Privacy Policy

Updated 12/30/19

TONI&GUY USA, LLC, TONI&GUY Hairdressing Academy USA, LLC, TONI&GUY Salon Franchising Company, LLC, TONI&GUY Hairdressing Academy Franchise, LLC and their affiliate companies (collectively, “TONI&GUY” or “we” or “us”) respect the privacy of our online visitors. If we make a material change to this Privacy Policy we will notify you by posting the change on our main website www.toniguy.edu or www.toniguy.com (the “Site”) or in this Privacy Policy and, if necessary, give you additional choices regarding such change prior to the change becoming effective. Your continued use of the TONI&GUY websites (the “TONI&GUY Websites”) will signify your acceptance to this Privacy Policy and of any changes.

TONI&GUY collects private data about you from various sources. We may collect this when you provide information at one of our TONI&GUY Hairdressing Academies, TONI&GUY Hairdressing Salons, through our interactions with you through the TONI&GUY Websites, when you register to book appointments online, when you make appointments by telephone, and through providing our services. You provide some of this data directly, and we get some of it by collecting data about your interactions, use, and experiences with our services and the TONI&GUY Websites. The data we collect depends on the context of your interactions with TONI&GUY and the choices you make, including your privacy settings and the products and features you use. When you visit the TONI&GUY Websites, we may also collect certain information by automated means, using technologies such as cookies, web server logs and web beacons. The types of personal data (“Personal Data”) you provide us usually include: (1) contact information, (2) gender, (3) age and birth date, (4) account registration information such as username and password, (5) payment information, (6) survey opinions or testimonials, (7) IP address, (8) physical location, (9) information provided on waiver forms at salon and academy locations, and/or (10) content you provide such as photographs and comments.

From time to time, we may post customer testimonials that contain Personal Data on the TONI&GUY Websites. We obtain the customer’s consent to post these testimonials prior to publication. We may use the information you provide to: send you promotional materials or other communications regarding the TONI&GUY Hairdressing Academies and/ or Salons, or advanced education; provide services to you; process your payment card transactions; create and manage your online account; respond to your inquiries; forward your information to the TONI&GUY Hairdressing Academy and/ or the TONI&GUY Hairdressing Salon you are interested in so that they may contact you; operate, evaluate, and improve our business (such as analyzing data and evolving our services, communications, and products); and comply with legal requirements. We also may use the information in other ways for which we provide specific notice at the time of collection.

We use third party web analytics services on the TONI&GUY Websites. Such third party web analytics service providers may include, but are not limited to, Google Analytics, HubSpot and Facebook. The service providers that administer these services use technologies such as cookies, web server logs and web beacons to help us analyze how visitors use the TONI&GUY Websites. We do this to better understand and serve our customers. The information collected through these means (including IP address and user location) is disclosed to these service providers, who use the information for the purpose of evaluating consumer use of the TONI&GUY Websites, compiling reports on the TONI&GUY Websites activity for our use, and providing other services relating to the TONI&GUY Websites activity and usage. To disable the Google Analytics, HubSpot and Facebook cookies and any other third party web analytics service provider cookies, some browsers indicate when a cookie is being sent and allow you to decline cookies on a case-by-case basis. The TONI&GUY Websites may include social media features such as the Facebook “Like” button and other widgets such as the Share button or interactive features that run on the TONI&GUY Websites. These features may collect your IP address, which page you are visiting on our websites, and may set a cookie to enable the feature to function properly. Social media widgets and other features are either hosted by a third party or hosted directly on the TONI&GUY Websites. Your interactions with these features are governed by the privacy policy of the company providing it. We recommend that you read the privacy policy of any third party website you may be directed to before providing any personally identifiable information.

