CLINIQUE DERMATOLOGIST MARKETING B2B PRIVACY POLICY


Last Update: April 25, 2025

The Estée Lauder Companies respects your privacy and values the relationship we have with you.


This Privacy Policy describes how we collect, use, disclose and safeguard personal information in relation to your business or commercial relationship with ELC, including any individual who interacts with ELC in a strictly commercial or business capacity.


References in this Privacy Policy to “we”, “us”, “our”, “ELC” are references to the entity or entities responsible for establishing the purposes for the processing of your personal information. See the “Your Data Controller” section below for details.



TABLE OF CONTENTS


PERSONAL INFORMATION WE PROCESS


We may collect or process the following types of personal information about you. The specific personal information we collect about you will vary depending on how you interact with us.


  • Contact information and personal identifiers, such as your name, address, email address, and telephone number.

  • Device identifiers, such as information about your device like your MAC address, IP address, or other online identifiers.

  • Online or network activity information, such as information regarding your interaction with our websites, mobile applications, and digital properties, information about your browsing and search history on our websites or mobile applications, and log file information like your browser type and webpages you visit.

  • Professional or employment-related information, such as your organization, role, location, and ownership percentage.

  • Inferences drawn from or created based on any of the personal information identified above.



We may collect personal information about you from various sources. For example:


  • Directly from you, such as when we scan your badge at an event, or when you visit our website.

  • When you interact with our websites or emails. When you visit our websites, or when you open or click on emails we send you, we (and third parties we work with) may automatically collect information from your browser or device, such as device identifiers and online and other network activity information using technologies such as cookies, pixel tags, and similar technologies. Cookies are small text files that websites place on your Internet-connected device to uniquely identify your browser or to store information or settings in your browser. Pixel tags are small images which are embedded into our websites or emails. We use pixel tags to collect information about your browser or device, how you interact with our websites, or whether you open or click on the emails we send you. Pixel tags also enable us (and third parties we work with) to place cookies on your browser.

  • From our business partners and service providers, such as third parties that we choose to collaborate or work with.

We may combine the personal information we obtain from the above sources.


HOW WE USE PERSONAL INFORMATION


We may use the personal information we have about you:


  • To communicate with you, including to respond to your inquiries, complaints and to otherwise assist you.

  • To administer your participation in special events, contests, or surveys.

  • For marketing and advertising, such as to send you postal mail, text messages, email, push notifications or other messages, show you advertisements for products and/or services tailored to your interests on social media and other websites.

  • To operate and understand your use of our websites and mobile applications, such as to remember your personal information so you do not have to re-enter it, determine what browser and devices you use to visit our websites or mobile applications; and to evaluate and improve our services, websites, and mobile applications. For example, we use Google Analytics on our websites. For specific details on how Google collects and uses your personal information when we use its services, please visit: How Google Uses Information From Sites Or Apps That Use Our Services.

  • To operate and improve our business, including to conduct analytics, provide quality assurance and process adverse event or product related claims, conduct research and development, and perform accounting, auditing and other internal business functions.

  • For legal and security purposes, such as to detect, prevent, and prosecute harmful, fraudulent, or illegal activity, loss prevention, identify and repair bugs on our websites or mobile applications, and to comply with applicable legal requirements, relevant industry standards and our policies.

We also may use your personal information in other ways for which we provide specific notice at the time of collection.


HOW WE SHARE PERSONAL INFORMATION


We may share your personal information with:


  • Our Subsidiaries and Affiliates. We may transfer your personal information to our subsidiaries and affiliates on a need-to-know basis for the purposes identified in this Privacy Policy.

  • Service providers. We may transfer personal information to service providers who perform services on our behalf based on our instructions. We do not authorize these service providers to use or disclose the information except as necessary to perform services on our behalf or comply with legal requirements. Examples of these service providers include entities that provide website and application functionality, hosting, analytics, advertising and marketing services.

  • Parties to a corporate transaction. We also reserve the right to transfer personal information we have about you in the event we sell or transfer all or a portion of our business or assets (including in the event of a merger, acquisition, joint venture, reorganization).

  • Advertising companies. We work with third party advertising companies (such as advertising networks) to serve advertisements on our behalf. For additional information, see the “How We Use Personal information to Advertise” section.

  • Other third parties. In addition, we may disclose personal information about you (i) if we are required to do so by law or legal process, (ii) to law enforcement authorities or other government officials, (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity, (iv) when disclosure of your personal information is otherwise required or permitted by law, or (v) with your consent.


