PRIVACY POLICY

 

Last updated on 21.07.2026

 

Protecting your privacy is extremely important to LEMAIRE.

This Privacy Policy is intended to give you a clear overview of how we process personal data in the new type of shopping experience tailored to our customers, which offers an up-to-date customer style profile, tailored style requests and suggestions.

With its advanced features, it helps our customers connect with us so they can have direct contact with their sales associates and stay up to date on the latest trends.

 

 

INDEX

1. DATA CONTROLLER AND DATA PROCESSORS FOR THE DATA YOU PROVIDE TO US

2. WHAT CATEGORIES OF DATA DO WE PROCESS

3. ON WHAT LEGAL BASIS WILL THE DATA BE PROCESSED

4. FOR WHICH PURPOSES WILL WE PROCESS YOUR DATA

5. MINORS’ PRIVACY

6. CONTROL OVER YOUR DATA

7. WITH WHOM WE SHARE YOUR DATA

9. TRANSFER OF DATA TO COUNTRIES OUTSIDE THE EU

10. FOR NON-EU RESIDENTS

11. HOW LONG YOUR DATA WILL BE STORED

12. WHAT DATA PROTECTION RIGHTS CAN YOU CLAIM AS A DATA SUBJECT

13. THE SUPERVISORY AUTHORITY FOR PERSONAL DATA PROTECTION

14. HOW YOUR DATA IS PROTECTED

15. COMMUNICATIONS

 

 

 

 

 

1.     DATA CONTROLLER AND DATA PROCESSORS FOR THE DATA YOU PROVIDE TO US

 

The data controller of personal data pursuant to Article 26 of the GDPR is the company LEMAIRE SAS JINGHI.

 

Our application is a SaaS and White Label licensed product and, as software providers, the following companies are Data Processors of your personal data pursuant to Article 28 of the GDPR:

·         MEETALPHA SRL, Via del Tiratoio 1, 50124, Florence (FI) – VAT number: IT07205120483 REA FI-687032, e-mail: legal@meetalpha.it

·         MEETALPHA, INC. 1643 Powell St, San Francisco, CA 94133, owner of the web domain https://www.meetalpha.it/, which does not collect any type of data and does not carry out any profiling. E-mail: legal@meetalpha.it

 

IN COMPLIANCE WITH THE REQUIREMENTS OF THE GDPR, THE COMPANIES RESPONSIBLE FOR THE PROCESSING HAVE SIGNED A SPECIFIC JOINT CONTROLLER AGREEMENT BETWEEN THEM. AS THE JOINT CONTROLLERS ARE LEGAL ENTITIES BELONGING TO THE SAME CORPORATE GROUP (INTRA-GROUP DATA TRANSFER), BUT SUBJECT TO ITALIAN AND US LAW RESPECTIVELY, THEY HAVE JOINTLY DECIDED TO REGULATE THE PROCESSING OF DATA THROUGH THE APPLICATION, PAYING CLOSE ATTENTION TO COMPLIANCE WITH THE GDPR, EXTENDING IT ALSO TO NON-EU USERS AS IT PROVIDES GREATER PROTECTION OF RIGHTS RELATED TO THE PROCESSING OF PERSONAL DATA.

 

Article 26(2) of the GDPR provides that 'the joint controller agreement shall adequately reflect the roles and relationships of the joint controllers with the data subjects. The main content of the agreement shall be made available to the data subjects'. The parties have signed a DPA (Data Processing Agreement) in order to limit the scope of circulation and processing of personal data (e.g. storage, archiving and retention of data on their servers or in the cloud) to countries belonging to the European Union.

 

2.    WHAT CATEGORIES OF DATA DO WE PROCESS

 

Personal data (hereinafter referred to as "Data") is information that refers to an identified or identifiable natural person.

