PRIVACY POLICY

Please find below the privacy policy of our company M2A, acting as the exclusive licensee of Herbalife in France.

M2A is a simplified joint stock company, with €118,420.00 in capital, registered at the Trade and Companies Register of Lyon under number 419 882 840. M2A’s head office is located at 24 rue Laure Diebold, 69009 Lyon.

The confidentiality of information given to us by our customers is a priority for our company.
In this context, we have implemented this policy (the “Privacy Policy”) in order to guarantee your rights in this regard. Thus, you acknowledge that we have the right to collect, store, use and disclose your personal data as defined in this Privacy Policy. The latter complies with French Law No. 78/17 of 6 January 1978 relating to data processing, files and personal freedom.

This Privacy Policy applies only to official Herbalife resellers.

 

Reasons for implementing the Privacy Policy:

M2A publishes this privacy policy in order to provide you with information relating to the conditions of:

-  collection

-  storage

-  use

-  disclosure

 

Thus, our company serves as data controller in the context of the use of the e-commerce website accessible at the following address: https://herbalifeukclothing.com/

 

For any request relating to your personal data, you can write to us at the contact details below:

-  Following email address: contact@herbalifeukclothing.com

-  Postal address: M2A, 24 rue Laure Diebold, 69009 Lyon, France

 

Personal data we collect

 

When you visit our Site, you may provide us with several types of personal data set out below:

 

Information that you voluntarily provide to us

 

•  Identification and communication data such as your title, surname, first name, your postal address, your e-mail address, your telephone number and possibly your date of birth.

 

For your complete information, we do not collect your bank details.

At the time of your purchase, STRIPE (payment by credit card) is the only entity that receives your bank details for this purpose. We invite you to consult their own privacy policies.

 

•  Connection data, such as your logins, which are the following:

your email address and your password, allowing us to clearly identify your account or to recognize you before authorizing you to access your account information or certain online activities.

 

Methods of collecting personal data

 

Here is the list of the various means of collection:

•  Registration on our e-commerce website

•  Registration to our newsletter

•  Customer service requests

Legal basis for data processing

 

Here is the list of our legal grounds for allowing the collection of your personal data:

•  Execution of a contract that binds you to our company

•  Obtaining consent

•  Legal and regulatory obligations

 

Use of your personal data

 

Here is the list of the different uses we make of your personal data:

•  To allow us to provide the type of content and offers that may be of interest to you

•  To offer and allow you to buy our products

•  To send you important messages, related to welcome letters, purchase confirmations or reminder notices.

•  To create and manage your account and your billing and order history, and recognize you when you try to log in.

•  To contact you about our products and adapt our special offers or promotions to your tastes, your habits or your needs

•  To provide follow-up for our customer service department

•  To process your requests for information quickly

•  To send you newsletters

 

Data collection related to our Newsletter

 

The newsletter will be sent to you in electronic format only after voluntary registration on your part.

Only when you withdraw your consent will you stop receiving the newsletter.

 

Data collection related to the contact form

 

You have the opportunity to voluntarily complete a contact form in which the following personal information is required so that we can process your request for information:

 

-E-mail address.

 

Thus, by completing this form, you agree to be contacted electronically for the proper processing of your request. Please be aware that withdrawing your consent will no longer allow us to contact you.

Strictly regulated sharing of your personal data

In our capacity as data controller, the personal data that you share with us is entirely intended for us.

However, some of our service providers may have access to it as part of your customer experience. This access is strictly supervised in accordance with the applicable regulations and ensuring the protection of your rights.

Thus, these service providers are recipients in order to carry out the services we entrust them with. Certain personal data may be sent to third parties or to legally authorized authorities to meet our legal, regulatory or contractual obligations.

 

In the event we share your personal data with our technical service providers and/or subcontractors for the proper execution of the e-commerce Site (delivery of products, price distribution, payment processing, etc.), we undertake that these technical service providers and/or subcontractors comply with the terms of this Privacy Policy.

In the event we subcontract, in part or in full, the processing of personal data, our company will approve, along with its subcontractors, guarantees of personal data security and privacy by means of technical data protection measures and the appropriate human resources.

In the event that judicial authorities demand the disclosure of your personal data, we may disclose any data collected, without any time limit. We will ensure that such disclosure will not exceed what is authorized or required by law, or where we believe, in good faith, that it is necessary (i) to protect your security and (ii) to protect the security of our e-commerce Site.

 

Storage periods

Below are the storage periods that we apply in order to guarantee a duration proportional to the purpose for which your personal data was collected.

Please note that certain durations are imposed by law.

-  User login data at each login: 6 months from the date of the last login

-  Customer account information: 1 year from the date of account closure

-  Data relating to the user for the purpose of invoicing/ delivery/ return of orders: Duration of the commercial relationship starting from finalization of the contract when delivery of the goods or performance of the service is immediate, and starting from finalization of the contract until the date of delivery of the goods or performance of the service in the other case.

-  User data for the purpose of statistical processing to understand usage (product improvement): 13 months maximum

-  Sales prospecting data: 3 years from the last contact from the prospect

-  Management of newsletter subscription cancellations: 6 years for a prospect and the duration of the commercial relationship for a client, starting from cancellation of the newsletter subscription

-  Customer service: Time required to process the customer request

-  User statistics: Duration of the analysis

Your rights:

 

The right to information

In this privacy policy, you are informed of the purposes, legal framework, interests, recipients or categories of recipients with whom your personal data is shared, the time period your personal data is kept, your rights and the terms for exercising them.

