Personal data protection policy

Concerned about protecting your privacy, we attach great importance to the confidentiality of the personal data that you transmit to us.

We wish to explain to you through this personal data protection policy (hereinafter “Policy”), the nature of the personal data that we collect, the way in which we process them, the measures we take to ensure their security and the nature of your rights.

Our Policy may be updated at any time by us and these changes will take effect immediately. We therefore invite you to refer to it regularly in order to be aware of its latest available version.

This Policy applies to all personal data you provide to us directly or indirectly.

1. Who collects your personal data?

Your personal data collected as part of our activity are mainly processed by:

The company Sarah Lavoine SAS, a simplified joint stock company with share capital of 50,000 euros, registered in the Paris trade and companies register under number RCS PARIS 507 947 778, whose head office is located at 9 rue Saint Roch – 75001 Paris -France, represented by the Maison Sarah Lavoine brand.

2. When do we collect your data?

We collect personal data from you, directly or indirectly through our service providers, in particular when:

  • You browse our Site or use our Services on our Site,
  • You create an account on our Site,
  • You log into your account on our Site,
  • You use your account on our Site,
  • You subscribe to our newsletter,
  • You place and pay for an order on our Site,
  • You contact us through various channels including contact forms, by post or by telephone,
  • You contact us via our chat
  • You participate in a game or competition, satisfaction surveys, polls,
  • You visit us in store
  • You have given your consent to third parties to transmit personal data about you to us,

We only collect your personal data when it is strictly necessary and lawful. We are committed to collecting only the minimum amount of personal information necessary for the purposes covered by this Policy.

3. How do we collect your data?

We may collect personal information about you from a variety of sources, including:

  • Personal data collected directly, which you voluntarily communicate to us, in particular when creating your account, via collection forms or when you make a purchase on our Site or in store. (for example: name, first name, contact details, etc.);
  • Personal data collected when using our Site, for example by using cookies (see the Cookies Charter);
  • Personal data about you from other legitimate sources, including commercially available sources, such as public databases, data aggregators, etc.

4. What personal data do we collect?

In this Policy, “your personal data” means information or pieces of information that allow you to be identified directly or indirectly. This generally includes information such as your name, addresses, email addresses and telephone numbers, but may also include other information such as your IP address, your purchasing habits, information about your lifestyle or your preferences.

When? What data?
When you browse our Site and/or log in to your account your name, first name, email addresses, connection data, technical data including your IP address, browsing information relating to your terminal
When creating your account on our Site your name, first name, title and email address.
When you subscribe to our newsletter Your email address and your title
When you order a product offered on our Site your name, first name, email addresses, the contents of your order, billing address (the type of address: home, work, etc.), delivery address, mobile/landline telephone number
When you pay for the products ordered on our Site your name, first name, order number, the amount of the order as well as your credit card number and its expiration date
When using our instant messaging your instant messaging login/creation/usage information (number, channel, duration, etc.), the content of your conversation
When you contact our Customer Service your name, first name, email address, postal address, telephone number, order number, the content of your request.

This data is collected fairly; no collection is carried out without the knowledge of individuals or without them being informed.

5. For what purposes do we collect your data?

The processing that we implement responds to an explicit, legitimate and determined purpose.

Any processing of your personal data for a purpose other than those set out below will require your consent if it is not justified by a legitimate interest.

For our part, the processing of your personal data allows us to provide you with the Site's services, to ensure their improvement and the maintenance of a secure environment and in particular to:

  • Provided that you have given your consent, manage our customer relationship through our CRM, in order to know you better, personalize our products and contact you regarding products that may interest you (new product launches, promotional offers, promotional events, VIP gatherings, store opening events, announcements/events, etc.), or that you have previously requested a product from us and that the communication is relevant or related to this prior request and made within the time limits set by applicable laws;
  • Manage the operation and optimization of our Site and our products;
  • Help speed up your future activities and experiences on our Site;
  • Evaluate the use of our Site, our products and analyze the effectiveness of our products, communication campaigns and promotions;
  • Get to know you better in order to anticipate and best meet your expectations;
  • Personalize your experience on our Site and other platforms and anonymously and aggregately assess activity on our Site and other platforms (in particular, we take into account the time you visited, whether you have visited before and which site referred you to it);
  • Make our Site easier to use and better tailor our Site and products to your interests and needs;
  • Carry out operations relating to our commercial relationship (orders, payment, deliveries, invoices, accounting, satisfaction surveys, consumer service, etc.);
  • Advise you, provide products that you request from us and answer your questions;
  • Provide customer service accessible by telephone and instant messaging to answer your questions;
  • To verify, identify and authenticate the personal data you have transmitted to us;
  • Prevent and detect fraud, malware (malicious software) and manage security incidents;
  • Manage any disputes.