Within the scope of the purposes of processing highlighted in the following paragraph, we process the following categories of data:

a)      "Common" personal data (identification and contact details) including, for example: name and surname, e-mail address, telephone number, date of birth, etc.

b)      Purchasing preferences and interests (likes/dislikes regarding Brand products, number of purchases made, personal preferences, information about your size, wishlist).

c)      History of interactions between the Customer and the Sales Associate (purchase history, CRM segmentation, customer status, customer feedback, products that may be of interest to customers, waiting lists)

d)      Aggregated data that we analyse by combining the information collected with other data for reporting, planning, development, operation/functionality, maintenance and management, and improvement of the application. We may share this aggregated data with our business partners.

 

 

3.    ON WHICH LEGAL BASES WILL THE DATA BE PROCESSED

·         We process data with your CONSENT.

By using the application, you explicitly approve the Privacy Policy, consenting the processing of personal data in point 2) in relation to the methods and purposes described below.    
This explicit consent will only be requested by ticking the box in the account creation window, if necessary.
Consent, according to Article 4 of the GDPR, is any freely given, specific, informed, and unambiguous indication of your will following our clear and concise request. If you do not give your consent, we will not be able to allow you to continue with the account registration and the use of the application's features.

 

Your consent applies to all processing activities carried out for the same purpose or purposes.

 

We process personal data without your consent only for the following legal bases and purposes:

·         CONTRACTUAL OR PRE-CONTRACTUAL BASIS   
- to perform/fulfil specific contractual or pre-contractual obligations undertaken towards you (Art. 6, letter b, GDPR).

·         LEGAL OBLIGATIONS           
- to comply with the provisions of laws and regulations (national and/or EU), or to comply with orders and requirements imposed on the Data Controller by judicial authorities, supervisory bodies, and professional associations (Art. 6, letter c, GDPR);    
 - exercise the rights of the Data Controller, in particular the right to defence in court (Art. 6, letter f, GDPR).

·         LEGITIMATE INTEREST      
Based on the Data Controller's legitimate interest in establishing and maintaining profitable and optimal professional relationships with its actual and potential customers (Art. 6, letter f, GDPR), your personal data may be processed by the Data Controller for the following purposes:

- To carry out "customer relationship management" activities, consisting mainly of tracking and managing relationships and interactions with the "contact persons" of actual and potential customers in order to better understand their needs and expectations, improve its services, and increase its business.

- Profiling may also be based on the legitimate interest of the Data Controller, as the level of detail, the completeness of the profile, the impact of profiling and the security measures to ensure fairness, non-discrimination and accuracy in the profiling process are limited and adequate.

 

4.       FOR WHICH PURPOSES WILL WE PROCESS YOUR DATA

We collect Personal Information directly from the User when they interact with us in order to:

·         Create a user account

·         Verify the user's identity

·         Request assistance

·         Request product information

·         Participate in surveys or evaluations

·         Interact with likes and dislikes

·         Create a wishlist

·         Invitations and appointments

·         Send questions or comments

·         Receive promotional messages via newsletters

·         Receive promotions, discounts and/or gifts.

 

We will process your data for the following main reasons:
To comply with requirements required by national, EU and/or non-EU regulations:

·         to meet the obligations set out in laws, regulations, EU legislation, civil and tax regulations.

·         We are subject to legal obligations in the management of the application. This includes, among other things, the obligation to ensure data security. To this end, we may process your data as part of the measures to be taken to ensure data security.

 

For profiling activities

·         To analyse or predict the preferences or behaviour of those who use the application.

·         The information collected is necessary to enable the Brand to provide personalised assistance, respond to customer requests, monitor, and improve the quality of the service.

The data will be processed for statistical and aggregate reporting purposes only, therefore anonymously, in order to improve the quality of the service, and will all be encrypted 'at rest'.

 

5.    MINORS’ PRIVACY

We recognise the importance of protecting the personal data of minors. For this reason, our application provides services that cannot be provided to minors as specified by law in your jurisdiction.

We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected personal information from a minor, we will take steps to delete that information as soon as possible. In this regard, our application implements "by design and by default" processes and protections to keep their personal data safe.

 

6.    CONTROL OVER YOUR DATA

You can control your data in the following ways:

·         Modify or delete your personal data

If you have any doubts or questions about how to rectify/delete your data, you can contact us at the following email address: customerservice@lemaire.fr

 

7.    WHO WE SHARE YOUR DATA WITH

We always take appropriate measures to ensure that your data is processed, protected and transmitted in accordance with applicable legal requirements.

For the purposes referred to in section 4 above, the personal data you provide may be made accessible to:

1.       employees and collaborators of the Data Controller, acting as persons authorised to process data (or so-called "Authorised person").

2.       judicial or supervisory authorities, administrations, public bodies and organisations (both national and international).

3.       professionals and consultants appointed by the Data Controller to carry out activities related to the administrative management of the company structure to which they belong, the management of professional assignments or any legal defence.

 

SUBPROCESSORS/THIRD PARTIES

To find out about Sub-processors/Third parties, the Data Controller keeps an up-to-date list that can only be consulted upon written request and with justification.

 

8.    LINKS TO THIRD-PARTY PROVIDERS

Interaction between you and the Brand Data Controller takes place through end-to-end messaging channels of Third-Party Providers, including, but not limited to, WhatsApp, etc. Therefore, please refer to the specific privacy policy, because under no circumstances can the Data Controller be held responsible for compliance with privacy regulations implemented by third parties.

 

9.    TRANSFER OF DATA TO NON-EU COUNTRIES

Your data will not be transferred outside the EU.

We guarantee that the management and storage of personal data take place within the European Union.

Any cross-border transfer of data to other countries is carried out in accordance with the regulations in force, as well as in compliance with the provisions adopted by the European Court of Justice and national and foreign authorities regarding the protection of personal data.

Without your consent, your personal data will not be disclosed. In any case, transfers of personal data to countries outside the European Economic Area (EEA) or to an international organisation are permitted provided that the adequacy of the third country or organisation is recognised by a decision of the European Commission (Article 45 of EU Regulation 2016/679).

In the absence of such a decision, the transfer is permitted where the controller or processor provides adequate safeguards that provide enforceable rights and effective legal remedies for data subjects (Article 46 of EU Regulation 2016/679).

 

10.  10. FOR NON-EU RESIDENTS

Non-EU residents will be subject to the privacy legislation in force, without prejudice to all security standards and respect for all rights recognised to European Union citizens.

 

SPECIFIC INFORMATION BY COUNTRY

USA: With the Adequacy Decision of 10 July 2023, the European Parliament, in agreement with the US leadership, adopted the EU-US Data Privacy Framework. For the purposes of Article 45 of Regulation (EU) 2016/679, the United States ensures an adequate level of protection for personal data transferred from the Union to organisations in the United States that are included in the 'Data Privacy Framework List', maintained and made public by the US Department of Commerce, in accordance with Section I.3 of Annex I. Each Party undertakes to update and supplement, within its own competence, its procedures for the protection of personal data in relation to regulatory developments and to liaise with the other Party regarding any innovations introduced. Any emergencies or irregularities that may arise at any stage of the processing of personal data connected with the Contract shall be promptly communicated between the Parties. The law requires companies to take reasonable measures to delete or destroy records or data containing personally identifiable information. To submit a request in this regard, please contact: customerservice@lemaire.fr

 

11.   11. HOW LONG WILL YOUR DATA BE STORED

Pursuant to Article 17 of the GDPR, your data will be stored for as long as we are legally required to do so or for as long as we need your data for the stated purposes.

 

Your data will then be deleted in accordance with the principle of data minimisation:

·         FOR ACCOUNT FUNCTIONALITY: your data is stored only for the time necessary to fulfil the purposes of managing the account you have created to access our services and, in any case, will be stored until you request deletion of the account, except where required by law.

·         FOR PROFILING PURPOSES: your data will be retained in accordance with the principle of proportionality and in any case until the purposes of the processing have been fulfilled or until - if earlier - the specific consent of the data subject is revoked, as specified in more detail in the table below.

