Privacy Notice


Last updated: 10/04/2024

At EssilorLuxottica, we are committed to protect our clients’ Personal Data.

Upholding this commitment is essential to our success and reputation, and ultimately our ability to fulfil our mission of helping people see more, be more and live life to its fullest.

1. Introduction

1.1 - Who we are

MyOptique Group Limited, with registered office at Level 2, The Kensington Building, 1 Wrights Lane, London W8 5RY United Kingdom, a company registered in England and Wales under company number 05139004, as part of EssilorLuxottica Group (hereinafter “Glasses Direct”)

Where Glasses Direct is the party that determines the purposes and the means of the processing, we are the Data Controller over your Personal Data.

Anyhow, in certain specified instances, Glasses Direct is joint controller with other entities over the processing of your personal data: this means that we are jointly responsible with them for deciding on the purposes and the means of the processing. In such instances, we conclude Joint Controllers Agreements and notify you about it in this Privacy Notice.

More specifically, we are in a joint controlling relationship over your Personal Data with Luxottica Group S.p.A., with registered office at Piazzale Cadorna no. 3 – 20123 Milan, Italy, as a part of EssilorLuxottica Group (“Luxottica”).

(hereinafter Glasses Direct and Luxottica are jointly referred to in as “EssilorLuxottica”).

For further details on the essence of the Joint Controlling Agreement in place with the above entity, you can contact us at the address set out in Section 8 of this Privacy Notice.

1.2 - What is the purpose of this Privacy Notice?

EssilorLuxottica, its Affiliates and its Brands, attach particular importance to the processing, confidentiality, and security of your Personal Data.

The purpose of this Privacy Notice is to inform you in a clear, simple and complete manner of the processing carried out on the Personal Data that you provide to us, or that each of our Affiliates can collect from the various contact you may have with us (e.g. customer care, sites, services, events, social networks, etc.), their possible transfer to third parties as well as your rights and the options you have to control your Personal Data and to protect your privacy, in accordance with the applicable legislation.

We may update this Privacy Notice at any time but if we do so, we will provide you with an updated copy of this Privacy Notice as soon as reasonably practical.

We may provide different or additional privacy notices in connection with certain activities, programs, and offerings. We may also provide additional “just-in-time” notices that may supplement or clarify our privacy practices or provide you with additional choices regarding your Personal Data.

Our Sites include links to websites and/or applications operated and maintained by third parties. Please note that we have no control over the privacy practices of websites or applications that we do not own. EssilorLuxottica encourage you to review the privacy notices of those third parties before connecting.

1.3 - What is this Privacy Notice about? Key definitions

Personal Data
Any action conducted concerning your Personal Data such as, the collection, recording, organization, storage, modification, transfer, deletion, access, consultation, etc. of such data.
Processing (of Personal Data)
Any action conducted concerning your Personal Data such as, the collection, recording, organization, storage, modification, transfer, deletion, access, consultation, etc. of such data.
Recipients (of the Personal Data)
A natural or legal person, public authority, agency or another body, to which the personal data are disclosed, whether a third party or not.
Purpose
Refers to the Purpose of the Processing. In other words, the reasons for which the Personal Data is collected.
Data Controller
Means the natural or legal person, department or organisation, alone or jointly with others, determines the Purposes and means of the Processing of Personal Data
Joint Controller
Refers to two or more Data Controllers that jointly determine the Purposes and means of Processing
Data Processor
Means a natural or legal person, department or other body which processes personal data on behalf of and on the instructions of the Data Controller
Affiliates
Means subsidiaries of EssilorLuxottica Group, its ultimate holding company and its subsidiaries, or companies that it controls, are controlled by or under common control, and its service providers and strategic business partners
Brands
The brands owned by the companies belonging to EssilorLuxottica Group
EssilorLuxottica Group
Jointly EssilorLuxottica SA (as ultimate holding company) and all its Affiliates
GDPR
Regulation (EU) 2016/679 (General Data Protection Regulation)
UK Data Protection Laws
All laws relating to data protection, the processing of personal data, privacy and/or electronic communications in force from time to time in the UK, including the UK GDPR and the Data Protection Act 2018.



Likewise, this Privacy Notice will apply to the following Data Subjects:

Clients
Clients who purchase goods, use the free home trial or use any other service offered by Glasses Direct as defined in our T&Cs available here.
Web Users
Users who access the Glasses Direct website(s) (the “Website”).
Marketing Communication Users
Users who have subscribed to receive marketing communications from Glasses Direct.

