This site has limited support for your browser. We recommend switching to Edge, Chrome, Safari, or Firefox.

Free shipping on orders over €100 (France only)



Language

Currency


CART 0

Congratulations! Your order qualifies for free shipping (France only) You have €100 left to benefit from free delivery. (France only)
Sorry, looks like we don't have enough of this product.

Products
Complete your routine with our packs
Subtotal Free

Overseas territories, UK, Canada, Switzerland : customs fees may apply at arrival. These are the customer's responsibility and are not handled by HACT.

Privacy Policy

Last updated: [02.02.2026]

 

HACT CARE (hereinafter “ HACT ”), acting as data controller within the meaning of Regulation (EU) No. 2016/679 of 27 April 2016 (“ GDPR ”) and Law No. 78-17 of 6 January 1978 as amended known as “Data Protection Act” (hereinafter collectively the “ Regulations ”), attaches particular importance to the protection of personal data and to respecting the privacy of Users of its services.

 

The Policy applies to the processing of personal data (hereinafter " Personal Data ") carried out by HACT in connection with the Services, concerning Users of the Site (hereinafter " Users "), whether this data is provided directly by the Users or collected indirectly during their browsing and use of the Site.

 

The personal data collected on the Site is processed by:

 

-        HACT, the company operating the Site ( https://hactparis.com/ ) (hereinafter " Site "), registered with the RCS of PARIS under number 941 620 114, whose registered office is located at 28 rue Vaneau, 75007 PARIS.

 

The purpose of this privacy policy (hereinafter the “ Policy ”) is to inform the persons concerned of the ways in which HACT collects, processes and protects personal data in the context of: (i) browsing the Site and accessing the online store, (ii) creating and managing an account, (iii) accessing and completing questionnaires intended to establish a declarative hair profile, (iv) sending hair routine guides and product recommendations for strictly cosmetic purposes, as well as (v) processing orders and customer relations, the Site being powered in particular by the Shopify solution (hereinafter collectively the “ Services ”).

 

HACT undertakes to limit the processing of Personal Data to only the cases listed in this Policy, and to update the latter in order to guarantee a high level of protection of Personal Data in accordance with the applicable Regulations.

 

By accessing or using the Services, the User acknowledges having read this Policy. If the User disagrees with this Policy, they must cease all use of the Services.

 

 

ARTICLE 1 - PERSONAL DATA COLLECTED

 

By using the HACT Website, Users may be required to transmit Personal Data, directly or indirectly, in particular through the User's use of the Site.

1.1 Data provided by Users

 

In the context of using the Services, and in particular when creating a User account, HACT is required to collect personal data directly from users necessary for accessing certain specific features of the Services.

-        Creating a User Account

In this capacity, HACT collects the following data via the service provider Shopify:

·       Contact details: email address;

·       User account data: email address, password, account preferences and settings.

This data is necessary for User authentication, account management and securing access to the Services.

 

-        Received the guide on female hair loss

When the User wishes to receive a hair care routine guide, including when this guide is based on information provided in a questionnaire, HACT may collect, in addition to or independently of the creation of an account, the following data:

 

·       E-mail address ;

·       First name ;

·       Language of communication.

This data is strictly necessary to enable the sending of the guide relating to female hair loss and to ensure follow-up of the relationship with the user.

-        Access to and completion of the questionnaire

When the User accesses the questionnaire offered by HACT, Personal Data is collected in order to establish a declarative hair profile and to allow the sending of a hair routine guide and product recommendations for strictly cosmetic purposes.

As part of the questionnaire, HACT is required to collect certain information relating to the User's lifestyle and hair condition (including smoking, hair loss, alopecia or similar information).

Some of this information constitutes health data within the meaning of Article 9 of the GDPR.

 

In this capacity, HACT is likely to process:

 

·       E-mail address ;

·       Sex;

·       Age;

·       Certain declarative information relating to the User's lifestyle and hair characteristics (including smoking, hair loss, alopecia, or similar information), strictly to the extent necessary for developing hair care routine recommendations.

