Confidentiality and data processing policy



– VERSION MAY 2018 –

Below we describe what personal data is collected or processed when you use our website. This confidentiality policy also explains how the data is used, shared and protected, your options and rights, and how to contact us.

I) I) ABOUT US

Rouje is responsible for your personal data and will be referred to as “we”, “us” or “our” in this confidentiality policy. Our company is registered with the Paris Registry of Commerce and Companies under number 817 934 797 00017.
Our registered office is situated at 5 rue Coq Heron - 75001 Paris, France. If you have any questions about our confidentiality policy or the use of your personal data on our website, please contact us by email by writing to the following address lesfillesenrouje@rouje.com

II) YOUR PERSONAL DATA

A) The information you provide us with

In order to place an order on our website, create a customer account, contact us or subscribe to our newsletter and other marketing activities, in general you provide us with the following data:
- Your identity and contact details: your first name, surname, the language in which and country from which you are contacting us, as well as your email address, postal address, delivery address and telephone number.
- Bank and payment details: your bank details (please note that all payment transactions are encrypted by the receiving bank. We do not store card numbers), information about your purchases, orders, returns etc.
- Log-in, geolocation and browsing data
- Your profile - if you open a customer account, you create a profile and log in each time you visit our website. In this case, data, including your customer username and password, recent purchases or preferences, will be saved.
- Your personal preferences: this includes your wish list and marketing and cookie preferences.
- Additional personal data
- You may also provide us with other personal information such as your date of birth, gender etc. We alone collect and store this additional data and use it in our analyses to improve our services.

When we ask you to enter your personal data to access a feature, certain fields are mandatory as we require this data in order to grant you access to this feature (e.g. to deliver a parcel we need your postal address).
It is important that the personal data shared about you is correct and kept up-to-date. Please inform us of any change in such details.
We do not store any sensitive personal data and, as our website is not intended for children, we do not store any data regarding children.

B) Data obtained from cookies

Subject to your consent, we use cookies and similar technology to improve your browsing experience on our website, by adapting it to your hardware or search engine, and to propose products which correspond to your purchasing habits.
- Usage data - this data includes products and services that you have purchased from us and the way in which you use our website and applications.
- Technical data - this data includes: - Your IP address, search engine and version of it, location and time zone, browser extension, operating system and platform, as well as other technical data about the device you use to browse our website.
- Information about your visit, including URLs and your click path, from and on our website (including the date and time); the products you consult or searched for; page response times, downloading errors, time spent on the pages, interaction on the pages (such as clicks and mouse movements), the way in which you exit the pages.

III) WHY DO WE USE YOUR PERSONAL DATA?

Depending on the type of data we have access to about you, we may process it for the following purposes:
- To manage your registration as a website user: if you wish to use our services, we need to process your data in order to identify you as a website user and allow you to access the various features and personalised services. You can delete your account at any time by contacting us.
- To enter into a purchase agreement with you: your data is used to keep you updated regarding the status of your order, to prepare your order, accept your payment, give you access to aftersales services or refund your order. It also allows us to inform you of any fraud against you or us during the purchase process. If we consider the action as fraudulent, this processing may allow us to block the transaction.
- To respond to requests sent to customer services
- To improve our services: when using our website, you are informed that we process your browsing and purchase data for analytical and statistical purposes. This data allows us to better understand the way in which you use our website, in order to improve the user-friendliness and quality of our services.
- For marketing purposes: if you have subscribed to our Newsletter, we process your data in order to manage your subscription and send you relevant information via email or SMS, based on the preferences you indicated. We can also contact you via push notifications if you have subscribed to this service. We need your consent for all direct marketing. You can also cancel your subscription for our communications at any time (for example to unsubscribe from the newsletter, simply click on the button “Click here to unsubscribe” found at the bottom of all of our newsletters and confirm cancellation of your subscription). If you agree to receive direct marketing content, whether via our newsletter or push notifications, we may use the information you have provided for the following purposes:
- To share information about our events, products, services or on-going offers
- To make recommendations about certain products or services which may interest you
- For market research, in order to better understand your expectations concerning our products and the services proposed by our website.

