The https://www.zebres.paris website is operated by OKO, a limited liability company with capital of 100,000 euros, whose registered office is at 14 rue François Miron 75004 Paris, registered with the Paris Trade and Companies Register under number 812 052 454 (hereinafter "ZEBRES" or "OKO", or "SARL OKO"), having the capacity of data controller within the meaning of the regulations on personal data, in particular General Regulation (EU) No. 2016-679 on the Protection of Personal Data of Individuals (RGPD).
1. What personal data is processed?
The personal data concerning you collected and processed are mainly, depending on the services of the Site used, your choices and the configuration of your terminal (in particular in relation to cookies and other tracers): your surname, first name, title, email address, postal address, telephone number, date of birth, information relating to your professional life, comments, your order history and product selection, your signatures, your preferences and centres of interest, as well as your connection logs (hereinafter the "Data").
We may allow you to share information related to our Services on social networking (Facebook, Twitter, etc.) websites (in their fixed or mobile version, including the corresponding applications), in particular through the share buttons. We remind you that access to these Social Networks requires your acceptance of their contractual terms and conditions containing provisions relating to the Personal Data Regulations for the processing carried out by them, independently of our pages on the said Social Networks.
To learn more about the protection of your Personal Data when browsing these Social Networks, we invite you to consult their respective privacy policies.
2. How do we collect your personal data?
This Data is collected either on the basis of your consent or is necessary for the execution of your orders (execution of a contract).
3. Why do we collect your personal data?
Your Data is collected in order to :
- Proceed to the creation and management of your user account;
- Proceed to the creation, management and follow-up of your orders;
- Allow you to comment on our content (blogs in particular) and to use our interactive services;
- Offer you content and advertising adapted to your interests;
- Allow you to access our content without being authenticated;
- Allow You to participate in the services and activities offered by ZEBRES or our partners, such as online surveys;
- Ensure the security of online transactions, prevent fraud and payment incidents (the fight against fraud is based on OKO's legitimate interest);
- Manage and optimize customer relations;
- To send you information on our offers, news and events (newsletters, alerts, invitations and other publications), in particular by means of campaigns on social networks;
- To carry out statistics and audience measurements.
The Data essential to ZEBRES to fulfil the purposes described above are indicated by an asterisk in the various pages of the Site. If you do not fill in these compulsory fields, ZEBRES will not be able to respond to your requests and/or provide you with the products and services requested.
4. To whom do we pass on your personal data?
Our shop is hosted on Shopify Inc. They provide us with the online e-commerce platform that allows us to sell you our services and products.
Your data is stored in Shopify's data storage system and databases, and in the general application of Shopify. Your data is stored on a secure server protected by a firewall.
If you make your purchase through a direct payment gateway, then Shopify will store your credit card information. This information is encrypted in accordance with the Payment Card Industry Data Security Standard (PCI-DSS). Your purchase transaction information is retained for as long as necessary to complete your order. Once your order is finalized, the purchase transaction information is deleted.
All direct payment gateways are PCI-DSS compliant, managed by the PCI Security Standards Council, a joint effort of companies such as Visa, MasterCard, American Express and Discover.
The PCI-DSS requirements ensure the secure processing of credit card data by our shop and its service providers.
Your Data will not be transferred or made accessible to any third party subject to (i) any subcontractors of ZEBRES for exclusively technical and logistical reasons (Site hosting and maintenance service providers, payment and fraud management service providers, moderators, database management service providers) and (ii) any restructuring of our company, including total or partial transfer of assets, merger, absorption, acquisition, spin-off and more generally any reorganisation operation.
Your Data may be used for the purposes of managing and optimising customer relations as well as, unless you object, for the purposes of sending information on ZEBRES offers and news, in particular by means of advertising campaigns on social networks. Social network companies and email routing service providers may therefore be recipients of your Data.
Finally, OKO may be led to communicate your Data to third parties when such communication is required by the law, a regulatory provision or a judicial decision, or if this communication is necessary to ensure the protection and defence of its rights.
5. Data transfers outside the European Union
Recipients of your Data may be located abroad, including outside the European Economic Area. Any transfer of your Data outside the European Economic Area is carried out subject to appropriate guarantees, in particular contractual guarantees, in accordance with the applicable regulations on the protection of personal data.
6. What are your rights?
In accordance with the regulations in force, you have the right to access and rectify your Data, as well as the right to request its deletion, to oppose its processing and to obtain its limitation or portability insofar as applicable.
You may also object to the use of your Data for the purpose of drawing up your customer profile; in this case you will no longer be able to benefit from personalized offers or services.
These rights can be exercised directly with ZEBRES by e-mail at email@example.com. You may be asked to provide proof of identity.
In addition, you can at any time ask to no longer receive our communications relating to our offers, news and events by using the hypertext link provided for this purpose in each email that we send you. You can also contact us by mail at SARL OKO, 14 rue François Miron 75004 Paris.
7. How long do we keep your personal data?
The Data relating to the creation of your user account and your subscription will be kept by ZEBRES for a period not exceeding the applicable legal prescription periods, i.e. 5 years from the end of the contractual relationship or the inactivity of your user account. At the end of this period, this Data (i) will be archived for accounting and probative purposes during the aforementioned prescription periods or (ii) will be destroyed if the said periods have expired.
In the event that we collect bank data, this data will be kept securely for the duration necessary for the validation of your order and payment and will then be immediately destroyed. In the event of a payment incident, your Data will be kept for the duration of the incident, then for a period of three (3) to five (5) years depending on the seriousness of the incident.
The Data used for the purpose of sending communications relating to offers, news and events proposed by ZEBRES will be kept for a period of three (3) years as from their collection or as from your last contact with ZEBRES. At the end of this period, ZEBRES may contact you again to find out whether you wish to continue to receive communications about our offers, news and events. Your Data will also be destroyed as soon as possible after your request to unsubscribe.
Finally, the connection logs collected, subject to your agreement, within the framework of cookies and other tracers set up on our Site, will be kept in accordance with the applicable regulations for a period not exceeding thirteen (13) months. For more details, see our Cookies charter.
8. Contact details of the Data Protection Officer (DPO) and right to lodge a complaint
For any questions related to the collection and processing of your Data by OKO, you can contact the Echos data protection officer by email at the following address: SARL OKO, 14 rue François Miron 75004 Paris or by email: firstname.lastname@example.org.
You also have the right to refer any complaint relating to the manner in which OKO collects and processes your Data to the Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy - TSA 80715 - 75334 PARIS CEDEX 07, France.