We may offer you certain choices regarding the Personal Data we collect from you. At the time you provide Personal Data, TONI&GUY may give you the option of declining any future offers or information about new products, promotions or services. In addition, many of the communications, such as promotions or newsletters, have procedures within them to unsubscribe from receiving them in the future. To update your preferences, ask us to remove your information from our mailing lists. We will apply your preferences going forward. This Privacy Policy may be updated periodically and without prior notice to you to reflect changes in our Personal Data practices. This Privacy Policy does not address the information practices of TONI&GUY Hairdressing Salons or other TONI&GUY Hairdressing Academies managed by parties other than TONI&GUY, such as for example franchised locations. Such other TONI&GUY locations may have their own privacy notices or policies, which we strongly suggest you review when you provide them with your Personal Data. We are not responsible for such other TONI&GUY Hairdressing Salons or Academies Personal Data practices.

We do not sell or otherwise disclose Personal Data we collect about you, except as described here. We may share your Personal Data with: our affiliates; service providers who perform services on our behalf based on our instructions, including but not limited to services such as payment processors for payment transactions, financial services or fraud prevention; our TONI&GUY Hairdressing Academies or Salons or other TONI&GUY locations you are interested in, which may be managed by third parties other than TONI&GUY; and/or other third parties with your consent. We may share Personal Data with a limited number of approved vendors, which are unaffiliated entities that make available TONI&GUY-branded products, services, or discounts. We may share Personal Data with vendors and social media networks we hire to provide services or perform business functions on our behalf (such as print, mail, or email vendors; web hosting vendors; cloud service providers; consultants; digital advertising and analytics vendors; and contest or sweepstakes operators). These vendors are contractually required to treat the Personal Data provided as confidential. The TONI&GUY Websites may have message boards, forums, and/or chat areas where users can exchange ideas and communicate with each other. When posting to these areas, please be aware that the information is being made publicly available online and the user does so at his or her own risk.

In addition, we may disclose information about you (i) if we are required to do so by law or legal process, (ii) to law enforcement authorities or other government officials, or (iii) when we believe disclosure is necessary or appropriate to prevent physical harm or financial loss, or in connection with an investigation of suspected or actual fraudulent or illegal activity. We also reserve the right to transfer Personal Data we have about you in the event we sell or transfer all or a portion of our business or assets. This is so you can continue to receive service and information in connection with that line of business with as little disruption as possible. Similarly, in the event of a merger, acquisition, reorganization, bankruptcy, or other similar event, your Personal Data may be transferred to TONI&GUY’s successor or assign. Should such a sale or transfer occur, we will use reasonable efforts to direct the transferee to use Personal Data you have provided to us in a manner that is consistent with our Privacy Policy. Following such a sale or transfer, you may contact the entity to which we transferred your Personal Data with any inquiries concerning the processing of that information.

If you are under thirteen years of age, you may browse the TONI&GUY Websites. However, you may not provide Personal Data to us. The TONI&GUY Websites are not directed to children under the age of thirteen and we do not knowingly collect Personal Data from children under the age of thirteen on the TONI&GUY Websites.

PRIVACY NOTICE FOR CALIFORNIA RESIDENTS:

Summary:

This Privacy Notice for California Residents supplements our Privacy Policy and applies solely to TONI&GUY consumers, as defined below. In the event of any conflict between the terms of this notice with respect to California Consumers only (as defined herein) and the Privacy Policy, the terms of the notice in this section prevail.

Beginning January 1, 2020, if you are a resident of California, you will have additional rights under the California Consumer Privacy Act (the “CCPA”) with respect to your Personal Information (as defined in this notice), as outlined below.

