APPLICANTS PRIVACY NOTICE

1 July 2020

Beauty in Motion SDN BHD, a Groupe LVMH subsidiary, located at Suite 02 & 03, Level 22 Centerpoint North Mid Valley City Lingkaran Syed Putra Kuala Lumpur 59200  (hereinafter ‘Sephora’, ‘we’ or ‘our’), attaches great importance to the protection of personal data relating to its applicants (hereinafter ‘you’).

Sephora respects your concerns relating to the protection of your privacy and your personal data. This Applicants Privacy Notice (hereinafter referred to as the ‘Privacy Notice’) describes how we use information about you collected when you apply to join Sephora.

This Privacy Notice contains information regarding the nature and the use we make of your personal data, as well as your rights relating to this use.

This Privacy Notice is therefore an important resource for you, helping to ensure that you have a positive and confident experience of Sephora’s handling of your personal data and enabling us to provide accurate and complete answers to any questions you may have and to take account of your wishes in this area.

In order to ensure protection of your personal data, Sephora has decided to designate a Data Protection Officer (hereinafter ‘DPO’), who may be contacted at +60193869313 or at the following email address: hr-my@sephora.my.

By submitting an application for employment to Sephora, you hereby consent to your personal data being collected, stored, used, processed and disclosed, including the potential transfer of your personal data outside of Malaysia, as set out in this Privacy Notice.

Modification of the Privacy Notice

We may occasionally wish to modify the terms of this Privacy Notice. In such an event, we shall notify you of this by changing the date indicated at the beginning of this document, which is permanently available for consultation through your applicant space (We are Sephora or any other communication resource relating to Sephora recruitment). We would encourage you to consult this Privacy Notice on a regular basis, in order to keep abreast of the procedures implemented by Sephora for processing your personal data, as well as the methods by which you can send us inquiries regarding our use of the data. Your continued use of your applicant space or continued relationship with us shall be deemed to be your acceptance of and consent to any changes made to this Privacy Notice.

Why do we collect your personal data?

Sephora collects and processes your personal data for the following purposes:

Management of your application for employment where the processing of your personal data is necessary in order to take steps at your request prior to entering into a contract;

Management of the job offers for which you may be suited where the processing of your personal data is based on the sharing options you have notified us about; and

Recruitment reporting where the processing of your personal data is necessary to facilitate recruitment follow up; and

Compilation of statistics regarding Sephora employment opportunities where the processing of your personal data is necessary to continuously improve our recruitment practices.

Sephora may also process your personal information to the extent necessary for the protection of our legitimate interests, to defend ourselves in case of a dispute and to comply with our legal obligations.

What type of personal data do we process?

We will only process your personal data that is strictly necessary for the purposes described in Article 2.

We collect your personal data when you send your curriculum vitae, whether online or in paper form, or when you apply for employment by indirect means, for example via an agency or recruitment firm, and more generally throughout the Sephora recruitment process.

For your information, we may process the following list of the categories of your personal data, depending on the purposes to be achieved by this processing:

Data relating to your civil status and identity, such as first name, last name, preferred name, nationality, gender, marital status, religion and ethnicity;

Data relating to your educational and professional background such as information in your curriculum vitae, training, professional experience, references, distinctions and certifications;

Contact details such as home address, telephone number and email address;

Data relating to your application such as referral source, candidature/application status and approval, your career expectations, compensation details, etc;

Results of any assessments and/or occupational testing;

Information about your entitlement to work in the EU or in the country where you applied such as work permit related details;

Publicly available information of your profile on social media channels (such as Linkedin); and

Data enabling connection to recruitment platform such as user ID and connection data.

The information we collect that are required in order to process your application are marked with an asterisk on the forms presented for you to complete on our online recruitment platform. If you do not complete the fields marked as mandatory, we shall be unable to process your application. In the case of other forms of application, if Sephora has been unable to identify the information required in order to process your application, Sephora reserves the right to re-contact you in order to collect the missing information.

