YUTYBAZAR Limited, (hereinafter "YUTYBAZAR", “we” or “us”) is a company that treats all the matters related to personal data with utter respect and integrity. Our full commitment to safeguarding your privacy, and the privacy of our website, represents a particularly high priority for our company.
We hereby state that we have taken all the necessary technical steps and measures to provide you with the highest security available, so you can have a clear and informed experience, throughout your interactions with our website and services.
As a Visitor or a User, you hereby agree and accept that the use of our website is not possible without any indication of personal data.
In this section we explain what terms will be used, inter alia, within the document:
- Personal Data – means any type of information about a physical person, whose particularities can lead to its identification, directly or indirectly. Examples: name, address, any identification number, political orientation, sexual orientation, email address, location information, IP address, cookie information, etc.
- Data Subject – means any identified or identifiable natural person, whose personal data is collected and processed by us.
- Processing – means an operation performed on personal data. Examples: collection, encryption, structuring, recording, organisation, storage, etc.
- Restriction of processing – is the marking of stored personal data with the aim of limiting their processing in the future.
- Profiling – means any form of automated processing of personal data consisting of the use of personal data to evaluate certain personal aspects relating to a natural person.
- Data Controller – is the natural or legal person, public authority, agency or other body, which determines the purposes and means of the processing of personal data.
- Processor – means a natural or legal person, public authority, agency or other body which processes personal data on behalf of the controller.
- Recipient – means a natural or a legal person, be they public authority, a company, an agency or another body, to which the personal data are disclosed
- Third party – means a natural or legal person, public authority, agency or body other than the ones above, who, under the direct authority of the controller or processor, are authorised to process personal data.
- Consent – means any informed, specific, unambiguous and freely given indication of acceptance to the processing of personal data.
The processing of personal data will be in line with these main international legislations:
- General Data Protection Regulation (GDPR), applicable in Europe;
- California Consumer Privacy Act (2018) and Privacy Act U.S.C. 552a (Privacy Act of USA);
- What Personal Data we collect and why we collect it;
- How we use Personal Data;
- Who we share Personal Data with;
- The choices we offer, including how to access, update, and remove Personal Data;
YUTYBAZAR collects, stores, uses and discloses certain information when the visitors use our website. As a data controller and data processor, we have undertaken to implement a series of technical, structural and organisational measures in order to ensure the best protection of personal data processed through our website.
Our website incorporates a full set of privacy controls which determine the way we will process your personal data.
In your relationship with us through the website, controller, for the purposes of the General Data Protection Regulation (GDPR), other data protection laws applicable in Member states of the European Union and other provisions related to data protection, is:
YUTYBAZAR Limited, a legal entity existing under the laws of the United Kingdom, with its head office located at:
71-75 Shelton Street,
Company Registration number 12636941
This Policy does not apply to other companies’ or organisations’ websites to which we may link to or may link to us. You should carefully review the privacy policies of those sites in order to determine how they treat your personal information.
Your privacy is really important to us, so whether you’re new to YUTYBAZAR or a long-time user, please take the time to get to know our practices.
Disclaimer: YUTYBAZAR does not need and does not specifically request, condition, control, store or otherwise process any type of medical data from its data subjects. Any provision of medical data disregarding this statement falls under sole and complete legal responsibility of the data subject that provided the data to us through any means of communication: email, enquiry form, telephone,etc. Under the circumstances, HIPAA or any other EU medical regulations are not applicable to YUTYBAZAR. Even so, we have taken all the necessary compliance precautions in order to ensure highest level security with regards to personal data.
- Website Visitor
You are a “Website Visitor” every time you visit our website www.yutybazar.com. We use your information for our own statistical purposes, primarily with the purpose of improving the visitor experience and thus to be able to provide you with more relevant content.
You become a “User” when you create an account on our website. The purpose of the account registration is to use one of our products. In case you are a User, our primary purpose is providing the products and its complementary services to you.
Types of Personal Data we collect
- a)Personal Information
Upon registering for an Account or the quiz, you will be requested to voluntarily provide certain pieces of personal information. Personal information includes (but is not limited to):
- Identity and Contact Data, such as: first and last name (including maiden name or married name as you provide it), physical address, gender, contact number, email, username or similar identifier, marital status or any other contact information we may deem necessary. You are requested to not supply any other person's personal data to us.
- Transaction Data, such as: details about payments to and from you and other details of products you have purchased by using the links contained on our website.
- Technical Data, such as: internet protocol (IP) address, your login data, browser type as detailed hereinafter.
- Usage Data, such as: information about how you use our website and services.
