PRIVACY STATEMENT - CHRISTIAN DIOR
The Maisons Christian Dior Couture and Parfums Christian Dior attach particular importance to the processing, confidentiality and security of your personal data. We are committed to offering you personalized services while respecting your privacy and personal choices.
During your shopping experience, and in order to inform you in advance, you will go from Maison Christian Dior Couture to Maison Parfums Christian Dior, or vice versa. Depending on the type of product ordered, the Data Controller will be either Maison Christian Dior Couture or Maison Parfums Christian Dior, within the meaning of the regulations applicable to personal data and in particular with regard to article 24 of the Regulations (EU) 2016/679 (hereinafter "GDPR").
As an example, referring to a few iconic products from the two Maisons:
Maison Christian Dior Couture
Lady Dior bag
30 Montaigne bag
Maison Parfums Christian Dior
J’adore or Sauvage perfume
Dior Prestige beauty care
Maquillage Dior Forever products
In this Statement, you will find information about:
• Who are we?
• What data we may collect about you
• How we collect or receive your data
• For what purposes we use your data
• How long we keep them
• Who are the recipients of your data
• How we protect them and ensure their confidentiality
• How we treat your preferences and your rights stemming from European Regulation
• The additional protections we offer to residents of certain regions
• How to contact us if you have questions about our use of your personal data
• How we protect children's privacy
• Modification of this privacy statement
WHO are we ?
The Maison Christian Dior Couture
Christian Dior Couture SA (head office), a public limited company under French law with its head office located at 30 avenue Montaigne, Paris 8, France, registered in the Paris Trade and Companies Register under number 612 035 832 and represented by Hien Tran Trung in his capacity as Administrative and Financial Director of Christian Dior Couture,
And all of the Christian Dior Couture affiliates with whom you share your information
Christian Dior Couture is a story of dreams and elegance, passion and excellence; it is also a story of know-how. The creations of Christian Dior Couture express the passion for beautiful gestures and exceptional objects. From haute couture to ready-to-wear, including leather goods, watchmaking and jewelry, know-how is transformed into the art of making.
• The Maison Parfums Christian Dior
Parfums Christian Dior (head office), a public limited company under French law whose head office is located at 33, avenue Hoche, 75008 Paris, France, registered in the Paris Trade and Companies Register under number 552 065 187, and represented by Claude Martinez in his capacity as Managing Director,
And all the affiliates of Parfums Christian Dior with which you share your information
Parfums Christian Dior is a story of dreams, glamor, creativity and excellence. The Maison, which has unique expertise, is made up of talented and ambitious professionals who are committed to perpetuating the heritage of the Dior heritage and transmitting their passion for beauty.
WHAT data do we collect about you?
"Personal data" means any information that identifies you either directly (such as your name) or indirectly (for example, using a unique customer number).
The personal data we collect depends on the point of contact through which you interact with us, as well as the purposes of this interaction as described in this Policy and are also limited to those which are relevant and appropriate for this interaction. Visitors to the Dior.com website who view our products, information and offers can choose to do so without logging in, and the same is true for point-of-sale search and browsing on social media. Unless you choose to interact with us through these contact points, for example:
• by creating an account and connecting to it,
• by making a purchase on our site,
• by subscribing to one of our programs or services,
• by writing to us via the consumer contact forms,
• or by writing us a comment in the free online order fields,
For one thing, for customers and others who sign up for programs or services, we need to collect certain relevant information from you. The information we collect is related to a given transaction as well as in the context of our business relationship with you. For example, if you make purchases on Dior.com or in our points of sale, we must collect information to process (and, if necessary, execute and dispatch) your order, to ensure its tracking and invoicing, to be in able to respond to any after-sales inquiries you may have. For customers and others who sign up for our programs or services, we generally collect your contact information, contact preferences and information that allows us to make recommendations to you about our products or services that may be of interest to you. We can centralize information about our customers to organize it in one place, as this helps us manage our relationship with you as well as your choices and preferences. Finally, if you subscribe to our newsletter, we collect your email address.
Depending on the data that you communicate to us or that you share with us, personal data may include information concerning:
• Your identity and contact details: surname, first name, postal address, email address, telephone number
• Your interests
• A history of your purchases (in store or online, including your orders, tracking and invoices, amount and type of purchase) and your repairs
• Your requests via our customer service or our public relations service
• The Dior events in which you participate
• Your size and stylistic preferences (only for Christian Dior Couture)
• Your date of birth in order to benefit from the Birthday offers eligible according to your program
• Your satisfaction and comments on our programs, services and products
• The information that you specify related to the possible undesirable effects that you could report to us (only for Parfums Christian Dior)
Regarding your purchases, payments are made via a secure payment platform, supplemented by control measures, including encryption of contact details, in order to guarantee the security of purchases made and to fight against fraud. Your bank details are therefore not accessible on Dior's servers.
We invite you to ensure that your data is regularly updated, either by modifying it directly on our sites or, by informing us in writing of any modification by referring to the dedicated section "How to contact us".
HOW do we collect or receive your data?
As part of our relationships, the data we collect may be collected through the following contact points:
• Course on Dior.com
• Exchanges with our advisers in Dior stores as well as points of sale in department stores
• Dior events in which you participate
• Relationship with our public relations services
• Contact with Customer Service
• Forms that you fill out (in store or online)
• Digital applications with which you interact
• Loyalty program from which you benefit
• Third party data providers with whom you share information
• Retailers for whom you agree to receive our communications
• Satisfaction surveys or questionnaires to which you answer
We make sure to identify the personal data essential for the purpose for which it is collected by indicating it with an asterisk like this ‘(*)’ on each personal data collection form. If you do not fill in these mandatory fields, we will not be able to respond to your requests and / or provide you with the services requested. The other information is optional and allows us to know you better and improve our communications and services to you. Although not mandatory, we recommend that you fill them in to allow you to benefit from the best possible experience during our interactions with you.
During your purchase journey, you will be able to choose between i) logging into your existing Dior account, ii) creating a new account, or iii) paying as a Guest (or also called Guest Check out). This last purchasing experience is thus summarized as follows:
Payment for purchases as a Guest refers to the possibility for any Dior customer or prospect to make a purchase in our online store without logging into an account. Your information is collected only for the process of payment and delivery of items or for Dior in order to comply with applicable laws. In accordance with your express consent, the information may be used for analytical purposes by Dior. Likewise, in accordance with your express consent, your information may also be used by Dior for communication purposes via its preferred channel (for example: subscribe to a newsletter). For more information on these purposes, please go to the section below, under the "Analysis and personalization purposes" section, here below.
FOR WHAT PURPOSES is your data used by Dior?
We are required to use your data for purposes defined according to the nature of our relationships. Thus, depending on the context in which your data is collected, it may be used for one or more of the following purposes:
• Managing your orders
• Management of personalized content and Dior communications (digital or not)
• Managing your profile
• Managing your loyalty program
• Managing your requests in connection with Dior
• The management of events in which you register / participate
• The management of alerts that you send us as part of our cosmetovigilance obligations (only for Parfums Christian Dior products)
• The management of our website and our digital applications
• Management and improvement of our products and services, image and reputation
• Transaction management (securing online payments, prevention of fraud, incidents related to payments and debts)
• Analysis and personalization purposes: with your explicit consent (when required), we use your personal data to send you personalized communications (newsletters, offers, invitations and surveys) and analyze your preferences and habits, anticipate your needs from of your consumer profile. We can make you benefit from our personalized communications by means of emails, postal letters, SMS or calls according to the communication preferences that you have indicated to us and your consumer profile (when authorized).
We ensure the legal basis for the processing of your data according to the purpose (s) concerned, which may be, depending on the context in which it is collected:
• Your explicit consent: for example, for the purposes of managing our personalized commercial offers, managing your browsing via cookies under the conditions defined by our Cookies Policy, or establishing your consumer profile in applicable cases;
• The implementation of a contract, for example for your access to your customer account, the processing and follow-up of your orders ...;
• A legal obligation when processing is required by law, for example, keeping purchase invoices to prevent fraud;
• Our legitimate interest: for example, to improve our products and services, defend ourselves or secure our tools
HOW LONG can we keep them?