Definitions:

  1. Consumer: natural persons who reside in California, including (1) individuals who are in California for other than a temporary and transitory purpose; and (2) individuals who are domiciled in California, but are outside the state for a temporary or transitory purpose.
  2. CCPA: the California Consumer Privacy Act of 2018, effective as of January 1, 2020, as amended or replaced from time to time, along with any implementing regulations.
  3. Personal Information: as defined in the CCPA, and includes information that can be used to identify you, either alone or in combination with other information, and any other information that could reasonably be linked with a particular Consumer or device. Personal Information includes any information that identifies, relates to, describes, or is capable of being associated with, a particular individual, including, but not limited to, his or her name, signature, social security number, physical characteristics or description, address, telephone number, passport number, driver's license or state identification card number, education, employment, employment history, bank account number, credit card number, debit card number, or any other financial information, medical information, or health insurance information. “Personal Information” does not include publicly available information that is lawfully made available to the general public from federal, state, or local government records.
  4. Registration Information: information you provide about yourself when registering for and/or purchasing our services (e.g. name, email, address, user ID and password, and payment information).
  5. Self-Reported Information: information you provide directly to us, either through the services or through a third party, and other information that you enter into surveys, forms, or features while signed in to your TONI&GUY account.
  6. Sensitive Information: certain Self-Reported Information such as gender and racial and ethnic origin.
  7. User Content: information, data, text, software, music, audio, photographs, graphics, video, messages, or other materials - other than Self-Reported Information-generated by users of TONI&GUY Services and transmitted, whether publicly or privately, to or through TONI&GUY.
  8. Inferences and Derived Data: information, data, assumptions, or conclusions that are derived directly or indirectly from another source of Personal Information.
  9. Web-Behavior Information: information on how you use our services collected through log files, cookies, web beacons, and similar technologies, (e.g., device information (device identifiers), IP address, browser type, domains, page views).

Consumer Rights:

I. Notice and access.

As a Consumer, you have the right to know:

  1. The categories of Personal Information we collect about you;
  2. The categories of sources from which the information was collected;
  3. The business or commercial purpose for collecting, disclosing, or selling Personal Information; and
  4. The categories of third parties we have disclosed Personal Information to for a business purpose and the categories of Personal Information disclosed.

You may request that TONI&GUY provide you access to the specific pieces of Personal Information collected about you in a readily usable format.

Your access rights under the CCPA are not absolute. Specifically, the CCPA limits the information you can request to Personal Information collected in the 12-month period preceding our receipt of the request. Additionally, under the CCPA, TONI&GUY is not obligated to respond to requests for access to Personal Information more than twice in a twelve month period. Further, in connection with any request made under the CCPA, TONI&GUY will need to collect information from you in order to verify your identity.

II. Deletion.

You may request that TONI&GUY delete the Personal Information we process about you, subject to certain limitations. Your Personal Information may not be deleted if the information is needed to:

  1. Complete the transaction for which the Personal Information was collected, provide a good or service requested by the Consumer, or reasonably anticipated within the context of a business’s ongoing business relationship with the Consumer, or otherwise perform a contract between the business and the Consumer.
  2. Detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity; or prosecute those responsible for that activity.
  3. Debug products to identify and repair errors that impair existing intended functionality.
  4. Exercise free speech, ensure the right of another Consumer to exercise his or her right of free speech, or exercise another right provided for by law.
  5. Comply with the California Electronic Communications Privacy Act pursuant to Chapter 3.6 (commencing with Section 1546) of Title 12 of Part 2 of the Penal Code.
  6. Engage in public or peer-reviewed scientific, historical, or statistical research in the public interest that adheres to all other applicable ethics and privacy laws, when the businesses’ deletion of the information is likely to render impossible or seriously impair the achievement of such research, if the consumer has provided informed consent.
  7. To enable solely internal uses that are reasonably aligned with the expectations of the Consumer based on the Consumer’s relationship with the business.
  8. Comply with a legal obligation.
  9. Otherwise use your Personal Information, internally, in a lawful manner that is compatible with the context in which you provided the information.

III. Opt-out of sales.

The CCPA provides you the right to opt-out of having your Personal Information sold by a business. TONI&GUY does not sell Personal Information to third parties. You are entitled to contact us to prevent disclosure of Personal Information to third parties for such third parties’ direct marketing purposes; in order to submit such a request, please contact us at DataPrivacy@toniguy.com.