2. Where are the personal data collected from?

The Personal Data we collect depends on the point of contact through which you interact with us, as well as the purposes of this interaction as described in this Privacy Notice and are also limited to those which are relevant and appropriate for this interaction.

We use different methods and various sources to collect data from and about you. We collect and obtain information:


3. What personal data may we process about you?

The Personal Data we collect depends on the point of contact through which you interact with us, as well as the purposes of this interaction as described hereafter in this Privacy Notice and are also limited to those which are relevant and appropriate for this interaction.

3.1 - Categories of Personal Data

Category of data
Type of data
Data subject
Identifiable information
Including such as name and surname, e-mail address, gender, date of birth, country of residence, postal address, billing address and phone numbers
Clients, Web Users, Marketing Communication Users
Category of data
Type of data
Data subject
Payment information
Including data related to your credit card or other payment methods (e.g. PayPal, Klarna, debit cards, etc.) for the purchase of products through the Sites and the Services (payments are made via secure third-party payment providers supplemented by control measures, including encryption of contact details) and details products which you have purchased from us
Clients
Category of data
Type of data
Data subject
Profile and Commercial data
Including account name, password, Personal Data published on your social network, billing and delivery addresses, details about products and services which you have purchased from us (in store or online, including your order, tracking and invoices, amount and type of purchase) and your interests, preferences, feedback and survey responses
Clients, Web Users, Marketing Communication Users
Category of data
Type of data
Data subject
Marketing and Communications Data
Including your preferences in receiving marketing from us, your communication engagement data, your communication preferences and information contained in any correspondence or requests sent by you to us or asked to you by us if problems with the Sites, service or purchased products are reported
Clients and Marketing Communication Users
Category of data
Type of data
Data subject
Health Data
Including ophthalmic prescription data, measurements (optical correction, pupillary distance, etc.), adaptations and information having an impact on your visual health and eyesight checks that has been provided to use via our website or submitted to our service team via phone, email or post.
Clients
Category of data
Type of data
Data subject
Navigation information
Including information regarding your interactions with our Sites, our Services, emails, products or advertisements and statistical data relating to these interactions
Web Users, Clients, Marketing Communication Users

3.2 - Processing of Sensitive data

Certain categories of Personal Data we process for the purposes set out below, are qualified as “sensitive” Personal Data. This particularly the case of the Health, as described above, that we may process.


However, we only process such sensitive data because:

  • where it is required or allowed under local applicable legislation
  • while implementing adequate safeguards to ensure the protection of such “sensitive” Personal Data, and;
  • where you give us your prior explicit consent pursuant to Article 9 of the GDPR or Article 9 of the UK GDPR as applicable


  • However, if you don’t grant your explicit consent to the processing of your Health Data, you will not be able to benefit from the services describe above in stores and through the Sites and the Services.



    4. Why do we process your personal data?

    We are required to use your data for purposes defined according to the nature of our relationships. Thus, depending on the context in which your data is collected, it may be used for one or more of the following purposes:

