PRIVACY POLICY

Last revised August 2018

The Kao Germany GmbH, Pfungstädter Straße 98-100, 64297 Darmstadt, GERMANY ("Kao Company" or "we" or "our") and each of its affiliates and subsidiaries in the EMEA region collectively, the "Kao Group") takes data privacy seriously. This Privacy Policy informs the users of “www.GOLDWELL.COM/StylistsFavorite” and any other Kao Company-owned websites or mobile applications on which this Privacy Policy is displayed ("GOLDWELL.COM/StylistsFavorite") how we, as controller within the meaning of the General Data Protection Regulation ("GDPR") collect and process the personal data and other information of such users in connection with their usage of the Website. Note that other Kao Group websites or mobile apps may be governed by other privacy policies.

1. Categories of Personal Data and Processing Purposes - What personal data do we process about you and why?

1.1 Metadata

You may use the Website without providing any personal data about you. In this case, we will collect only the following metadata that result from your usage of the Website: browser type and version, operating system and interface, website from which you are visiting us (referrer URL), webpage(s) you are visiting on our Website, date and time of accessing our Website, and internet protocol (IP) address.

Your IP address will be used to enable your access to our Website. The metadata, including the shortened IP address, will be used to improve the quality and services of our Website and services by analyzing the usage behaviour of our users.

1.2 Google Analytics

This website uses Google Analytics, a web analytics service provided by Google, Inc. (“Google”). Google Analytics uses “cookies”, which are text files placed on your computer, to help the website analyze how users use the site. The information generated by the cookie about your use of the website will be transmitted to and stored by Google on servers in the United States.

In case IP-anonymization is activated on this website, your IP address will be truncated within the area of Member States of the European Union or other parties to the Agreement on the European Economic Area. Only in exceptional cases the whole IP address will be first transferred to a Google server in the USA and truncated there. The IP-anonymization is active on this website.

Google will use this information on behalf of the operator of this website for the purpose of evaluating your use of the website, compiling reports on website activity for website operators and providing them other services relating to website activity and internet usage.

The IP-address, that your Browser conveys within the scope of Google Analytics, will not be associated with any other data held by Google. You may refuse the use of cookies by selecting the appropriate settings on your browser, however please note that if you do this you may not be able to use the full functionality of this website.

You can also opt-out from being tracked by Google Analytics with effect for the future by downloading and installing Google Analytics Opt-out Browser Addon for your current web browser: tools.google.com/dlpage/gaoptout.

As an alternative to the browser plug-in and especially for mobile browsers, please click on the following link to set an opt-out cookie. This opt-out cookie prevents detection by Google Analytics within this website. http://www.goldwell.co.uk/data-protection-policy/?google-analytics-opt-out=true

2. Processing Basis and Consequences - What is the legal justification for processing your personal data and what happens if you choose not to provide it?

We rely on the following legal grounds for the collection, processing, and use of your personal data:

your consent to the processing of your data for one or more specific purposes;

The provision of your personal data is not required by a statutory or contractual obligation. The provision of your personal data is not necessary to enter into a contract with us or to receive our services/products as requested by you. The provision of your personal data is voluntary for you.

Not providing your personal data may result in disadvantages for you, for example, you may not be able to receive certain products and services. However, unless otherwise specified, not providing your personal data will not result in legal consequences for you.

3. Categories of Recipients and International Transfers - Who do we transfer your personal data to and where are they located?

We may transfer your personal data to third parties for the processing purposes described above as follows:

4. Retention Period - How long do we keep your personal data?

Your personal data will be retained as long as necessary to provide you with the services and products requested. Once you have deleted your account or otherwise ended your relationship with us, we will remove your personal data from our systems and records and/or take steps to properly anonymize it so that you can no longer be identified from it (unless we need to keep your information to comply with legal or regulatory obligations to which the Kao Company is subject--e.g., taxation purposes).

We may retain your contact details and interests in our products or services for a longer period of time if the Kao Company is allowed to send you marketing materials. Also, we may be required by applicable law to retain certain of your personal data for a period of 10 years after the relevant taxation year. We may also retain your personal data after the termination of the contractual relationship if your personal data are necessary to comply with other applicable laws or if we need your personal data to establish, exercise or defend a legal claim, on a need to know basis only. To the extent possible, we will restrict the processing of your personal data for such limited purposes after the termination of the contractual relationship.

5. Your Rights - What rights do you have and how can you assert your rights?

Right to withdraw your consent: If you have declared your consent regarding certain collecting, processing and use of your personal data (in particular, regarding the receipt of direct marketing communication via email, SMS/WhatsApp, and telephone), you can withdraw this consent at any time with future effect. Such a withdrawal will not affect the lawfulness of the processing prior to the consent withdrawal. Please contact us as stated in Section 7 below to withdraw your consent. Further, you can object to the use of your personal data for the purposes of marketing without incurring any costs other than the transmission costs in accordance with the basic tariffs.

Additional data privacy rights: Pursuant to applicable data protection law, you may have the right to: (i) request access to your personal data; (ii) request rectification of your personal data; (iii) request erasure of your personal data; (iv) request restriction of processing of your personal data; (v) request data portability; and/or (vi) object to the processing of your personal data (including objection to profiling).

Please note that these aforementioned rights might be limited under the applicable local data protection law. Below please find further information on your rights to the extent that the GDPR applies:

To exercise your rights, please contact us as stated under Section 7 below. You also have the right to lodge a complaint with the competent data protection supervisory authority.

6. Questions and Contact Information

If you have any questions about this Privacy Policy or wish to exercise your rights listed under Section 5, please contact us at: www.kao.com/global/en/EU-Data-Subject-Request/ . The data protection officer of Kao Germany can be reached at: datenschutz.de@kao.com.

7. Changes to this Privacy Policy

We may update this Privacy Policy from time to time in response to changing legal, regulatory or operational requirements. We will notify you of any such changes, including when they will take effect, by updating the "Last revised" date above or as otherwise required by applicable law. Your continued use of our Website after any such updates take effect will constitute acceptance of those changes. If you do not accept updates to this Privacy Policy, you should stop using our Website.