IMPORTANT :  For the exercise of the right to information, we may not be required to act on it if:

•  you already have this information

•  the recording or communication of your personal data is expressly provided for by law

•  communication of the information proves to be impossible

•  disclosure of the information would require disproportionate effort

The right to access and rectify

 

You can access and you can have your personal data rectified by sending an email to the following address: contact@herbalifeukclothing.com 

You have access to your data as well as to information concerning:

•  the purposes of the processing

•  the categories of personal data concerned

•  the addressees or categories of addressees

•  the length of time it will be kept

•  the existence of your rights

•  the right to lodge a complaint with the CNIL

You can ask us to have your personal data be, depending on the case, rectified or completed if they are inaccurate, incomplete, ambiguous or outdated.

The right to erasure

 

You can ask us to erase your personal data in the following situations:

•  the personal data is no longer necessary for the purposes for which it was collected or otherwise processed

•  you withdraw your previously given consent

•  you oppose the processing of your personal data when there is no legal reason for said processing

•  the processing of personal data does not comply with the provisions of the applicable legislation and regulations

•  However, exercising this right will not be possible when keeping your personal data is necessary with regard to legislation or regulations and in particular, for example, for the recognition, exercise or defense of legal rights.

The right to limit processing

You can request the limitation of the processing of your personal data in the cases provided for by legislation and regulations.

The right to object

You have the right to object to the processing of personal data concerning you when the processing is based on the legitimate interest of the controller.

The right to portability

 

The data this right can be exercised on are:

•  only your personal data, which excludes anonymized personal data or data that does not concern you

•  declarative personal data as well as the personal operating data mentioned above

•  personal data that does not infringe the rights and freedoms of third parties such as those protected by business secrecy

 

This right is limited to processing based on consent or on a contract as well as to personal data that you have personally generated.

 

Withdrawal of consent

 

When the data processing that we implement is based on your consent, you can withdraw it at any time. We then stop processing your personal data without the previous operations for which you had consented being called into question, subject to compliance with the legal and regulatory retention obligations to which we are held.

The right to appeal

 

You can lodge a complaint with the CNIL in France, without prejudice to any other administrative or judicial remedy.

 

The right to set post-mortem guidelines

 

You can specify guidelines on the storage, erasure and communication of your personal data after your death, with a trusted third party, certified and responsible for enforcing the wishes of the deceased, in accordance with the requirements of the applicable legal framework.

The conditions for exercising your rights or for any question relating to the privacy policy:

 

You can exercise your rights at the following e-mail address: contact@herbalifeukclothing.com

 

At the following postal address: M2A, 24 rue Laure Diebold 69009 Lyon

Unless you expressly request, the data communicated to the e-mail address and postal address above will not be used to send promotional messages.

 

Under no circumstances may third parties collect data through our e-commerce site.

It should, however, be noted that our e-commerce Site may contain hyperlinks to websites managed by third parties, including advertising agencies and other content providers.

These sites may collect data or request personal data from you. In this context, we recommend you always read the personal data protection policy of each of the sites concerned.

Our company has no control over the websites in question, is not responsible for their content, their respective privacy policies, or the possible collection, use or disclosure of any information by the sites in question. In any event, our company cannot be held liable should the content of one of the sites contravene the legal and regulatory provisions in effect.

 

Updating of your login details

 

You can access your login credentials (through sections named "My Account" "Settings" or similar names), and we may offer a number of options for updating your account and information about you contained therein. If such options are not offered on the e-commerce site you are browsing, or if you wish to make a request or change other than what is offered by these account management sections, you have a few additional remedies:

 

•The right to refuse commercial and marketing messages from our company – At the time of registration or data collection, you may be offered to subscribe to commercial and marketing messages from our company by checking the box provided for this purpose.

Some initiatives or registration procedures may automate the sending of certain messages (including commercial and marketing messages) as soon as you provide us with personal data (for example, an e-mail address in a registration form provided for this sole purpose) or during a procedure related to the receipt of messages.

In addition, we accompany our commercial and marketing messages with an optional procedure for refusing any other marketing and commercial message of the same type (for example, by unsubscribing). Simply follow the unsubscribe procedure or instructions contained in such marketing and commercial messages.

It should be noted that even in the event you refuse to receive any commercial or marketing messages emanating from our company, you remain likely to receive messages from us, concerning for example news, information relating to your account, certain obligatory messages, etc.

•  Customer Service Department

For any further assistance, do not hesitate to contact Customer Service, by post or by e-mail at the following addresses: M2A, 24 rue Laure Diebold 69009 LYON, France

contact@herbalifeukclothing.com

 

Please note that it is your responsibility to ensure the correctness and accuracy of your account details (including your e-mail address) and to notify us if your e-mail account changes or is closed.

Our company declines all liability in the event a message is misdirected (for example, sent to an e-mail address that you no longer use), knowing that messages of this type are likely to reveal data concerning you to third parties.

Our security measures

 

Our company undertakes to implement the necessary measures required to ensure the security of the processing of personal data, in accordance with data protection regulations.

All technical, administrative and physical security measures with regard to the nature of the data have been taken to preserve the security of your data and to prevent it from being distorted, damaged or accessed by unauthorized third parties.

We also provide ad hoc assessments of our own security protocols in order to take the necessary measures to deal with possible new or unprecedented technologies and methods. However, despite the extent of our initiatives and the measures put in place, no security protocol can be perfect, infallible or impenetrable.

For your complete information, in the event we subcontract, in part or in full, the processing of personal data, our company approves in cooperation with its subcontractors guarantees of personal data security and privacy using technical measures to protect this data and the appropriate human resources.

 

Privacy policy updates

 

This Privacy Policy may be modified or amended at any time. If we make material changes to our protocols for collecting, using, or sharing your personal information, a prominent notice will be posted on the e-commerce site notifying visitors of the changes to this Privacy Policy. Any material changes to this Privacy Policy will be effective within 30 days of posting notice of the change to this Privacy Policy.

 

Last modification: 26 Mars 2026