IV. Non-discrimination.

The CCPA prohibits businesses from discriminating against a consumer for exercising their rights under the CCPA. TONI&GUY will not discriminate against you for exercising any of your CCPA rights.

V. Designated methods for submitting rights requests.

For additional details regarding account deletion, see our Privacy Policy.

If you have not created a TONI&GUY account, you may contact us directly to submit your request by emailing DataPrivacy@toniguy.com with the subject line “CCPA Rights Request” or calling our Chief Data Protection Officer at 214-273-2250.

VI. Verifying consumer requests.

Only you or someone legally authorized to act on your behalf may make a verifiable consumer request related to your Personal Information. Your request must:

  1. Provide sufficient information that allows us to verify you are the person about whom we collected Personal Information or an authorized representative.
  2. Describe your request with sufficient detail that allows us to properly understand, evaluate, and respond to it.

Generally, requests submitted through your TONI&GUY account will be considered sufficiently verified when the request relates to Personal Information associated with that specific account. However, if you have not created, or no longer have access to your TONI&GUY account, we may request additional materials or information for the purposes of validating the authenticity of your request.

TONI&GUY will use the information provided in connection with a verification request solely for the purposes of verification. We cannot fulfill your request if we are unable to verify your identity or authority to make the request and confirm that the Personal Information relates to you.

There may be other situations where TONI&GUY is unable or not required to fulfill your request. In such circumstances, TONI&GUY will respond to your request within the period required by the CCPA. The response will provide relevant details regarding TONI&GUY’s determination and any additional, pertinent information about your request.

Categories of Personal Information collected:

When you choose to use our services, including visiting the TONI&GUY Websites, we may collect and process your Personal Information. TONI&GUY has collected the following categories of Personal Information from its consumers within the last twelve (12) months as necessary to provide our services and/or as otherwise allowed under our Privacy Policy. The categories of Personal Information and other terms used below are defined in California Civil Code 1798.140.


I. Information you provide directly to us.

Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Identifiers
  • Registration Information, such as your name and email address.
  • User Content, such as your government-issued ID which may be requested in exceptional circumstances to assist you in regaining access to your account.
  • Web-Behavior Information, such as your device ID or IP address, automatically collected when you visit the TONI&GUY Websites.
  • Generally identifiers are provided directly to us, collected automatically when you visit the TONI&GUY Websites, or created on your behalf when you sign up for our services to allow TONI&GUY to provide our services.
  • Provide you with products and services and analyze and improve our products and services (Read more in our Privacy Policy)
  • Allow you to share your Personal Information with others
  • Allow you to share your Personal Information for research purposes
  • Provide customer support
  • Conduct surveys or polls, and obtain testimonials
  • Provide you with marketing communications
  • Identifiers are sometimes processed by our third party service providers for the following purposes:
  • Audit
  • Security
  • Debugging
  • Transient use
  • Quality assurance and product improvement
Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Personal Information categories listed in the California Customer Records statute (Cal. Civ. Code §1798.80(e)) and also defined above herein
  • Registration Information, such as your name and address.
  • Self-Reported Information, such as details about your employment or education.
  • User Content, such as your government-issued identification which may be requested in exceptional circumstances to assist you in regaining access your account.
  • Information filled out on waiver forms for certain services provided at TONI&GUY salons and academies
  • Payment information
  • Some Personal Information included in this category may overlap with other categories.
  • Provide you with products and services and analyze and improve our products and services
  • Allow you to share your Personal Information with others
  • Allow you to share your Personal Information for research purposes
  • Provide customer support
  • Provide you with marketing communication
  • Reporting and measurement
  • Improvement and development of product features
  • Personal Information is sometimes processed by our service providers for the following purposes:
  • Audit
  • Security
  • Transient use
  • Quality assurance and product improvement
Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Commercial information
  • Self-Reported Information, such as survey responses regarding past purchasing history or information filled out on waiver forms.
  • ser Content, such as information you share on TONI&GUY forums about products you purchased or considered.
  • Generally, this information is collected directly from you.
  • Provide you with products and services and analyze and improve our products and services
  • Allow you to share your Personal Information for research purposes
  • Recruit you for external research
  • Provide customer support
  • Conduct surveys or polls, and obtain testimonials
  • Provide you with marketing communications
  • Commercial information is sometimes processed by our service providers for the following purposes:
  • Audit
  • Security
  • ransient use
  • Quality assurance and product improvement
Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Professional, education, or employment-related information.
  • Self-Reported Information including education, household income, occupation, and other professional information.
  • Generally, this information is collected directly from you.
  • Allow you to share your Personal Information for research purposes
  • Recruit you for external research
  • Provide customer support
  • Conduct surveys or polls, and obtain testimonials
  • Provide you with marketing communications
  • Professional, education and employment-related information is sometimes processed by our service providers for the following purposes:
  • Quality assurance and product improvement

