CONFIDENTIALITY POLICY

Updated: March 1st, 2019

Seller: JSB, a SAS with share capital of €1,000 having its registered office at 29 Rue des Petites Ecuries 75010 Paris, registered with the Registry of Trade and Companies of Paris under number 832 106 660, represented by Mr. Jérémy Schimmel-Bauer, Intra-Community VAT number: FR 638321006660

Email contact: eshop@schimmel-paris.com/ phone: 01 48 00 08 81 from Mondays to Fridays between 9 am and 5 pm

I- PERSONAL DATA POLICY

Section 1. Purpose

1. The purpose of this personal data protection policy (“Confidentiality Policy”) is to provide information on how JSB collects, uses and keeps the personal data of users of the website www.schimmel-paris.fr (the “Website”), and of the rights available to them to, in particular, object or withdraw their consent to processing, as well as how they can exercise those rights effectively.

2. Viewing the Website, and by extension registering and placing orders, entails the strict application of this Confidentiality Policy.

3. JSB acts as the “data controller” of the personal data and takes decisions concerning the purposes and manner of processing and tools to be used, as well as those used as security measures. It warrants compliance with the rules applicable to the protection of personal data, namely French Data Processing Act No. 78-17 dated January 6th, 1978, as well as European General Data Protection Regulation No. 2016/679 dated April 27th, 2016 (“GDPR”).

4. Users are informed that this Confidentiality Policy should be checked regularly as it may be modified and updated from time to time. 

Section 2. Personal data collected

1. Data provided directly via the forms contained in the Website (registration, order, request submitted via the “contact us” section): surname, first name, date of birth, postal address, invoicing address, email, phone number.

Whether or not such information is mandatory will be specified.

2. Data collected automatically when using the Website: Internet protocol address (IP) of the user (via the placement of cookies, see II).

Section 3. Recipient of the personal data 

1. JSB is the recipient of the personal data.

2. Personal data may be shared with outside companies to ensure services and with shipping companies to ensure order deliveries.

3. Payment information is transmitted to payment service providers and financial institutions.

4. These third parties are under contractual obligations to comply with the confidentiality of such data and only to use them for the purposes for which they were transmitted.

5. No personal data of a user will be transferred to any other third party without the user’s consent. 

Section 4 - Purposes 

1. Personal data is collected for purposes in relation to the use of the Website and of the services (registration, order, delivery, management of complaints), and for customer and prospect relationship management. 

2. With the specific consent of the user, obtained through ticking a consent box, personal data may be used for the following purposes: sending promotional offers and newsletters, and/or transfer to commercial partners.

Section 5 – Hosting and security 

1. JSB has implemented security measures to mitigate to the fullest extent possible the risk of data destruction or loss, including accidental, of unauthorized viewing or processing of data or for purposes that are not compatible with the collection purposes stated in this Confidentiality Policy.

2. Considering the specificities inherent to the Internet, it is not possible to guarantee that the security measures implemented for the protection of the Website restrict or exclude any risk of unauthorized access or loss of such data.

3. Users are advised to use software tools ensuring the protection of network data transmission/reception (up-to-date antivirus system) and to ensure that the Internet service provider has taken the necessary measures to ensure the security of the network data transmission (firewall and antispam filters). 

4. JSB agrees to choose processors presenting sufficient guarantees in terms of security and reliability. The data collected are hosted by the hosting provider indicated in the legal notice published on the Website on secure servers located within the EU. 

Section 6 – Retention period

1. IP addresses are kept for 13 months from the user’s first visit.

2. Other personal data are kept for the entire length of the contractual relationship plus (i) a maximum of 5 years following the last use of the Website, or (ii) 1 year following the deletion of the user’s account at the user’s request, or (ii) 10 years if JSB has suspended, restricted access or terminated a user’s account.

Section 7 - Rights

1. Users have, at all times, a right to access, to modify, to rectification of, to withdraw consent to processing and of erasure (“right to be forgotten”), to portability, to object to processing, to the erasure of their data or to obtain a copy thereof. 

2. To exercise these rights or for any question concerning the processing of your data, send a request by postal mail or by email to the addresses indicated in the header of the ToS. JSB will reply to you without undue delay and advise you of the follow-up and outcome of any actions taken. 

3. You have a right to lodge a complaint with the French Data Protection Authority (CNIL - 3 Place de Fontenoy, 75007 Paris) or with the courts of competent jurisdiction, in accordance with personal data protection legislation.

4. Before responding to any such request, JSB has the right to verify your identity by asking you to provide it with additional information.

Section 8 – Links to third-party websites

The Website may contain links to third-party websites over which JSB has no control. JSB disclaims any and all liability for their content, and for the way in which personal data may be stored or used on the servers of such third parties. Users should read the terms of use and the confidentiality policy of such third-party websites.

II- COOKIE POLICY

1. Browsing on the Website may result in a cookie or cookies being placed on your computer. A cookie is a small text-file that records information about a computer’s browsing on a website. 

2. Users are informed of the use of cookies by a banner displayed on the Website, informing them of the purposes pursued by such cookies, and of the possibility and technical means of objecting to them.

3. While users may refuse such cookies, access to some of the functionalities of the Website may be impaired as a result.

4. Cookie consent is valid for a maximum of 13 months.

5. Your browser’s help menu will provide you with information on how to express or modify your cookie preferences. 

6. Data collected: the user’s IP address, URLs of links used to access the Website, Internet service provider, information about the user’s devices (connection data, browser types and versions used, types and versions of browser plugins, operating systems and platforms, Website clickstream data, the content viewed, search terms used, downloading errors, the time spent viewing certain pages). 

7. Purposes. The data thereby obtained are intended to: 

- Facilitate subsequent browsing on the Website and improve the user experience, in particular through the recognition of the user’s devices, the user name and password previously provided.

- Enable traffic measurement statistics, traffic analytics and measurement of the number of users, 

- Measure browsing habits and speed up searches, 

- Carry out marketing operations (ad cookies used to disseminate targeted ads)

Schimmel news, exclusive content and offers in your mailbox