Privacy Policy
Last updated: 8 June 2026
This privacy policy is intended to inform you about how [RAISON SOCIALE] (hereinafter "we", "our", "the Data Controller") collects, uses and protects your personal data, in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act.
1. Data Controller
[RAISON SOCIALE][Adresse], [Code postal] [Ville], France
SIRET: [SIRET 14 chiffres]
Email: contact@maison-famille.fr
Data Protection Officer (DPO) :
dpo@maison-famille.fr
2. Personal data collected
We collect the following data when you use our site and services:
2.1 Customer account data
- Last name, first name
- Email address
- Password (encrypted)
- Phone (optional)
- Marketing preferences (opt-in)
2.2 Order data
- Delivery and billing address
- Purchase history
- Transaction amounts
2.3 Browsing data (cookies)
- IP address
- Pages visited, visit duration
- Browser type and operating system
- Approximate geolocation data (country, city)
See our Cookie Policy for more details.
2.4 Correspondence
- Emails exchanged with our customer service
- Messages via the contact form
3. Purposes and legal bases for processing
| Purpose | Legal basis |
|---|---|
| Order and delivery management | Performance of the sales contract |
| Invoicing and accounting | Legal obligation (French Tax Code) |
| Customer service and after-sales | Performance of the contract + legitimate interest |
| Newsletters and marketing communications | Explicit consent (opt-in) |
| Site improvement and statistics | Legitimate interest |
| Fraud prevention | Legitimate interest + legal obligation |
4. Data recipients
Your personal data may be passed on to the following categories of recipients:
- Authorised staff: our internal teams (customer service, logistics, accounting)
- Payment providers: Stripe, PayPal (secure transactions)
- Carriers: logistics partners for delivery
- Hosting provider: data storage on secure servers (European Union)
- Analytics tools: Google Analytics (anonymised), subject to your cookie consent
- Marketing services: email platform (Resend, Brevo), subject to your consent
Transfers outside the EU: some providers may be located outside the European Union (e.g. Stripe, Google). In this case, we ensure that appropriate safeguards are in place (European Commission standard contractual clauses, Privacy Shield, etc.).
5. Retention periods
- Active customer account data: as long as the account is active + 3 years after the last activity
- Order data: 10 years (accounting and tax obligation)
- Payment data: 13 months (banking obligation, stored by Stripe/PayPal only)
- Analytics cookies: 13 months maximum
- Browsing history: 6 months (security and fraud)
- Newsletters: until consent is withdrawn (unsubscribe)
At the end of these periods, your data is deleted or irreversibly anonymised.
6. Your GDPR rights
In accordance with the GDPR, you have the following rights:
- Right of access: obtain a copy of your personal data
- Right to rectification: correct inaccurate or incomplete data
- Right to erasure ("right to be forgotten"): delete your data under certain conditions
- Right to restriction of processing: temporarily suspend processing
- Right to portability: receive your data in a structured format (JSON, CSV)
- Right to object: object to processing for marketing purposes or based on legitimate interest
- Right to withdraw your consent: at any time for processing based on consent (newsletters, non-essential cookies)
- Right to set post-mortem directives: instructions on what happens to your data after your death
How to exercise your rights?
You can exercise your rights:
- From your customer account ("My personal data" section)
- By email to the DPO: dpo@maison-famille.fr
- By post to the registered office address (copy of ID required)
We undertake to respond to your request within 1 month (extendable by 2 months in complex cases).
7. Data security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, disclosure or unauthorised access:
- Encryption: emails and sensitive data encrypted (AES-256-GCM)
- HTTPS: all pages of the site are secured by an SSL/TLS certificate
- Authentication: hashed passwords (argon2id) + complexity policy
- Restricted access: only authorised staff have access to customer data
- Backups: daily encrypted security copies
- Audits: regular security tests and updates to our systems
In the event of a data breach likely to result in a high risk to your rights and freedoms, we will inform you within 72 hours and notify the CNIL.
8. Changes to the policy
We reserve the right to modify this privacy policy at any time. The version in force is the one published on this page. We will inform you of any substantial change by email or via a banner on the site.
9. Right to lodge a complaint with the CNIL
If you believe that your rights are not being respected, you have the right to lodge a complaint with the French Data Protection Authority (CNIL):
CNIL3 Place de Fontenoy - TSA 80715
75334 PARIS CEDEX 07
Tel: 01 53 73 22 22
www.cnil.fr
Contact the DPO
For any question relating to the protection of your personal data: