Privacy policy
In accordance with the provisions of the legislation in force on the protection of personal data, we inform you that your data will be integrated into the processing system belonging to XXXXXX whose registered office is located at 17 avenue de Villier, 75017 Paris
Manager of the processing
According to article 4.7 of the RGPD, XXXXXX is the controller of the personal data collected on the website https://www.XXXXXX.com. XXXXXX determines the purposes and means of the processing carried out.
Why does XXXXXX collect personal data?
XXXXXX collects data for the following purposes: analysis of website usage behavior. Some data are collected automatically. You are then scrupulously informed beforehand. Other collections are imposed by law and/or regulation, and others are of strategic and commercial importance and require your prior consent. In each case, XXXXXX takes care to respect the regulations whose requirements vary from simple information to the prior collection of your consent.
1) Data collected automatically
- the device and the browser used
- the IP address (anonymize)
- the date and time of your navigation
- the history of your navigation (from the site https://www.XXXXXX.com)
In order for this data collection to be authorized by the regulations, we make available to you the mechanism of opposition by updating your preferences in the section “privacy policy” of our website. This possibility is available on all browsers, and all types of terminals (including smartphones and tablets). Please contact us via the contact form if you have any difficulties in using this mechanism. In accordance with the regulations, we inform you that :
- The data collected is not cross-referenced with other processing (customer files or statistics on visits to other sites for example).
- The data collected by this means only gives rise to the production of anonymous statistics
- We do not follow your navigation on other websites.
- The IP address collected does not allow us to obtain a more precise geolocation than the scale of a city:
- This data is not kept beyond 13 months from your first visit.
- the raw data of frequentation associating an identifier must not be kept more than 13 months.
Any collection of data going beyond those aiming at feeding these statistics give place to the collection of your preliminary consent if it is not assists on another legal basis.
2) Data collected when you contact the customer service
You are likely to transmit personal data to us when you contact the customer service, so that we can treat your requests. Again, the legal basis for this is Article 6.1.b of the GDPR. The legal basis for this collection and processing is Article 6.1.b of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27 April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or “GDPR”) .
3) Data collected at the creation of your customer account and during an order
In order to create your account and access the ordering process, you will have to provide us with your company information as well as contact information, considered as personal: your name, your contact information (email and postal address and phone number), your bank information. The legal basis for this collection and processing is based on Article 6.1.b of REGULATION (EU) 2016/679 OF THE EUROPEAN PARLIAMENT AND OF THE COUNCIL of 27April 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation or “GDPR”)
Conservation of data
In accordance with the regulations in force, XXXXXX informs you that the data will be kept for the period strictly necessary for their processing, in accordance with the regulations in force locally. For example, in accordance with French law, we are obliged to keep payment and billing information for a period of 10 years.
Data processing
XXXXXX informs that it will process data in a lawful, fair, transparent, adequate, relevant, limited, accurate and up-to-date manner. Therefore, XXXXXX undertakes to take all reasonable steps to ensure that your data is deleted or corrected without delay when it is inaccurate.
XXXXXX will process your data in order to be able to contact you again following your contact request.
Users’ rights
In accordance with Articles 15 to 22 GDPR, regarding the data we hold about you, you have the following rights:
– right of access (article 15 of the RGPD)
– right of rectification (article 16 of the GDPR)
– right to erasure (article 17 of the GDPR)
– right to limitation of processing (article 18 of the GDPR)
– right to data notification: rectification, erasure, restriction (Article 19 of the GDPR)
– right to data portability (article 20 of the GDPR)
– right to object (article 21 of the GDPR)
– right not to be profiled (article 22 of the GDPR)
You can exercise these rights by sending your request to the following postal address: 17 avenue de Villier, 75017 Paris or to the e-mail address contact@XXXXXX.com. Any request to exercise a right must be accompanied by a copy of a valid proof of identity to enable us to ensure that the request is made by the legitimate owner of the data concerned. You may also contact the relevant supervisory authority (CNIL) to make any complaint you consider appropriate.
Transfer of data
XXXXXX informs that it will not transfer your data to a third party.
Duration of data retention
The length of time your data is kept varies according to the state of the law and when the constraints are less, according to the recommendations of the CNIL and our needs.
As an indication, you will find in the attached table the retention periods of the main data applied by XXXXXX
Type of data processing : Customer relationship
Purpose of the processing : Management of the commercial relationship
Legal basis of the treatment : Article L123-22 paragraph 2 of the Commercial Code
Retention period : 365 days
Remarks (the simplified standards of the CNIL have only an indicative value since the
25.05.2018. Future referentials are expected). Simplified standard
of the CNIL NS-048
Type of data processing : Order management
Purpose of the processing : Management of the commercial relationship
Legal basis of the processing : Article L123-22 paragraph 2 of the Commercial Code
Retention period : 10 years
Remarks (the simplified standards of the CNIL have only an indicative value since the
25.05.2018. Future referentials are expected). Simplified standard
of the CNIL NS-048
Type of data processing : Use of the customer area
Legal basis for processing : Article 6.1.b of the RGPD
Retention period : Data that cannot be kept beyond the retention period strictly necessary for the management of the commercial relationship, with some exceptions
Changes to this Privacy Policy
This Privacy Policy was updated on May 26, 2020. From time to time, XXXXXX may make changes to its privacy policy and update it on its website. Any updates to this policy will be communicated to you by means of easily identifiable notices on our web site and/or by sending you informational emails.