Who can access your personal data?

We do not sell, rent or trade your personal data; however, we may disclose your personal data to the following persons for the purposes described in Article 2:

Authorised personnel within the following departments of Sephora and/or its affiliates (including the LVMH group of companies) to the extent needed in order to carry out their respective duties such as:

HR department, including those responsible for international careers and talent management;

Recruitment department;

Departments issuing job offers; and

IT department, for the purposes of security and maintenance;

Service providers working for Sephora and/or its affiliates; or

Regulatory authorities and/or courts where required by any applicable laws or pursuant to a court order of a competent jurisdiction.

In particular, we rely on third party processors to provide you our recruitment platform and job application. These third-party processors are only allowed to process your personal data on our behalf and upon our explicit written instructions.

In addition, for purposes connected to maintenance of the IT systems, your personal data may be accessible to Sephora IT services employees or to the employees of external providers of certain IT services. These employees shall only be able to access your data in order to carry out security and maintenance activities on the IT systems. They shall carry out their duties in accordance with Sephora’s instructions and in total compliance with the legislation on personal data.

Where are your personal data stored and processed?

We process your personal data first and foremost within Malaysia.

As Sephora is part of an international group, in order to process your personal data for the purposes outlined in Article 2 above, your personal data (as described in Article 3) may also be transferred outside of Malaysia to:

organizations within Sephora group of companies around the world;

organizations within the LVMH group of companies around the world; and

external service providers helping Sephora entities in dealing with recruitment which may be located worldwide.

How long do we store your personal data?

Sephora keeps your data for a maximum period of 2 years after the last contact between Sephora and yourself. In this way we will be able to re-evaluate your application if a similar post becomes vacant and Sephora believes it may interest you.

At the end of this period, your personal data will be deleted.

Your rights

You have the right to request access to your personal data.

You have the right to request that any personal data pertaining to you that are inaccurate, be corrected free of charge. If you submit a request for correction, such request has to be accompanied by proof of the flawed nature of the data for which correction is asked.

You have the right to withdraw your earlier given consent for the processing of your personal data; however, this may result in us not being able to continue processing your application for employment.

You have the right to request that personal data pertaining to you be deleted if these data are no longer required in the light of the purposes outlined in Article 2 above or if you withdraw your consent for processing the data. However, we will evaluate a request for deletion against:

Overriding interests of Sephora or any other third party permitted by applicable laws; and

Any legal or regulatory obligations or administrative or judicial orders which may contradict such deletion.

Instead of deletion, you can also ask that we limit the processing of your personal data, or the personal data relating to other individuals who may be identified from that personal data such as your next of kin or emergency contact.

You may exercise your right to object to the processing of personal data that relates to you on grounds of your specific situation, unless we demonstrate compelling legitimate grounds for the processing which override your interests, rights and freedoms or for the establishment, exercise or defence of legal claims.

You are also entitled to request a copy of the personal data you have directly provided to us through automated means in a format that is structured, commonly used and machine-readable.

Furthermore, you have the right to issue advance instructions regarding use or disposal of your personal data after your death.

We would invite you to exercise these rights by writing to the following address: Suite 02 & 03, Level 22 Centerpoint North Mid Valley City Lingkaran Syed Putra Kuala Lumpur 59200 or by contacting the DPO at +6 0193869313  or at this email address: hr-my@sephora.my.

Finally, you have the right to lodge a complaint with the Malaysian Department of Personal Data Protection at Aras 6, Kompleks Kementerian Komunikasi dan Multimedia, Lot 4G9, Persiaran Perdana, Presint 4 Pusat Pentadbiran Kerajaan Perseketuan, 62100 Putrajaya, Malaysia. We would however suggest that you first send us any claims via the DPO, so that we can deal with your questions and work together to find solutions that will resolve any issues you may have.

Notification of changes

We will keep you informed of any modifications to this Privacy Notice.

This Privacy Notice was last updated and revised on the 1 July 2020.