Privacy policy
PRIVACY POLICY
Last updated: 24 July 2026
This privacy policy (“Policy”) is issued by Remi Scalp Care Ltd, trading as Remi Scalp Care, a company registered in Ireland with its registered office at 8 Merville Avenue, Dublin, D03 P584, Ireland (“Remi”, “we”, “us” or “our”). This Policy explains, in plain and complete terms, how and why we collect, use, store, disclose and otherwise process personal data when you:
· visit or browse our website at https://www.remiscalp.com or any other website we operate that links to this Policy (the “Website”);
· create a customer account, place an order, or purchase a one-off or subscription product through our online store;
· sign up to receive marketing communications or otherwise join our mailing list;
· contact our customer support team, or otherwise correspond with us by email, telephone or post; or
· otherwise interact with us in connection with our scalp care and hair care products and services (together, the “Services”).
We are committed to protecting your privacy and to processing your personal data fairly, lawfully and transparently, in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679) (“GDPR”), the Irish Data Protection Act 2018, the UK General Data Protection Regulation and the UK Data Protection Act 2018 (together, the “UK GDPR”), and applicable Irish and EU consumer protection law.
Please take the time to read this Policy carefully. It describes what personal data we collect, why we collect it, the legal grounds we rely on, who we share it with (including our key service providers, Shopify, Stripe, Recharge, Klaviyo and An Post), how long we retain it, and the rights available to you under applicable data protection law. If, having read this Policy, you have any questions or concerns, please contact us at privacy@remiscalp.com.
Summary of Key Points
This summary highlights certain points from this Policy, but you should read the full Policy to understand our practices in detail. You can navigate directly to any section using the Table of Contents below.
What personal data do we process?
We process personal data that you provide to us directly, such as your name, contact details, delivery address and payment-related information, as well as data generated automatically through your use of our Website, such as device information and cookies. We do not process any special category (sensitive) personal data, and we do not knowingly collect personal data from children. See Categories of Personal Data.
Do we receive personal data from third parties?
We do not purchase or otherwise obtain marketing lists from third parties. We do, however, receive limited data from the third-party platforms that support our Website and orders, such as order and payment confirmation data from Shopify and Stripe, and subscription status updates from Recharge, strictly for the purpose of operating our Services. See When and With Whom Do We Share Your Personal Data.
How do we process your personal data?
We process your personal data to operate our Website, take and fulfil your orders, manage your subscription, communicate with you, provide customer support, prevent fraud, meet our legal and tax obligations, and, where you have consented, to send you marketing communications. We only process personal data where we have a valid legal basis for doing so. See How Do We Process Your Personal Data and What Legal Bases Do We Rely On.
With whom do we share your personal data?
We share personal data with a limited number of trusted service providers who process data on our behalf, namely Shopify (our e-commerce and hosting platform), Stripe and Apple Pay (payment processing), Recharge (subscription management), Klaviyo (email marketing) and An Post (delivery and fulfilment). Each of these providers is contractually bound to process your data only as instructed by us and in accordance with applicable data protection law. See Third-Party Service Providers.
How do we keep your personal data safe?
We maintain appropriate technical and organisational security measures, including encryption, access controls and staff training, to protect your personal data. However, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security. See How Do We Keep Your Information Safe.
What are your rights?
Subject to certain exceptions and conditions under applicable law, you have the right to access, correct, erase, restrict or object to our processing of your personal data, the right to data portability, and the right to withdraw consent at any time. You also have the right to lodge a complaint with the Irish Data Protection Commission or, where relevant, the UK Information Commissioner’s Office. See Your GDPR Rights.
How do you exercise your rights?
You can exercise your rights by emailing us at privacy@remiscalp.com. We will respond to all valid requests within the timeframes required by applicable data protection law, generally within one month.
TABLE OF CONTENTS
1. Definitions and Interpretation
2. Who We Are: The Data Controller
3. What Personal Data Do We Collect?
4. How Do We Process Your Personal Data?
5. What Legal Bases Do We Rely On?
6. When and With Whom Do We Share Your Personal Data?
7. Third-Party Service Providers
8. Subscriptions and Recurring Payments
9. Email Marketing and Other Communications
11. Cookies and Similar Tracking Technologies
12. Shipping and Order Fulfilment
14. Automated Decision-Making and Profiling
15. International Transfers of Personal Data
16. How Long Do We Keep Your Personal Data?
17. How Do We Keep Your Information Safe?
18. Do We Collect Information From Children?
20. Marketing Preferences and Account Information
21. Controls for Do-Not-Track Features
22. Complaints: The Irish Data Protection Commission
23. Do We Make Updates to This Policy?
26. Governing Law and Jurisdiction
28. How Can You Review, Update or Delete Your Data?
1. DEFINITIONS AND INTERPRETATION
In this Policy, the following terms have the meanings set out below, unless the context requires otherwise:
· “Controller” means the entity that determines the purposes and means of the processing of personal data, which in this case is Remi Scalp Care Ltd.
· “Data Subject” means an identified or identifiable living individual to whom personal data relates, including our customers, prospective customers, Website visitors and mailing list subscribers.
· “GDPR” means the EU General Data Protection Regulation (Regulation (EU) 2016/679), as implemented in Ireland by the Data Protection Act 2018.
· “UK GDPR” means the General Data Protection Regulation as it forms part of the law of England and Wales, Scotland and Northern Ireland by virtue of section 3 of the European Union (Withdrawal) Act 2018, together with the UK Data Protection Act 2018.
· “Personal Data” means any information relating to an identified or identifiable natural person, as defined in Article 4(1) GDPR.
· “Processing” means any operation performed on personal data, including collection, recording, organisation, storage, adaptation, retrieval, use, disclosure, erasure or destruction.
· “Processor” means a third party that processes personal data on behalf of, and under the instructions of, a controller, such as Shopify, Stripe, Recharge, Klaviyo and An Post in respect of their respective functions described in this Policy.
· “Services” means our Website, our online store, our subscription programme, and any related customer support, marketing or fulfilment activity carried out by or on behalf of Remi.
· “Special Category Data” means personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person’s sex life or sexual orientation, as defined in Article 9 GDPR. We do not knowingly collect or process Special Category Data through the Services.
· “Supervisory Authority” means, in Ireland, the Data Protection Commission (“DPC”), and in the United Kingdom, the Information Commissioner’s Office (“ICO”).
2. WHO WE ARE: THE DATA CONTROLLER
For the purposes of the GDPR and the UK GDPR, Remi Scalp Care Ltd is the data controller in respect of the personal data described in this Policy. This means that we decide why and how your personal data is processed in connection with the Services.
Our contact details are:
Remi Scalp Care Ltd
8 Merville Avenue
Dublin, D03 P584
Ireland
Email: privacy@remiscalp.com
Website: https://www.remiscalp.com
Where we engage third-party service providers, such as Shopify, Stripe, Recharge, Klaviyo and An Post, to process personal data on our behalf, those providers act as our processors (or, in certain limited circumstances described below, as independent controllers of the data they hold, such as Stripe in respect of its own regulatory and anti-money-laundering obligations). We have entered into, or rely on, appropriate data processing terms with each such provider as required by Article 28 GDPR.
3. WHAT PERSONAL DATA DO WE COLLECT?
We collect different categories of personal data depending on how you interact with us. We set these out below, organised by the context in which the data arises.
3.1 Account Information
If you create a customer account with us through our Shopify-hosted store, we collect the information necessary to establish and administer that account, which typically includes:
· your first and last name;
· your email address and telephone number;
· your billing and delivery address(es);
· your account username and a securely hashed password;
· your order history and any saved payment method reference (we do not store full card numbers ourselves; see Third-Party Service Providers below); and
· your marketing and communication preferences.
You are responsible for ensuring that the information you provide to us is accurate, complete and kept up to date, and for notifying us promptly of any changes.
3.2 Orders
When you place an order for our scalp care or hair care products, whether as a one-off purchase or through our subscription programme, we collect the information necessary to process, fulfil and deliver that order, including the products ordered, order value, delivery address, delivery instructions, and correspondence relating to that order (for example, queries about delivery or product suitability).
3.3 Subscriptions and Recurring Payments
If you subscribe to receive our products on a recurring basis through our subscription platform, Recharge, we (and Recharge, acting on our behalf) collect and process information relating to your subscription plan, delivery frequency, next billing and delivery dates, subscription status (active, paused, skipped or cancelled), and your subscription payment history. Further detail is set out in Section 8 (Subscriptions and Recurring Payments) below.
3.4 Payment Data
We do not directly collect or store your full payment card details. Payment data (such as your card number, expiry date and security code, or your Apple Pay token) is collected and processed directly by our payment processor, Stripe, and, where you choose to pay using Apple Pay, by Apple. We receive only limited confirmation data from these providers, such as the payment status, the last four digits of your card, and the card type, which we use to reconcile and fulfil your order.
3.5 Marketing Preferences and Email Marketing Data
If you sign up to our mailing list, or otherwise consent to receive marketing communications, we collect your email address, name (where provided), marketing consent status and consent timestamp, and, through our email service provider Klaviyo, data relating to your engagement with our marketing emails (such as opens, clicks and browsing or cart activity used to personalise our communications). See Section 9 (Email Marketing and Other Communications) below.
3.6 Device Information, Cookies and Analytics
When you visit our Website, certain information is collected automatically through cookies, pixels and similar technologies, including your IP address, browser type and version, device type and operating system, referring website, pages viewed, time spent on pages, and general (non-precise) location derived from your IP address. This information does not, on its own, identify you by name, but it is personal data because it relates to your device and browsing activity. See Section 11 (Cookies and Similar Tracking Technologies) below.