This data is collected and processed exclusively to provide content and recommendations for cosmetic and comfort purposes. It does not constitute a medical device, cannot be used to establish a diagnosis, is not intended for the prevention or treatment of any disease, and in no way replaces a medical consultation or the advice of a healthcare professional.

The processing of health data collected in the context of the questionnaire is based on the explicit consent of the User, obtained specifically during the validation of the questionnaire.

The User may withdraw this consent at any time, without affecting the lawfulness of processing carried out previously.

-        Purchasing products on the Site

When the User purchases products via the online store, HACT, through SHOPIFY, KLARNA or PAYPAL, collects the data necessary for processing the order and fulfilling the contractual relationship, including:

·       Identification and contact details (surname, first name, postal address, delivery address, email address, telephone number)

·       Commercial data: transaction number, order history and details, purchase amount, invoice settlement data (payments, outstanding balances, discounts), product returns, exchanges with customer service;

·        Order data (products viewed, added to cart, purchased, returned or exchanged);

·       Payment and transaction data, it being specified that bank data is processed exclusively by payment providers and is not stored by HACT.

-        Exchanges with HACT

HACT also collects data from exchanges with users, including the content of communications addressed to customer service or via any contact form on the "Contact" page.

Certain data is essential for accessing your personal account, the guide, the questionnaire, and, more broadly, for providing the Services. Failure to provide this information may limit or prevent access to all or part of the Services.

1.2 Data collected automatically during browsing of the Site

When the User accesses the Site, personal data is collected to enable their navigation.

In this capacity, HACT is likely to collect:

·       Connection and browsing data: IP address, browser type, device information, pages viewed, date and duration of visits;

·       Service usage data: interactions with the store, consultation of the guide, access to and completion of the questionnaire, frequency of navigation and purchasing behavior.

 

For more information, the User is invited to consult " ARTICLE 5 – COOKIES AND TRACKER " of this Policy.

 

 

ARTICLE 2 - PURPOSES OF PROCESSING PERSONAL DATA

 

HACT collects and processes Users' Personal Data in compliance with the Regulations for the following purposes:

 

·       Create, manage and administer personal accounts;

·       Handling complaints, disputes, and customer returns;

·       To allow access to personalized guides and content relating to hair care routines, developed from information declared by the User, for strictly cosmetic and informational purposes;

·       To allow access to and use of the questionnaire proposed by HACT;

·       To process and analyze questionnaire responses, including data relating to hair health and age, based on the explicit consent of the user, strictly for the purposes of guidance and provision of Services;

·       To provide, operate and improve the Services, including order processing, payments, deliveries, returns and exchanges;

·       To ensure customer relations, support and processing of requests;

·       Personalize the user experience and offer product recommendations;

·       To measure audience, compile statistics and analyze the use of the Services;

·       To ensure the security of the Services, prevent fraud and misuse;

·       Sending marketing and promotional communications when permitted by regulations;

·       Comply with applicable legal and regulatory obligations;

·       Ensure the management of requests to exercise rights and the traceability of actions carried out in order to demonstrate HACT's compliance with the Regulations.

 

 

ARTICLE 3 - LEGAL BASIS FOR PROCESSING AND STORAGE PERIODS

 

In accordance with the requirements of Articles 6, 9 and 13 of the GDPR, the processing of Personal Data implemented by HACT is based on separate legal bases depending on the purposes pursued.

 

Personal data concerned

Legal basis for processing

Shelf life

Processing related to the creation and management of the user account, access to the guide, and access to the questionnaire

Contractual execution

Until account deletion (or prolonged inactivity); archiving period 5 years (statute of limitations)

Commercial data: transaction number, order history and details, purchase amount, invoice payment data (payments, outstanding balances, discounts), product returns, exchanges with customer service

Contract execution

5 years after collection or last contact, then archiving to comply with legal limitation periods.

The processing of data from the questionnaire relating to age and hair health.

Consent

2 years from the date of collection, corresponding to the duration of relevance of the proposed hair care routine, unless deleted earlier at the User's request.

