesses our Services. We may also receive/store information about your location and your mobile device, including a unique identifier for your device. We may use this information for internal analysis and to provide you with location-based services, such as advertising, search results, and other personalized content.
We collect information from you when you visit our website, register on our site, place an order, subscribe to our newsletter, respond to a survey or fill out a form
INFORMATION FROM OTHER SOURCES:
We might receive information about you from other sources, such as updated delivery and address information from our carriers, which we use to correct our records and deliver your next purchase more easily.
CATEGORIES OF PERSONAL DATA
Categories of Personal Data collected and processed by us are as follows;
Demographic & Identity data
Contact details such as Name, email address, contact number, shipping address, country, date of birth, profile picture
Open data and public records such as information about YOU that is openly available on the internet
Details such as Transaction amount, Bank Name, Card Type, Card number.
Online Identifiers and other Technical Data
Location details such as data we get about your location, IP address, logs, or from where you connect a computer to the internet
Technical details such as device information, location and network carrier when you use our mobile applications
Communications details such as the Metadata and other Personal Data we get from communications done through e-mails, SMS, instant messages and calls
Usage data details such as data about how you use our website or web-based properties, pages viewed, etc.
PURPOSES OF GATHERING YOUR PERSONAL DATA
We use your personal information to operate, provide, develop, and improve the products and services. These purposes include:
Any of the information we collect from you may be used in one of the following ways:
To improve our website (we continually strive to improve our website offerings based on the information and feedback we receive from you)
To improve customer service (your information helps us to more effectively respond to your customer service requests and support needs)
To process transactions
To administer a contest, promotion, survey or other site feature
To take and handle orders, deliver products and services, process payments, and communicate with you about orders, products and services, and promotional offers.
To provide functionality, analyze performance, fix errors, and improve the usability and effectiveness of the Website.
To recommend features, products, and services that might be of interest to you, identify your preferences, and personalize your experience with Website.
To communicate with you in relation to Esskay Beauty via different channels (e.g., by phone, periodic e-mail, chat).
To display interest-based ads for features, products, and services that might be of interest to you.
HOW DO WE USE YOUR EMAIL ADDRESS?
By submitting your email address on this website, you agree to receive emails from us. You can cancel your participation in any of these email lists at any time by clicking on the opt-out link or other unsubscribe option that is included in the respective email. We only send emails to people who have authorized us to contact them, either directly, or through a third party. We do not send unsolicited commercial emails, because we hate spam as much as you do. By submitting your email address, you also agree to allow us to use your email address for customer audience targeting on sites like Facebook, where we display custom advertising to specific people who have opted-in to receive communications from us. Email addresses submitted only through the order processing page will be used for the sole purpose of sending you information and updates pertaining to your order. If, however, you have provided the same email to us through another method, we may use it for any of the purposes stated in this Policy. Note: If at any time you would like to unsubscribe from receiving future emails, we include detailed unsubscribe instructions at the bottom of each email.
LAWFUL BASES OF PROCESSING YOUR PERSONAL DATA
We are permitted to process your Personal Data in compliance with applicable laws and regulations by relying on one or more of the following lawful bases:
You have explicitly agreed to us processing your Personal Data for a specific reason
The processing is necessary to perform the agreement we have with you or to take steps to enter into an agreement with you
The processing is necessary to be in compliance with our Legal Obligations
The processing is necessary for the purposes of a legitimate interest (“Legitimate Interest”) pursued by us, such as
to provide services to you,
to evaluate, develop or improve our products and services
Where the processing is based on your consent, you have a right to withdraw your consent at any time. You may withdraw consent by contacting us. Upon receipt of your written request to withdraw your consent, consequences of withdrawal will be communicated to you and, upon your agreement, your request for withdrawal will be processed.
DO NOT TRACK
Some web browsers have a “Do Not Track” feature. This feature lets you tell websites you visit that you do not want to have your online activity tracked. These features are not yet uniform across browsers. Our sites are not currently set up to respond to those signals
WHEN DOES ESSKAY BEAUTY USE END USER INFORMATION FROM THIRD PARTIES?
Esskay Beauty will collect End User Data necessary to provide the Esskay Beauty services to our customers.
