ARTICLE 1: PREAMBLE
The way in which their personal data is collected and processed. All data capable of identifying a user must be considered personal data. This includes the first and last name, age, postal address, email address, location of the user or even their IP address;
What are the rights of users regarding this data;
Who is responsible for the processing of personal data collected and processed;
To whom this data is transmitted;
Possibly, the site’s policy regarding “cookie” files.
This confidentiality policy supplements the legal notices and the General Conditions of Use which users can consult at the addresses below:
Legal notices: https://nacahelmet.com/mentions-legales/
ARTICLE 2: GENERAL PRINCIPLES COLLECTION AND PROCESSING OF DATA
In accordance with the provisions of Article 5 of European Regulation 2016/679, the collection and processing of data from users of the site respects the following principles:
Secularism, loyalty and transparency: data can only be collected and processed with the consent of the user who owns the data. Each time personal data is collected, the user will be informed that their data is being collected, and for what reasons their data is being collected;
Limited purposes: the collection and processing of data is carried out to meet one or more objectives determined in these general conditions of use;
Minimization of data collection and processing: only the data necessary for the proper execution of the objectives pursued by the site are collected;
Retention of data reduced over time: data is retained for a limited period, of which the user is informed. If the shelf life cannot be communicated to the user;
Integrity and confidentiality of data collected and processed: the data controller undertakes to guarantee the integrity and confidentiality of the data collected.
In order to be lawful, and in accordance with the requirements of Article 6 of European Regulation 2016/679, the collection and processing of personal data can only take place if they comply with at least one of the conditions below. after listed:
The user has expressly consented to the processing;
The processing is necessary for the proper performance of a contract;
The processing meets a legal obligation;
The processing is explained by a necessity linked to the protection of the vital interests of the data subject or of another natural person;
The processing may be explained by a necessity linked to the execution of a mission of public interest or which relates to the exercise of public authority;
The processing and collection of personal data is necessary for the purposes of the legitimate and private interests pursued by the controller or by a third party.
ARTICLE 3: DATA COLLECTED AND PROCESSED IN THE CONTEXT OF NAVIGATION ON THE SITE
- DATA COLLECTED AND PROCESSED AND METHOD OF COLLECTION
The personal data collected on the nacahelmet.com site are as follows:
The information given by the user in the order preparation forms (last name, first name, address, etc.) allowing the sale to be made, or in the contact form to contextualize the request and respond to it
The technical characteristics of the means of connection to the website (screen size, IP address, etc.) and possibly information relating to the use of the site: number of orders, time spent, articles consulted, etc.
This data is collected when the user performs one of the following operations on the site:
- Register on the site,
- Order a product,
- Buy a product on the site,
- Consult an information article,
- Join the NACA Guarantee Club
- Subscribe to a newsletter,
- Requires online or telephone technical support.
Furthermore, when paying on the site, proof of the transaction including the order form and invoice will be kept in the site publisher's computer systems. The data controller will keep in its computer systems of the site and under reasonable security conditions all the data collected for a period of: between 1 day and 3 years, for simple visits, up to 5 years if the user validates an order. The collection and processing of data serves the following purposes in particular:
- Creation and control of access to customer accounts,
- Product customization
- Completion of formalities,
- Payment monitoring and invoicing,
- Connecting with third-party partners,
- Sending marketing and commercial information.
And more generally all activities related to the sale of services or products related to the information presented on the website.
- TRANSMISSION OF DATA TO THIRD PARTIES
2.1. SHARING YOUR PERSONAL DATA WITH THIRD PARTY COMPANIES
When browsing the Site, users' personal data may be transmitted to external service providers. These third parties provide a service on our behalf and in our name with the aim of enabling the proper functioning of credit card payments and other Services, or may offer their services or products to users.
Personal data may be transferred to countries outside the European Union (such as the United States) for the purpose of processing your requests and securing personal data.
In accordance with the GDPR, all transfers of personal data to a country located outside the European Union and/or not offering a level of protection considered sufficient by the European Commission have been the subject of cross-border flow agreements. in accordance with the standard contractual clauses decreed by the European Commission and declared to the CNIL. Other transfers of personal data to the United States, particularly for customer relationship management (CRM), are governed by the EU – US PRIVACY SHIELD (European Union-United States Data Protection Shield).
We will never share, without obtaining your prior consent, your personal data with third party companies for marketing and/or commercial purposes.
2.2. SHARING WITH AUTHORITIES:
We may disclose your personal data to administrative or judicial authorities when their disclosure is necessary for the identification, arrest or prosecution of any individual likely to harm our rights, any other user or a third. Finally, we may be legally required to disclose your personal data and cannot object to this in this case.
- DATA HOSTING
The nacahelmet.com site is hosted by 7IDEAL, on the OVH infrastructure
SARL with capital of €8,000
RCS REIMS 432 621 18300057
VAT number FR69432621183
Head office: 8 bis rue Gabriel Voisin – CS 40003 – 51688 Reims Cedex 2 – France
Tel: +33 9 72 12 12 35
SAS with capital of €10,069,020
RCS Lille Métropole 424 761 419 00045
APE code 2620Z
VAT number: FR 22 424 761 419
Head office: 2 rue Kellermann – 59100 Roubaix – France
Tel: +33 9 72 10 10 07
ARTICLE 4: DATA PROCESSING RESPONSIBLE AND DATA PROTECTION DELEGATE
- THE DATA PROCESSOR
Those responsible for processing personal data are: Pascal Robin, Ophélie Pillet, Carole Merveille.