The processing carried out for the purposes of commercial prospecting and sending marketing communications

Consent

 

Until account deletion (or prolonged inactivity) or a request to withdraw consent; archiving period 5 years (statute of limitations)

Billing and transaction data (only bank details are processed by Shopify, KLARNA, PAPYPAL in accordance with their privacy policies)

Legal obligation

Until the account is deleted; archiving period 10 years (accounting obligations)

Connection data (IP address, browser type, etc.)

Consent

6 months from the date of consent

Technical data and logs necessary for the security of the Site (e.g., abuse detection, fraud prevention, form protection)

 

 

Legitimate interest

Maximum duration 6 months, unless longer retention is required in the event of a security incident or litigation (evidence archiving)

Browsing data collected via non-essential cookies (audience measurement, personalization, advertising)

Consent

Cookie retention period: maximum 13 months; associated data retention period: maximum 25 months, depending on settings and CNIL recommendations

 

HACT may also process certain data strictly necessary for fraud prevention, securing the Site, managing complaints and defending its rights, on the basis of its legitimate interest (Art. 6.1.f GDPR) or compliance with a legal obligation (Art. 6.1.c GDPR), for periods limited to what is strictly necessary for the purposes pursued, then archived in a restricted manner for the applicable limitation period.

To determine the applicable retention period, HACT takes into account various criteria, including the need to retain the data in order to:

 

·       Administer and maintain a User account;

·       To provide the services and ensure their proper functioning;

·       Maintain the content and productions generated via the Services;

·       Ensure the security and integrity of systems;

·       Prevent risks, abuse, fraud or damage;

·       Conduct internal audits and controls;

·       Comply with legal and regulatory obligations, and be able to demonstrate compliance;

·       Resolving disputes and asserting or defending rights;

·       To enforce contractual agreements.

 

At the end of these periods, the data is deleted or anonymized.

 

HACT conducts reviews, when necessary, to verify whether the retention of data remains justified.

 

In the event of a deletion request, HACT will endeavor to process the request as soon as possible and, in any event, within a maximum period of one (1) month from its receipt, except where the retention of data is required or authorized by applicable legislation.

 

For more information, see section " ARTICLE 6 - USER RIGHTS ".

 

Finally, if a new processing of Personal Data is carried out, in other words if HACT intends to use them for purposes other than those set out above, HACT will specifically inform Users by reasonable means so that they can exercise their rights.

 

 

ARTICLE 4 - RECIPIENTS OF PERSONAL DATA

 

HACT only discloses Users' Personal Data in the cases described in this Privacy Policy. Unless otherwise stated, HACT will never sell its Users' data. Users have the rights provided by the Regulations and may exercise them under the conditions described in Article 7.

 

In certain circumstances, HACT may be required to disclose Personal Data to third parties for the purposes described in this Privacy Policy, including in the following cases:

·       SHOPIFY acts as a service provider for store authentication and management

·       Payments made on the Site are processed by payment providers (including Klarna, PayPal and/or the payment solutions offered via Shopify). In this context, certain data is processed directly by these providers, in accordance with their own privacy policies and security standards.

Shopify's privacy policy can be accessed via the following URL: https://www.shopify.com/fr/legal/confidentialite

PayPal's privacy policy can be accessed via the following URL: https://www.paypal.com/fr/legalhub/paypal/privacy-full

KLARNA's privacy policy is available at the following URL: https://www.klarna.com/fr/confidentialite/#

·       OVHCloud as a web hosting and cloud services provider.

·       Commercial and marketing partners, when permitted by regulations;

·       Administrative or judicial authorities when required by law. HACT may also disclose information to comply with applicable law, enforce its contractual agreements and policies, or protect and defend the Services, its rights and those of its Users or third parties.

 

Technical service providers working on behalf of HACT generally act as data processors. Some providers, particularly payment processors, may process certain data as separate data controllers, in accordance with their own privacy policies.