3.7 Customer Support Correspondence
If you contact our customer support team, we collect the information you provide in that correspondence, including your name, contact details, order reference and the content of your query, in order to investigate and respond to it.
We do not collect or process any Special Category Data (as defined in Section 1) through the Services, and we ask that you do not provide us with any such information, for example in free-text fields such as customer support messages or product reviews.
4. HOW DO WE PROCESS YOUR PERSONAL DATA?
We process your personal data for the following purposes:
· to create and administer your customer account, and to authenticate you when you log in;
· to process, fulfil, deliver and, where applicable, return or exchange your orders;
· to establish, administer, bill and manage your product subscription, including recurring billing, delivery scheduling, and subscription amendments, skips or cancellations;
· to process payments securely through Stripe and, where selected, Apple Pay;
· to communicate with you about your order, account or subscription, including transactional emails such as order confirmations, shipping notifications and payment receipts;
· to send you marketing communications where you have provided your consent, and to manage your marketing preferences, including unsubscribe requests;
· to respond to customer support enquiries and resolve any issues you raise with us;
· to detect, investigate and prevent fraud, unauthorised transactions, and other misuse of the Services;
· to maintain the security, integrity and proper functioning of our Website and IT systems;
· to comply with our legal, regulatory, accounting and tax obligations, including record-keeping obligations under Irish company and tax law; and
· to enforce our website terms of use and applicable store policies, and to establish, exercise or defend legal claims.
We only process your personal data for the purposes described above, or for closely related purposes that would reasonably be expected in that context. Where we wish to use your personal data for a materially different purpose, we will notify you and, where required by law, seek your consent before doing so.
5. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL DATA?
Under the GDPR and the UK GDPR, we must have a valid legal basis for each purpose for which we process your personal data. Depending on the circumstances, we rely on one or more of the following legal bases:
Performance of a contract
Much of our processing is necessary to perform our contract with you, for example processing your order, taking payment, arranging delivery, and administering your subscription under our terms of sale. Without this processing, we would not be able to supply the products or services you have requested.
Consent
Where we rely on your consent, for example to send you marketing emails, or to place non-essential cookies on your device, we will ask for that consent clearly and separately from other matters, and you may withdraw it at any time with future effect, as described in Section 19 (Your GDPR Rights) below.
Legitimate interests
We rely on our legitimate interests, and those of third parties, to carry out certain processing, such as fraud prevention, maintaining the security of our Website, improving our Services through aggregated analytics, and direct marketing to existing customers in respect of similar products (in accordance with Irish e-privacy rules). Where we rely on legitimate interests, we have considered and balanced our interests against your rights and freedoms, and we do not rely on this basis where our interests are overridden by your interests or fundamental rights.
Legal obligation
We process certain personal data to comply with our legal obligations, such as retaining invoices and transaction records for tax and accounting purposes under Irish law, and responding to lawful requests from public authorities or regulators.
Vital interests
In rare circumstances, we may process personal data where necessary to protect someone’s vital interests, for example where there is a serious risk to health or safety.
6. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL DATA?
We do not sell your personal data. We share personal data only in the following circumstances:
· with the third-party service providers described in Section 7 (Third-Party Service Providers) below, each of which processes personal data on our behalf and under our instructions, strictly for the purposes of operating the Services;
· with professional advisers, such as our accountants, auditors, insurers and legal advisers, where necessary in connection with their services to us, subject to applicable confidentiality obligations;
· with regulators, law enforcement or other public authorities, where we are required to do so by law, or where necessary to protect our legal rights, prevent fraud, or protect the safety of any person;
· with a prospective buyer or its advisers, in connection with an actual or proposed merger, acquisition, restructuring, financing or sale of all or part of our business or assets, subject to appropriate confidentiality protections; and
· with your consent, or at your direction, in any other circumstances not described above.
7. THIRD-PARTY SERVICE PROVIDERS
We work with a small number of specialist service providers to operate our Website, process orders, manage subscriptions, communicate with customers and fulfil deliveries. Each provider is contractually required to process personal data only for the purposes we specify, in accordance with a data processing agreement that reflects the requirements of Article 28 GDPR, and to implement appropriate technical and organisational security measures. We set out below the providers we currently use, and the categories of personal data and purposes involved.
Shopify: E-Commerce Platform, Hosting and Checkout
Our online store is built on, and hosted by, Shopify International Limited (“Shopify”). Shopify provides the underlying e-commerce infrastructure for our Website, including product listings, the shopping cart and checkout process, customer account functionality, order management, and certain built-in analytics regarding Website usage and sales performance. In providing these services, Shopify processes personal data such as your name, contact details, billing and delivery addresses, order details, and technical data relating to your use of our Website. Shopify acts as our data processor in this respect, and further information about Shopify’s privacy practices is available at https://www.shopify.com/legal/privacy.
