Privacy policy
MIM SKIN S.A.S. is responsible for the processing of personal data as established by Law 1581 of 2012 and complementary regulations.
Data subjects accept the processing of their personal data according to the terms of this Privacy Policy and authorize us to process it as per this policy when providing data to MIM SKIN S.A.S through various means, either virtual or physical.
MIM SKIN S.A.S is a commercial entity, which implies seeking profit in its various transactions.
Our contact details are:
- Business Name: MIM SKIN S.A.S
- Address: Cra 41 # 32 – 30 Itagüí, Antioquia
- Phone: +57 43220406
CONTACT CENTER:
- Email: servicioalcliente@mimskincare.com
Types of personal data stored in our databases:
The personal data we collect in our database, which is used and processed to fulfill our purpose, includes:
- Name
- Last Name
- Username
- Email Address
- Password
- Date of Birth
- Gender
Additionally, we collect the following information from our employees and suppliers:
- Personal information related to their date and place of birth, nationality, marital status, gender, educational levels, work experience, personal references, socioeconomic status, and financial situation.
- Personal information related to their health status, social security entities to which they are affiliated, disciplinary and judicial records.
- Personal information related to their family and dependents, as well as their personal preferences in terms of activities and hobbies.
The provided information will be stored for the necessary maximum term to allow us to fulfill legal and/or contractual obligations on our behalf, especially in accounting, contractual, tax, and fiscal matters, or to comply with the applicable provisions concerning administrative, accounting, tax, legal, and historical aspects of the information.
We presume the accuracy of the provided information and do not verify, nor assume the obligation to verify the truthfulness, validity, sufficiency, and authenticity of the data provided to us.
Purposes of Data Processing
By providing your Personal Data, the Data Subject authorizes us to use this information for the purposes indicated in the respective request in accordance with the provisions of this Privacy Policy.
If you provide us with personal data, you authorize us to use this information for the purposes indicated in accordance with the provisions of this Privacy Policy, and we will not proceed to transfer or disclose it outside of our databases unless (i) you authorize us to do so, (ii) it is necessary to allow our contractors, suppliers, or agents to provide the services that we have entrusted to them, (iii) we or third parties use it to provide our products or services, (iv) it is delivered to entities that provide marketing services on our behalf or to other entities with which we have joint marketing agreements, (v) it is related to a merger, consolidation, acquisition, divestment, or other restructuring process, (vi) we implement a personal data transmission contract in the terms of Decree 1377 of 2013, or (vii) as required or permitted by law or for the purposes set out in this privacy policy.
By accepting this privacy policy, you authorize us to process the information collected for the purpose of fulfilling the objectives of MIM SKIN S.A.S. These purposes are:
- Sending communications, through different means, related to events organized by MIM SKIN S.A.S or by third parties.
- Sending communications, through different means, related to training and other educational activities organized by MIM SKIN S.A.S or by third parties.
- Providing information to third parties that require establishing commercial contacts with customers and their representatives, regarding e-commerce and Internet matters.
- Sending information to customers and/or third parties regarding advertising and commercial offers to promote products and/or services offered or not by MIM SKIN S.A.S.
- Sending promotional and/or advertising information and messages to customers and/or third parties regarding events, activities, promotions, or offers in which MIM SKIN S.A.S is involved in any capacity or to carry out marketing activities.
- Consulting and updating personal data, at any time, in order to keep such information up to date in our databases.
- Managing relationships with suppliers and employees, which may include updating data or carrying out regulatory controls.
- Managing compliance with the terms established in the employment relationship such as: affiliation and contributions to social security entities, creation of employment contracts, generation of payments and labor benefits, as well as training, development, well-being, occupational health, and safety programs.
- Conducting market studies to define the profile of our users, carry out advertising, and commercial prospecting.
- Managing social media and/or editorial content.
- Developing guides/catalogs of e-commerce services.
- Managing loyalty, as well as sanctions, reprimands, warnings, and exclusions of customers.
- Facilitating the registration of incoming and outgoing documents.
- Carrying out activities for historical, scientific, or statistical purposes.
- Carrying out transactions for profit with customer databases.
