Privacy and data protection policy

Preamble

 

This privacy policy makes it possible to clearly and precisely present to Users what personal data may be collected when browsing the Website www.densmoredirect.com.

 

We are committed to respecting the privacy of Users. Also, we set out below, the conditions under which the personal data of Users, during their navigation on the Website, are likely to be the subject of Processing of their Data.

 

 

  1. Definitions

 

“Data(s)”: any information(s) relating to an identified or identifiable natural person (as defined by the GDPR);

 

“GDPR”: refers to the European Regulation on the Protection of Personal Data n°2016/679 of April 27, 2016;

"RT" or "we": means Havea Group, data controller, including its subsidiaries, whose registered office is located at Parc d'Activité Sud Loire - BOUFFÉRÉ - 85 612 MONTAIGU Cedex, registered with the RCS of La Roche sur Yon under the number 823 334 578;

“Website”: refers to the website accessible from the URL www.densmoredirect.com ;

"Processing": refers to "any operation or set of operations whether or not carried out using automated processes and applied to data or sets of personal data, such as the collection, recording, organization , structuring, storage, adaptation or modification, extraction, consultation, use, communication by transmission, dissemination or any other form of making available, reconciliation or interconnection, limitation , erasure or destruction ” (definition given by the GDPR);

“Users” or “you”: refers to all natural persons who browse the Website and access its functionalities and content.

 

 

II. Data collection

 

1. Time of Data collection

 

This privacy policy applies to all Data that you communicate to us or that we collect, directly or indirectly, in particular by:

  • Browsing on the Website;
  • Making purchases/orders (including subscriptions);
  • Creating a customer account on the Website;
  • Subscribing to the newsletter;
  • Contacting after-sales service and/or Consumer Services;
  • Participating in a contest;
  • Consulting our commercial offers and/or our advertisements;
  • Responding to our questionnaires;
  • Requesting any information, in particular via the contact form on the Website.

When the collection of specific Data is necessary for the associated Processing, we mark the mandatory fields with an asterisk.

Your Data may also be collected from third parties subject to having obtained your prior consent.

 

  1. Details of Data processing

 

The table below allows you to have an overview of the Data processed by the RT, the purposes of Data Processing as well as the legal basis of said Processing.

 

Treatment

Data collected

Purpose of Data Processing

Legal Basis(s) of Data Processing

Managing the customer account and preferences

Sex
First name
Name
E-mail
Date of birth
Password
Complete mailing address,

Phone Number
Order history

Personal preferences

These Data will allow us to:

- to manage your customer account (including the loyalty program) and your preferences (in particular related to orders, purchases, subscriptions, etc.);

- to produce statistics, audience measurements;

- to monitor our site and improve its content, in particular according to your preferences.

Contractual execution

 

User Consent

 

Legitimate interest

Management of orders, purchases, subscriptions

Sex
First name
Name
E-mail
Password,
Complete postal address,

Phone Number
Order history

All information transmitted about you (including health data)

These Data will allow us to:

- to manage your orders, purchases, subscriptions and the consequences of these (in particular their processing and follow-up, delivery, invoicing, management of complaints and after-sales service);

- to interact with you according to your requests/needs of any kind following orders, subscriptions, purchases made, and in the event of missing information, for the purpose of finalizing your orders, purchases, subscriptions;

- to contact you in case of unavailability of one of our products.

 

 

Contractual execution

Managing payments and collections

Payment data

Name

First name

Full mailing address

Order history

These Data will allow us to:

- To process and track the payment made via the chosen payment method;

- To process the collection of payments in the event of non-payment.

 

Regarding the retention of your payment data:

- either these are kept by the RT for the time of the transaction, these being then deleted,

- either the RT does not collect them (for example the bank card data entered on the Website are not collected in full. Only a payment identifier (token) and part of the numbers of your bank card are collected. all payment data is collected by our PCI-DSS certified payment provider guaranteeing payment security).

Contractual execution

Management of commercial communications (including newsletters)

E-mail

Name

First name

Full mailing address

Order history

These Data will allow us to:

- To send you commercial communications by email and/or by post and/or by telephone*;

- To carry out advertising targeting in connection with advertising partners or others (Facebook, Google, etc.);

- to produce statistics, audience measurements.