Depending on local laws, you may have rights with respect to your personal information. For example, you may be able to request access to the personal information we maintain about you, update and correct inaccuracies in your personal information, and have the personal information deleted or transmitted to a third-party. For details on what rights apply to you and how to submit a data subject rights request, submit a request through our Privacy Request Portal. We may take reasonable steps to verify your identity when you make a request. You may also have the right to lodge a complaint with a data protection authority.


HOW WE USE COOKIES


Cookies are small text files that websites place on your Internet-connected device to uniquely identify your browser or to store information or settings in your browser which allows us to remember you when you come back to our websites and provide you with personalized experiences. We use different types of cookies on our websites, which may include strictly necessary cookies, performance cookies, functional cookies and targeting cookies.


You can edit your preferences by editing your browser settings. When editing your cookie preferences, please note that your settings only apply to the browser you use, so if you use multiple browsers or devices, you must change the setting on each browser, on each device.


HOW WE USE PERSONAL INFORMATION TO ADVERTISE


We may use, disclose or otherwise process your personal information to advertise our products and services in different ways, including targeted advertising. We work with third party advertising companies (such as advertising networks) to serve advertisements on our behalf. These advertising companies may use cookies, pixel tags and similar technologies to collect device identifiers, online or network activity information, commercial information, or inferences, such as information about the websites you visit over time and the advertisements you click on to deliver advertisements that are targeted to you or your profile. You can opt-out of cookie-based advertising based on your visits to our sites by editing your cookie preferences as described in the “How we Use Cookies” section. Please note that even if you opt-out, you may still see ads from us, but the ads will not be targeted based on the websites you visit over time and the advertisements you click on and may therefore be less relevant to you and your interests.


We also work with third-party platforms, including platforms operated by social networks, to show you advertisements or measure the effectiveness of our advertisements. We may convert your email address, telephone number, or other personal information into a unique value and have these third-party platforms match this unique value with a user on their platform or with other data they may have. This matching enables us to deliver advertisements to you and others on these platforms. You also can request that we refrain from using your personal information in this way by contacting us through our Privacy Request Portal.


INTERNATIONAL TRANSFERS


In offering and providing our products and services, your personal information may be transferred, stored or processed in countries other than the country in which the personal information was originally collected (such as the United States). Those countries may not have the same data protection laws as your country of residence, and your personal information will be subject to applicable foreign laws. When we transfer your personal information to other countries, we will protect that personal information in the manner described in this Privacy Policy. We will also comply with applicable legal requirements providing adequate protection for the transfer of personal information, such as the conclusion of data transfer agreements, E.U. Standard Contractual Clauses, or other applicable data transfer mechanisms. If you have questions about our data transfers or would like to receive a copy of any applicable data transfer agreements (where required by law), you can submit a request through our Privacy Request Portal.


HOW WE PROTECT PERSONAL INFORMATION


We maintain administrative, technical, and physical safeguards designed to protect the personal information you provide against accidental, unlawful or unauthorized destruction, loss, alteration, access, disclosure, or use. We restrict access to personal information on a need-to-know basis to employees and authorized service providers who require access to fulfil their job requirements.


HOW LONG WE RETAIN PERSONAL INFORMATION


In general, we retain personal information for the duration of your relationship, plus a reasonable period of time thereafter or such other time as may be required or permitted by applicable law.


UPDATES TO OUR PRIVACY POLICY


This Privacy Policy may be updated periodically and without prior notice to you to reflect changes in our personal information practices. We will post a notice on our websites to notify you of any significant changes to our privacy practices and indicate at the top of the Privacy Policy when it was most recently updated.


HOW TO CONTACT US


If you have questions or comments about this Privacy Policy or if you would like to exercise your rights, please submit a request through our Privacy Request Portal. You can locate your local data controller below.


YOUR DATA CONTROLLER


CountryContact
CanadaEstée Lauder Cosmetics Ltd.
161 Commander Blvd.
Agincourt, ON M1S 3K9
CANADA

privacyinfo@estee.ca
United StatesClinique Laboratories LLC
7 Corporate Center Drive
Melville, NY 11747
USA

UNITED STATES - CALIFORNIA-STATE-SPECIFIC DISCLOSURES


This section applies solely to California residents and supplements our Privacy Policy above.


Collection and Disclosure of Personal Information


We may collect and disclose or may have collected and disclosed your personal information to certain categories of third parties, as described below.


