Privacy Policy
At The Seoul Palette, we respect your privacy and are committed to protecting your personal information. This Privacy Policy outlines how The Seoul Palette (“we”, “us”, or “our”) collects, processes, stores, and discloses your personal information in accordance with the Protection of Personal Information Act (POPIA), No. 4 of 2013 of South Africa.
This policy applies to all personal information processed via our online store, our AI Skin Analysis tool, our newsletter registration, or when you interact with us via email, social media, or in-person at our boutique.
1. CONTACT DETAILS OF THE RESPONSIBLE PARTY (INFORMATION OFFICER)
In terms of POPIA, The Seoul Palette is the designated "Responsible Party." If you have any questions about this policy or wish to exercise your data rights, please contact our Information Officer:
- Entity Name: The Seoul Palette
- Physical Address: 91 Soofie Saheb Drive, Athlone, Durban North, 4051
- Contact Email: info@kbeauty-sa.com
2. THE PERSONAL INFORMATION WE COLLECT
Depending on how you interact with our Services, we collect and process the following categories of personal information:
- Contact & Delivery Information: Full name, email address, physical delivery address, billing address, and contact telephone number (required for fulfilment under ECTA).
- Financial Information: Credit card, debit card, or third-party payment confirmation details (securely captured via integrated payment gateways; we do not store raw card credentials).
- Account Credentials: Username, password, order history, and Wishlist items.
- Skincare & Profile Data: Information you voluntarily provide when utilizing our Product Finder, taking quizzes, booking or completing the AI Skin Analysis. This includes data regarding your skin type (e.g., oily, dry, sensitive) and specific skin concerns (e.g., acne, hyperpigmentation, damaged skin barrier, redness).
- Automated Device Data: IP address, browser type, device information, and interaction history on our site collected via cookies (powered by Shopify).
A Note on Skin Data: While information regarding skin appearance for cosmetic curation does not strictly constitute clinical medical records, we handle your voluntary skin profile data with the highest degree of security and confidentiality.
3. PURPOSE OF PROCESSING YOUR DATA
In line with POPIA’s condition of Purpose Specification, we only collect and process your personal information for specific, explicitly defined, and lawful purposes:
- To Fulfil Our Contract: Processing payments, generating shipping waybills, and delivering your authentic Korean skincare orders.
- To Provide Personalised Curation: Running the AI Skin Analysis tool to deliver custom ingredient recommendations (such as PDRN, Exosomes, or Niacinamide) matched to your unique profile.
- Direct Marketing: Sending you our email newsletters, exclusive offers (like your 10% sign-up discount), and skincare advice. You can opt out of direct marketing at any time by clicking the "Unsubscribe" link at the bottom of our emails.
- Security & Fraud Prevention: Authenticating accounts and safeguarding our digital storefront against malicious activities.
4. HOW WE DISCLOSE PERSONAL INFORMATION
We will never sell your personal information. We only share your data with trusted third parties (Operators under POPIA) strictly required to perform services on our behalf under strict confidentiality agreements:
- Shopify: Our e-commerce platform provider, which hosts our database and securely processes store infrastructure.
- Payment Gateways: To securely authorize and clear your transactions.
- Domestic Courier Services: Providing your name, physical address, and phone number to courier partners to execute fast door-to-door delivery across South Africa.
- Legal Obligation: Where required by South African law enforcement, tax authorities, or court orders.
5. CROSS-BORDER DATA TRANSFERS
Because The Seoul Palette is powered by Shopify, your personal information is transmitted, processed, and stored securely across international borders (including servers located in Canada and the United States).
- In compliance with Section 72 of POPIA, we ensure that our international infrastructure providers (like Shopify) adhere to data protection binding corporate rules or data privacy frameworks that offer an adequate level of protection substantially similar to POPIA.
6. DATA SECURITY AND RETENTION
- Security Measures: We and our hosting provider (Shopify) implement rigorous technical and organizational security measures, including SSL encryption, secure firewalls, and strict access controls to shield your personal data against unauthorized access, loss, or alteration.
- Retention Boundaries: We will only retain your personal information for as long as it is reasonably necessary to fulfil the purposes outlined in this policy, unless a longer retention period is mandated by South African financial, tax, or commercial laws.
7. YOUR LEGAL RIGHTS UNDER POPIA
As a South African data subject, you hold the following absolute rights regarding your personal information:
- Right of Access: You have the right to request confirmation of whether we hold personal information about you, and to receive a record of that information free of charge.
- Right to Rectification: You can request that we update, correct, or complete inaccurate or out-of-date personal information at any time.
- Right to Erasure ("Right to be Forgotten"): You have the right to request that we delete or destroy your personal information, subject to instances where legal retention requirements override this right.
- Right to Object: You have the right to object to the processing of your personal information for direct marketing purposes at any time.
To exercise any of these rights, simply email our team at info@kbeauty-sa.com with your formal request.
8. THE INFORMATION REGULATOR (COMPLAINTS)
If you believe that The Seoul Palette has processed your personal information in a manner that infringes on your rights under POPIA, you have the right to lodge a formal complaint with the South African Information Regulator:
- Website: https://inforegulator.org.za/
- Email Address: complaints.IR@inforegulator.org.za
9. CHANGES TO THIS PRIVACY POLICY
We reserve the right to modify this Privacy Policy at any time to stay perfectly aligned with local regulatory changes or adjustments to our store features. Any updates will be published instantly on this page with an updated "Last Updated" date.