PRIVACY POLICY

The PLMB company (As defined in Article 1 below), operating under the Mahogany trademark, offers high-end ready-to-wear items and accessories for sale on its website www.mahogany-cashmere.co.uk, on its ISO & Android devices.

In order to offer for sale, sell and deliver its products, PLMB collects personal data from users of its website and mobile application from its customers when purchasing.

The purpose of this privacy policy is to inform users of the means used to collect, access, process and store users’ personal data.

PLMB, as controller, undertakes to comply with the provisions of Regulation (EU) No 2016/679 of 27 April 2016 on the protection of personal data.

The customer is informed that certain data must be collected by PLMB in order to perform its services. If the customer does not wish to disclose this data, PLMB will not be able to perform its services.

This Privacy Policy (“Policy”) may be modified at any time by PLMB, in particular in order to comply with any regulatory, jurisprudential, editorial or technical changes. The user must refer to the latest version of the Policy before browsing.

1. Controller

The controller, who collects the personal data and implements the data processing operations, is: PLMB, sàrl with a capital of €500,000, registered with the Trade and Companies Register in Angers under number 433 219 011, whose registered office is located at 32 rue des Prévoyants de l'avenir, 490000 Angers France

2. Collection of personal data

PLMB collects users’ personal data on the website https://www.mahogany-cashmere.co.uk, on the IOS & Android mobile devices

The personal data that may be collected are as follows:
– User account data: the data provided by the User when creating an account by filling in the registration form (name, surname, billing and delivery postal addresses, email address, mobile phone number, password for connecting to the customer account);
- personal data of the user when he/she enters it in his/her customer account: date of birth, clothing size;
- transaction data: means the data that the user provides when making purchases, information relating to orders placed and returned items such as telephone number, address, e-mail address and information relating to payment method;
- exchanges with customer service;
- browsing data: refers to the data collected by the Publisher while the User is browsing the Website and the Applications, such as the date, time of connection and/or browsing, browser type, browser language, IP address, location data and geographical location. 

The data relating to the payment method (credit card number, expiry date, authorization number, security code) are collected directly by our service providers Payzen, Paybox and PayPal.

Third-party providers of applications, tools, gadgets and plug-ins on our website and mobile application, as well as the networks on which we publish editorial and promotional content (such as Facebook and Instagram) may also use automated, context-based and interest related means to collect user data (interactions with functions and profiling of the online activity). This data is collected directly by such providers and/or third parties and is subject to their policies. To the extent permitted by applicable law, PLMB is not responsible for the practices of such service providers and third parties.

Some of the services may be altered or inaccessible if consent to the collection of the data mentioned in this Privacy Policy is not granted.

3. Purposes of the collection of personal data

Data collected in connection with the use of the website, the application or in physical outlets are processed for the purposes described in the table below.