 

Purposes

Data recipient service

Authentication; store management; order processing

SHOPIFY

Payment management

SHOPIFY, KLARNA, PAYPAL

Website Hosting

OVHCloud

Application of Regulations and Legislation

Jurisdictions, governmental or administrative authorities

 

 

ARTICLE 5 – COOKIES AND TRACKER TECHNOLOGIES USED

In connection with the use of the Site, HACT uses cookies and other tracking technologies to ensure the operation of the Site, improve the user experience, measure audience, offer suitable content and strengthen security.

Cookies are small text files that may be placed on the user's device (computer, smartphone, tablet) during browsing.

They allow, in particular, the recognition of a terminal, the storage of certain information, or the collection of data relating to the navigation and use of the Site.


Other similar technologies (such as web beacons or technical identifiers) can also be used for the same purposes.

HACT is likely to use the following categories of cookies:

  • Strictly necessary cookies

These cookies are essential for the operation of the Site and access to its essential features, particularly in terms of security, shopping cart management, access to services and remembering consent preferences.
These cookies are exempt from consent in accordance with applicable regulations.

  • Audience measurement and performance cookies

These cookies allow us to measure Site traffic, analyze navigation and improve the performance and ergonomics of the Site.


Their submission is subject to the user's prior consent.

  • Personalization cookies

When not strictly necessary for the operation of the Site, their placement is subject to the User's prior consent. These cookies allow the Site's display or certain functionalities to be adapted according to technical or browsing preferences.

  • Advertising and social media cookies

These cookies, placed by HACT or by third parties, allow in particular to measure the effectiveness of advertising campaigns, to offer content adapted to the user's interests and to allow interaction with social network content.


As such, the Site may integrate cookies linked to third-party services, including TikTok, subject to the prior consent of the user.

Cookies that are not strictly necessary are only placed after obtaining the user's consent.

·       Consent management

Upon their first visit to the Site, the User is informed about the use of cookies via a dedicated banner allowing them to:

  • To accept all cookies;
  • To refuse non-essential cookies;
  • To configure your choices by cookie category.

The user can modify their preferences at any time via the cookie management module accessible on the Site.

Refusing non-essential cookies does not prevent access to the Site, but may limit certain functionalities.

In principle, cookies requiring consent are stored for a maximum of thirteen (13) months from the date they are placed, in accordance with the recommendations of the CNIL (French Data Protection Authority). Strictly necessary cookies are stored for the period necessary to fulfill their purpose.

HACT provides Users with a concise overview of the use of cookies below:

 

Purpose

Cookie concerned

Cookie lifespan

Consent

Social media cookies placed by social networks when you share content from our websites with others or express your opinion about this content via an application button, advertising cookie used to measure the effectiveness of advertising campaigns and to provide tailored content

TikTok

6 months from the date of consent, once this period expires, consent is requested again

Yes

Advertising cookie used to measure the effectiveness of advertising campaigns

Google / DoubleClick

6 months from the date of consent, once this period expires, consent is requested again. 

Yes

Utility cookie used to remember certain technical preferences      

Google / NID

13 months

Yes

 

HACT relies on the Shopify platform to operate its online store. As such, cookies may be placed during browsing. The list of cookies used, their description, and their retention period can be consulted at the following address: https://www.shopify.com/fr/legal/cookies

ARTICLE 6 – SECURITY OF PERSONAL DATA

 

HACT implements reasonable and appropriate administrative , technical and organizational security measures, as well as physical safeguards, to protect Personal Data processed through the Services against loss, misuse, and any unauthorized access, disclosure, alteration or destruction, taking into account the nature of the data and the risks associated with the processing.

 

However, since no information system can guarantee absolute security, HACT cannot ensure that the collection, transmission and storage of Personal Data will be completely secure in all circumstances.

 

In particular, HACT cannot be held responsible for the security of data transmitted via networks not under its control (including the Internet or wireless networks).

 

When the creation of an account is offered, the security of the login credentials is also the responsibility of the Users, in particular with regard to the confidentiality of access, the protection of passwords and the limitation of access to the devices used.