We strive to minimize the data collected, keep it accurate and up to date while facilitating the rights of the persons concerned.

6. How long do we keep your data?

We only keep your personal data in an active database for the time strictly necessary to achieve the purposes pursued.

However, in order to meet our administrative, legal, accounting and tax obligations, your data may be archived and kept beyond the aforementioned periods, in accordance with current legislation.

The data type Shelf life
> The personal data that you have completed in your profile.
> Data concerning your browsing, your use of the Site, the use of instant messaging, or even exchanges with our customer service
Duration of three (3) years from your last activity on the Site
> Data relating to an order Duration of three (3) years from your order
> Cookies Duration specified for each cookie (Cookie Charter)
>Audience measurement statistics and your raw traffic data for our Site Duration of thirteen (13) months
> Prospect/customer data Duration of three (3) years from their collection or the last contact, or the end of the commercial relationship.
> Bank details

Duration of the transaction.

7. What is our cookie policy?

For more details, we invite you to consult our cookie policy.

8. Who are the recipients of your data?

Maison Sarah Lavoine is the sole recipient of your personal data and does not market it.

On the other hand, for the provision of our services, we may communicate your personal data to authorized and determined recipients, namely:

  • all employees of the company Maison Sarah Lavoine subject to an obligation of confidentiality,
  • our advertising, marketing and promotion agencies to help us deliver and analyze the effectiveness of our advertising campaigns and promotions,
  • third parties required to deliver a product to you, such as a delivery or postal service delivering a product you have ordered,
  • third party service providers, such as website hosting service providers...
  • web analytics tool providers, such as Google,
  • our service providers and/or economic partners when sharing is necessary to meet the purposes mentioned above,
  • administrative or judicial authorities when they ask us to disclose your information to them,

We require these recipients to implement all necessary and appropriate technical and organizational measures to ensure the confidentiality and optimal security of your data against any misuse and to use them only in accordance with our instructions and the legislation and regulations in force, in particular by signing a personal data protection agreement.

9. How do we protect your data?

As data controller, we take all reasonable precautions to preserve the security and confidentiality of your personal data by implementing organizational, technical, software and physical measures and require our partners to do the same.

Access to your personal data is limited to prevent unauthorized access, modification, interference, loss and/or abuse. Although Maison Sarah Lavoine takes all reasonable measures to protect your personal data, no transmission or storage technology is infallible.

10. How to exercise your rights?

In accordance with the Data Protection Act of 6 January 1978, as amended, and the General Data Protection Regulation No. 2016/679 of 27 April 2016, you have:

  • A right of access to your personal data,
  • A right to rectify your personal data,
  • A right to object to the processing of your personal data,
  • A right to erasure of your personal data subject to legitimate reasons,
  • Of a right to portability of your personal data from May 25, 2018,
  • A right to “digital death”, in accordance with the law for a digital Republic, by communicating to us instructions relating to the retention, deletion and communication of your personal data after your death. These instructions may be registered with a “digital trusted third party” certified by the CNIL.

In the absence of a person designated to ensure the execution of these directives, your heirs will be designated.

In the absence of instructions given during your lifetime, your heirs will then have the possibility of exercising certain rights, in particular:

  • the right of access, if it is necessary “for the settlement of the deceased’s estate”,
  • the right to object to the closure of your user accounts and to the processing of their data.

For more information about your rights: https://www.cnil.fr/fr/les-droits-pour-maitriser-vos-donnees-personnelles .

To exercise these rights, simply send a written request by email to the address contact@maisonsarahlavoine.com by specifying the subject of your request “Personal Data & GDPR”.

A response will be sent to you within one (1) month from the date of receipt of your request.

How to unsubscribe from our newsletter lists?

Unsubscribing from our newsletter lists is accessible via the unsubscribe link at the bottom of all our newsletters.

11. What is our data policy?

Our Site is intended for adults or minors with the authorization of their legal representative allowing them to place an order on the Site.

We do not knowingly collect or process personal data relating to minors.

12. Social networks/links

Maison Sarah Lavoine is not responsible for the illicit collection or processing of personal data carried out by the social networks we use such as Facebook, Instagram and Twitter.

As a service to our visitors, our Site may contain hyperlinks to other websites that are neither operated nor controlled by Maison Sarah Lavoine.

Maison Sarah Lavoine will therefore not be held responsible for the content of such websites, nor for the data protection practices of the third parties who operate them. We draw your attention to the fact that the data protection practices of third parties may differ from those presented in this Policy. We encourage you to check and understand their practices in this area before entrusting them with your personal data.