Stripe and Apple Pay: Payment Processing
We use Stripe, Inc. (“Stripe”) to process payments made through our Website. When you make a purchase, your payment card details are submitted directly to Stripe’s secure payment infrastructure; we do not receive or store your full card number, expiry date or security code. Where you choose to pay using Apple Pay, your payment is processed by Apple Inc. in accordance with Apple’s own privacy practices, with payment authorisation then passed to Stripe for processing. Stripe acts as an independent controller in respect of certain processing it carries out for its own regulatory, fraud-prevention and anti-money-laundering purposes. Further information is available at https://stripe.com/ie/privacy and https://www.apple.com/legal/privacy/data/en/apple-pay/.
Recharge: Subscription Management
Our product subscription programme is powered by Recharge Payments, Inc. (“Recharge”), trading as Recharge (getrecharge.com). Recharge integrates with our Shopify store to manage recurring billing, generate and process subscription renewal orders, and provide you with a customer subscription portal through which you can view your subscription, skip or reschedule an upcoming delivery, update your delivery or payment details, amend your subscription plan, or cancel your subscription. In providing these services, Recharge processes personal data such as your name, contact details, delivery address, subscription plan details, and payment status information. Recharge acts as our data processor. Further information is available at https://getrecharge.com/privacy-policy/.
Klaviyo: Email Marketing and Marketing Automation
We use Klaviyo, Inc. (“Klaviyo”) to send transactional and marketing emails, including order and shipping confirmations, newsletters, promotional offers, abandoned cart reminders, and other marketing automation. Klaviyo processes your email address, name (where provided), marketing consent status, purchase history and Website browsing behaviour (such as products viewed or added to your cart) in order to send targeted, consent-based marketing communications and to segment our customer base for more relevant messaging. Klaviyo acts as our data processor in this respect. Further information is available at https://www.klaviyo.com/privacy.
An Post: Shipping, Fulfilment and Delivery
We use An Post, Ireland’s national postal service, to deliver orders placed through our Website. In order to fulfil and deliver your order, we share your name, delivery address, telephone number (where provided) and order/tracking reference with An Post, solely for the purposes of delivery and providing you with tracking information regarding the status of your parcel. An Post acts as our data processor in respect of this limited data-sharing. Further information about An Post’s privacy practices is available at https://www.anpost.com/privacy.
We periodically review our service providers and this Policy will be updated to reflect any change in the providers we use. We do not use, and this Policy does not refer to, any payment or service providers other than those listed above.
8. SUBSCRIPTIONS AND RECURRING PAYMENTS
Certain products are available on a recurring subscription basis, managed through our subscription partner, Recharge. This Section explains, in detail, how your personal data is used in connection with your subscription, and the controls available to you.
Recurring billing and automatic renewal
When you subscribe to a recurring delivery of one or more of our products, you authorise us (through Recharge and Stripe) to charge your chosen payment method automatically, in advance of each scheduled delivery, at the frequency you selected at checkout (for example, every 30, 60 or 90 days), until you skip, pause, amend or cancel your subscription in accordance with this Section, or until we are otherwise required to suspend your subscription (for example, following repeated failed payments).
The customer subscription portal
Recharge provides you with a self-service customer portal, accessible via a link in your subscription confirmation and reminder emails, or via your account on our Website. Through the portal, you can view your upcoming deliveries and billing dates, and manage your subscription as described below.
Skipping or rescheduling a delivery
You may skip or reschedule any upcoming delivery through the customer portal. Skipping a delivery will postpone that charge and shipment to your next scheduled delivery date, without cancelling your subscription.
Updating your payment method
You can update the payment card or Apple Pay details associated with your subscription at any time through the customer portal. It is your responsibility to keep your payment details up to date to avoid a failed or delayed charge.
Amending your subscription
You may amend your subscription at any time, including changing the products included, the delivery frequency, or the delivery address, through the customer portal or by contacting our customer support team.
Cancelling your subscription
You may cancel your subscription at any time through the customer portal, or by contacting us at info@remiscalp.com. Cancellation will take effect from your next scheduled billing date; any delivery already processed or dispatched prior to cancellation will not be affected.
Subscription reminders
We (or Recharge, on our behalf) will send you an email reminder in advance of each upcoming subscription charge and delivery, so that you have the opportunity to skip, amend or cancel before you are charged. These reminder emails are transactional in nature and relate to the performance of our contract with you; they are sent regardless of your marketing communication preferences, for as long as your subscription remains active.
Personal data processed in connection with your subscription, including your subscription history, billing and delivery schedule, and communications relating to skips, amendments or cancellations, is processed on the legal basis of performance of a contract, and is retained in accordance with Section 16 (How Long Do We Keep Your Personal Data) below.