- Marketing and Communications Data, such as: your preferences in receiving marketing from us and/or our third-party partners and your communication preferences as detailed hereinafter.
- Sensitive data, such as: skin tone, hair type, environment etc, in order to provide personalised beauty recommendations using our machine learning algorithms.
How we collect your personal data: through account registration and through direct or indirect interactions, such as: when you complete the quiz, interact with the site, wishlist and through other marketing procedures, etc.
Reviews, questions or comments submitted by Visitors may also be regarded as Personal information.
- b)Non-Personal Information
As previously stated, we may collect and track statistical information about your visits on our website, about your behaviour on the website, including the domain name and the name of the web page from which you have accessed our website, the time spent on each of our web pages, the IP address, operating system and platform, information searched for or requested for, and other relevant statistics. If you send YUTYBAZAR a message, it can be stored and processed in order to compile statistical information, to improve our services and support, or to get in touch with you.
Upon usage of our products, we will ask for your personal information included in the Account. In addition, we will ask you to provide us with secure payment data, which will be used for processing the order. We do not collect and store the payment data, such data being collected and processed exclusively by the payment processor. Under the circumstances, we have no way of storing credit/debit card details, and we have no way of selling, sharing, renting or leasing such data to any third parties. However, we cannot guarantee the security of any information that is disclosed online.
Purpose of collection
To fulfil our commercial purpose.
Our commercial purpose is provision of recommendation of beauty products (skincare, haircare, cosmetics, etc.) and the new rules of personal data protection (GDPR, CCPA, etc.) are part of this context.
To improve our services.
As previously stated, statistical data helps us improve our services and your experience with us. So, because we want to offer you the best online experience, we collect and use certain information about your behaviour and preferences when using the website.
To improve your marketing activity
In case you opted for our Newsletter, we want to keep you informed about products you may be interested in. With this purpose in mind, we may send you any type of message (such as: email / SMS / phone / mobile push / web push / etc.) containing general and thematic information about products or services, information on offers or promotions, as well as other commercial communications.
To defend our legitimate interests
Our legitimate interest may include:
- § measures to protect the website and platform Visitors and Users against cyber-attacks;
- § measures to prevent and detect fraud attempts;
- § transmission of information to the competent public authorities;
- § other risk management measures.
We therefore commit ourselves:
- § to protect the privacy of your data, which is a top priority for our company
- § to use this data for the sole purpose of providing you with a personalised experience on our website as well as on the online platforms that we promote our products and services (social media and search engines, etc.).
We want to ensure full transparency with regards to the purposes for which we will use your personal data, so we have set out below a table format describing such potential procedures:
Type of data
Performance of Contract
To process and deliver our service including:
To manage our relationship with you which will include:
To enable you to partake in a prize draw, competition or complete our beauty quiz and surveys
To administer and protect our business and this website (including troubleshooting, data analysis, testing, system maintenance, support, reporting and hosting of data)
To deliver relevant website content and advertisements to you and measure or understand the effectiveness of the advertising we serve to you
Legitimate interests (to study how customers use our services, to develop them, to grow our business and to inform our marketing strategy)
To use data analytics to improve our website, products/services, marketing, customer relationships and experiences
Legitimate interests (to define types of customers for our services, to keep our website updated and relevant, to develop our business and to inform our marketing strategy)
To make suggestions and recommendations to you about products or services that may be of interest to you
Legitimate interests (to develop our services and grow our business)
“Automatically Collected" Information:
We are collecting a series of general data by automated means. This general data is stored in our server log files.
Collected may be:
- §the ISP;
- §the operating system used by the accessing system;
- §the website from which an accessing system reaches our website (so-called referrers);
- §the sub-website;
- §the date and time of access to the website;
- §an Internet Protocol address (IP address);
- §screen Resolution;
- §locale Preferences;
- §web page visited before you came to our website;
- §information you search for on our website;
- §date and time stamps associated with transactions;
- §system configuration information and other interactions with the website;
- §social networking information (if we are provided with access to your account on social network connection services);
- §any other similar data and information that may be used in the event of attacks on our information technology systems.
When using this data, we are not able to not draw any conclusions about you in person, or to identify you with certainty. We rather use this information to correctly deliver the content of our website, to optimise the content, to ensure the long-term viability of our information, and last but not least to protect ourselves against data breaches and to provide law enforcement authorities with the information necessary for criminal prosecution in case of cyber-attacks;
How do we use your personal data?
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Performance of Contract – we will process your data whenever you make a purchase from our website in order to fulfil your request for acquisition, and when making beauty recommendations.
- Whenever necessary to protect our legitimate interests (or those of a third party),as provided by law, and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal obligation that we are subjected to, as detailed hereinafter.