End users may voluntarily provide us with information they have made available on social media websites. If you provide us with any such information, we may collect publicly available information from the social media websites you have indicated. You can control how much of your information social media websites make public by visiting these websites and changing your privacy settings
WHEN DOES ESSKAY BEAUTY USE CUSTOMER INFORMATION FROM THIRD PARTIES?
We receive some information from the third parties when you contact us. For example, when you submit your email address to us to show interest in becoming a Esskay Beauty customer, we receive information from a third party that provides automated fraud detection services to Esskay Beauty. We also occasionally collect information that is made publicly available on social media websites. You can control how much of your information social media websites make public by visiting these websites and changing your privacy settings
DO WE SHARE THE INFORMATION WE COLLECT WITH THIRD PARTIES?
We may share the information that we collect, both personal and non-personal, with third parties such as advertisers, contest sponsors, promotional and marketing partners, and others who provide our content or whose products or services we think may interest you. We may also share it with our current and future affiliated companies and business partners, and if we are involved in a merger, asset sale or other business reorganization, we may also share or transfer your personal and non-personal information to our successors-in-interest
We may engage trusted third party service providers to perform functions and provide services to us, such as hosting and maintaining our servers and the website, database storage and management, e-mail management, storage marketing, credit card processing, customer service and fulfilling orders for products and services you may purchase through the website. We will likely share your personal information, and possibly some non-personal information, with these third parties to enable them to perform these services for us and for you.
We may share portions of our log file data, including IP addresses, for analytics purposes with third parties such as web analytics partners, application developers, and ad networks. If your IP address is shared, it may be used to estimate general location and other technographic such as connection speed, whether you have visited the website in a shared location, and type of the device used to visit the website. They may aggregate information about our advertising and what you see on the website and then provide auditing, research and reporting for us and our advertisers.
We may also disclose personal and non-personal information about you to government or law enforcement officials or private parties as we, in our sole discretion, believe necessary or appropriate in order to respond to claims, legal process (including subpoenas), to protect our rights and interests or those of a third party, the safety of the public or any person, to prevent or stop any illegal, unethical, or legally actionable activity, or to otherwise comply with applicable court orders, laws, rules and regulations.
HOW LONG DO WE KEEP YOUR INFORMATION?
We keep your information only so long as we need it to provide Ola Candy to you and fulfill the purposes described in this policy. This is also the case for anyone that we share your information with and who carries out services on our behalf. When we no longer need to use your information and there is no need for us to keep it to comply with our legal or regulatory obligations, we’ll either remove it from our systems or depersonalize it so that we can't identify you.
HOW DO WE PROTECT YOUR INFORMATION?
We implement a variety of security measures to maintain the safety of your personal information when you place an order or enter, submit, or access your personal information. We offer the use of a secure server. All supplied sensitive/credit information is transmitted via Secure Socket Layer (SSL) technology and then encrypted into our Payment gateway provider’s database only to be accessible by those authorized with special access rights to such systems, and are required to keep the information confidential. After a transaction, your private information (credit cards, social security numbers, financials, etc.) is never kept on file. We cannot, however, ensure or warrant the absolute security of any information you transmit to Esskay Beauty or guarantee that your information on the Service may not be accessed, disclosed, altered, or destroyed by a breach of any of our physical, technical, or managerial safeguards.
COULD MY INFORMATION BE TRANSFERRED TO OTHER COUNTRIES?
Esskay Beauty is incorporated in India. Information collected via our website, through direct interactions with you, or from use of our help services may be transferred from time to time to our offices or personnel, or to third parties, located throughout the world, and may be viewed and hosted anywhere in the world, including countries that may not have laws of general applicability regulating the use and transfer of such data. To the fullest extent allowed by applicable law, by using any of the above, you voluntarily consent to the trans-border transfer and hosting of such information.
You understand and accept that these countries may have differing (and potentially less stringent) laws relating to the degree of confidentiality afforded to the information it holds and that such information can become subject to the laws and disclosure requirements of such countries, including disclosure to governmental bodies, regulatory agencies and private persons, as a result of applicable governmental or regulatory inquiry, court order or other similar process. In addition, a number of countries have agreements with other countries providing for exchange of information for law enforcement, tax and other purposes.
We take precautions to protect the security of your information. We have physical, electronic, and managerial procedures to help safeguard, prevent unauthorized access, maintain data security, and correctly use your information. However, neither people nor security systems are foolproof, including encryption systems. In addition, people can commit intentional crimes, make mistakes or fail to follow policies. Therefore, while we use reasonable efforts to protect your personal information, we cannot guarantee its absolute security. If applicable law imposes any non-disclaimable duty to protect your personal information, you agree that intentional misconduct will be the standards used to measure our compliance with that duty.
CAN I UPDATE OR CORRECT MY INFORMATION?
The rights you have to request updates or corrections to the information Esskay Beauty collects depend on your relationship with Esskay Beauty. Personnel may update or correct their information as detailed in our internal company employment policies.
You should be aware that it is not technologically possible to remove each and every record of the information you have provided to us from our system. The need to back up our systems to protect information from inadvertent loss means that a copy of your information may exist in a non-erasable form that will be difficult or impossible for us to locate. Promptly after receiving your request, all personal information stored in databases we actively use, and other readily searchable media will be updated, corrected, changed or deleted, as appropriate, as soon as and to the extent reasonably and technically practicable.
If you are an end user and wish to update, delete, or receive any information we have about you, you may do so by contacting the organization of which you are a customer.
If you are aa Esskay Beauty worker or applicant, we collect information you voluntarily provide to us. We use the information collected for Human Resources purposes in order to administer benefits to workers and screen applicants.
SALE OF BUSINESS
LINKS TO OTHER WEBSITES
This website may contain third party advertisements and links to third party sites. Esskay Beauty does not make any representation as to the accuracy or suitability of any of the information contained in those advertisements or sites and does not accept any responsibility or liability for the conduct or content of those advertisements and sites and the offerings made by the third parties.
Advertising keeps Ola Candy and many of the websites and services you use free of charge. We work hard to make sure that ads are safe, unobtrusive, and as relevant as possible.
Third party advertisements and links to other sites where goods or services are advertised are not endorsements or recommendations by Esskay Beauty of the third party sites, goods or services. Esskay Beauty takes no responsibility for the content of any of the ads, promises made, or the quality/reliability of the products or services offered in all advertisements.
COOKIES FOR ADVERTISING
These cookies collect information over time about your online activity on the website and other online services to make online advertisements more relevant and effective to you. This is known as interest-based advertising. They also perform functions like preventing the same ad from continuously reappearing and ensuring that ads are properly displayed for advertisers. Without cookies, it’s really hard for an advertiser to reach its audience, or to know how many ads were shown and how many clicks they received.
BLOCKING AND DISABLING COOKIES AND SIMILAR TECHNOLOGIES
Wherever you're located you may also set your browser to block cookies and similar technologies, but this action may block our essential cookies and prevent our website from functioning properly, and you may not be able to fully utilize all of its features and services. You should also be aware that you may also lose some saved information (e.g. saved login details, site preferences) if you block cookies on your browser. Different browsers make different controls available to you. Disabling a cookie or category of cookie does not delete the cookie from your browser, you will need to do this yourself from within your browser, you should visit your browser's help menu for more information.
Below are the categories of cookies used on our website along with a description of what they are used for:
These cookies are needed to run our website, to keep it secure if you are logged on and to obey regulations that apply to us.
If you are a customer, they help us know who you are so that you can log on and manage your accounts. They also help us keep your details safe and private.
These cookies are used for remembering things like:
Your user ID on the log on page
Your region or country
Your preferred language
Accessibility options like large font or high contrast pages
These cookies tell us how you and our other customers use our website. We combine all this data together and study it. This helps us to:
Improve the performance of our services
Improve the products we provide
Most web browsers allow some control of most cookies through the browser settings. Please note disabling the ‘Strictly Necessary’ cookies may cause certain parts of our website to remain inaccessible to you.
We use remarketing services. What Is Remarketing? In digital marketing, remarketing (or retargeting) is the practice of serving ads across the internet to people who have already visited your website. It allows your company to seem like they're “following” people around the internet by serving ads on the websites and platforms they use most.
If you transact with us, some additional information such as a billing address, information about your credit/debit card number and expiration date, and/ or other payment instrument details are collected by our service provider that performs the function of a payment gateway, we commit that this confidential information will be stored in the most secure manner possible.