IV) THIRD PARTIES

In the context of your use of our website, you may receive information from third parties with which we work, offering you certain services. This may include:
- Financial establishments - Fraud detection and prevention entities
- Logistical, transport and delivery services
- Marketing or advertising service providers

We may share your personal data with our third parties for the following reasons, for example:
- Payment services in order to complete payments;
- Delivery companies to deliver your order;
- Credit and fraud prevention agencies to carry out a credit check and confirm your identity;
- Analysis software which allows us to process your data in order to optimise your purchase experience on our website.
We ask third parties to undertake to respect the security of your personal data, in accordance with the law. Third parties can only use your personal data in accordance with our instructions and not for their own purposes.

V) WHAT ARE YOUR RIGHTS?

A) Legal grounds

We process your data based on legal grounds which depend on the way in which you interact with our website.
- When you purchase products from our website, we need your personal data to perform the contract between us.
For example, we need your contact details to deliver your order.
- Our processing is also based on other legal grounds such as your legitimate interests. We deem for example that it is in your interest that your identity cannot be used for fraudulent purposes, the people on our customer service team can have access to your order information to better help you, and we have a better understanding of your use of our website in order to improve the customer experience and services we propose.
- We respect the importance given to consent in the new GDPR law.

B) Consent

Your consent must be clearly and unequivocally given. That is why, when you agree to receive our communications (in particular via newsletters):
- We explain how we will use your data and the type of communication you will receive;
- You must tick a box confirming your consent to subscribe;
- You can withdraw your consent at any time.
Should you wish to unsubscribe from our direct marketing via newsletter, you can do so at any time by clicking on the link at the bottom of each email “
To unsubscribe, visit this page.” A page will open. Simply click on the button “Confirm cancellation of your subscription”. If you have a customer account on our website, you can also unsubscribe or change your preferences by logging in to your account.
Cookies (incuding those in advertising banners) require a specific cancellation of subscription. Please click here for more information.

C) Other rights

In accordance with the French Data Protection Act of 6 January 1978, as amended by the law of 6 August 2004, the Customer is entitled to access or request rectification, modification or erasure of their personal data.
- Right to access data: gives you to opportunity to receive a copy of the personal data we have concerning you
- Right to request rectification: gives you the opportunity to request the correction of incorrect personal data.
- Right to request erasure of your personal data or “right to be forgotten”: gives you the means to request the erasure of your data.
- Right to limit data processing: possibility to request that your personal data is no longer used in certain cases.
- Right to object: possibility to object to use of your personal data. Irrespective of the purpose for which or legal grounds by virtue of which we process your data, you can therefore exercise your rights, at any time and without any cost, by sending us an email.
Email address: lesfillesenrouje@rouje.com

Or sending us a letter to the following address:
Rouje
5, rue du Coq Héron
75001 Paris
France
Please note, however, that we cannot always meet requests for legal reasons, which we will explain, as may be relevant, after receiving your request. If you have a customer account, you can aso change your personal details via your customer account by logging in using your email address and password.

VI) SECURITY OF YOUR PERSONAL DATA

If you created an account, you chose a password. You are responsible for keeping this password confidential. That is why we recommend choosing an effective password and not sharing it. We recommend that you only log in using secure networks, preferably private networks. Be aware of the risks of using public Wi-Fi networks.
If you receive an email claiming to be from the brand for which we work asking you to provide personal details, please do not reply. Forward the email to us so we can take the necessary measures.
All of our service providers work in the European Economic Area (EEA) and must respect the same legislation as us. In the case of a service provider situated outside the EEA, we undertake to ensure that your data is transferred with the appropriate care. We have signed contractual clauses with each of them in the context of the GDPR.

VII) STORAGE PERIOD OF YOUR PERSONAL DATA

We will store your data for as long as you remain a customer, but also afterwards, in order to answer all questions, respond to complaints or maintain all necessary data in order to meet legal, accounting or analytical requirements. We may also store your data for research purposes or statistical analysis. More specifically: In the context of a subscription to our newsletter, we will no longer contact you if you have not opened our newsletters for more than three years.

Any modification of this policy will be updated on this page, if appropriate, and you will be notified thereof by email.