They can be contacted as follows:
By telephone at 04.94.14.74.94 from Monday to Friday from 9 a.m. to 12 p.m. and from 2 p.m. to 4 p.m. or by email at email@example.com
The data controller is responsible for determining the purposes and means used to process personal data.
- OBLIGATIONS OF THE DATA PROCESSOR
The data controller undertakes to protect the personal data collected, not to transmit them to third parties without the user having been informed and to respect the purposes for which these data were collected.
The site has an SSL certificate to guarantee that the information and data transfer passing through the site are secure.
An SSL certificate (“Secure Socket Layer” Certificate) aims to secure the data exchanged between the user and the site.
In addition, the data controller undertakes to notify the user in the event of rectification or deletion of the data, unless this entails disproportionate formalities, costs and procedures for the user.
In the event that the integrity, confidentiality or security of the user's personal data is compromised, the data controller undertakes to inform the user by any means
- DATA SECURITY OFFICER
7IDEAL SARL ensures the security of data hosted on its servers. It implements site security updates and backups,
Security manager: Christophe Diancourt
Tel: +33 (0)9 72 12 12 35
ARTICLE 5: USER RIGHTS
In accordance with the regulations concerning the processing of personal data, the user has the rights listed below.
In order for the data controller to grant his request, the user is required to communicate to him: his first and last name as well as his email address, and if relevant, his account or personal space number or subscriber.
The data controller is required to respond to the user within a maximum of 30 (thirty) days.
- PRESENTATION OF USER RIGHTS REGARDING DATA COLLECTION AND PROCESSING
1.A. RIGHT OF ACCESS, RECTIFICATION AND RIGHT TO DELETION
The user can read, update, modify or request the deletion of data concerning him, by respecting the procedure set out below:
The user must send an email to the person responsible for processing personal data, specifying the subject of their request and using the contact email address provided above.
If he has one, the user has the right to request the deletion of his personal space by following the following procedure:
The user must send an email to the person responsible for processing personal data, specifying their personal space number. The request for deletion of data will be processed within 30 working days
1.B. RIGHT TO DATA PORTABILITY
The user has the right to request the portability of his personal data, held by the site, to another site, by complying with the procedure below:
the user must make a request for portability of their personal data to the data controller, by sending an email to the address provided above
1 C. RIGHT TO LIMITATION AND OBJECTION TO DATA PROCESSING
The user has the right to request the limitation or to oppose the processing of his data by the site, without the site being able to refuse, unless he demonstrates the existence of legitimate and compelling reasons, which can prevail over the interests and the rights and freedoms of the user.
In order to request the limitation of the processing of their data or to formulate an opposition to the processing of their data, the user must follow the following procedure:
the user must make a request for limitation of the processing of their personal data to the data controller, by sending an email to the address provided above
1.D. RIGHT NOT TO BE SUBJECT TO A DECISION BASED EXCLUSIVELY ON AN AUTOMATED PROCESS
In accordance with the provisions of Regulation 2016/679, the user has the right not to be the subject of a decision based exclusively on an automated process if the decision produces legal effects concerning him, or significantly affects him in a way similar way.
1.E. RIGHT TO DETERMINE THE FATE OF DATA AFTER DEATH
The user is reminded that he can organize what should happen to his data collected and processed if he dies, in accordance with law no. 2016-1321 of October 7, 2016.
1.F. RIGHT TO SEIT THE COMPETENT SUPERVISORY AUTHORITY
In the event that the data controller decides not to respond to the user's request, and the user wishes to contest this decision, or, if he believes that one of the rights listed above, he is entitled to refer the matter to the CNIL (Commission Nationale de l’Informatique et des Libertés, https://www.cnil.fr) or any competent judge.
- PERSONAL DATA OF MINORS
In accordance with the provisions of Article 8 of European Regulation 2016/679 and the Data Protection Act, only minors aged 15 or over can consent to the processing of their personal data.
If the user is a minor under 15 years of age, the consent of a legal representative will be required so that personal data can be collected and processed.
The site editor reserves the right to verify by any means that the user is over 15 years old, or that he or she has obtained the consent of a legal representative before browsing the site.
ARTICLE 6: CONDITIONS FOR MODIFICATION OF THE CONFIDENTIALITY POLICY
The site editor reserves the right to modify it in order to guarantee its compliance with current law.
Consequently, the user is invited to regularly consult this confidentiality policy in order to stay informed of the latest changes that will be made to it.
The user is informed that the last update of this confidentiality policy took place on: 02/12/2020.
ARTICLE 7: USER ACCEPTANCE OF THE CONFIDENTIALITY POLICY
By browsing the site, the user certifies having read and understood this confidentiality policy and accepts its conditions, particularly with regard to the collection and processing of their personal data.