Your Bag


It is important that you read this Privacy Policy together with any other privacy notice or fair processing notice we may provide on specific occasions when we are collecting or processing personal information about you so that you are fully aware of how and why we are using your information. This Privacy Policy explains how personal information will be treated as you access and interact with KOOKAÏ.

If you are under 18, please make sure your parent or guardian reads and explains the following information to you.

  1. KOOKAÏ’s Privacy Obligations

The websites,,, and (the, ‘Websites’) are operated by or on behalf of Magi Enterprises Pty Ltd ABN 491 544 236 13 or entities within the KOOKAÏ corporate group  as listed in clause 12 below (‘Related Entities’), trading as 'KOOKAÏ' (‘KOOKAÏ’, ‘we’, ‘us’ or ‘our’). KOOKAÏ is the controller responsible for your personal information. A reference in this Privacy Policy to KOOKAÏ, we, us or our also refers to our Related Entities.

KOOKAÏ respects the privacy of your personal information as a visitor to the Websites and is bound by the Australian Privacy Principles under the Privacy Act 1988 (Cth), the Privacy Act 1993 (NZ) (together, the ‘Acts’) the Data Protection Act 2018 (UK) and the General Data Protection Regulation (together, the ‘GDPR’) and other laws which may be enacted to protect your privacy from time to time. 

All personal information held by us will be governed by our most recent Privacy Policy, posted on the Websites. We will post any changes to this Privacy Policy on the Websites, including to take into account new laws, regulations, practices and technology. Please check this Privacy Policy for updates from time to time. In addition to the Privacy Policy, there may also be specific and additional privacy provisions that apply to certain sections of the Websites and/or your interactions with KOOKAÏ – you should read and consider these wherever they appear. In the event of any inconsistency between this Privacy Policy and the specific provisions, the specific provisions will apply.

It is important that the personal information we hold about you is accurate and current. Please keep us informed if your personal information changes during your relationship with us. We have appointed a Privacy and Data Protection Officer (‘PDPO’) who is responsible for overseeing questions in relation to this privacy notice. If you wish to make any inquiries regarding this Privacy Policy, you should contact our PDPO in any of the ways specified in clause 10 below.

  1. Collection and Use of Personal Information

When referring to 'personal information', we mean information or an opinion, whether true or not, and whether recorded in a material form or not, about an identified individual or an individual who is reasonably identifiable. Your name, age, postal and email address, phone number and payment details (such as your credit card details and billing address) as well as your resume, skills, qualifications and residency status are examples of personal information. 

(a)   Information collected

KOOKAÏ may, from time to time, collect personal information about you in the course of its business in a number of different ways, including when you:

  • Visit our Websites or social media;
  • Visit our boutiques;
  • Enter a competition, promotion or survey;
  • Sign up for our mailing list/newsletter;
  • Enquire about or order products through our Websites or via phone;
  • Apply for a position with KOOKAÏ;
  • Provide feedback;
  • Fill in a form on our Websites; and/or
  • Otherwise contact us.

Personal information may be collected by us and by our third-party service providers who assist us in operating the Websites and the KOOKAÏ business.

Google Analytics

We use Google Analytics to help analyse how you use our Websites. Google Analytics generates statistical and other information about website use by means of cookies. Google will store this information.

If you do not want your website visit information reported by Google Analytics, you can install the Google Analytics opt-out browser add-on. For more details on installing and uninstalling the add-on, please visit the Google Analytics opt-out page at

Click Stream Information

In common with many websites, when you read, browse or download information from our Websites, we or our internet service provider may also collect information such as the date and time of your visit to the Websites, the pages accessed and any information downloaded. This information is used for statistical, reporting and website administration, maintenance and improvement purposes only.


Like many websites, our Websites may use ‘cookies’ from time to time. For more information about the cookies we use, please see our Cookies Policy.

Cookies are small text files that we transfer to your computer's hard drive through your web browser to enable our systems to recognise your browser. Cookies may also be used to record non-personal information such as the date, time or duration of your visit, or the pages accessed, for website administration, statistical and maintenance purposes. Any such information will be aggregated and not linked to particular individuals.

Cookies may also be used for other purposes on our Websites but in each case none of the information collected can be used to personally identify you. The default settings of browsers like Internet Explorer always allow cookies, but users can easily erase cookies from their hard-drive, block all cookies, or receive a warning before a cookie is stored. Please note that some parts of the Websites may not function fully for users that disallow cookies.

While we take great care to protect your personal information, unfortunately no data transmission over the Internet can be guaranteed to be 100% secure. Accordingly, we cannot ensure or warrant the security of any information you send to us or receive from us online. This is particularly true for information you send to us via email. We have no way of protecting that information until it reaches us.

Security of your information on the Websites

Once we receive your transmission, we make our best effort to ensure its security in our possession. The Websites may contain links to other sites. We are not responsible for the privacy practices or policies of those sites.

(b)  Use of personal information

KOOKAÏ will only use the information we collect about you for purposes connected with our business operations. Below we set out a description of the ways we plan to use your personal information and the legal bases we rely on to do so.


