Privacy policy 

1.- Purpose       
The purpose of this personal data protection policy is to inform you of the way in whichMESOESTETIC E-COMMERCE, S.L. (hereinafter, “MESOESTETIC”), and where applicable DERMAFRICA, obtain, process and protect the personal data that you provide or we collect, in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (on the protection of natural persons with regard to the processing of personal data and on the free movement of such data) – General Data Protection Regulation, and other relevant regulations relating to the protection of personal data. 

2.- Data Protection Officer     
The controller of the personal data that you provide or that we obtain in other ways is MESOESTETIC with C. I. F. B-66. 959. 370, domiciled at Calle de la Tecnología, 25, 08 840, Viladecans (Barcelona), email [email protected] and contact phone +34 93 325 20 30. 

Likewise, some services of the website may also be processed by the entity DERMAFRICA, with C.I.F. 4340223348, with address at Suite A, Building 1, 5 Boundary Rd, Century City, Cape Town, 7441, e-mail [email protected] and contact telephone 0219171911, therefore, it will also be responsible for the processing of the data you provide during the completion of the online purchase. 

3.- Platform Users, Clients and Potential Clients   
Users are informed of the personal data that may be collected, their purpose and the legitimacy of their processing.  

DATA: 

  • Sensitive data: skin type.
  • Identification data: name, surname, identity number, address, city, country, postal code, date and place of birth. 
  • Academic and professional data: profession, level of education, work experience, company name, type of health professional. 
  • Contact details: email address, phone number. 
  • Economic data: bank and financial details. 

PURPOSE OF THE PROCESSING OF PERSONAL DATA : 

  • The purpose of the processing of your personal data is to guarantee the security of the service and to manage your queries, requests for information or complaints, through the Contact Form. 
  • Participation through comments on social networks such as Facebook, LinkedIn, Twitter and Instagram. 
  • Participation through comments on blogs. 
  • The processing may also consist, provided that we have received prior and express consent by marking the Terms and Conditions of the MESOESTETIC Community, on the part of the user, in the receipt of communications, promotions of new products, company advertising, advertisements, newsletters, etc. 

 

MESOESTETIC, and where applicable DERMAFRICA, may create a marketing profile based on the information provided. No automated decisions will be taken based on this profile.  

 In the event that the User registers on the Website through the social login, MESOESTETIC, and where applicable DERMAFRICA, will only access the User's personal data to which the User has consented when setting up access to the social network in question. Any information provided in connection with such social applications may be accessed by members of the relevant social network. Such actions shall be governed by the privacy policies of the service providers. MESOESTETIC, and where applicable DERMAFRICA, has no control over and is not responsible for such entities or their use of the User's information.  

 

LEGITIMISATION FOR THE PROCESSING OF PERSONAL DATA: 

  • Generally speaking, the legal basis that legitimates the processing of personal data by MESOESTETIC and where applicable DERMAFRICA, is the fulfilment of legal obligations. 
  • Some processing operations may also require the consent of the data subjects (receipt of communications, advertising, announcements, newsletters, etc.). This consent must be given by a clear affirmative action and may be withdrawn at any time by the data subject. 
  • Other processing is based on the legitimate interest we have to manage and respond to your requests for information and requests in MESOESTETIC, and where applicable [DISTRIBUER’S NAME], as well as to know your assessment of our services and operations, or to send you communications of interest to you about the contracted services. 

4.- Personal data collection and recording of processing 

MESOESTETIC, and where applicable DERMAFRICA, processes your personal data in a lawful, fair and transparent manner and limiting the purposes for which they were collected.  

The personal data collected from the data subject are incorporated into the processing operations owned by MESOESTETIC, and where applicable DERMAFRICA, and are included in the Register of Processing Activities.   

These personal data will be treated confidentially and in a manner that ensures adequate security for the protection of these data.  

5.- Data transfer and International data transfer 

We inform you that the data provided by you in the different forms on the website will be transferred to DERMAFRICA, for the following purposes: 

  • Regarding the contact form: To resolve queries issued through the contact form, whose competence or knowledge lies with the e-commerce manager, DERMAFRICA.
  • Regarding the "work with us" form: To store data of users who make use of the "Work with us" section of the website in order to consider said candidate for other possible vacancies that fit their profile in its company. 
  • Regarding product information request forms or stock availability notices: Provide to the user as much information as it can about the products for sale on the website.