CategoryDisclose to Third Parties
Contact information and personal identifiersWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • fraud detection providers
  • law enforcement authorities or other government officials where required or permitted by law
Device IdentifiersWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • fraud detection providers
  • law enforcement authorities or other government officials where required or permitted by law
Online or network activity informationWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • fraud detection providers
  • law enforcement authorities or other government officials where required or permitted by law
Geolocation informationWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • fraud detection providers
  • law enforcement authorities or other government officials where required or permitted by law
Audio and visual informationWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • law enforcement authorities or other government officials where required or permitted by law
Professional or employment related informationWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • law enforcement authorities or other government officials where required or permitted by law
InferencesWe may disclose or may have disclosed this information to:
  • Our Brands
  • Our Subsidiaries and Affiliates
  • Service Providers
  • Law enforcement authorities or other government officials where required or permitted by law

In addition to the purposes set forth in the “How We Use Personal information” and “How We Share Personal information” sections set forth and above, we collect and may disclose this personal information for the following business or commercial purposes:

  • To audit our interactions with you to ensure compliance with applicable law and to measure the effectiveness of our products, services, and advertisements;
  • To detect, prevent, and prosecute harmful, fraudulent, or illegal activity;
  • To identify and repair bugs on our websites or mobile applications;
  • To provide services, such as customer service, order fulfillment, and payment processing, which we either conduct or engage service providers to conduct on our behalf;
  • For research and development;
  • To further our business goals, including to advertise our products and services; and
  • For quality assurance.


Sale or Sharing of Personal Information

We do not sell or share your personal information for monetary consideration. Certain advertising practices, such as those described in the “How We Use Personal information to Advertise” sectionS, may be considered a “sale” under California law when the personal information is exchanged for non-monetary consideration. You have the right to opt out of these types of disclosures of your personal information. We may “sell” or “share” (or may have “sold” or “shared”) the following categories of personal information to the third parties listed below:


CategorySold to or shared with Third Parties
  • Contact Information and personal Identifiers
  • Device identifiers
  • Commercial information
  • Online or network activity information
  • Inferences
We may sell or share or may have sold or shared this information to:
  • Advertising companies
  • Our Brands

We do not have actual knowledge that we sell or share the personal information of minors under 16 years of age. We do not sell or share sensitive personal information.


Financial Incentives

We may offer you various financial incentives such as discounts and special offers when you provide us with contact information and identifiers such as your name, email address and/or mobile phone number. When you sign-up for one of our brand loyalty programs, email lists or other discounts and special offers, you opt-in to a financial incentive. You may withdraw from a financial incentive at any time by opting out from the brand emails you initially signed up for, or closing your brand loyalty member account. Generally, we do not assign monetary or other value to personal information, however, California law requires that we assign such value in the context of financial incentives. In such context, the value of the personal information is related to the estimated cost of providing the relevant financial incentive(s) for which the personal information was collected.


Your Rights

If you are a California resident, you have the right to:


  • Request, twice in a 12-month period, access to the personal information we have collected, used, disclosed, and sold or shared about you;
  • Deletion of the personal information we have collected from you (subject to certain exceptions);
  • Correction of the personal information we maintain about you, if that personal information is inaccurate; or
  • Opt-out of the sale of your personal information or sharing of your personal information for cross-context behavioral advertising purposes.

You can exercise your rights by submitting a request through our Privacy Request Portal. Before processing your request, we will take reasonable steps to verify your identity, which will include verifying that the email address from which you submit the request matches the email address we maintain on file for you. To ensure you are the owner of the email address, you must respond to a confirmation email that we will send to such email address. In some cases, we may ask that you provide additional information to verify your identity. You may also designate an authorized agent to make a request on your behalf. The authorized agent may submit the request through our Privacy Request Portal and will be required to provide proof that they have been authorized to act on your behalf. If the authorized agent does not provide such proof, you will be required to confirm your identity and the authenticity of the request.

To opt-out of the sale or sharing of your personal information for cross-contextual behavioral advertising purposes, you must also edit your preferences using the or “Do Not Sell or Share My Personal Information / Target Ads” link at the bottom of each our Brand websites. You may also use the Global Privacy Control signal. For more information about the Global Privacy Control, visit https://globalprivacycontrol.org/.

We will not discriminate against you on account of your exercise of your California privacy rights.

If you would like us to read this Privacy Policy to you, please contact us at 1.800.588.0070.