Enabling you to enter an online competition or promotion.    

(a)        Identification details

(b)        Contact Details

(c) Details of how you use our Websites

(d)        Marketing and Communication preferences

(e)Technical information about your device and browser

Performance of a contract with you

 Necessary for our legitimate interests (to study how customers use our products/services, to develop them and grow our business)

Processing your payments for purchasing any products

(a)        Identification details

(b)        Contact Details

(c)        Your payment details

(d) Details of your transactions on our Websites

(e)        Marketing and Communication preferences


Performance of a contract with you

Necessary for our legitimate interests (to recover debts due to us)

Providing purchased goods or services to you


(a)        Identification details

(b)        Contact Details

(c) Purchase information

(d) Details of how you use our Websites

(e)        Marketing and Communication preferences

 Performance of a contract with you

Providing advertising material to you regarding us, our clients, and other third parties such as our sponsors and business partners

(a)        Identification details

(b)        Contact Details

(c) Details of how you use our Websites

(d)        Marketing and Communication preferences

(e)Technical information about your device and browser

Necessary for our legitimate interests (to study how customers use our products/services, to develop them, to grow our business and to inform our marketing strategy)

Responding to questions about our products and services

(a)        Identification details

(b)        Contact Details

(c)        Account login and password

(d) Details of how you use our Websites

(e)        Marketing and Communication preferences

5.               (f) Technical information about your device and browser

Performance of a contract with you

Necessary to comply with a legal obligation

Developing and improving our products and business

(a)        Identification details

(b)        Contact Details

(c) Details of how you use our Websites

(d)        Marketing and Communication preferences

(e)Technical information about your device and browser

Necessary for our legitimate interests (to define types of customers for our products and services, to keep our Websites updated and relevant, to develop our business and to inform our marketing strategy)

Assessing your suitability for employment with KOOKAÏ (if you apply for a job online)

(a)          Identification details

(b)         Contact details

(c)          Resume, CV, skills, qualifications

(d)         Referee and police checks

Necessary for our legitimate interests in assessing suitability for employment


We may also use your personal information for other more specific purposes for which it was collected which were notified to you at the time of collection.

We will only use your personal information for the purposes for which we collected it, unless we reasonably consider that we need to use it for another reason and that reason is compatible with the original purpose. If you wish to get an explanation as to how the processing for the new purpose is compatible with the original purpose, please contact us.

Please note that we may process your personal information without your knowledge or consent, in compliance with the above rules, where this is required or permitted by law.

If you choose not to provide your personal information to us for the purposes set out in this Privacy Policy, we may not be able to undertake certain activities for you such as providing you with requested information, products or services, or allowing you to enter competitions and promotions.

(c)   Disclosure of personal information

KOOKAÏ will not otherwise disclose your personal information without your permission, unless the disclosure is:

  • In accordance with this Privacy Policy or any agreement you enter into with us; or
  • Required or authorised by law, including without limitation under the Acts and the GDPR.

KOOKAÏ may disclose, or provide access to, your personal information to third parties in connection with the purposes described in 2(b) of KOOKAÏ’s Privacy Policy.

We may disclose your personal information:

  • To third party service providers appointed by KOOKAÏ to perform services for us or on our behalf (such as order fulfilment, reference and police checks, website and data hosting providers, payment processing services and PR agencies);
  • To Related Entities;
  • As required or authorised by law;
  • To third parties to whom we may choose to sell, transfer, or merge parts of our business or our assets; or;
  • Otherwise with your consent.

We require all third parties to respect the security of your personal information and to treat it in accordance with the law. We do not allow our third-party service providers to use your personal information for their own purposes and only permit them to process your personal information for specified purposes and in accordance with our instructions.

For visitors to the Websites located in the European Economic Area (‘EEA’), your personal information will be transferred outside the European Economic Area (‘EEA’).

KOOKAÏ, its Related Entities and some of our third-party service providers may be based outside of the EEA.

Whenever we transfer your personal information out of the EEA, we ensure a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

  • We transfer personal information pursuant to binding corporate rules of KOOKAÏ and its Related Entities.
  • We use specific contracts, or data protection clauses, which have been adopted or approved by the Information Commissioner’s Office or the European Commission which give personal information the same protection it has in Europe.
  • Where we use providers based in the US, we may transfer information to them if they are part of the Privacy Shield which requires them to provide similar protection to personal information shared between the Europe and the US

Please Contact Us if you want further information on the specific mechanism used by us when transferring your personal information out of the EEA.

  1. Opt out

If you decide that you no longer want to receive KOOKAÏ emails or other marketing messages then please use the unsubscribe feature set out in the email or write to:

The Privacy and Data Protection Officer


8-14 Hall Street, Hawthorn East

Victoria 3123 Australia


Where you opt out of receiving marketing messages, we may still need to contact you as a result of a product purchase.

  1. Security of personal information

Irrespective of whether personal information is stored electronically or in hard copy form, KOOKAÏ will take reasonable steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification or disclosure. However, except to the extent liability cannot be excluded due to the operation of statute, we exclude all liability for the consequences of any unauthorised access.