II. Information collected through tracking technology (e.g. from cookies and similar technologies).

Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Internet or other electronic network activity information
  • Web-Behavior Information, including data generated from your use of our services and collected through web server log files, cookies, web beacons, widgets and similar technologies, (e.g., browser type, domains, page views).
  • Our Privacy Policy contains more information about how TONI&GUY processes Web-Behavior Information.
  • Provide you with products and services and analyze and improve our products and services
  • Allow you to share your Personal Information with others
  • Allow you to share your Personal Information for research purposes
  • Recruit you for external research
  • Provide customer support
  • Conduct surveys or polls, and obtain testimonials
  • Provide you with marketing communications
  • Internet information is sometimes processed by our service providers for the following purposes:
  • Audit
  • Security
  • Debugging
  • Transient use
  • Quality assurance and product improvement
Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Geolocation data
  • Web-Behavior Information that includes the identification or estimation of physical location or movement.
  • Our Privacy Policy contains more information about how TONI&GUY processes Web-Behavior Information.
  • Provide you with products and services and analyze and improve our products and services
  • Allow you to share your Personal Information with others
  • Allow you to share your Personal Information for research purposes
  • Recruit you for external research
  • Provide customer support
  • Conduct surveys or polls, and obtain testimonials
  • Provide you with marketing communications
  • Geolocation data is sometimes processed by our service providers for the following purposes:
  • Audit
  • Security
  • Debugging
  • Transient use
  • Quality assurance and product improvement

III. Derived information created from other Personal Information.

Information Type Description Business or commercial purpose(s) of collection Business purpose(s) for disclosure
Inferences and Derived Data
  • Inferences and Derived Data are any information, data, assumptions, or conclusions TONI&GUY infers based on analyses of facts, evidence, or another source of information or data.
  • TONI&GUY may derive data to better understand and serve our customers, and to analyze how visitors use the TONI&GUY Websites.
  • Generally this information is created by TONI&GUY and not collected directly from you. TONI&GUY may derive information from data that was collected in relation to our services, directly from you, or through tracking technology.
  • Provide you with products and services and analyze and improve our products and services
  • Allow you to share your Personal Information with others
  • Allow you to share your Personal Information for research purposes
  • Recruit you for external research
  • Conduct surveys or polls, and obtain testimonials
  • Provide you with marketing communications
  • Inferences and derived data are sometimes processed by our service providers for the following purposes:
  • Audit
  • Security
  • Debugging
  • Transient use
  • Quality assurance and product improvement

IV. Disclosures of Personal Information for a business purpose.

TONI&GUY may share information listed above under “Categories of Personal Information collected” with our service providers for operational business purposes including:

