Privacy policy
legal.last_updated
01.Data controller
ISSA EURL, 45 Grande Rue, 50100 Cherbourg-en-Cotentin, France. Contact: issadecoche@gmail.com.
02.Purposes of processing
- Order management — legal basis: contract performance.
- Newsletter — legal basis: explicit consent (opt-in, opt-out possible at any time).
- Customer accounts (when introduced) — legal basis: contract performance.
- Anonymous usage statistics — legal basis: legitimate interest.
03.Data collected
Email address, first and last name, postal address, phone number, order history, IP address (for security and abuse prevention).
04.Subprocessors
- Stripe (Ireland & US) — payment processing, signed DPA.
- Resend (US) — transactional emails (order confirmations, shipping). Subject to SCCs.
- Supabase (Ireland) — database and storage.
- Vercel (US) — site hosting. Subject to SCCs.
- Mondial Relay (France) — shipping carrier.
05.Retention periods
- Order data: 10 years (legal accounting obligation).
- Newsletter: until you unsubscribe.
- Server logs: 12 months max.
06.Your GDPR rights
You have the right to:
- Access your data and obtain a copy
- Rectify inaccurate data
- Erase your data (right to be forgotten)
- Restrict processing
- Data portability
- Object to processing
- Withdraw consent at any time
To exercise these rights, write to issadecoche@gmail.com. We respond within 30 days.
08.Security
All data is encrypted in transit (HTTPS) and at rest. Access to administration is restricted by authentication and role-based access control.
09.CNIL complaint
If you believe your rights are not respected, you may lodge a complaint with the CNIL (French data protection authority): cnil.fr.