    Purpose
    Details
    Legal basis
    Follow-up and execution of your online orders and the after-sales services management
    • Formalise a quotation
    • Manage product sales, online and in-store orders (purchase, delivery and supply of products and services)
    • Manage your invoicing and your warranty
    • Manage follow-up and provide after-sales service and customer relations (including, for example, returns, warranty and customer support)
    Execution of a contract
    Purpose
    Details
    Legal basis
    Transaction and potential unpaid invoices management
    • When making a payment to Glasses Direct, we will allow you to use one of our carefully selected and authorised payment service providers who will process the transaction independently and securely.
    • Manage incidents related to payment and debts
    • Process potential unpaid invoices:
    - Identify your known unpaid invoices
    - Inform you of this unpaid amount, of the means available to you to regularise it, of the possibility of making observations and of requesting a review of your situation if necessary
    Execution of a contract
    Purpose
    Details
    Legal basis
    Account and inscriptions creation and management
    • Allow you to register to our Sites and create your own account
    • Provide the services available through the Sites (e.g. management of the registration process and access to the account, account management, etc.)
    • Manage your client profile
    • Permit you to join our engagement programs
    • Allow you to participate in our contests, prize competitions and initiatives promoted
    Execution of a contract
    Purpose
    Details
    Legal basis
    Communication between us
    • Send you commercial and promotional communications via e-mail on similar products, events, services already provided to you, unless you object to such a processing at the time of the collection and on the occasion of each communication
    • Send you communications and periodical updates (e.g., via e-mail, phone, SMS/MMS, postal service, social network and newsletter, including invites to take part in surveys and reminders for products in the shopping cart) related to our products, services, initiatives and events
    • Manage our personalised commercial offers based on the analysis of your Personal Data related to spending volume, product category, date of birth and methods of purchase)
    • Fulfil your requests (e.g., management of requests for information, to notify with the “back in stock” feature, etc.)
    Consent
    Purpose
    Details
    Legal basis
    Appointment booking
    • Booking of eyesight checks or pre-sale appointments
    Consent
    Purpose
    Details
    Legal basis
    Analysis purposes
    • Management of personalised content and communications
    • Carry out statistical analysis on the customer audience
    • Analyse the performance of our Sites and services, our media investments and marketing campaigns, and our web orders & related transactional data.
    Consent
    Purpose
    Details
    Legal basis
    Legal obligations complying
    • Comply with the requirements of the laws, regulations, protocols and national and EU legislation (including target medical device legislation)
    • Implement the decisions of public Authorities
    • Manage of the requests to exercise your rights (DSARs)
    • Product traceability (Order of 28 April 2017 on the nature of the identification and traceability information for optics and eyewear products).
    • Data retention with regard to accounting and tax obligations
    • Combating fraud (certain automatic or manual processes are designed to verify your online payments and to combat fraud involving payment methods and identity theft)
    Legal obligations
    Purpose
    Details
    Legal basis
    Legitimate interests pursuit
    • Exercise or defend legal claims in court proceedings or in administrative or out-of-court procedures relating to our rights, of our group companies and/or of our representatives, shareholders, officers and directors
    • Enable the technical management of the Sites and the services and its operational functions, including solving any technical problems, to perform tests, updates and upgrades that cannot be performed through non-personal data
    • Prevent or identify fraudulent activities or misuses of the Sites and the services or against the EssilorLuxottica group and/or the Users of the Sites and the services
    • Complete a potential merger, sale of assets, transfer of all or a material part of its business, or financing transaction by disclosing and transferring the Personal Data to the third party or parties involved in the transaction as part of the transaction
    • Conduct, surveys and market research relating to our products and services via website, post, telephone or e-mail
    • Anonymise Personal Data in order to perform statistical analysis
    Legitimate interest


    5. How do we process your personal data?

    5.1 - What modalities do we use to process your personal data?

    The processing of your Personal Data is carried out, electronically and manually, only within the limits necessary to pursue the purposes outlined above.

    We undertake to protect your Personal Data.

    We advise that the password is one of the protection mechanisms of the account. Therefore, you are invited to use a password sufficiently secure and stored in a safe place, limiting access to it on their own computers and browsers, disconnecting it after having visited the Sites and/or the Services.

    All Personal Data provided by you is kept on secure servers, adopting adequate security measures to protect Personal Data from non-authorised access, to maintain the accuracy of Personal Data and guarantee the proper use of information.

    Furthermore, a secure system for authorizing credit & debit card payments and identifying fraudulent activities is used. We use the standard SSL (Secure Sockets Layer) to protect the confidentiality of your Personal Data.

    5.2 - We share your Personal Data with other Affiliates of the Group

    EssilorLuxottica is a global organization with offices and operations throughout the world and most of your Personal Data relating to is stored and processed within a range of global applications that is used globally by the Affiliates of EssilorLuxottica. The majority of the processing of your personal data is carried out through the concentrated services of two entities: Essilor International and Luxottica S.p.A

    We may share your Personal Data with certain Affiliates or Brand of the EssilorLuxottica group, based on your preferences and interests about these Affiliates or Brand, for the purposes set out in this Privacy Notice, in each case in or outside your country, as permitted and required by applicable law and/or in other circumstances with your consent.

    We may also share your information for our internal business purposes.

    5.3 - Is your Personal Data transferred to third parties?

    a) Service provider

    We may disclose your Personal Data with our third parties service providers entrusted with processing activities that provide services or assistance and advice to us, with special – but not exclusive – reference to technology, accounting, payment, administrative, legal, insurance, IT, marketing, customer service, data subjects requests management, data analysis matters.

    Each service provider will act as a data processor, on behalf of and in accordance with the instructions received from us, by virtue of a specific agreement in place per Article 28 of the GDPR and Article 28 of the UK GDPR as applicable, which sets out its obligations and guarantees the implementation of appropriate technical and organizational measures to respect the Applicable Legislation and the protection of your rights.