We also inform you that the data provided by you during the online purchase process will be transferred to the manufacturer of the brand, MESOESTETIC, for the following purposes: 

  • Regarding the E-commerce form: To obtain data from customers who purchase products through the E-commerce, as well as to carry out a market study, to know the public/target of the different products sold through this website, in order to improve the products offered and to be able to carry out a wider internal marketing.

If we process personal data in a third country (i.e. outside the European Union (EU) or the European Economic Area (EEA)) or if this is done in the context of the use of third party services or if personal data is disclosed or transferred to third parties, MESOESTETIC guarantees the users of this platform that the transfer will only take place in the event of compliance with our (pre)contractual obligations, on the basis of your consent, on the basis of a legal obligation or on the basis of our legitimate interests.  

Furthermore, MESOESTETIC guarantees that the special requirements of Art. 44 et seq. of the GDPR are complied with in any case. This means that the processing is carried out on the basis of special safeguards, namely the officially recognized establishment of an EU-equivalent level of data protection and the fulfillment of officially recognized special contractual obligations (so-called "standard contractual clauses"). 

6.- Data Storage 

In general, the personal data processed by MESOESTETIC, and where applicable DERMAFRICA, shall be kept for the time necessary to fulfil the purpose for which they were collected, considering the deadlines set out in the regulations in general and specifically in Act 10/2001 of 13 July and Decree 13/2008 of 22 January, without prejudice, where appropriate, to making them available to the competent authorities or to respond to claims. In this case, the data will be kept blocked until the end of the limitation period, at which time they will be deleted.  

7.- Confidentiality 

MESOESTETIC, and where applicable DERMAFRICA, guarantees, under the terms established in the current legislation, that it will use the personal data of users confidentially, and that it has adopted the appropriate technical and organisational security measures in its facilities and systems. This protection covers everything related to the collection and use of the information provided via the Internet.  

We therefore undertake to maintain and apply the necessary levels of security, considering the state of technology, the category of data stored and the risks, to protect your personal data from accidental loss and unauthorised access, processing or disclosure, and not to disclose the information unless this is strictly for the performance of an order or in order to comply with a legal obligation. In short, to treat your data in accordance with current legislation on data protection. MESOESTETIC, and where applicable DERMAFRICA, provides users with the appropriate technical resources so that, prior to providing their personal data, they can access the privacy policy notice or any other relevant information and, if necessary, give their consent for their personal data to be processed.  

 

8.- Data Protection Rights 

The data subject may exercise his/her rights of access, rectification, cancellation, portability, limitation and opposition by writing to the e-mail [email protected] , indicating as reference "RGPD rights", and here applicable to the e-mail [email protected] 

Access to your Personal Data: It is the right to request and obtain information about your personal data facilitated in this website, as well as the processing done on them, for what purpose and for what specific uses.   

Right of rectification: This is the right you have to rectify your personal data when they are incorrect or incomplete.  

Right of cancelation (right to forget): This is the right you have to ask for access to your personal data to be suppressed when it is inappropriate, excessive or unnecessary, when it is kept for a longer period than is appropriate or when it is contrary to the Regulation.   

Right of opposition: This is the right you have to request that no processing of your personal data be carried out.   

Right of limitation: It is a right to mark your personal data kept by MESOESTETIC, and where applicable DERMAFRICA, in order to limit the processing in the future.   

Right to data portability: This is the right to receive the personal data you have provided to [MESOESTETIC, and where applicable DERMAFRICA, in a structured, commonly used and machine-readable format, and to transmit them to another controller, if the processing is based on consent or a contract or if it is done by authorized means.  

Right not to be subject to automated individual decisions: This is the right not to be subject to a decision based solely on automated processing of data, including profiling, which produces legal effects on you or significantly affects you.   

In Exercise of right GDPR, you will find all the information to be able to exercise rights.   

You also have the right to lodge a complaint with the competent supervisory authority at any time about the processing of your personal data.  

9.- Changes to our notice 

If we change the way we process Personal Data, we will update this Policy and the corresponding Privacy and Data Protection Legal Notice. We reserve the right to make changes at any time to our practices and to this Policy, so we encourage you to check back frequently for updates or changes.  

10.- Further information 

We will be happy to provide you with more information about how we protect and use your personal information. Please contact us at the following email address [email protected], and here applicable to the e-mail [email protected].