In addition, we limit access to your personal information to those employees, agents and contractors who have a business need to know. They will only process your personal information on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected personal information breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

  1. Information Retention

We will only retain your personal information for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements.

To determine the appropriate retention period for personal information, we consider the amount, nature, and sensitivity of the personal information, the potential risk of harm from unauthorised use or disclosure of your personal information, the purposes for which we process your personal information and whether we can achieve those purposes through other means, and the applicable legal requirements.

Details of retention periods for different aspects of your personal information are available in our Retention Policy which you can request from us by Contacting Us

In some circumstances we may anonymise your personal information (so that it can no longer be associated with you) for research or statistical purposes in which case we may use this information indefinitely without further notice to you.

  1. Accessing and updating your personal information and further information

Under certain circumstances, you will have certain rights in relation to your personal information, including to give you the right to access or correct your personal information.

In certain circumstances, as set out in the Acts and GDPR, we may not be required by law to provide you with access or to correct your personal information. If that is the case, we will give you our reasons for that decision to the extent that it is reasonable to do so. We take reasonable steps to make sure that the personal information we collect, use and disclose is accurate, complete and up-to-date.

You have the right to:

Request access to your personal information. This enables you to receive a copy of the personal information we hold about you and to check that we are lawfully processing it.

Request correction of the personal information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected, though we may need to verify the accuracy of the new information you provide to us.

Request erasure of your personal information. This enables you to ask us to delete or remove personal information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your personal information where you have successfully exercised your right to object to processing (see below), where we may have processed your information unlawfully or where we are required to erase your personal information to comply with local law.

Object to processing of your personal information where we are relying on a legitimate interest (or those of a third party) and there is something about your particular situation which makes you want to object to processing on this ground as you feel it impacts on your fundamental rights and freedoms. You also have the right to object where we are processing your personal information for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.

Request restriction of processing of your personal information. This enables you to ask us to suspend the processing of your personal information in the following scenarios: (a) if you want us to establish the information’s accuracy; (b) where our use of the information is unlawful but you do not want us to erase it; (c) where you need us to hold the information even if we no longer require it as you need it to establish, exercise or defend legal claims; or (d) you have objected to our use of your information but we need to verify whether we have overriding legitimate grounds to use it.

Request the transfer of your personal information to you or to a third party. We will provide to you, or a third party you have chosen, your personal information in a structured, commonly used, machine-readable format. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.

Withdraw consent at any time where we are relying on consent to process your personal information. However, this will not affect the lawfulness of any processing carried out before you withdraw your consent. If you withdraw your consent, we may not be able to provide certain products or services to you. We will advise you if this is the case at the time you withdraw your consent.

      7. No Fee Usually Required

You will not have to pay a fee to access your personal information (or to exercise any of the other rights listed in clause 6). However, we may charge a reasonable fee if your request is clearly unfounded, repetitive or excessive. Alternatively, we may refuse to comply with your request in these circumstances.

  1. What We May Need From You

We may need to request specific information from you to help us confirm your identity and ensure your right to access your personal information (or to exercise any of your other rights). This is a security measure to ensure that personal information is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our responses.

  1. Time Limit To Respond

We try to respond to all legitimate requests within one month. Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

  1. Concerns about Privacy

If you:

  • have a query or are concerned that KOOKAÏ may have breached the Acts, GDPR or this Privacy Policy;
  • wish to make a complaint in relation to a breach of your privacy;
  • would like to access your personal information held by us;
  • would like to correct your personal information held by us; or
  • would like to opt out of direct marketing,

please contact our PDPO in any of the following ways:

  • by mail at:

The Privacy and Data Protection Officer


8-14 Hall Street

Hawthorn East VIC 3123, Australia; or

  • by phone on +613 9804 7906.
  • By email via

We will investigate your queries and complaints within a reasonable period of time of receiving the complaint and will notify you of the outcome of our investigation.

For information about privacy generally, or if your concerns are not resolved to your satisfaction, you can contact the relevant privacy, data protection or information office in your country of residence:


Office of the Australian Information Commissioner

1300 363 992 or via


New Zealand

Office of the Privacy Commissioner



United Kingdom

Information Commissioner’s Office



United States

Federal Trade Commission



  1. Third-Party Links  


The Websites may include links to third-party websites, plug-ins and applications. Clicking on those links or enabling those connections may allow third parties to collect or share information about you. We do not control these third-party websites and are not responsible for their privacy statements. When you leave our Websites, we encourage you to read the privacy notice of every website you visit.

  1. KOOKAI and Related Entity Details


Magi Enterprises Pty Ltd

8-14 Hall Street

Hawthorn East VIC 3123 Australia


Magi Enterprises UK Ltd

27-28 Eastcastle Street

London, W1W 8DH


Beba New Zealand Limited

8-14 Hall Street

Hawthorn East VIC 3123 Australia


Magi Corporation Pty Ltd

8-14 Hall Street

Hawthorn East VIC 3123 Australia


Kookai SAS

6-10 boulevard Foch 93807

Epinay-sur-Seine Cedex



Last updated: 30 July 2018



Top Top