    We require that any such third-party provider is subject to strict control and implements appropriate guarantees of security and confidentiality of your Personal Data.


    b) Sale or merger

    We may also disclose Users Personal Data:

    - in the event that we sell any business or assets, in which case we may disclose Users Personal Data to the prospective purchaser of such business or assets; or

    - if we sell, buy, merge with, are acquired by, or partner with other companies or businesses, or sell some or all of our assets. In such transactions, Users Personal Data may be among the transferred assets.

    We may share all of the information we collect in connection with a substantial corporate transaction, such as the sale of a website, a merger, consolidation, asset sale, or in the unlikely event of bankruptcy.


    c) Legal process

    We may disclose your Personal Data to any authority, court, administrative body, or other authorised third party (including, without limitation, counsel), where the disclosure of Personal Data is required by law, regulation or court order or where such disclosure is necessary for the protection and defence of our rights.


    d) Other instance

    Our Website may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share data about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our website, we encourage you to read the privacy policy of every website you visit.

    Furthermore, we may ask if you would like to disclose your information with other third parties who are not described elsewhere in this Privacy Notice. Furthermore, we do not sell, rent, or lease your Personal Data to third parties but we may, from time to time, contact you on behalf of external business partners about a particular offering that may be of interest for you. In those cases, without your consent, your Personal Data would not be transferred to the third party.

    The abovementioned recipients will process your Personal Data as data controllers, data processors or persons in charge of processing, depending on the circumstances. A complete list of data processors is available, upon request to us, through the modalities as per this Privacy Notice.

    5.4 - Is your Personal Data transferred across the border?

    Given the presence of EssilorLuxottica in many countries around the world and in order to provide you with personalised service worldwide, some of your data may be collected, accessible or stored outside your country of residence.

    As a result of the above, your Personal Data may be accessed and/or transferred to countries which do not have equivalent data protection laws to those required within the European Economic Area (EEA).

    In such cases, EssilorLuxottica ensures that, at all times, appropriate safeguards are implemented to ensure that your Personal Data is processed in accordance with applicable legislation. In this respect, where your Personal Data is processed by another EssilorLuxottica entity, the safeguards are based on the commitments taken on the basis of (ii) a dedicated transfer agreement binding upon the EssilorLuxottica entity involved in the processing and (ii) a set of common rules applicable through the EssilorLuxottica Group Data Protection Policy.

    Where your data is processed by EssilorLuxottica entities or third parties located outside the European Economic Area, EssilorLuxottica ensures that specific contractual protection is implemented to ensure that this requirement is addressed in accordance with the Applicable Legislation as per Articles 44 et seq. of the GDPR and/or Articles 44 et seq. of the UK GDPR.

    For further information with regard to the appropriate or suitable safeguards and the means by which to obtain a copy of them, you can contact us with the modalities as per this Privacy Notice.

    5.5 - For how long do we retain your Personal Data?

    We retain all or part of your Personal Data for the time strictly necessary for the reason:

    (a) to meet applicable statutory requirements for data retention,

    (b) to meet and comply with our legal and/or contractual obligations,

    (c) for as long as necessary to carry out each of the purposes mentioned in this Data Protection Privacy Notice, including for the purposes of satisfying any legal, accounting, reporting requirements.


    To determine the appropriate retention period for Personal Data, we consider jointly the amount, nature, and sensitivity of the personal data, the potential risk of harm from unauthorised use or disclosure of your Personal Data, the purposes for which we process your personal data and whether we can achieve those purposes through other means, and the applicable legal requirements(for example, the identity Data – including Ophthalmic Prescription and Medical Data – is retained for 10 years, in line with the requirements of the General Optical Council).

    In any case, please note that, as general rule, within EssilorLuxottica, retention and archiving of Personal Data will not exceed ten (10) years overall calculated as of the first record, which is a maximum in EssilorLuxottica exception made for legal hold obligations.

    In some circumstances we may anonymise your Personal Data so that it can no longer be associated with you, in which case we may use such information without further notice to you.

    5.6 - We keep your data safe, updated, and accurate

    EssilorLuxottica has a responsibility for the security and accuracy of the Personal Data that it processes about you and also for keeping data up to date. EssilorLuxottica has taken steps to eliminate duplicate copies of data and to facilitate updating of data that may change over time.