User Consent

Legitimate interest

Management of customer knowledge, statistics and performance of the Website

Login data

Browsing data

Name

First name

E-mail

Order history

These Data will allow us to:
- to subsequently assess your satisfaction with the orders and purchases made;
- to carry out satisfaction surveys;
- enrich your customer profile (preferences);

- to analyze the activity of our Website and improve the services offered;

- to carry out analyzes of customer journeys, audience measurements, statistics.

 

Legitimate interest

 

User Consent

The management of promotional operations (such as games, contests, etc.)

Sex
Name,

First name
Complete postal address

Phone Number
E-mail
Date of birth

This Data will allow us to:

- register in our program of participation in the promotional operations offered

- to follow up on it (in particular in the event of a win in the context of a game)

User Consent

Management of all types of requests

Civility

Name,

First name,
E-mail

Full mailing address

Phone Number

All information transmitted about you (including health data)

These Data will allow us to:

- to provide a personalized response to your request;

- produce statistics, satisfaction surveys;

- to process your request as part of our vigilance approach (prevention and monitoring of undesirable effects of products - monitoring of corrective actions taken if necessary)

User Consent

 

Legal obligation

 

Legitimate interest

Management of customer reviews

Name,

First name

This Data will allow us to publish your opinions on the products you have purchased.

User Consent

Online browsing management

Login data

Browsing data

This Data will allow us to:

- ensure the proper functioning of our Website;

- produce statistics;

- proceed with the dissemination of targeted advertisements online on our Website and on other sites (for example on social networks).

User Consent

 

Legitimate interest

 

*The RT, including its subsidiaries, may send you and/or offer you commercial offers by post or telephone, which you are informed of and which you can oppose by following the procedure detailed in article 7 of this policy.

In addition, the RT, including its subsidiaries, may be required to send you by email offers relating to products or services similar to those already purchased by you through the site www.densmoredirect.com insofar as you are already client. You will be able to unsubscribe from newsletters sent by clicking on a link at the bottom of said newsletter. If you are only a prospect, your prior consent will be required in accordance with the regulations in force.

In addition, we may use certain techniques qualified as "profiling", i.e. any form of automated processing of personal data consisting of using the Data collected to analyze and evaluate certain personal aspects relating to a natural person, in particular to analyze and /or deduce, via dynamic segmentation, the development of scenarios, audiences, certain elements and/or behaviors relating in particular to personal preferences, centers of interest, purchasing habits.

Based on these analyzes and inferences, we send and/or display communications and/or content (concerning HAVEA GROUP and its subsidiaries) tailored to your interests/needs that we have identified. It is also possible that automated decisions are made based on profiling, in particular we may use this type of process to determine whether or not it is appropriate to send you certain communications.

You have the right, in certain circumstances, to object to the use of your data for “profiling” purposes. In this case, please refer to point 7 below.

 

  1. The destination of the Data

 

The Data subject to Processing is intended for the internal teams of the RT (and its subsidiaries) and possibly the service providers to which the RT may call, in particular within the framework of the processing of orders, purchases or subscriptions, the management of reviews customers, statistics, audience measurements, etc. (processors within the meaning of the GDPR). These service providers may contact you to send you commercial offers as well as satisfaction surveys in order to assess the quality of their service. If you wish to object to this, we invite you to contact the said service providers directly at the initiative of these possible mailings.

The Data may also be transmitted to third-party service providers to whom we entrust your Data to carry out commercial or marketing missions on our behalf (in particular web analytics, advertising agencies in the context of carrying out marketing and commercial campaigns).

The Data may also be transmitted to RT partners for prospecting purposes by post, of which you are informed beforehand. In this specific case and in accordance with the regulations in force, you have the right to oppose the use of these for prospecting purposes by sending us a request in accordance with point 7 below. We also recommend that you make any request to oppose prospecting with the partner concerned who contacted you. Furthermore, the RT cannot be held responsible for the conditions under which the Data is used by these third-party partners (namely use of the Data for a purpose other than prospecting by post).

