Privacy Policy

Dermalogica Pty Limited whose registered office is at 111 Chandos Street, Crows Nest, NSW 2065 (ABN 46 067 065 105 ) trading as Dermalogica, is committed to protecting and respecting the privacy of its customers and other users of this Site (collectively "Customers").

Dermalogica acknowledges the importance of privacy to its Customers.

This policy sets out the basis on which any personal data Dermalogica collects from its customers, or that Customers provide to Dermalogica, will be processed by Dermalogica.

The National Privacy Principles

Dermalogica is bound by the National Privacy Principles as provided in the Commonwealth Privacy Act,1988.

Information Dermalogica may collect from Customers

Dermalogica may collect and process the following data about Customers:

a) information that Customers provide by filling in forms on the site dermalogica.com.au or buy.dermalogica.com.au ("the Sites") or that Customers have already provided at the time of becoming an account holder. Dermalogica may also ask Customers for information when Customers report a problem with Dermalogica's sites;

b) if Customers contact Dermalogica , Dermalogica may keep a record of that correspondence;

c) details of transactions Customers carry out through Dermalogica's site and of the fulfilment of Customers' orders;

d) details of Customers' visits to Dermalogica's sites including, but not limited to, traffic data, location data, weblogs and other communication data, whether this is required for Dermalogica's own billing purposes or otherwise and the resources that Customers access.

IP addresses and cookies

Dermalogica may collect information about Customers' computers, including, where available, Customers' IP addresses, operating systems and browser types, for system administration. This is statistical data about Dermalogica's users' browsing actions and patterns, and does not identify any individual.

For the same reason, Dermalogica may obtain information about Customers' general internet usage by using a cookie file which is stored on the hard drive of Customers' computer. Cookies contain information that is transferred to Customers' computer's hard drives. They help Dermalogica to improve Dermalogica's sites and to deliver a better and more personalised service. They enable Dermalogica :

a) to estimate Dermalogica's audience size and usage pattern;

b) to store information about Customers' preferences, and so allow Dermalogica to customise Dermalogica's site according to Customers' individual interests;

c) to speed up Customers' searches; and

d) to recognise Customers when Customers return to Dermalogica's sites.

Customers may refuse to accept cookies by activating the setting on their browsers which allows them to refuse the setting of cookies. However, if Customers select this setting they may be unable to access certain parts of Dermalogica's site. Unless Customers have adjusted their browser settings so that they will refuse cookies, Dermalogica's system will issue cookies when Customers log on to Dermalogica's sites.

Where Dermalogica stores Customers' personal data

The data that Dermalogica collects from Customers may be transferred to, and stored at, a destination outside Australia. It may also be processed by staff operating outside Australia who work for Dermalogica or for one of Dermalogica's suppliers. Such staff may be engaged in, among other things, the fulfilment of Customers' orders, the processing of Customers' payment details and the provision of support services. By submitting Customers' personal data, Customers agree to this transfer, storing or processing. Dermalogica will take all steps reasonably necessary to ensure that Customers' data is treated securely and in accordance with this privacy policy.

All information Customers provide to Dermalogica is stored on Dermalogica's secure servers. Any payment transactions will be encrypted. Where Dermalogica has given Customers (or where Customers have chosen) a password which enables Customers to access certain parts of Dermalogica's sites, Customers are responsible for keeping this password confidential. Dermalogica require Customers not to share a password with anyone.

Unfortunately, the transmission of information via the internet is not completely secure. Although Dermalogica will use reasonable efforts to protect Customers' personal data, Dermalogica cannot guarantee the security of Customers' data transmitted to Dermalogica's sites; any transmission is at Customers' own risk. Once Dermalogica has received Customers' information, Dermalogica will use strict procedures and security features to try to prevent unauthorised access

Uses made of the information

Dermalogica use information held about Customers in the following ways:

a) to ensure that content from Dermalogica's site is presented in the most effective manner for Customers and for Customers' computers;

b) to provide Customers with information, products or services that Customers request from Dermalogica or which Dermalogica feel may interest Customers, where Customers have consented to be contacted for such purposes;

c) to carry out Dermalogica's obligations arising from any contracts entered into between Customers and Dermalogica; and

d) to notify Customers about changes to Dermalogica's service.

If Customers are existing customers of Dermalogica, Dermalogica will only contact Customers by electronic means (e-mail or SMS) with information about goods and services similar to those which were the subject of a previous sale to Customers. If Customers are new customers of Dermalogica, Dermalogica will contact Customers by electronic means only if Customers have consented to this.

Disclosure of Customers' information

Dermalogica may disclose Customers' personal information to any member of Dermalogica's group, which means Dermalogica's subsidiaries, Dermalogica's ultimate holding company and its subsidiaries, as defined in section 9 of the Corporations Act, 2001.

Dermalogica may disclose Customers' personal information to third parties:

a) in the event that Dermalogica sell or buy any business or assets, in which case Dermalogica may disclose Customers' personal data to the prospective seller or buyer of such business or assets;

b) if Dermalogica or substantially all of its assets are acquired by a third party, in which case personal data held by it about its customers will be one of the transferred assets;

c) if Dermalogica is under a duty to disclose or share Customers' personal data in order to comply with any legal obligation, or in order to enforce or apply Dermalogica's terms and conditions of online trading and other agreements; or to protect the rights, property, or safety of Dermalogica, Dermalogica's customers, or others. This includes exchanging information with other companies and organisations for the purposes of fraud protection and credit risk reduction.

Customers' rights

Customers have the right to ask Dermalogica not to process Customers' personal data for marketing purposes. Dermalogica will usually inform Customers (before collecting Customers' data) if Dermalogica intend to use Customers' data for such purposes or if Dermalogica intend to disclose Customers' information to any third party for such purposes. Customers can exercise Customers' right to prevent such processing by checking certain boxes on the forms Dermalogica use to collect Customers' data. Customers can also exercise the right at any time by contacting Dermalogica at info@dermalogica.com.au.

Dermalogica's sites may, from time to time, contain links to and from the websites of Dermalogica's partner networks, advertisers and affiliates. If Customers follow a link to any of these websites, please note that these websites have their own privacy policies and that Dermalogica do not accept any responsibility or liability for these policies. Customers must please check these policies before submitting any personal data to these websites.

Access to information

We consider it is the responsibility of parents to monitor their children's use of our web site. Nevertheless it is our policy not to require personal information from persons known to be under the age of 18 years or offer to send any promotional material to persons in that category.

You are entitled to have access to any personal information relating to you which you have previously supplied to us over Dermalogica's website. You are entitled to edit or delete such information unless we are required by law to retain it.

If you wish to comment on or query our privacy policy, or if you wish to make a complaint or an inquiry regarding any personal information relating to you which may be in our possession, contact us at info@dermalogica.com.au or write to The Privacy Officer Dermalogica Australia,111 Chandos Street, CROWS NEST, NSW 2065

Retention of data

We will retain in a secure manner any information you provided us in connection with a particular transaction for a period of seven years after which we may destroy it.

Changes to Dermalogica's privacy policy

Any changes Dermalogica may make to Dermalogica's privacy policy in the future will be posted on this page and, where appropriate, notified to Customers by e-mail.