1. Purpose
This personal data protection policy (hereinafter the "Policy") aims to inform the Data Subjects about how data is collected and processed by the Publisher, and to inform them of their rights as well as the means of exercising those rights provided by the Publisher.
Data Controller
For all browsing and purchases on the Site, the Data Controller is Céline Staubli.
2. Processing
Purpose of Processing
As part of the operation of the Site, the Publisher collects and processes data according to the purposes specified at the time of collection, namely:
- Conducting statistical studies on navigation,
- Creating and properly operating the personal space,
- Managing orders placed through the site,
- Managing cookies,
- Managing contacts made via the dedicated form.
Data Processed
In the context of collection, the Publisher may collect the following data:
Identity: name, first names, email address, address, mobile phone number; data that must be communicated to the Publisher's services is indicated as such.
The mode of collection is the input of data in designated fields or collection via cookies previously accepted.
For online payment of purchases, banking data transmitted is not collected or processed by the Publisher.
These data are exclusively and directly processed securely by the secure payment service set up by the Publisher, whose terms are available on its site:
https://www.cdermabyceline.com/
The purpose of collecting data is the proper operation of the Site and the follow-up of orders placed through it.
Only data necessary for this purpose are collected and processed.
3. Data Security
Processed data is stored securely, and access is strictly controlled and limited to persons who need it.
Access to data is subject to secure specialized module access, protected by technical measures and strong passwords.
4. Recipients of Data
In accordance with regulations, the Publisher has implemented organizational and technical measures to preserve the security, integrity, and confidentiality of data, and to prevent unauthorized access.
Recipients are the Publisher and its employees who have an interest in consulting them.
5. Data Transferred to Authorities and/or Public Bodies
In accordance with regulations, data may be transmitted to competent authorities upon motivated request, notably to public bodies, exclusively to comply with legal obligations, justice auxiliaries, judicial officers, and organizations responsible for debt recovery.
6. Data Retention Periods
Data related to accounts or orders are not kept beyond two years from the last account login or order.
By exception, accounting data, including invoices, will be archived for 10 years from the invoice date in accordance with regulations.
7. Rights of Data Subjects
Data Subjects have rights of access, rectification, erasure (right to be forgotten), objection, restriction of processing, and data portability.
These rights may be exercised under law n°78-17 of January 6, 1978, as amended, and the GDPR.
- By simple request via email at:
- By postal mail to the Publisher's address
- Via the contact page on the Site.
Proof of identity may be requested when processing any request.
Subject to breaches of these provisions, users may file a complaint with the CNIL (https://www.cnil.fr).
8. Data Transfer
By principle, data collected on the site is exclusively reserved for the Publisher.
However, for orders placed on the Site, Data may be transmitted to the Publisher's logistics partners (delivery and shipping services). The legal basis for this transfer is the sales contract.
Furthermore, consent will be obtained from the Data Subject before any transfer of Data to third parties.
However, the Publisher reserves the right to transmit data to comply with legal obligations, notably if compelled by judicial order.
9. Security
The Publisher attaches particular importance to the protection of personal data of its users and partners but relies on their active collaboration. The Publisher recommends using strong passwords. (For more information, see: https://www.ssi.gouv.fr/guide/mot-de-passe).
10. Cookies
A cookie is a small file stored by a server on a user's device and associated with a web domain (usually all pages of a website). This file is automatically sent during subsequent contacts with the same domain.
Cookies have multiple uses: they can remember your client ID on a merchant site, the current content of your shopping cart, the language of the page, an identifier for tracking navigation for statistical or advertising purposes, etc.
There are several types of cookies:
- "Necessary" cookies: internal, used to store information between visits on the same device. They can save shopping cart contents, login IDs, or personalization elements. They do not require user consent.
- "Statistical" cookies: track user actions on the site. When anonymous, user consent is not required.
- "Internal" or "first-party" cookies: set by the site visited, used in addition to necessary cookies to collect personal data, track user behavior, or serve advertising purposes.
"Third-party" cookies are set by a site B (often an advertising network) on site A, allowing site B to see pages visited by a user on site A and collect information about them.
Information stored is theoretically limited to the visited domain but can also include embedded content from other domains.
Non-essential cookies require acceptance during site connection.
Essential cookies are deleted at the end of the session and are not used for data collection.
Cookie retention varies by type.
For proper site operation, BOONDOOA/Céline Staubli may place cookies in the visitor's browser.
For statistics, BOONDOOA/Céline Staubli and the client’s name may collect navigation data using cookies.
The visitor can accept or refuse cookies by configuring their browser.
Disabling cookies may make some site services unavailable.
The visitor can delete cookies anytime via browser privacy settings.
More info on cookie management is available at: https://www.cnil.fr/fr/cookies-les-outils-pour-les-maitriser.
Cookies last up to thirteen (13) months.
Data retention from cookies is a maximum of 25 months.