Privacy policy

legal.last_updated

01.Data controller

ISSA EURL, 45 Grande Rue, 50100 Cherbourg-en-Cotentin, France. Contact: issadecoche@gmail.com.

02.Purposes of processing

  • Order management — legal basis: contract performance.
  • Newsletter — legal basis: explicit consent (opt-in, opt-out possible at any time).
  • Customer accounts (when introduced) — legal basis: contract performance.
  • Anonymous usage statistics — legal basis: legitimate interest.

03.Data collected

Email address, first and last name, postal address, phone number, order history, IP address (for security and abuse prevention).

04.Subprocessors

  • Stripe (Ireland & US) — payment processing, signed DPA.
  • Resend (US) — transactional emails (order confirmations, shipping). Subject to SCCs.
  • Supabase (Ireland) — database and storage.
  • Vercel (US) — site hosting. Subject to SCCs.
  • Mondial Relay (France) — shipping carrier.

05.Retention periods

  • Order data: 10 years (legal accounting obligation).
  • Newsletter: until you unsubscribe.
  • Server logs: 12 months max.

06.Your GDPR rights

You have the right to:

  • Access your data and obtain a copy
  • Rectify inaccurate data
  • Erase your data (right to be forgotten)
  • Restrict processing
  • Data portability
  • Object to processing
  • Withdraw consent at any time

To exercise these rights, write to issadecoche@gmail.com. We respond within 30 days.

07.Cookies

We use essential cookies (cart, session) and, only with your consent, anonymous statistics cookies. You can change your preferences anytime via the banner at the bottom of the site.

08.Security

All data is encrypted in transit (HTTPS) and at rest. Access to administration is restricted by authentication and role-based access control.

09.CNIL complaint

If you believe your rights are not respected, you may lodge a complaint with the CNIL (French data protection authority): cnil.fr.