In addition, the Data could also be transmitted to any police, judicial or administrative authorities (in the context of a legal obligation or the legitimate interest of the RT).

 

  1. Data of minors

 

The Website is accessible to any natural person, adult or minor. However and in principle, this Website is intended for adults and capable of entering into contractual obligations.

 

  1. Data retention

 

Your Data is kept for a period in accordance with legal provisions or proportional to the purposes for which it was processed. Certain retention periods meet the legitimate interest of the RT.

The retention periods vary depending on whether we have an ongoing contractual relationship (active customer), whether we have had a contractual relationship with you in the past (inactive customer) or whether we have never had a relationship with you. this guy (prospect). The Data related to your browsing on the Website and collected by the cookies you have authorized have a specific retention period as provided below.

For exemple :

  • all Prospect Data is kept for 3 years from the date of collection or the last contact from the prospect;
  • all data relating to an inactive customer is kept for the duration of the contractual relationship and for up to 5 years from the end of the contractual relationship or the last contact from the inactive customer;
  • Browsing Data is kept for a maximum of 13 months (except in the event that the desired duration is exceeded by a third party for which the RT cannot be the decision-maker and/or responsible)
  • Billing Data is kept for 10 years.

Archiving in an intermediate database is also possible for administrative reasons, particularly in matters of litigation, commercial, civil or even tax, in the context of compliance with a legal obligation.

In any case, when their retention is no longer justified by legal, commercial, marketing requirements or linked to the legitimate interest of the RT or if the User has made use of a right of modification or deletion or opposition (except in the case of conservation for the purposes of compliance with a legal obligation), we anonymize or delete them in a secure manner.

 

  1. The transfer of your Data

 

We store your Data within the European Union. However, it is possible that the Data will be transferred to subcontractors and/or commercial partners located in other countries and in particular outside the European Union. In the event of a transfer of this type, we ensure that the Processing is carried out in accordance with this privacy policy and that it is governed by the standard contractual clauses of the European Commission which make it possible to guarantee a sufficient level of protection of the Data and allowing respect for the privacy and fundamental rights of individuals.

 

  1. The terms and conditions for exercising the rights of Users

 

In accordance with the regulations on the protection of personal data (and in particular the GDPR), you have a right of access, rectification, erasure, opposition, limitation and portability of your Data. You also have the possibility of formulating directives concerning the fate of your Data after your death.

To exercise these rights, simply send a formal written and complete request accompanied by any element allowing your identification (identity document, customer number, etc.) according to the following reception methods:

  • By email: contact@havea.com
  • Via the contact form (if existing)
  • By post: Consumer Service densmoredirect.com – Sud Loire Business Park, 85612 Montaigu Cedex

The precise procedures relating to the exercise of your rights are mentioned in the regulations on the protection of personal data (and in particular the RGPD) and also on the CNIL website.

Before responding to any request, we may verify your identity and/or ask you to provide us with more information to respond to your request.

From the receipt of any written and complete request, we undertake to respond to any request within one (1) month, this period may be extended by two months in the event of a complex request.

In the event that we have not responded satisfactorily to your request, a complaint may be lodged with the Commission Nationale de l'Informatique et des Libertés (CNIL) via its website https://www.cnil.fr/ en/ .

 

  1. Data security

 

As RT, we implement appropriate technical and organizational measures in accordance with applicable legal provisions, to protect your Data against alteration, accidental or unlawful loss, use, disclosure or unauthorized access.

 

  1. Privacy Policy Changes

 

We may occasionally modify this privacy policy (in particular for reasons of legislative or regulatory change). Users are therefore advised to regularly consult this page to be aware of any changes or updates made to this privacy policy.

 

III Applicable law and attribution of jurisdiction

 

This privacy policy is governed by French law.

 

In the event of a dispute and in the absence of an amicable agreement, the User may seize either one of the courts with territorial jurisdiction under the Code of Civil Procedure, or the court of the place where he lived at the time of the conclusion of the contract or the occurrence of the harmful event.