9. EMAIL MARKETING AND OTHER COMMUNICATIONS
We distinguish between transactional communications, which are necessary to provide the Services you have requested, and marketing (promotional) communications, which we send only where you have provided your consent.
Transactional emails
We will send you transactional emails relating to your account, order or subscription, for example order confirmations, payment receipts, shipping and delivery notifications, and subscription reminders, regardless of your marketing preferences, as these are necessary for the performance of our contract with you and cannot be unsubscribed from while you continue to use the relevant Service.
Marketing and promotional emails
If you opt in to our mailing list, whether at checkout, through a sign-up form on our Website, or otherwise, we will, through Klaviyo, send you marketing emails such as our newsletter, promotional offers, product announcements, and abandoned cart reminders relating to items left in your cart without completing checkout. We only send marketing emails where you have given your consent (opt-in), in accordance with the Irish ePrivacy Regulations and GDPR.
Opt-in and opt-out
You may opt in to marketing communications at any time by providing your email address and actively consenting, for example by ticking a consent checkbox or submitting a sign-up form. You may opt out (unsubscribe) at any time, free of charge, by clicking the “unsubscribe” link included in every marketing email we send, by managing your preferences through your account, or by emailing us at privacy@remiscalp.com. Once you unsubscribe, we will stop sending you marketing emails within a reasonable period, and Klaviyo will record your unsubscribed status to ensure that preference is respected going forward.
Customer segmentation and personalisation
To make our marketing more relevant, Klaviyo may group customers into segments based on factors such as purchase history, product preferences, engagement with previous emails, and general browsing activity on our Website. This segmentation is carried out only in respect of customers who have consented to marketing, and is used solely to determine the content and timing of the marketing communications we send.
10. SMS MARKETING
We do not currently send SMS (text message) marketing communications to our customers. Should we introduce SMS marketing in the future, we will only do so with your prior, separate opt-in consent, and this Policy will be updated accordingly to explain how your mobile number and related data would be collected, used and protected, and how you could opt out.
11. COOKIES AND SIMILAR TRACKING TECHNOLOGIES
Our Website uses cookies and similar tracking technologies (such as pixels and local storage) to operate correctly, to understand how our Website is used, and, where you consent, to deliver relevant marketing. This Section explains the categories of cookies we use and how you can control them.
Essential cookies
These cookies are strictly necessary for our Website to function, for example to remember the contents of your shopping cart, to keep you logged in to your account, and to enable secure checkout through Shopify and Stripe. Essential cookies do not require your consent, as they are necessary for the provision of the Service you have requested, but we will still tell you about them.
Analytics cookies
These cookies help us understand how visitors use our Website, for example which pages are visited most, how long visitors spend on the Website, and where visitors have come from, so that we can improve our Website and Services. Analytics cookies are used only with your consent, except where they are strictly anonymised and fall outside the scope of consent requirements under Irish ePrivacy rules.
Marketing cookies
These cookies, including those associated with Klaviyo and any advertising platforms we use, are used to recognise repeat visitors, to measure the effectiveness of our marketing campaigns, and, where applicable, to serve relevant advertising to you on other websites and platforms. Marketing cookies are only placed with your consent.
Our cookie consent banner
When you first visit our Website, you will be shown a cookie consent banner allowing you to accept all cookies, reject all non-essential cookies, or customise your preferences by category. Your choice is recorded and respected for future visits, and you may change your cookie preferences at any time by accessing the cookie preference centre available via the link in our Website footer.
Third-party cookies
Some cookies on our Website are set by third parties, such as Shopify (to operate the store and checkout) and Klaviyo (for marketing personalisation, where you have consented). We do not control these third-party cookies directly; you can find further information about them, and how to manage them, through our cookie preference centre and the respective third party’s own privacy or cookie policy.
Browser controls
Most web browsers allow you to control cookies through their settings, including blocking all cookies, deleting existing cookies, or being notified when a cookie is set. Please note that if you block or delete essential cookies, certain features of our Website, including the shopping cart and checkout, may not function correctly.
12. SHIPPING AND ORDER FULFILMENT
Once your order is confirmed and payment has been processed, we prepare your order for dispatch and arrange delivery through An Post. To enable delivery, we share with An Post the personal data necessary for that purpose, namely your name, delivery address, telephone number (where provided), and order or tracking reference. This information is used by An Post solely for the purposes of delivering your parcel and providing you (and us) with delivery status and tracking updates. We do not share any further personal data with An Post beyond what is reasonably necessary for fulfilment and delivery.
Detailed information regarding delivery timeframes, shipping charges, and our approach to lost, damaged or delayed deliveries is set out in our Store Policies, available at https://remiscalp.com/en-ie/policies, which are incorporated by reference into this Policy as described in Section 24 (Store Policies) below.