We keep your personal data only for the time necessary for the purpose pursued. In general, your personal data is stored in our database, as shown in the table below:
• Data subject: Regular customer (ie: having a Customer profile in one of the two Dior Houses)
• Duration: 10 years from the date of the first purchase; 5 years for business development
• Specificity: A first period of 5 years when your status is "active". A second period of 5 years also when your status becomes ‘inactive’. If the status is still "inactive" after the second period of 5 years, your customer profile is deleted. The status becomes “active” when interacting with Dior such as a purchase or an update of your profile.
• Data subject: Prospect
• Duration: 3 years from the date of data collection
• Specificity: This period will be renewed each time you interact with Dior (for example participation in an event) or your consent to continue interacting after this period.
• Data subject: Client ‘Guest’ (i.e. not having a Client profile in one of the two Dior Houses)
• Duration: For the duration of the transaction until the delivery of the order
• Specificity: Intermediate archive of 5 years maximum from the end of the commercial relationship.
• Data subject: Customer Service (ie: calls for assistance, complaints or information)
• Duration: For the duration of the request management, or by default 30 days maximum
Specificity: Intermediate archive of 5 years maximum from the end of the management of the request
• Data subject: Privileged interlocutors (eg agents, stylists, celebrity managers, artists) in relation to Dior Public Relations services
• Duration: 10 years from the date of your first contact
• Specificity: This period will be renewed each time you interact with Dior (for example a request for information on the Maison Dior)
When we no longer need to use your personal data, it is deleted from our systems and our registers or made anonymous so that it can no longer be identified, subject to retention for archival purposes. claims and litigation management as well as to meet our legal and / or regulatory obligations and / or to respond to requests from authorities authorized to make the request
WHO can access your data?
Your data is intended for the services of Maison Christian Dior concerned by your requests. We ensure that only duly authorized persons can access your personal data when this is necessary for the aforementioned purposes.
We do not pass your data on to third parties for commercial purposes.
We are only required to communicate your information if necessary, and if possible in a form that does not allow direct identification to:
• Other Dior entities as well as department stores where you buy our products in order to provide you with identical personalized service worldwide
• Our trusted third-party providers, including other entities of the LVMH group, acting as subcontractors according to our instructions and on our behalf only.
For example, we entrust certain services to third parties responsible for delivering a product to you, payment service providers and transaction security against fraud, third parties who assist us in the organization of our events, third parties providing services IT, digital communication and public relations agencies, third parties who assist us in customer service, third parties who assist us in qualitative surveys of our products, programs or services.
• Third parties including the LVMH group wishing to know your preferences and consumption trends for our programs and services in order to improve visibility, accessibility and performance.
• Our trusted third party partners assist us in the management of your orders. In particular, we entrust certain services to third parties responsible for delivering a product to you, to payment service providers and to providers ensuring the security of anti-fraud transactions.
Please note that these partners may act as data controllers; in this case, they have their own privacy policies. We illustrate some examples in the list below:
DHL orders and deliveries (delivery), BlueLink (call center management), FluentCommerce (order and stock management) and any other service provider in management.
Ecommerce management SMILE (website host), CapGemini (eCommerce solution), Salesforce (management of customer profiles) and any other service provider in the management of your ecommerce shopping experience.
Payments and transaction security Cybersource (securing transactions against electronic commerce fraud), PayPal (payment service provider), OneyTrust (securing transactions against electronic commerce fraud) and any other payment service provider, verification, or banking provider.
• Third parties wishing to know your interests so that they can build similar audiences and target prospects corresponding to your profile. In the context of this specific processing, we are not the data controller relating to prospecting and you will not be the subject of prospecting, your data being only used to constitute profiles similar to yours.
• Third Parties in the event of a change of control or of status or company name, for legal reasons, or with your prior consent
HOW do we protect and ensure the confidentiality of your data?
We take all the necessary precautions to guarantee the confidentiality and security of your data and to prevent it from being distorted, damaged, destroyed or from unauthorized third parties having access to it.
We ask our partners and group companies to maintain a level of protection similar to ours concerning your personal data. The security measures put in place are evaluated and updated to face new threats and new challenges, as well as new legal requirements in the countries where we operate.
HOW do we deal with cross-border protections?