    6. How do we protect your personal data?

    EssilorLuxottica regards the protection of Personal Data as an essential priority.

    In this respect, EssilorLuxottica has implemented appropriate measures and safeguards to protect the Personal Data it processes.

    This is reflected in EssilorLuxottica’s procedures described in the EssilorLuxottica Group Data Protection Program, guidelines, and policies and in the actual measures implemented throughout the Group.

    We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a business need to know. They will only process your Personal Data on our instructions, and they are subject to a duty of confidentiality. These measures range from technical security measures that protect IT systems to the physical security measures employed at EssilorLuxottica sites. EssilorLuxottica also requires its staff to participate in information security trainings. Details of these measures may be obtained from the Group Information Security Department.

    We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a breach where we are legally required to do so.


    7. Your rights

    You can exercise any of the following rights, subject to verification of your identity where necessary:

    a) Right of Information and Access

    You may request the confirmation of the existence of your Personal Data and to be informed of its content and source and obtain a copy of those Personal Data which our databases currently contain.


    b) Right to Rectification

    You may request to rectify what Personal Data our databases currently contain. We may not accommodate a request to change Personal Data if we believe the change would violate any law or legal requirement or cause the information to be incorrect.


    c) Right to Restriction of the Processing

    When applicable, you may restrict the processing of your Personal Data. When such restrictions are not possible, we will advise them accordingly. You can then choose to exercise any other rights under this Privacy Notice, including withdrawing your consent to the processing of your Personal Data.


    d) Right to Object to the Processing

    When applicable, you have the right to object to the processing of your Personal Data on grounds relating to your particular situation, if the processing is based on our legitimate interest. In addition, you have the right to object at any time to processing where Personal Data are processed for direct marketing purposes, which includes profiling to the extent that it is related to such direct marketing. When such objections are not possible, we will advise you accordingly. You can then choose to exercise any other rights under this Privacy Notice, to include withdrawing your consent to the processing of your Personal Data.


    e) Right to Erasure

    If you should wish to have your Personal Data deleted, then you may submit a request. Upon receipt of such a request for erasure, we will confirm receipt and confirm once your Personal Data have been deleted.


    f) Right to data Portability

    Upon request and when possible and where applicable by local laws, we can provide to you with copies of your Personal Data. When such a request cannot be honoured, we will advise you accordingly. You can then choose to exercise any other rights under this Privacy Notice, including withdrawing your consent. Where applicable, we will ensure such changes are shared with any trusted third parties.


    g) Right to Withdraw your Consent

    Where processing is based on consent, you may withdraw his/her consent at any time to the processing of your Personal Data. Upon receipt of such a withdrawal of consent, we will confirm receipt and proceed to stop processing your Personal Data.


    h) Right to lodge a complaint with the relevant data protection supervisory authority

    If you are not satisfied with the way we process your Personal Data and/or responds to a request to exercise the rights you have exercised, you can lodge a complaint with the relevant data protection competent supervisory authority.

    In order to exercise your rights, please refer to the following e-mail address: dpo@myoptiquegroup.com

    Furthermore, we offer tools to you to update and amend your Personal Data. Indeed, every registered User may access his/her own information and update it (e.g., through User account).

    Besides, it is also possible for you to modify and update your preferences on how you wish to receive e-mails or other communications from us. You may also request that your information on your account is deleted.


    8. How can you contact us?

    8.1 - Contact of the Data Controller

    The Data Controller of the processing of your Personal Data is Glasses Direct, with its registered office at Veale Wasbrough Vizards, Narrow Quay House, Bristol BS1 4QA United Kingdom.

    Should you have questions or comments on this Privacy Notice or on any data processing carried out by Glasses Direct, Glasses Direct may be contacted to the postal address above and through the e-mail address available in the previous paragraph.

    8.2 - Contact of the Data Protection Officer

    Glasses Direct has appointed a Data Protection Officer, who can be contacted at the following email address dpo@myoptiquegroup.com.

    You can also send an email to the above email address in case of any question related to this document.


    9. How can you keep track of changes to this privacy notice?

    For legal and/or organizational reasons, this Privacy Notice may undergo changes. We suggest, therefore, to check this Privacy Notice regularly and to refer to the latest version of it, we will post the date it was last updated at the top of this Privacy Notice.

    In any case, an updated version of the Privacy Notice will be always available on the Sites and the services, and we will provide additional notice to you if we make any changes that materially affect your privacy rights.