The regulations in force protect the privacy of users and require any controller to be able to provide legitimate grounds for such processing. The regulations thus provide, among the legal bases for treatment, the following:
- Performance of an agreement to which the relevant person is a party, such as a sales contract. For example, certain personal data of the customer is necessary to deliver the item, manage the customer’s account and process any returned items;
- compliance with a legal obligation, in particular an accounting obligation by retaining invoices;
- prior consent of the relevant person;
- legitimate interest of the controller, while complying with users’ rights and freedoms. For example, improving the customer experience or preventing fraud may justify data collection. 
Purpose of the processing Use of data Legal base for treatment
Manage­ment of orders and sales of products and provi­sion of services; manage­ment of customer complaints, with­draw­als and product returns Use of data to provide products and services (from shop­ping cart and orders; sale, return and refund of purchased products) Fulfil­ment of the agree­ment by and between the client and the seller
Carry­ing out trans­ac­tions, in partic­u­lar payment trans­ac­tions Our payment providers (Paybox, Payzen and PayPal) use the inform­a­tion relat­ing to the payment meth­ods when perform­ing the payment for each order. This data can also be used for the preven­tion of fraud upon payment of the order and/or manage­ment of any unpaid amounts after the order has been placed. Fulfil­ment of the agree­ment by and between the client and the seller
Customer account creation and manage­ment The personal data of a customer registered on the website is used (e-mail address, pass­word) – Fulfil­ment of the agree­ment by and between the client and the seller - Compli­ance to legal oblig­a­tions
Oper­at­ing the website and fight­ing against fraud Personal data (cook­ies) is used to update, enhance our Website and fight against Inter­net fraud – Fulfil­ment of the agree­ment by and between the client and the seller - Compli­ance to legal oblig­a­tions
After-sales support: exchanges with customer service Personal data is used to inter­act with custom­ers. As such, the exchanges between customer service and the customer carried out by tele­phone or chat can be recor­ded in order to improve the qual­ity of service. Custom­ers may refuse this at any time Fulfil­ment of the agree­ment by and between the client and the seller
Taking part in special events (such as contests, games, random draws, offers) and parti­cip­at­ing in the loyalty scheme, with the excep­tion of online gambling that is subject to approval by the French Online Gaming Control Author­ity Personal data, includ­ing purchas­ing inform­a­tion, is used to manage parti­cip­a­tion in vari­ous special events, as well as the loyalty program – Fulfil­ment of the agree­ment by and between the client and the seller - Legit­im­ate interest of the control­ler in order to propose products and services adap­ted to the needs of clients
Oper­at­ing, assess­ing and improv­ing products and services as well as user exper­i­ence (includ­ing devel­op­ing new products and services, analysing the customer base; perform­ing data analysis, account­ing and audit­ing), profil­ing. Personal data is used to assess and improve products and services, and to improve customer exper­i­ence, the products and services offered by PLMB, through stat­ist­ical oper­a­tions and analysis of anonym­ous customer behaviour, and the meas­ure­ment of website and mobile applic­a­tion traffic Legit­im­ate interest of the control­ler in order to propose products and services adap­ted to the needs of clients
Send­ing news­let­ters and special offers subject to the user check­ing the relev­ant box indic­at­ing his/her accept­ance, when regis­ter­ing for the Services Personal data is used to inform custom­ers about our products and services and to custom­ize the products offered on social networks. Legit­im­ate interest of the control­ler in order to propose products and services adap­ted to the needs of clients and consent (opt-in)
Analysing website traffic and frequency, audi­ence metrics, research, stat­ist­ics, surveys (cook­ies) Personal data, includ­ing cook­ies, is collec­ted to under­stand how the Website and the mobile applic­a­tion are used. Legit­im­ate interest of the control­ler in order to propose products and services adap­ted to the needs of clients and consent (opt-in)

Accessible to the user. PLMB does not share any personal data for commercial purposes with third parties. Users may edit their personal data and withdraw their consent at any time by connecting to their customer account.

4. Contractors that have access to user’s personal data

The personal data collected is transmitted to PLMB service providers, who may process it on behalf of PLMB (processors) and/or on their own behalf (recipients of the data).

The recipients of the data are:
- Payzen, Paybox and PayPal, payment providers
- any police or administrative authority in connection with judicial requisitions concerning the fight against fraud
- customs authorities and service providers in the event of delivery abroad. 
PLMB processors may have access to data collected for the purpose of:
- preparing, shipping orders and returning products
- improving the content of websites and mobile applications
- technical maintenance and development of PLMB website, mobile application and internal applications, including entities that perform orders and provide web hosting, information storage, email service providers, as well as analysis services, and tag management, such as Google Analytics. For further details on these analysis services and the opposition  

PLMB may also share the personal data of customers who have a customer account in its physical outlets. Their access is limited to orders placed by the customer.

5. Users’ rights over their personal data

In accordance with Articles 14 to 22 of Regulation 2016/679 of April 27, 2016, any natural person using the PLMB website or the mobile application has the right to exercise the following rights:

- A right of access, rectification and erasure of the data collected,
- a right to object to the processing of their data
- a right to the restriction of the processing,
- a right to the portability of the data collected the option to formulate instructions relating to the retention, erasure and transmission of his/her personal data after his/her death in accordance with Article 40–1 of Law 78–17 of January 6, 1978 

Finally, if PLMB detects a violation of personal data likely to create a significant risk to the rights and freedoms of its users, it undertakes to inform the relevant users in the shortest possible time.

Users may exercise all these rights by connecting to their customer account, by contacting customer service welcome@e-mahogany.com or by mail Mahogany – Service Client 32, rue des Prévoyants de l'avenir 49000 ANGERS, France.

Users must enclose proof of identity with their application. In case of non-response or unsatisfactory response, users may contact the supervisory authority of their country of residence, for the UK, at welcome@e-mahogany.com

6. Transfer of personal data outside of the European Union

The personal data of PLMB customers may be transferred to PLMB. This transfer takes place within the scope of the standard contractual clauses of the European Commission.

7. Data retention period

User data will not be retained beyond the period strictly necessary for the purposes set out herein and in accordance with applicable regulations and laws. In this respect, the data used for canvassing purposes may be retained for a maximum period of 3 years from the termination of the user’s account or the last contact with the relevant prospect. User data is deleted upon expiry of storage periods. Nevertheless, the data may be archived beyond the specified periods for the purposes of investigating, establishing and prosecuting criminal offences for the sole purpose of making the data available to the judicial authority, where necessary.

Archiving implies that this data will be anonymized and will no longer be available online but will be extracted and stored on an autonomous and secure medium.

8. Security measures for the personal data collected

In its capacity as data controller, PLMB undertakes to take all necessary measures to preserve the security and confidentiality of the data and, in particular, to prevent it from being altered, distorted or accessed by unauthorised third parties.

PLMB has entered into service agreements with business partners who have extensive expertise in the field of data protection. All data is hosted in France or in the European Union.

Payment service providers

PAYBOX is a simplified joint-stock company called Verifone Systems France SAS, based at 12 rue Paul Dautier, 78140 Velizy-Villacoublay, Frabnce, registered with the Versailles Trade and Companies Register under number 380248609 For any information, the Customer can consult the following website: https://www.paybox.com PAYZEN is the brand of the company LYRA, a simplified joint-stock company with a single partner based at 109 rue de l'innovation, 31670 Labège, France, registered with the Toulouse Trade and Companies Register under number 434075719 For any information, the Customer can consult the following website: https://www.lyra.com PLMB never has access to customer payment data. The User can choose to save his payment card data in his customer account. This data is not stored with PLMB, but with Paybox, Payzen and/or Paypal. The User may at any time modify or delete these bank details by logging into their customer account. 9. Cookies, tags and tracers When browsing our website and mobile applications, information relating to the browsing of the user's terminal (computer, tablet, smartphone, etc.) may be recorded through files called "Cookies".

The cookie makes it possible to monitor browsing or analyse the behaviour of the User, and in particular:

PLMB does not have access to customer payment data.

However, users may opt to save their payment card data in their customer account. This data is not stored with PLMB, but with Payzen, Paybox and/or PayPal. Users may edit or delete these bank details at any time by connecting to their customer account.

9. Cookies, TAGS and trackers

When browsing our website and the mobile application, information relating to the navigation of the user’s terminal (computer, tablet, smartphone, etc.) may be saved through files referred to as “Cookies”.

A cookie allows tracking the browsing or analysing user behaviour, including:
- measuring the number of visitors to our website and application, as well as their content;
- saving customer account information when the user is logged in;

- saving the shopping cart for 30 minutes; customizing the display of content

10. Social Networks

PLMB official Facebook and Instagram accounts can allow users to post their content. Users are informed that the content published on these social networks may be viewed by any third party, and that greater vigilance is required from users when they provide certain personal data on these sites or applications such as financial data, addresses or any sensitive data. PLMB is in no case liable for any damage caused by third parties as a result of or resulting from the publication of their personal data by users.

11. Links to third-party sites

The website and the application may provide links to websites, applications and services other than those of PLMB, which may be operated by third parties. PLMB is not responsible for the processing of personal data by these third-party websites. Users should consult the relevant personal data protection policies.

HAND MADE IN NEPAL
SIZES FROM XS TO XXXXL
USE OUR 24 HOUR EXPRESS DELIVERY SERVICE
UP TO 45 DAYS FOR REFUNDS / EXCHANGES
At your service