  • Audit: Auditing related to a current interaction and concurrent transactions.
  • Security: Detecting security incidents, protecting against malicious, deceptive, fraudulent, or illegal activity, and prosecuting those responsible for that activity.
  • Debugging: Debugging to identify and repair errors that impair existing intended functionality.
  • Transient use: Short-term, transient use, where Personal Information is not disclosed to another third party and is not used to build a profile about a consumer or otherwise alter an individual consumer’s experience outside the current interaction.
  • Quality assurance and product improvement: Activities to verify or maintain the quality or safety of a service or device that is owned, manufactured, manufactured for, or controlled by TONI&GUY, and otherwise to improve, upgrade, or enhance the service or device that is owned, manufactured, manufactured for, or controlled by TONI&GUY.

V. Disclosures of Personal Information for a commercial purpose.

If you have given your explicit consent, for example via a data transfer authorization or other consent document, we may disclose the categories of Personal Information detailed above for commercial purposes. The purpose, such as recruitment for external research, may vary and will be specified in the consent.

Changes to this notice

TONI&GUY will review and update this notice at least once every 12 months and more frequently as needed. We recommend visiting this page periodically to stay aware of any changes. If we modify this notice, we will make the revised notice available through the TONI&GUY Websites.

Contact information

If you have questions about this section or our data practices generally, or if you wish to submit a complaint, request or inquiry, please contact TONI&GUY’s Chief Data Collection Officer at DataPrivacy@toniguy.com, or send a letter to:

TONI&GUY
Attn: Privacy Policy/Legal
4251 Kellway Circle
Addison, TX 75001
214-273-2250

PRIVACY NOTICE TO EU RESIDENTS

Legal Basis for Processing Information: If you are located in the EU or Switzerland, we rely on several legal bases to process your Personal Information. These legal bases include where:

  • The processing is necessary to perform our contractual obligations, such as to provide you with our services;
  • You have given your prior consent, which you may withdraw at any time (such as for marketing purposes or other purposes we obtain your consent for from time to time);
  • The processing is necessary to comply with a legal obligation, a court order or to exercise or defend legal claims;
  • The processing is necessary for the purposes of our legitimate interests, such as in improving, personalizing, and developing our services, marketing new features or products that may be of interest, and promoting safety and security as described above.

If you have any questions about, or would like further information concerning the legal basis on which we collect and use your Personal Information, please contact us by emailing DataPrivacy@toniguy.com.

Rights Under the General Data Protection Regulation: If you are located in the EU or Switzerland, you have the following rights with regard to your personal data that we hold:

  • Right of access. The right to obtain access to your personal data.
  • Right to rectification. The right to obtain rectification of your personal data without undue delay where that personal data is inaccurate or incomplete.
  • Right to erasure. The right to obtain the erasure of your personal data without undue delay in certain circumstances, such as where the personal data is no longer necessary in relation to the purposes for which it was collected or processed.
  • Right to restriction. The right to obtain the restriction of the processing undertaken by us on your personal data in certain circumstances, such as where the accuracy of the personal data is contested by you, for a period enabling us to verify the accuracy of that personal data.
  • Right to portability. The right to portability allows you to move, copy or transfer personal data easily from one organization to another.
  • Right to object. You have a right to object to processing based on legitimate interests and direct marketing.

If you wish to exercise one of these rights, please email us at DataPrivacy@toniguy.com.You also have the right to lodge a complaint to your local data protection authority. Further information about how to contact your local data protection authority is available at http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm.

Obligations to Data Protection Officers: We will respond diligently and appropriately to requests from a Data Protection Officer (“DPA”) about this policy or compliance with applicable data protection privacy laws and regulations. We will, upon request, provide DPAs with names and contact details of the individuals designated to handle this process. With regard to transfers of Personal Information, we will (1) cooperate with inquiries from the DPA responsible for the entity exporting the data and (2) respect its decisions, consistent with applicable law and due process rights. With regard to transfers of data to third parties, we will comply with DPAs’ decisions relating to it and cooperate with all DPAs in accordance with applicable legislation.