Data Retention and Data Deletion
We retain the personal data collected for clearly stated periods, as follows:
- §for as long as the Accounts are active;
- §for as long as the email address is active on our mailing list;
- §otherwise for a limited period of time, the retention term being based on the 2 year criteria after your last interaction with us, or after your relationship with us is ended by either of the parties.
All Personal Data that is collected through the use of the website is stored on secure AWS servers.
Use and Disclosure of personal data to others
We do not rent or sell your information to third parties outside of YUTYBAZAR without your consent. We may share your information, be it personal or non-personal, with third-party organisations that help us provide you with the services, but only as far as is reasonably necessary.
Compliance with Laws and Law Enforcement Requests: We may disclose to parties outside YUTYBAZAR, files stored in our database and personal data about you that we collect when we have a good faith belief that disclosure is reasonably necessary to (a) comply with a law, regulation or compulsory legal request; or (b) to protect YUTYBAZAR’s intellectual property rights. If we provide your files to a law enforcement agency as set forth above, we will remove YUTYBAZAR’s encryption from the files before providing them to law enforcement.
In the situation in which we are involved in a merger, an acquisition, or even a sale of all or a portion of our assets, your personal data may be transferred as part of that transaction. Under such circumstances, we will make sure we will notify you of any change in control or use of your personal data.
In addition, we may access and share your information with the authorities, if we deem in good faith that this is necessary to: detect and prevent frauds, scams and other illegal activities. This is to protect ourselves, you and other people.
We may provide you with targeted advertisements or marketing communications that may be of interest to you. For more information about how targeted advertising works, you can visit the Network Advertising Initiative’s (“NAI”) educational page at http://www.networkadvertising.org/understanding-online-advertising/how-does-it-work.
You can always opt out of targeted advertising by visiting the following links:
- FACEBOOK - https://www.facebook.com/settings/?tab=ads
- GOOGLE - https://www.google.com/settings/ads/anonymous
- BING - https://advertise.bingads.microsoft.com/en-us/resources/policies/personalized-ads
If you subscribed to our newsletter, you can also unsubscribe by clicking the correspondent button on our emails.
For information on how our advertising partners allow you to opt out of receiving ads based on your web browsing history, please visit: http://optout.aboutads.info/.
Links to Other Websites
Our website may contain links to and from the Platforms of advertisers and affiliates, from time to time. The fact that YUTYBAZAR links to a website is not an endorsement, authorisation or representation of YUTYBAZAR affiliation with that third party. YUTYBAZAR does not exercise control over third party websites. These websites may place their own cookies or other files on the User’s device. If you follow a link to any of these third-party websites, you do so at his own risk, and you are bound to submit to their own privacy policies. Under such circumstances, you waive any claim against YUTYBAZAR for any responsibility or liability for these policies.
Personal Data Breaches
We will notify the relevant Personal Data Breaches to competent authorities and/or affected Data Subjects as soon as possible after we become aware of any Personal Data Breach affecting any Personal Data.
Data Subject Requests
In case Data Subjects are seeking to exercise their rights under any data protection law with respect to Personal Data (including access, rectification, restriction, deletion or portability of Personal Data, as applicable), we have implemented all the technical measures to respond to such requests legally and in a timely manner. If such a request is made directly to a sub-processor, it will promptly inform the Controller and will advise Data Subjects to submit their request to the Controller. The controller shall be solely responsible for responding to any Data Subjects’ requests. The controller shall reimburse the sub-processor for any potential costs arising from this assistance.
Privacy of minors
Given the nature of our business, we do not collect information from Users under the age of 16 only with parental consent.
In case we find out that we have collected personal information from a person under 16 years of age without parental consent, we will make sure to delete the information immediately. If you believe we have any information about a child under the age of 16, without parental consent, please contact us at firstname.lastname@example.org
Cookies and Tracking Technologies
The majority of cookies contain a cookie ID, which basically represents a unique identifier of the cookie. Navigating without the use of certain cookies is impossible. The single purpose of the basic cookies is for YUTYBAZAR to provide you with visiting the website or using our services with a more user-friendly experience. This would not be possible without the use of a certain cookie setting, but those cookies do not render you as an identifiable person, when navigating on our website.
By using cookies, we are also able to provide you with optimised information and offers. Certain cookie categories allow us to recognise our website’s Visitors and Users. The purpose is to make it easier for Data Subjects to use our website, e.g. they do not have to enter access data each time the website is accessed. Such cookies are stored locally, on the Data Subject's computer system.
You can also, at any time, instruct your browser, by accessing its settings and changing its options, to stop accepting cookies or to prompt you before accepting a cookie from our websites. Warning: if you do not accept cookies, you may not be able to use our website correctly and at its full potential.
Strictly necessary cookies
These are the essential cookies. They enable you to move around the website and use its features. Without these cookies you do not have the possibility to use a whole series of services, such as account creation, etc.
These cookies help us make our website work as efficiently as possible. Usually such cookies remember your login details, your settings, your preferences and they also serve the purpose of administering your subscription.
These are statistical cookies, and they collect information about your behaviour on the website, for example, which pages you go to most often. As previously stated, these cookies do not gather the information that lead to your identification. All information these cookies collect is anonymous and their purpose is to improve how our website works.
Analytics and Functionality cookies
This type of cookie anonymously remembers your device type (computer, mobile, etc.) or the choices you make (username, language, or the region you are in) when you visit our website. These cookies can also be used to remember changes you have made to text size, font and other parts of pages. They keep track of browsing patterns and build up a profile based on which we may target advertisements to you, if you accept the receival of our promotional newsletter.
Obviously, these cookies are used to deliver advertisements that are more relevant to you and your interests, if you accepted our newsletter and promotions. They also have a functional side, regarding their capability to limit the number of times you see an advertisement as well as help measure the effectiveness of an advertising campaign.
Third party cookies
In the event you will come across such cookies when navigating on our website, these are advertising and analytics cookies placed by, or on behalf of, independent advertisers who are advertising on our site. Such cookies are anonymous, so they cannot identify individuals. They are used for statistical analysis by allowing the advertiser to count how many people have seen their advertisement or have seen it more than once.
Here you can find details about the cookies we are using:
It lets the website know that multiple pages within the website are being accessed by the same browser. This cookie is essential to the functionality of the website. It enables us to:
Cross-site Request Forgery Detection XSRF-TOKEN
Helps prevent "external" requests from being maliciously redirected to the YUTYBAZAR website, ensuring attackers cannot impersonate you on the YUTYBAZAR website while you are logged on.
Cookie Preferences yutybazar_opt
It lets the YUTYBAZAR website know your preferences regarding 3rd-party cookies. While some cookies are essential to website functionality, you have the option of disabling third-party cookies. This cookie is used to indicate these preferences. You can update your preferences by clicking here
Google Analytics _gat,_gid,_ga
Collects anonymous statistics regarding usage of the YUTYBAZAR website. These are third-party cookies. While YUTYBAZAR's use of Google Analytics causes these cookies to be used, YUTYBAZAR itself does not control the data within the cookies themselves. The names of the cookies listed are provided as examples. YUTYBAZAR does not directly control the names of the cookies involved, and the actual names may differ.
These cookies enable us to:
You can learn more about Google Analytics here
Disclaimer: YUTYBAZAR has no control over software provided by third-parties. This link is provided for informational purposes and does not constitute an endorsement of any software contained on the linked third-party website. Neither YUTYBAZAR nor its partners assume or accept any liability relating to use of third-party software.
Facebook Pixel _fpb,datr,dpr,fr,wd
Collects anonymous statistics regarding usage of the YUTYBAZAR website.
These are third-party cookies. While YUTYBAZAR's use of Facebook causes these cookies to be used, YUTYBAZAR itself does not control the data within the cookies themselves. The names of the cookies listed are provided as examples. YUTYBAZAR does not directly control the names of the cookies involved, and the actual names may differ.
These cookies enable us to:
You can learn more about Facebook's Tracking Pixel here
You can update your preferences regarding third-party cookies on the YUTYBAZAR website by clicking here.
We may use, when necessary, third-party data Processors in order to process your information on our behalf. Such Processors may be:
- Service Providers - we may collaborate with companies and individuals to facilitate our Services, to perform service-related services. These third parties may be permitted access to your personal data only to perform these tasks on our behalf. We have taken all the legal steps in order to ensure they will not disclose or use your personal data for any other purpose.
- Communications - We may use your personal data to contact you with newsletters, marketing or promotional materials.
- Payment Provider - We will use third-party payment providers which will process all payments you may make to us by collecting any relevant data directly from you. We do not store such data.
Generally, it is in your legal obligation to keep your personal data accurate and up to date.
We have taken all the reasonable steps to keep your personal data secure and encrypted at all times, in accordance with the legal obligations. We have also taken the measures to protect your personal data from unauthorised access, misuse, modification, loss or disclosure. While we will endeavour to take all reasonable and appropriate steps to keep secure any information which we hold about you and prevent unauthorised access, you acknowledge that the internet is not 100% secure and that we cannot provide any absolute assurance regarding the security of your personal information. We will not be liable in any way in relation to any breach of security or unintended loss or disclosure of information due to the website being linked to the internet.
Opting out from Communications
If you receive emails from us, you may unsubscribe at any time by following the instructions contained within the email or by sending an email. Please note that you may still receive important administrative messages from us regarding our services. Please email email@example.com
You hereby authorise us to exchange and share all personal and non-personal data, across borders and from your country and jurisdiction to any other countries and jurisdictions across the world, with any agent/third party service provider, as may be required to provide Services to you or as may be required by law, and shall not hold us liable for use or disclosure of this information.
This is a list of your legal rights pertaining to your personal data.
Your principal rights under data protection law are:
- the right to access;
- the right to rectification;
- the right to erasure;
- the right to restrict processing;
- the right to object to processing;
- the right to data portability;
- the right to complain to a supervisory authority; and
- the right to withdraw consent.
a) You have the right to confirmation as to whether or not we process your personal data. In case we do, you have access to your personal data, and also certain additional information. Additional information includes: details of the purposes of the processing, categories of personal data collected and eventual recipients of your personal data. We are able to supply you, upon request, with a copy of your personal data.
b) You have the right update or rectify your personal data, and also to have any incomplete personal data about you completed.
c) Under certain circumstances, you have the right to request the erasure of your personal data. Such circumstances include: the personal data is no longer necessary to be stored by us, you withdraw your consent to processing, etc. However, there are exceptions to the right to erasure, such as: for compliance with the law, or for the exercise or defence of legal claims.
d) In some circumstances, you have the right to restrict the processing of your personal data. For example: you contest the accuracy of the personal data, you consider that the processing is unlawful, etc. In case processing has been restricted on this basis, we may continue to store your personal data, anyway, but we may not process it without your express consent, or for the exercise or defence of legal claims, or for reasons of important public interest.
e) You have the right to object to our processing of your personal data to the extent that the legal basis for the processing is that the processing is necessary for the performance of a task carried out in the public interest, or the purposes of a legitimate interest. If the objection is grounded, we will cease to process the personal information unless we can demonstrate compelling legitimate grounds for the processing which override your interests, rights, and freedoms.
f) You have the right to transfer your personal data from us (as controller) to another organisation, in the context of digital personal data and automated processing. This right is complementary to the right of access, stated at letter a).
g) If you consider that processing of your personal data infringes on any of your rights or the data protection laws, you have a legal right to lodge a complaint with a supervisory authority. You may do so in the EU member state of your habitual residence, your place of work or the place of the alleged infringement.
h) Provided that the legal basis for our processing of your personal data is consent, you have the right, at any time, to withdraw your consent. It should be noted, though, that withdrawal of consent will not affect the lawfulness of data processing before the withdrawal.
US Privacy Rights
For US residents we have decided to relate to the most advanced piece of legislation, which is California Consumer Privacy Act of 2018 (“CCPA”), effective January 1, 2020. Under the circumstance, in addition to the rights already provided for above, in case you are a US resident or citizen, you have the right to request information regarding whether we share certain categories of your personal data with third parties, for the third parties' direct marketing purposes. If it is the case, you may receive the following information:
- the categories of information we disclosed to third parties for the third parties' direct marketing purposes during the preceding calendar year; and
- the names and addresses of third parties that received such information, or if the nature of their business cannot be determined from the name, then examples of the products or services marketed.
US residents have certain rights in relation to their personal information, subject to limited exceptions, as follows:
- §YUTYBAZAR will not discriminate against those who exercise their rights. Specifically, upon any exercise of your rights, we hereby state that we will not deny you services, we will not charge you different prices for our services and we will not provide you a different level or quality of services.
- §To the extent we sell your personal data to third party collaborators, you have the right to request information about: (i) the categories of your personal data that we sold, and (ii) the categories of third parties to whom your personal data was sold. You have the right to restrict us from selling your personal data. Even so, YUTYBAZAR does not sell your personal data in its ordinary course of business, and undertakes to never sell your personal data without your explicit and prior consent.
- §You may designate an authorised agent to make requests to access or delete on your behalf. We will only respond to your authorised agent's request if they submit proof that they are registered to be able to act on your behalf, or submit evidence you have provided them with power of attorney. We will deny any requests from authorised agents who do not submit such proof, or who are unable to verify their identity.
You can exercise your rights by contacting us via email.
We are committed to providing you with a fair and responsive system for handling and resolving complaints remitted directly to us. Your complaint will be handled efficiently. Any time you wish to lodge a complaint in respect of the handling, use or disclosure of your personal information by us, you may do so by contacting us at: firstname.lastname@example.org