13. FRAUD PREVENTION
We, and our payment processor Stripe, use automated and manual fraud-screening measures to protect our customers and our business against fraudulent transactions, chargebacks and other misuse of the Services. This may involve the analysis of order data, payment data, device and IP information, and historical transaction patterns to assess the risk associated with a given order. We process this data on the basis of our legitimate interest in preventing fraud and protecting our customers, our business and our payment processor from financial loss and unauthorised activity. Where an order is identified as high-risk, we may take additional steps to verify your identity before dispatching your order, or, in some cases, decline or cancel an order.
14. AUTOMATED DECISION-MAKING AND PROFILING
We do not use your personal data to make decisions based solely on automated processing (including profiling) that produce legal effects concerning you, or that similarly significantly affect you, within the meaning of Article 22 GDPR. Certain automated processes are used in a limited and supporting capacity, for example automated fraud-risk scoring by Stripe, and automated email segmentation by Klaviyo for marketing purposes, but these processes do not result in decisions that are made without the possibility of human review, and do not produce legal or similarly significant effects on you. Should this change in the future, we will update this Policy and, where required, obtain your explicit consent or otherwise ensure appropriate safeguards, including the right to obtain human intervention, are in place.
15. INTERNATIONAL TRANSFERS OF PERSONAL DATA
We are established in Ireland, and our primary processing of personal data takes place within the European Economic Area (“EEA”). However, certain of our service providers, including Shopify, Stripe, Recharge and Klaviyo, may store or process personal data in, or transfer personal data to, countries outside the EEA and the United Kingdom, including the United States, in the course of providing their services to us.
Where personal data is transferred outside the EEA or the UK, we ensure that an appropriate safeguard recognised under the GDPR and UK GDPR is in place before the transfer occurs. Depending on the recipient and circumstances, this may include:
· reliance on the European Commission’s EU-U.S. Data Privacy Framework, where the recipient is a certified participant;
· the use of the European Commission’s Standard Contractual Clauses (and, for transfers from the UK, the UK International Data Transfer Addendum), incorporated into our agreements with the relevant service provider; or
· another adequacy decision or transfer mechanism recognised under Chapter V of the GDPR or the equivalent provisions of the UK GDPR.
You may request further information about the specific safeguards applicable to a particular transfer by contacting us at privacy@remiscalp.com.
16. HOW LONG DO WE KEEP YOUR PERSONAL DATA?
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, tax or reporting requirements. Where no specific statutory retention period applies, we determine the appropriate retention period by reference to the amount, nature and sensitivity of the data, the purposes for which it is processed, and applicable legal and regulatory requirements. Our general retention practice is as follows:
· Customer accounts: for as long as your account remains active, and for a period of up to 2 years following your last order or account activity, after which inactive accounts and associated personal data are deleted or anonymised, save where a longer period applies below.
· Orders and order history: for 6 years from the date of the relevant order, in line with our obligations to retain commercial records under Irish law.
· Invoices and tax records: for a minimum of 6 years, in accordance with the record-keeping requirements of the Irish Revenue Commissioners under the Taxes Consolidation Act 1997.
· Subscription history: for the duration of your active subscription and for 6 years thereafter, consistent with our order and invoicing retention obligations.
· Marketing consent records: for as long as you remain subscribed to our marketing communications, and for a further period of 2 years following unsubscription, so that we can demonstrate compliance with consent requirements and ensure your opt-out preference continues to be honoured.
· Customer support correspondence: for 2 years from the date the query is resolved, unless a longer period is required to address an ongoing complaint, dispute or legal claim.
· Data relating to actual or potential legal claims: for as long as necessary to establish, exercise or defend such claims, having regard to applicable statutes of limitation under Irish law.
When personal data is no longer required for any of the purposes described above, we will securely delete or anonymise it. Where immediate deletion is not technically feasible (for example, where data is contained within secure backup archives), we will isolate that data from further active processing until deletion can be completed.
17. HOW DO WE KEEP YOUR INFORMATION SAFE?
We take the security of your personal data seriously and have implemented a range of technical and organisational measures designed to protect it against unauthorised access, alteration, disclosure or destruction. These measures include, without limitation:
Encryption
All data transmitted between your browser and our Website is encrypted in transit using TLS (HTTPS). Sensitive data, including payment information, is encrypted both in transit and at rest by our payment processor, Stripe, in accordance with the Payment Card Industry Data Security Standard (PCI DSS).
Access controls and role-based access
Access to personal data within our systems is restricted to personnel and service providers who require it to perform their role, on a least-privilege, role-based basis. Administrative access to our Shopify store, Klaviyo account, Recharge dashboard and other systems is protected by strong, unique credentials and, where supported, multi-factor authentication.
Secure hosting
Our Website and customer data are hosted on Shopify’s secure, PCI-compliant infrastructure, which incorporates network security controls, firewalls and regular security patching maintained by Shopify as part of its platform-wide security programme.