- Stating on social media or any means in case of commercial break-up or clarification of information explaining the reasons for it.
By accepting this Privacy Policy, the data subjects authorize us to send them, through different means and channels (including, but not limited to, email, SMS or text messages, etc.), information about products and services, and offers of products and/or services that are of interest to our customers, employees, and suppliers.
Security
We have established policies, procedures, and information security standards aimed at protecting and preserving the integrity, confidentiality, and availability of information, regardless of its medium or format, its temporary or permanent location, or the means by which it is transmitted.
Third parties contracted by us are equally obliged to adhere to and comply with our information security policies and manuals, as well as the security protocols we apply to all of our processes.
Any contract with third parties (contractors, employees, external consultants, temporary collaborators, etc.) involving the handling of information and personal data will include a confidentiality agreement detailing their commitments to protecting, caring for, securing, and preserving the confidentiality, integrity, and privacy of the information.
Our payment gateway is a service provided through a third party (MercadoPago, Wompi, and PayPal), which is responsible for collecting payments as required by each client and the chosen payment method. The security system is implemented through the secure servers of MercadoPago, PayU, Wompi, and PayPal.
Rights and Procedures
You declare freely, expressly, and previously to have been informed about the rights granted to you by law as the owner of your personal data. These rights are outlined below:
(i) Know, update, and rectify your personal data in front of the entity responsible for the processing or in charge of the treatment of your personal data.
(ii) Request proof of the authorization granted to the data controller, except when expressly exempted as a requirement for processing.
(iii) Be informed by the data controller or the data processor, upon request, regarding the use that has been made of the personal data.
(iv) File complaints with the Superintendence of Industry and Commerce for breaches of the personal data protection regime.
(v) Revoke the authorization and/or request the deletion of personal data in the terms of Law 1581 of 2012.
(vi) Access your personal data that has been processed free of charge once a month, in accordance with current regulations.
The procedures for exercising your rights will be as follows:
Procedure for Inquiries
The owners, authorized persons, or successors in interest may inquire about their personal information held in our databases, in which case we will provide the requested information, after verifying the legitimacy to make such request. The inquiry will be addressed within a maximum period of ten (10) business days from the date of receipt. If it is not possible to address the inquiry within this period, the reasons for the delay will be provided, indicating the date by which the inquiry will be addressed, which in no case may exceed five (5) business days following the expiration of the initial term.
If the owners or the authorized persons believe that the information contained in a database should be corrected, updated, or deleted, or if they become aware of the alleged non-compliance with any of the duties contained in the law, they may file a claim with us, which will be processed under the following rules:
Your claim must be submitted by a request addressed to MIM SKIN S.A.S with your identification details, a description of the facts giving rise to the claim, your address, and the accompanying documents that you wish to submit as evidence of the facts. If the claim is incomplete, you will be required, within five (5) days from the receipt of the claim, to remedy the deficiencies. If two (2) months have passed from the date of the request without you providing the requested information, it will be deemed that you have withdrawn the claim, in accordance with Article 17 of Law 1755 of 2015, which is statutory of the Right to Petition.
If we are not competent to resolve your claim, MIM SKIN S.A.S will transfer it to the relevant authority within a maximum period of two (2) business days, a fact that will be timely informed to the Owner.
- If applicable, once the complete claim is received, a statement saying "claim in process" and the reason for it will be included in the database within a period not exceeding two (2) business days. This statement must be maintained until the claim is decided.
- The maximum term to address the claim will be fifteen (15) business days from the day following the receipt date. If it is not possible to address the claim within this period, the reasons for the delay and the date by which the claim will be addressed will be provided, which in no case may exceed eight (8) business days following the expiration of the initial term.
The owners of personal data can exercise their rights to know, update, rectify, and delete their personal data by sending their request to the email address servicioalcliente@mimskincare.com or by calling +57 43220406 in accordance with the provisions of this Privacy Policy.
Modifications and Validity
We may modify the terms and conditions of this Privacy Policy at any time. Any modification will be communicated on the website by publishing an updated version of the privacy policy. The databases will remain valid indefinitely, in accordance with the purposes and uses of the information.
This policy comes into effect from the date of publication.