·         FOR LEGAL OBLIGATIONS: data of a civil, accounting and fiscal nature will be stored for a period of ten years, as required by law. It will be processed and stored under the following terms:     
- with regard to the execution/fulfilment of contractual or pre-contractual obligations assumed by the Data Controller, for a period of 10 years plus 12 months;     
- with reference to compliance with the provisions of laws and regulations, processing aimed at complying with orders and requirements imposed by judicial authorities and supervisory bodies, as well as to allow the Data Controller to exercise its rights, in particular the right to defence in court: for the limitation/expiry period established by the specific reference legislation; 
- with regard to the transmission of publications, studies, reports and other types of professional information material: for no more than 2 years from the date of the last transmission;        
- with regard to customer relationship management activities: for a period of 6 months following the last interaction (e.g. exchange of emails, phone calls, organisation of meetings or similar activities) certifying that there is an active relationship with the Data Subject.

                                                           DATA RETENTION

TYPE OF DATA

BRIEF DESCRIPTION

RETENTION PERIOD

"COMMON" PERSONAL DATA

INFORMATION RELATING TO THE INDIVIDUAL, e.g. first and last name, date of birth, email address, telephone number.

5 YEARS or until the account is deleted, unless required by law. 

PURCHASE PREFERENCES AND INTERESTS

INFORMATION AIMED AT EVALUATING CERTAIN PERSONAL ASPECTS RELATING TO A NATURAL PERSON, in particular to analyse or predict aspects concerning personal preferences and interests, e.g. likes for brand products, information about your size, etc. This data is shared voluntarily with the Brand's Sales Associates.

12 MONTHS (for profiling purposes, to which a further period of 3 months may be added)

 

24 MONTHS from consent

or from the last significant interaction* (for direct marketing purposes by the brand)

 

or until the account is deleted, except where required by law.

TIMELINE OF INTERACTIONS

LIKES OR DISLIKES OF BRAND PRODUCTS AND OTHER INTERACTIONS with the Sales Associate and the Brand.

12 MONTHS (for profiling purposes, to which a further period of 3 months may be added)

 

24 MONTHS from consent

or from the last significant interaction* (for direct marketing purposes by the brand)

 

or until the account is deleted, except where required by law.

AGGREGATED DATA

Aggregated data may be derived from PERSONAL DATA PROVIDED BY THE USER, COMBINING THE INFORMATION COLLECTED WITH OTHER DATA, but is not considered personal data as it does not allow the identification of the data subject either directly or indirectly.

It may be stored for statistical and analytical purposes even for longer periods, as it does not allow the identification of the data subject.

* Meaningful interaction means any voluntary activity by the data subject that shows active engagement with the brand. By way of example, such interactions may include opening or selecting (clicking on) marketing communications; accessing the reserved area or updating user preferences; purchasing products or services; participating in events or promotional initiatives; interacting with customer service or sales staff. Such interactions can be used as indicators of the data subject's current interest, allowing the data controller to assess the reasonable continuation of marketing activities in compliance with regulatory requirements.

 

12.  WHICH DATA PROTECTION RIGHTS CAN YOU CLAIM AS A DATA SUBJECT

You can exercise multiple rights as a data subject. To do so, please refer to the contact details in section 15 of this privacy policy.

 

Right of access

You may request information about your stored personal data (Art. 15 of the GDPR). This information includes the categories of data processed by us, the purposes of the processing, the origin of the data, if we did not collect it directly from you, and, if applicable, the recipients to whom we have transmitted your data. You may receive a free copy of your data from us, which is the subject of the agreement. If you are interested in further copies, we reserve the right to charge for any additional copies.

 

Right to rectification and deletion

You may request the rectification of inaccurate personal data and the completion of incomplete personal data concerning you (Art. 16 of the GDPR). In addition, you may request the deletion of your data in accordance with and under the conditions of Art. 17 of the GDPR. This could happen, for example:

·         if your personal data is no longer necessary for the purposes for which it was collected or otherwise processed.

