• ✨ Free delivery on purchases of $50 or more ✨

  • ✨ Free delivery on purchases of $50 or more ✨

  • Confidentiality charter

    Confidentiality charter

    We collect personal data via the website http://www.mustela.com and its local versions or for mobile devices.

    This privacy policy describes how we, as data controller, process personal data relating to our customers and potential customers that have been collected via the Site.

    Please note that we also collect personal data from visitors to the Site through the use of cookies. To find out about our use of cookies, please read our cookies policy.

    I. What personal data do we process and for what purposes?

    Below you will find the list of personal data that we collect from you, the purpose and the legal basis used for each processing carried out.

    Categories of people concerned

    Users of the website using the site's contact form and people wishing to receive Expanscience newsletters.

    Type of personal data

    Your civility
    Your name, first name
    Your email address
    Your phone number
    Your postal address
    Your situation
    Your date of birth or those of your children

    Purpose of processing

    Sending commercial communications (including our newsletter) regarding our products or services

    The answer to any question or request left via the contact form

    Legal basis for processing

    Our legitimate interest, namely to benefit you from offers on our products and services.

    We believe that the risk linked to personal data that we process on the basis of our legitimate interests is controlled and that, out of concern for your well-being and respect for your privacy, this risk is neither excessive nor intrusive. We have also put in place measures to protect your rights by applying appropriate retention periods and ensuring appropriate security controls.

    If you choose not to provide the requested and necessary personal data, we may not be able to provide the services you have requested or fulfill the purposes for which we requested the personal data. When the provision of personal data is necessary, we indicate this on the forms by means of an asterisk.

    II. Who are the recipients of your personal data?

    We may share your personal data with various service providers who support our activity, including:

    • Hosting and maintenance service providers;
    • Marketing providers and advertising partners;
    • Service providers responsible for carrying out satisfaction surveys and surveys.

    We have carefully selected these service providers and taken measures to ensure adequate protection of your personal data. All of our service providers are required by written contract to process the personal data provided to them solely for the purpose of providing a specific service to us and to maintain appropriate security measures to protect your personal data.

    III. International transfer of personal data

    By default, your personal data is hosted within the European Union.

    However, depending on the origin of the data, and according to the specifically expressed needs, there may be a transfer of data outside the EU, in the case of requests concerning countries outside the EU. In these specific cases, the data will then be transferred to subcontractors with the same level of data protection and processing as within the EU.

    IV. How long do we keep your personal data?

    We delete the personal data of potential customers that we collect after a period of three years following your last contact with us (for example, a request for documentation or a click on a hyperlink contained in an email).

    Beyond these periods, we may keep your data in archive databases (without sending email marketing) in order to meet our tax, accounting and social obligations (5 to 10 years maximum).

    V. Security of your personal data

    We have adopted physical, electronic and administrative security measures including the use of extensive firewalls and passwords to secure access to personal data. In addition, we limit access to personal information to those employees who need to know this information to provide you with the requested services. Any person accessing it is bound by confidentiality obligations and is trained in the protection of personal data.

    VI. Your rights

    As a data subject, you have various rights. These rights are not absolute and each of these rights is subject to certain conditions in accordance with the General Data Protection Regulation n°2016/679 and applicable national laws (in France, the “Informatique et Libertés” law of January 6, 1978 modified).

    • The right of access - you have the right to obtain confirmation from us as to whether or not your personal data is being processed by us, as well as certain other information (similar to that provided in this privacy policy) about how they are used. You also have the right to access your personal data, by asking us to send you a copy of the personal data concerning you. This allows you to know and verify that we are using your information in accordance with data protection laws. We may refuse to provide you with this information in particular when it may contain or reveal personal data of another person or negatively affect the rights of another person.
    • The right to rectification – you can ask us to take steps to correct your personal data if it is inaccurate or incomplete (for example, if we have the wrong name or address).
    • The right to erasure - or "right to be forgotten", this right allows you, in simple terms, to request the erasure or deletion of your personal data when, for example, we no longer have a compelling reason to continue using them or their use has become illegal. However, this is not a general right to erasure and there are several exceptions, for example where we need to use the information to defend a legal claim or to be able to comply with a legal obligation.
    • The right to restrict processing – you have the right to “block” or prevent further use of your personal data when we are assessing a rectification request or as an alternative to erasure. Where processing is restricted, we may still retain your personal data, but we cannot use it further.
    • The right to data portability – you have the right to obtain and reuse certain personal data for your own purposes across different companies (which are separate data controllers). This only applies to personal data that you have provided to us, which we process with your consent and for the purposes of contract performance, which are processed by automated means. In this case, we will provide you with a copy of your data in a structured, commonly used and machine-readable format or if you ask us to do so we may transmit your data directly to another data controller (where technically possible) .
    • The right to object - you have the right to object to certain types of processing, for reasons relating to your particular situation, at any time, to the extent that such processing takes place for the purposes of the legitimate interests pursued by Expanscience. We may, however, continue to process your personal data if we can demonstrate that the processing is justified by compelling and legitimate reasons which override your interests, rights and freedoms or if we need it for the establishment, the exercise or defense of legal actions. If you object to the processing of your personal data for direct marketing purposes, we will no longer process your personal data for such purposes.
    • The right to withdraw your consent - where we process your personal data based on your consent, you have the right to withdraw your consent at any time. However, such withdrawal does not affect the lawfulness of the processing which took place before such withdrawal.

    VI. General information

    This Privacy Policy may be updated periodically. We will inform you of any substantial modification relating to the use of your personal data.

    If you have any questions regarding this privacy policy or our use of your personal data, please contact us by email at mypersonaldata@expanscience.com or by post at the following address: Laboratoires Expanscience – 1 Place des Saisons – 92048 PARIS LA DEFENSE Cedex.

    Before evaluating your request, we may ask you for additional information to identify you. If you do not provide the requested information and, as a result, we are unable to identify you, we may refuse to comply with your request.

    If you are not satisfied with our response to your complaint or if you believe that the processing of your personal data does not comply with data protection laws, you can lodge a complaint with the competent supervisory authority regarding data protection. The Commission Informatique et Libertés (CNIL) is the data protection authority in France (www.cnil.fr).

    © Laboratoires Expanscience – All rights reserved – June 2019