 

In case of suspected account compromise, HACT must be informed as soon as possible at the following email address: hello@hactparis.com 

 

 

ARTICLE 7 - USER RIGHTS

 

In accordance with the Regulations, Users have the following rights:

 

·       Right of access to their personal data;

·       Right to rectification of inaccurate or incomplete data;

·       Right to erasure of data;

·       Right to restriction of processing;

·       Right to object to processing;

·       Right to data portability;

·       Right to withdraw their consent at any time when processing is based on it, without affecting the lawfulness of processing based on consent before such withdrawal.

·       Right to lodge a complaint with the CNIL.

 

These rights can be exercised by contacting HACT at the following address: hello@hactparis.com

 

HACT can rely on service providers like SHOPIFY to ensure the management of User rights.

 

HACT has one (1) month from receipt of the request to respond. This period may be extended by two (2) months in the event of a complex request or a high number of requests, in accordance with the Regulations.

Users have the option to join mailing lists and agree to receive personalized marketing and promotional information from HACT via email. Users can change their promotional communication preferences at any time, as described below:

-        If the User has an account: They log in to their online account and modify their settings by unchecking the corresponding box(es) in the "My account settings" section.

-        In each of our communications (Newsletters): It is possible to click on the unsubscribe link.

-        By contacting HACT at the following address: hello@hactparis.com 

If the User unsubscribes from promotional communications, HACT may continue to communicate by email for non-promotional purposes.

ARTICLE 8 – CHILDREN'S PRIVACY

The services offered by HACT are not intended for individuals who have not reached the age of legal majority. HACT does not knowingly collect personal data concerning minors.

In the event that HACT becomes aware that personal data concerning a minor has been collected without the required consent, HACT undertakes to take all appropriate measures to delete this data as soon as possible.

Parents or legal guardians who believe that a minor under their care has provided personal data to HACT can contact HACT at the following address: hello@hactparis.com to request the deletion of said data.

 

ARTICLE 9 - TRANSFERS OF PERSONAL DATA

In the course of operating the Services, HACT may use technical and payment service providers which involve transfers of Personal Data outside the European Union.

The Services are operated primarily through the Shopify platform, a company based in Canada. As such, certain data may be transferred to or accessed from Canada. Canada benefits from an adequacy decision by the European Commission guaranteeing an adequate level of protection for personal data.

Furthermore, in the context of payment processing, certain Personal Data may be transferred to countries not benefiting from an adequacy decision, including the United States, due to the use of third-party payment providers such as PayPal.

In this case, HACT ensures that these transfers are framed by appropriate safeguards, in particular by the use of standard contractual clauses adopted by the European Commission.

Personal Data may therefore be transferred, stored or processed outside the European Union when necessary for the provision of Services (hosting, technical support, payment) and for the security and proper functioning of the Site.

 

ARTICLE 10 - AMENDMENT TO THE PRIVACY POLICY

This Policy may be modified at any time to take account of legal, regulatory, jurisprudential, technical or operational developments affecting the processing of personal data implemented by HACT.

HACT will update the " last updated " date shown in the header of the Policy and will post the updated version on the Site.

When the changes made are substantial and are likely to have a significant impact on the rights or obligations of users, HACT will implement reasonable means of information to notify the persons concerned, in particular by posting an information message on the Site or, where appropriate, by sending a notification.

HACT invites users to regularly consult this Privacy Policy to be aware of any updates or modifications .

 

 

ARTICLE 11 - RIGHT TO FILE A COMPLAINT

 

HACT is committed to processing Personal Data in compliance with applicable regulations, and in particular Regulation (EU) 2016/679 (GDPR).

 

Therefore, any person concerned may, in the event of a question, request or complaint relating to the collection or use of their Personal Data by HACT, contact HACT first at the following address: hello@hactparis.com

 

HACT will make its best efforts to review the request and provide an appropriate response within a reasonable timeframe.

 

Without prejudice to any other administrative or judicial remedy, any data subject has the right to lodge a complaint with the competent supervisory authority for the protection of personal data, and in particular:

 

·       For France, the National Commission for Information Technology and Freedoms (CNIL) – www.cnil.fr](http://www.cnil.fr ;

 

HACT, however, favours, where possible, prior exchange in order to allow the amicable resolution of any difficulty relating to the processing of personal data.