POLICY ON DATA PROTECTION
1. WHO WE ARE AND THE SCOPE OF THIS POLICY
This Policy on Data Protection applies to the personal data we collect when you use our website SamFries.com (hereinafter referred to as the "site"). Below, we will explain how we collect, use, and share your personal data, as well as the choices available to you regarding your personal data.
2. WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA?
Frédéric Pérat, with headquarters located at 76, rue Saint Maur – 75 011 Paris - France, is responsible for the processing of data carried out on this site.
3. WHAT PERSONAL DATA DO WE COLLECT WHEN YOU USE OUR SITE?
We collect your personal data when you provide it directly to us or when you use our site.
3.1. Personal data you provide to us
We collect your personal data during various interactions with us, including when you create your customer account on our site or when you place an order. The personal data we collect includes:
Information related to your account: We require basic information to create your customer account, including your name, first name, email address, and password.
Personal data related to transactions and billing: If you place an order, we collect your name, first name, shipping and billing addresses, as well as your banking details to process your payment and finalize the transaction.
Communications with us: When you contact our customer service, you may provide us with information such as your name, email address, and order number.
Newsletter: If you choose to subscribe to our newsletter, we collect your email address.
3.2. Personal data we collect automatically
We also collect certain information automatically when you use our site:
Personal data related to your connections: We collect all the personal data that browsers, mobile devices, and servers transmit to us, such as the browser type, IP address, unique device identifiers, language preferences, date and time of access, operating system, and mobile network information. We collect this connection information when you use our services.
4. WHAT ARE THE PURPOSES FOR WHICH WE COLLECT YOUR PERSONAL DATA?
The SamFries store's website ensures that your personal data is processed on an adequate basis and for specific purposes.
4.1. Legal bases for collecting and processing your data
The SamFries store's website ensures that your personal data is processed on a lawful and relevant basis. Therefore, the processing we carry out is based on:
The performance of a contractual commitment, for example: creating your customer account and processing your billing data when you place an order.
Compliance with a legal obligation that applies to us.
The existence of a legitimate interest that drives us to process your personal data, such as improving our site to offer you a better user experience, ensuring the proper functioning of our site, and responding to your requests when you use the contact form on the site.
Your consent, for example, when you subscribe to our newsletter.
4.2. Purposes for which we use your personal data
We use your personal data for the following purposes:
- To enable you to fully utilize our website and order our products, such as setting up and maintaining your account, tracking your orders, reviewing your order history, adding and modifying your shipping and billing addresses.
- To monitor and analyze trends and gain a better understanding of how you interact with our website, which will help us improve and make it more user-friendly.
- To measure, assess, and improve the effectiveness of our advertising and gain a better understanding of customer loyalty mechanisms. For example, we may conduct analyses on the number of individuals who have ordered a product after receiving a marketing message.
- To monitor and prevent any issues on our website.
- To inform you, via email for example, about offers and promotions provided by SamFries that may be of interest to you, solicit your feedback, or keep you updated on our product news (you can unsubscribe at any time).
- To personalize your user experience on our website, target our marketing messages to specific customer groups (e.g., those who haven't placed an order in a certain period), and deliver relevant advertisements.
5. WHO CAN ACCESS YOUR PERSONAL DATA?The SamFries online store shares your personal data under specific and limited circumstances. We have implemented appropriate safeguards to protect your privacy.
We may share your personal data with the following entities and/or for the following purposes:
- External service providers: We may share your personal data with our service providers in order to provide you with our services.
- Business partners: We may also share your personal data with our business partners.
- Law enforcement, judicial, or administrative authorities: We may disclose your personal data when legally obligated, such as in response to a judicial order.
- Protection of our rights: We may also disclose your personal data to defend or assert our rights in legal proceedings.
6. HOW LONG DO WE RETAIN YOUR PERSONAL DATA?We delete your personal data when it is no longer necessary for the purposes for which we collected it, provided that there is no legal or regulatory obligation requiring us to retain it.
For example, we retain your login data for a period of 12 months from the date of collection, in accordance with our legal obligations.
7. HOW DO WE PROTECT YOUR PERSONAL DATA?The SamFries online store implements various measures to ensure the security of your personal data against loss, misuse, unauthorized access, disclosure, alteration, or destruction.
- Upon receiving your personal data, we apply strict procedures and security measures to strive to prevent unauthorized access. Access to personal databases is strictly limited to authorized personnel who require access for their assigned tasks.
- We require our subcontractors to commit to respecting the security and confidentiality of your personal data through contractual agreements.
8. ARE YOUR PERSONAL DATA TRANSFERRED OUTSIDE OF THE EUROPEAN UNION?In principle, we keep your personal data within the European Union. However, there may be cases where we need to transfer your personal data to some of our subcontractors or partners located outside of the European Union for the aforementioned purposes.
When transferring your personal data to a country that does not provide an adequate level of protection in accordance with regulations, we take appropriate measures to ensure that the recipients of your personal data will adequately protect them in accordance with this Policy and applicable regulations.
9. WHAT ARE YOUR RIGHTS AND HOW CAN YOU EXERCISE THEM?In accordance with applicable data protection regulations, you have the following rights:
- Request access to your personal data;
- Request the correction or deletion of your personal data;
- Object to the use and processing of your personal data;
- Request the limitation of the use and processing of your personal data;
- Withdraw your consent when the processing is based on consent;
- Request the portability of your personal data.
- Additionally, you can provide us with instructions regarding the storage, erasure, and disclosure of your personal data in the event of your death.
If you wish to contact us regarding any of these rights, you can reach us by mail at:
Frédéric Pérat, 76 rue Saint Maur - 75011 PARIS - FRANCE
Or by email at the following address: firstname.lastname@example.org
We will respond to your request within 1 month after receiving it.
For privacy and data protection purposes, a copy of a signed identification document may be requested.
If you are not satisfied with our response, you have the right to lodge a complaint with the CNIL (French Data Protection Authority). However, we encourage you to contact us using the above contact details before lodging any complaint with the CNIL.