Given the presence of Dior in many countries around the world and in order to provide you with personalized service worldwide, some of your data may be collected, accessible or stored outside your country of residence. You should be aware that data protection and security requirements differ from place to place and may not offer the same level of protection as those of your country of origin. However, Dior and our group companies have taken measures to guarantee an adequate level of protection of your data, regardless of their location, for example by using standard data transfer clauses, or any other method approved by the Commission. European (where data protection legislation is considered to be the most effective in the world) and / or the National Data Protection Authorities. We also ask our third party partners to comply with the applicable data transfer obligations, for example by contractual clauses, with regard to the personal data they receive on our behalf.
HOW are consumer preferences and individual rights treated?
In accordance with applicable laws and requirements, Dior and its group companies have put in place measures to guarantee respect for the rights of individuals with regard to personal data that we (or our third parties) have about them. This includes, for example, the right to know the data that we hold about you or to obtain a copy, as well as the limited rights to modify your data, to request erasure or to object to the processing of your data. We encourage those who have given their data to us to keep it up-to-date (for example, if you change your email address, address or telephone number), so that we keep your correct information in our files. We also encourage consumers to update their preferences with us, for example regarding products and frequency of contact, so that we can customize our service to suit your expectations and needs. Finally, we offer individuals the right to withdraw their consent from our programs and offers at any time. To do this, or to exercise any of these other rights, please use or the contact possibilities in the section "How to contact us" below. For people wishing to access their data, we also need authentication to ensure that we do not provide personal data to an unauthorized person.
WHAT additional protections are provided for residents of certain regions?
In particular, the GDPR provides the following rights:
• Right to information: you have the right to obtain clear, transparent and understandable information about how we use your personal data and about your rights. You will find all of this information in this policy
• Right of access: you have the right to access the personal data that Dior holds about you
• Right of rectification: you have the right to have your personal data rectified if it is inaccurate or obsolete and / or to supplement it if it is incomplete
• Right to erasure / right to be forgotten: you have the right to have your data erased or deleted. However, this right may be limited by a legal reason or our legitimate interest in keeping your personal data
• Right of opposition: you can at any time request to no longer receive our communications relating to our offers, news and events. You can in particular use the hypertext link provided for this purpose in each email or communication that we send to you. You can also request to receive non-personalized communications about our products and services
• Right to withdraw consent at any time for data processing based on consent: you can withdraw your consent relating to our processing of your data when this processing is based on consent
• Right to data portability: you have the right to move, copy or transfer data from our database to another. This right only applies to the data you have provided, and provided that the processing is based on a contract or your consent and carried out using automated processes
You, or one of your legally designated representatives, also have the right to formulate specific or general directives concerning the conservation, erasure and communication of your post-mortem data and this in application of the Law for a Digital Republic .
HOW to contact us ?
1 / Please contact us in the manner below if you wish to exercise these rights or if you have questions or complaints regarding the processing of your personal data.
Christian Dior Couture
- By email to firstname.lastname@example.org
- By online form: https://www.dior.com/en_gb/contact-couture
- By phone: +44 (0) 207 172 0172
- By post: Christian Dior UK Limited 49a Pavilion Road - SW1X OHD London - England
Christian Dior perfumes
- By email to Dpo_uk@diormail.com
- By online form: https://www.dior.com/en_gb/contact-parfum
- By phone: +44 (0)207 216 0216
For the sake of speed of management of your requests, it is advisable to favor the email address.
2 / You also have the right to contact the Dior lead data protection authority, the CNIL, at any time, in order to lodge a complaint against Dior's data protection and privacy practices. The CNIL can be contacted using the following information:
Commission Nationale pour l’Informatique et les Libertés (CNIL)
3 Place de Fontenoy
TSA 80715 - 75334 Paris, Cedex 07
Phone. +33 1 53 73 22 22
Fax +33 1 53 73 22 00
3 / We also wish to inform you about the contacts of other authorities in Europe that you can find and contact on the website of the European Data Protection Board: https://edpb.europa.eu/about-edpb/board/members_en
HOW does Dior protect the privacy of children?
Dior has adopted practices aimed at avoiding collecting or storing information on children under the age of 15, in accordance with French law. If we learn that we have mistakenly collected information from people under the age of 15, we will purge it immediately, except to answer a single question or request from the person, their parent or legal guardian.