Monitoring and incident response
We monitor our systems for signs of unauthorised access or unusual activity, and maintain an incident response process to identify, contain, investigate and remediate any security incident promptly. In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Irish Data Protection Commission without undue delay, and in any event within 72 hours of becoming aware of the breach where required by Article 33 GDPR, and will notify affected individuals directly where the breach is likely to result in a high risk to their rights and freedoms, in accordance with Article 34 GDPR.
Backups
We maintain regular, encrypted backups of critical data to protect against accidental loss, corruption or destruction, consistent with our data retention obligations described in Section 16 above.
Staff awareness
Personnel who have access to personal data receive appropriate guidance regarding their data protection obligations and our internal policies and procedures for handling personal data securely.
Despite these measures, no method of electronic transmission or storage is completely secure, and we cannot guarantee the absolute security of your personal data. You should also take appropriate steps to protect your own account credentials and access our Website only through a secure and trusted connection.
18. DO WE COLLECT INFORMATION FROM CHILDREN?
Our Services are directed at adults, and we do not knowingly collect, solicit, or market our products to individuals under the age of 18. By using the Services, you confirm that you are at least 18 years of age, or, if you are the parent or legal guardian of a person under that age, that you consent to their use of the Services under your supervision.
If we become aware that we have inadvertently collected personal data from a child under the age of 18 without appropriate parental or guardian consent, we will take reasonable steps to delete that information promptly. If you believe we may hold personal data relating to a child, please contact us immediately at privacy@remiscalp.com.
19. YOUR GDPR RIGHTS
If you are located in the EEA, the UK, or another jurisdiction which affords equivalent rights, you have the following rights in respect of your personal data, subject to certain exceptions and conditions set out in applicable law. To exercise any of these rights, please contact us at privacy@remiscalp.com; we will respond within one month of receiving a valid request, extendable by a further two months where the request is complex, in which case we will explain the reason for the delay.
Right of access
You have the right to obtain confirmation as to whether we process your personal data, and, where we do, to obtain a copy of that data together with certain information about how and why it is processed.
Right to rectification
You have the right to have inaccurate personal data corrected, and incomplete personal data completed, without undue delay. You can update most account information directly through your account settings.
Right to erasure (‘right to be forgotten’)
You have the right to request the deletion of your personal data in certain circumstances, for example where the data is no longer necessary for the purpose for which it was collected, or where you withdraw consent and there is no other legal basis for processing. This right is not absolute, and we may need to retain certain data to comply with a legal obligation, such as our tax record-keeping obligations described in Section 16.
Right to restriction of processing
You have the right to request that we restrict the processing of your personal data in certain circumstances, for example while we verify the accuracy of data you have contested, or where processing is unlawful but you oppose erasure.
Right to object
You have the right to object, on grounds relating to your particular situation, to processing based on our legitimate interests, and an unconditional right to object to processing of your data for direct marketing purposes at any time, including via the unsubscribe mechanisms described in Section 9 above.
Right to data portability
Where processing is based on your consent or on a contract, and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used and machine-readable format, and to have that data transmitted to another controller, where technically feasible.
Right to withdraw consent
Where we rely on your consent as the legal basis for processing (for example, marketing emails or non-essential cookies), you have the right to withdraw that consent at any time, with effect for the future. Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, nor does it affect processing carried out on another lawful basis.
Rights related to automated decision-making
As explained in Section 14 above, we do not currently carry out processing that would engage your right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Should this change, we would ensure appropriate safeguards, including the right to obtain human intervention, are made available to you.
Right to lodge a complaint
You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement. Further detail regarding complaints to the Irish Data Protection Commission is set out in Section 22 below.
20. MARKETING PREFERENCES AND ACCOUNT INFORMATION
Managing your marketing preferences
You can update your marketing preferences, or unsubscribe from marketing communications entirely, at any time by clicking the unsubscribe link in any marketing email, updating your preferences through your account, or contacting us at privacy@remiscalp.com. Please note that even where you unsubscribe from marketing, we will continue to send you transactional communications necessary for the performance of our contract with you, such as order confirmations and subscription reminders.
Reviewing or closing your account
You can review and update the information held in your customer account at any time by logging into your account settings on our Website. If you wish to close your account, you can do so by contacting us at privacy@remiscalp.com. Upon closure, we will deactivate your account and delete or anonymise the associated personal data in accordance with Section 16 above, save where we are required or entitled to retain certain information for the purposes described in that Section, such as fraud prevention, dispute resolution, or compliance with our legal obligations.
21. CONTROLS FOR DO-NOT-TRACK FEATURES
Some web browsers incorporate a ‘Do Not Track’ (DNT) signal that you can enable to indicate your preference not to be tracked online. Because no common industry standard for recognising and responding to DNT signals has yet been adopted, our Website does not currently respond to DNT browser signals. We will reconsider this position, and update this Policy accordingly, if a recognised standard for responding to such signals is adopted in the future. In the meantime, you can manage tracking through the cookie controls described in Section 11 above.
