Personal data policy
The General Data Protection Regulation is a regulation implemented by the European Commission from May 25, 2018 for all companies that have an activity in Europe. At Lucine & Bastien, we are therefore concerned!
Here are some definitions that will be useful to you in understanding the commitments of Lucine & Bastien set out below:
Personal data: means any information likely to relate to an identified or identifiable natural person directly or indirectly.
DPO: The Data Protection Officer (DPO) is responsible for implementing compliance with the European Data Protection Regulation within the organization that designated him/her with regard to all processing operations implemented by this organization.
Data controller: The data controller is the legal or natural person who determines the purposes and means of processing. In practice and in general, this is the legal person embodied by its legal representative.
The data controller is the company Lucine & Bastien, hereinafter (“We”).
What does this change?
To protect Internet users from data leaks or the misuse of personal data, it is now mandatory for companies to keep visitors informed of all computer processing operations carried out using the data collected.
Like all e-retailers, we collect data on our Internet users and we work with several third-party service providers, who therefore have access to some of our data. This data is essential to offer you the best possible experience on our site and to ensure the smooth running of your order.
We have nothing to hide, we want to be as transparent as possible, so we will tell you everything!
Where are our servers?
The servers of the Lucine & Bastien website are located in Graveline, France. This country provides an adequate level of protection for your personal data in accordance with the Commission’s decision of 20 December 2001, noting the adequate level of protection of personal data provided by the Canadian Personal Information Protection and Electronic Documents Act.
These servers contain our database, which is necessary for the operation of the site. Information concerning customer accounts and your orders is stored there.
What data do we process?
Lucine & Bastien, as data controller, collects and processes the following personal data:
For an order:
Email address
Last name
First name
Postal address
Phone number
For product reviews:
Last name
First name
Email address
Order reference
For a contact request from the “contact us” page:
Last name
First name
Phone number
Email
Message content
On the order tracking form:
Email address
Order number
When you browse our site:
IP address
Is your data safe with us?
Lucine & Bastien is committed to working to protect your personal data. Only our authorized personnel participate in operating the site.
In addition, Lucine & Bastien implements appropriate technical and organizational measures to prevent the loss, misuse, alteration and deletion of your personal data.
These measures are adapted according to the level of sensitivity of the data processed and the level of risk presented by the processing or its implementation.
If a breach of the security of your data occurs, Lucine & Bastien will inform the User within the time limits and in accordance with the procedures specified by the legal and regulatory provisions in force.
Concerning your passwords, they are stored “encrypted” and it is impossible to decrypt them. Your passwords and your data are therefore safe at Lucine & Bastien
And your credit card number?
For credit card payments, we work with a major service provider Stripe, which guarantees the security of your data. At no time do we have access to your credit card number.
Our service provider has numerous approvals justifying the security of their IT system: https://stripe.com/fr/legal/ssa
Who do we share your data with?
The personal data collected on the site https://lucine-et-bastien.fr are intended mainly for the company Lucine & Bastien, however they may be shared with our partners and/or service providers.
We ensure that your rights are respected
Lucine & Bastien is responsible for the proper application of the General Data Protection Regulations. We ensure that you can enjoy the following rights under this regulation:
Right of access and rectification of your data:
You have the right to obtain from the data controller confirmation as to whether or not Personal Data concerning you is being processed and, where it is, the right to access it and/or have it rectified. (See Articles 15 and 16 of the GDPR.)
Right to erasure of your data.
In accordance with Article 17 of the GDPR, you have the right to ask us to erase your Personal Data as soon as possible; for certain reasons/under certain conditions that you can consult in said article/in the cases provided for by the article.
Right to limitation of data processing.
You have the right to ask us to limit the processing of your Personal Data in the cases provided for by Article 18 of the GDPR.
Right to object to data processing.
In accordance with Article 21 of the GDPR, you have the right to object to the processing of Personal Data concerning you when the processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, unless the interests or fundamental rights and freedoms of the data subject which require protection of Personal Data prevail, in particular when the data subject is a child.
Right to the portability of your data.
You have the right to the portability of your Personal Data, which gives you the possibility to receive the Personal Data that you have provided to us, in a structured, commonly used and machine-readable format, as well as the possibility to transmit this data to another controller. The exercise of this right will be subject to the conditions provided for in Article 20 of the GDPR.
Right to withdraw your consent.
In accordance with Article 7 of the GDPR, in cases where processing is based on consent, you have the right to withdraw your consent at any time. This will end the processing of your data.
Right to define post-mortem directives.
You have the possibility to define directives relating to the conservation, deletion and communication of your Personal Data after your death and this with a trusted third party, certified and responsible for ensuring that the wishes of the deceased are respected in accordance with the requirements of the applicable legal framework (Article 85 of Law No. 78-17 of January 6, 1978 relating to information technology, files and freedoms.)
Nothing is more important to Lucine & Bastien than respecting your rights, you can exercise your rights as follows:
By sending your request to the following email address contact@lucine-et-bastien.fr or by mail accompanied by a copy of an identity document by contacting the company LB Lab at the following address: 32 impasse des campagnols, 69490 Saint Forgeux – FRANCE
You can also file a complaint with the CNIL.
Update
In order to comply with regulatory changes and reflect our practices, Lucine & Bastien reserves the right to modify this policy.
We will publish the changes on this page, we advise you to regularly consult our privacy policy to be kept up to date with Lucine & Bastien’s developments concerning your personal data.
Last update date: 03/10/2024