We do not address anyone under the age of 13. We do not knowingly collect personally identifiable information from anyone under the age of 13. If You are a parent or guardian and You are aware that Your child has provided Us with Personal Data, please contact Us. If We become aware that We have collected Personal Data from anyone under the age of 13 without verification of parental consent, We take steps to remove that information from Our servers.
YOUR RIGHTS AS A CUSTOMER
We understand that when you interact with Esskay Beauty, you have rights over your Personal Data. These rights involve providing reasonable steps to allow you to access your personal data, correct any errors among others. In the event that you are not satisfied with our response or have unresolved concerns, you can get in touch with us to resolve the issue by means of Email.
We may display, include or make available third-party content (including data, information, applications and other products services) or provide links to third-party websites or services ("Third- Party Services").
You acknowledge and agree that Esskay Beauty shall not be responsible for any Third-Party Services, including their accuracy, completeness, timeliness, validity, copyright compliance, legality, decency, quality or any other aspect thereof. Esskay Beauty does not assume and shall not have any liability or responsibility to you or any other person or entity for any Third-Party Services.
Third-Party Services and links thereto are provided solely as a convenience to you and you access and use them entirely at your own risk and subject to such third parties' terms and conditions.
Local Storage sometimes known as DOM storage, provides web apps with methods and protocols for storing client-side data. Web storage supports persistent data storage, similar to cookies but with a greatly enhanced capacity and no information stored in the HTTP request header.
uses "Sessions" to identify the areas of our website that you have visited. A Session is a small piece of data stored on your computer or mobile device by your web browser.
INFORMATION ABOUT GENERAL DATA PROTECTION REGULATION (GDPR)
WHAT IS GDPR?
GDPR is an EU-wide privacy and data protection law that regulates how EU residents' data is protected by companies and enhances the control the EU residents have, over their personal data.
The GDPR is relevant to any globally operating company and not just the EU-based businesses and EU residents. Our customers’ data is important irrespective of where they are located, which is why we have implemented GDPR controls as our baseline standard for all our operations worldwide.
WHAT IS PERSONAL DATA?
Any data that relates to an identifiable or identified individual. GDPR covers a broad spectrum of information that could be used on its own, or in combination with other pieces of information, to identify a person. Personal data extends beyond a person’s name or email address. Some examples include financial information, political opinions, genetic data, biometric data, IP addresses, physical address, sexual orientation, and ethnicity.
The Data Protection Principles include requirements such as:
Personal data collected must be processed in a fair, legal, and transparent way and should only be used in a way that a person would reasonably expect.
Personal data should only be collected to fulfil a specific purpose and it should only be used for that purpose. Organizations must specify why they need the personal data when they collect it.
Personal data should be held no longer than necessary to fulfil its purpose.
People covered by the GDPR have the right to access their own personal data. They can also request a copy of their data, and that their data be updated, deleted, restricted, or moved to another organization.
WHY IS GDPR IMPORTANT?
GDPR adds some new requirements regarding how companies should protect individuals' personal data that they collect and process. It also raises the stakes for compliance by increasing enforcement and imposing greater fines for breach. Beyond these facts it's simply the right thing to do. At Esskay Beauty we strongly believe that your data privacy is very important and we already have solid security and privacy practices in place that go beyond the requirements of this new regulation.
INDIVIDUAL DATA SUBJECT'S RIGHTS - DATA ACCESS, PORTABILITY AND DELETION
We are aware that if you are working with EU customers, you need to be able to provide them with the ability to access, update, retrieve and remove personal data. We got you! We've been set up as self-service from the start and have always given you access to your data and your customers data. Our customer support team is here for you to answer any questions you might have about working with the API.
RIGHTS OF THE DATA SUBJECT
Pursuant to statutory provisions, you can assert the following rights vis-à-vis the data processing controller free of charge:
Right to access by the data subject (Art. 15 GDPR);
Right to rectification and erasure (Art. 16 and Art. 17 GDPR);
Right to restriction of processing (Art. 18 GDPR);
Right to data portability (Art. 20 GDPR);
Right to object (Art. 21 GDPR).
You also have the right to complain to a data protection supervisory authority concerning the controller’s processing of your personal data.
Don't hesitate to contact us if you have any questions.