22. COMPLAINTS: THE IRISH DATA PROTECTION COMMISSION
If you have concerns about how we process your personal data, we would ask that you contact us first at privacy@remiscalp.com so that we can attempt to resolve the matter directly. However, you are entitled to lodge a complaint with the relevant supervisory authority at any time, whether or not you have raised the matter with us first.
As we are established in Ireland, our lead supervisory authority is the Irish Data Protection Commission. You can contact the Data Protection Commission as follows:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
Website: www.dataprotection.ie
If you are located in the United Kingdom, you may instead, or in addition, lodge a complaint with the Information Commissioner’s Office (ICO), whose contact details are available at www.ico.org.uk. If you are located in another EEA Member State, you may lodge a complaint with your own national supervisory authority.
23. DO WE MAKE UPDATES TO THIS POLICY?
We may update this Policy from time to time to reflect changes in our practices, the service providers we use, or applicable law. Any updated version will be indicated by a revised ‘Last updated’ date at the top of this Policy, and will take effect as soon as it is published on our Website. Where we make material changes that significantly affect how we process your personal data, we will take reasonable steps to notify you, for example by email or by way of a prominent notice on our Website, before the change takes effect. We encourage you to review this Policy periodically to stay informed of how we protect your personal data.
24. STORE POLICIES
This Policy addresses the collection, use and protection of your personal data. It does not set out the commercial terms applicable to your order, such as delivery timeframes, shipping charges, returns, refunds, exchanges, or our terms of sale. Those matters are governed by our separate store policies, which are available at https://remiscalp.com/en-ie/policies, and which are incorporated into, and form part of, the contract between you and us for any order you place through our Website. In the event of any conflict between this Policy and our store policies on a matter of data protection, this Policy shall prevail; on all other commercial matters, our store policies shall apply.
25. WEBSITE TERMS OF USE
Intellectual property
All content available on our Website, including text, graphics, logos, product images, trade marks, and the design and layout of the Website itself, is owned by, or licensed to, Remi Scalp Care Ltd, and is protected by Irish and international copyright, trade mark and other intellectual property laws. You may view and download material from our Website for your own personal, non-commercial use only. You may not reproduce, republish, distribute, modify, or otherwise exploit any content from our Website for commercial purposes without our prior written consent.
Acceptable use of our Website
When using our Website, you agree that you will not: use the Website for any unlawful purpose or in a manner that infringes the rights of any third party; attempt to gain unauthorised access to our systems, accounts, or networks; introduce any virus, malware or other harmful code; scrape, harvest or otherwise extract data from our Website using automated means without our consent; or engage in any conduct that restricts or inhibits any other person’s use or enjoyment of the Website. We reserve the right to suspend or terminate your access to the Website, or to any account you hold with us, if we reasonably believe you have breached these terms.
Limitation of liability
To the fullest extent permitted by applicable Irish law, we shall not be liable for any indirect, special, incidental or consequential loss or damage arising out of, or in connection with, your use of our Website or Services, including loss of profits, revenue, data, or business opportunity, save that nothing in this Policy shall limit or exclude our liability for death or personal injury caused by our negligence, for fraud or fraudulent misrepresentation, or for any other liability which cannot lawfully be limited or excluded under Irish or EU consumer protection law. Nothing in this Section affects your statutory rights as a consumer under the Consumer Rights Act 2022 or other applicable Irish consumer protection legislation.
26. GOVERNING LAW AND JURISDICTION
This Policy, and any dispute or claim arising out of or in connection with it (including non-contractual disputes or claims), shall be governed by and construed in accordance with the laws of Ireland. The courts of Ireland shall have exclusive jurisdiction to settle any such dispute or claim, save that, if you are a consumer resident in the European Union or the United Kingdom, you may also be entitled to bring proceedings in the courts of the EU Member State or UK jurisdiction in which you are habitually resident, and mandatory consumer protection provisions of that jurisdiction may also apply to your benefit.
27. HOW CAN YOU CONTACT US?
If you have any questions, comments or concerns about this Policy or our data protection practices, please contact us using the details below. We aim to respond to all enquiries promptly and, in any event, within the timeframes required by applicable data protection law.
Remi Scalp Care Ltd
8 Merville Avenue
Dublin, D03 P584
Ireland
Email: privacy@remiscalp.com
Website: https://www.remiscalp.com
28. HOW CAN YOU REVIEW, UPDATE OR DELETE YOUR DATA?
Depending on the law applicable to you, you may have the right to request access to, correction of, or deletion of the personal data we hold about you, as set out in Section 19 (Your GDPR Rights) above. To make such a request, please contact us at privacy@remiscalp.com with sufficient detail to allow us to identify you and understand the nature of your request. We may need to verify your identity before actioning certain requests, in order to protect your personal data from unauthorised access or disclosure.