·         if you withdraw the consent on which the processing is based and there is no other legal basis for the processing.

·         if you object to the processing of your data and there is no overriding legitimate reason for proceeding with the processing.

·         if the personal data has been processed unlawfully, except where the processing is necessary to comply with a legal obligation that requires us to process your data:

- in particular, with regard to legitimate retention periods.

- to establish, exercise or defend a right. 

 

Right to restriction of processing

You have the right to restrict the processing of your personal data, for example, by flagging your stored data for the purpose of restricting its future processing. For this purpose, one of the conditions specified in Art. 18 of the GDPR must be met, e.g.

·         you contest the accuracy of the personal data, therefore, during the period of verification of the accuracy of such personal data, we restrict the processing.

·         the processing is unlawful, but you request that its use be restricted instead.

·         we no longer need your personal data, but you need it for the establishment, exercise or defence of legal claims.

·         you have objected to the processing pending verification of whether our legitimate grounds for processing override yours.

 

Right to data portability

You have the right to receive the personal data you have provided to us, but not including specific content, in a structured, commonly used and machine-readable format. You may transfer this data to another data controller without hindrance. You have the right to have your personal data transmitted directly to another data controller, if technically feasible (Art. 20 of the GDPR).

 

Right to objection

You have the right to object at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, provided that the processing is based on your consent or on our legitimate interests or those of a third party. In this case, we will refrain from further processing your personal data unless we can demonstrate compelling legitimate grounds for the processing that override your interests, rights and freedoms, or for the establishment, exercise or defence of legal claims. You may object to the processing at any time if your personal data is processed by us for direct marketing purposes (Art. 21 of the GDPR). The right to withdraw your consent to processing remains freely revocable at any time, regardless of your right to object.

 

Right to lodge a complaint with a supervisory authority

We will work with you to find a fair solution to any complaint regarding data protection. You have the right to lodge a complaint with the Data Protection Authority if you believe that our processing of your personal data violates applicable data protection law.

Please note that you can exercise your rights by simply sending a request by e-mail to the address indicated in point 16 of this Privacy Policy, as well as using the additional IT systems adopted by the Data Controller, which will allow you to independently modify or revoke your previously expressed consent and, where possible, to reassess your preferences regarding the processing carried out (e.g. mail-in and preference centres managed on IT platforms).

 

13.  THE SUPERVISORY AUTHORITY FOR THE PROTECTION OF PERSONAL DATA

The provisions on personal data protection contained in the GDPR are available and can be consulted by clicking on this link.

The relevant supervisory authorities for the processing of personal data covered by this privacy policy are:

- Italian Data Protection Authority

- European Data Protection Supervisor

- Federal Trade Commission/FTC (USA)

 

14.  HOW YOUR DATA IS PROTECTED

The processing of your personal data is carried out by means of the operations indicated in Article 4, no. 2) of the GDPR - performed with or without the aid of IT systems - and specifically: collection, recording, organisation, structuring, updating, storage, adaptation or alteration, retrieval and analysis, consultation, use, communication by transmission, comparison, interconnection, restriction, minimisation, erasure or destruction. In any case, the logical and physical security of the databases and, in general, the confidentiality of the personal data processed will be guaranteed by implementing all the necessary technical and organisational measures to ensure their security.

Please note that:

·         the connection to the server is encrypted

·         the saved data is encrypted "at rest" and visible only after authentication

·         All our servers are physically located in Europe.

It should be noted that 'at rest', i.e., 'not yet (or no longer) in use or in motion', refers to all data stored on any local or remote storage unit, backups made on our local storage units or on cloud network servers, which are encrypted by us for data security purposes.

 

15.  COMMUNICATIONS

If you have any questions, doubts, concerns or requests regarding this Privacy Policy or the processing of your personal data, you can contact our Customer Service at the following email address: customerservice@lemaire.fr