PERSONAL DATA
The site owner, hereinafter "the Company", undertakes as Data Controller within the meaning of the General Data Protection Regulation No. 2016/679 of 27 April 2016 (GDPR) to respect the right to respect for private life, and in particular personal data, of any person visiting and/or communicating and/or receiving information on the Group's websites and social media pages as well as by emails (including newsletters) and correspondence forms (hereinafter "the Users").
The purpose of this Privacy Policy is to inform you about how the Company processes personal data (hereinafter "Personal Data"), and in particular to specify how the collection, use, storage and archiving of Users' Personal Data is carried out.
1. PURPOSE OF THE PROCESSING
The Company, as Data Controller, collects and uses Users' Personal Data in accordance with applicable regulations to manage their orders on the Site, Newsletters if they subscribe to them, for marketing purposes but only with the Users' consent, for the purpose of analyzing User behavior, or to manage requests made by Users via the contact form.
The data collected may be processed by the Company and/or its business partners for prospecting purposes, including commercial prospecting.
2. LEGAL BASIS FOR PROCESSING
The legal basis for the processing is the contract between the User and the Company.
However, processing may also be based on the consent of the Buyer concerned by the processing, when such consent is required (for example, for the use of data for commercial prospecting purposes).
3. DATA SOURCE
Personal Data is collected directly from Users (during registration on the Site or during the collection of information for product delivery upon purchase).
While complying with applicable legal obligations, the Company may use various technological tools to collect and provide information about how Users access and use the Company's websites and services. The Company may use demographic information about Users of its websites, which may be obtained from third parties, such as Google or the social networks on which Users are registered (hereinafter, "Usage Information"). This Usage Information may include the pages Users viewed on the Website, when they viewed them, information about specific beverages or other content the User accessed or provided, the language in which the User accessed the websites, and demographic information about the User (such as age, gender, and interests, where applicable).
4. RECIPIENTS
The recipients of this data are:
- the Company,
- the Company's business partners,
- the Company's subcontractors.
The Company ensures that the recipients of the data offer serious guarantees of security and confidentiality of the personal data transmitted to them by the Company.
5. TRANSFER OF DATA OUTSIDE THE EUROPEAN UNION
The data is in principle processed exclusively within the European Union.
In the event that they need to be transferred outside the European Union, the Company will take all necessary measures to ensure their protection.
Thus, the Company will ensure the protection of the User's Personal Data during the transfer, and that third-party entities respect a high level of protection of the User's Personal Data, in accordance with European requirements (such as the Standard Contractual Clauses of the European Commission, and/or by the adherence of the entities receiving the data to the Privacy Shield, when they are located in the United States).
6. DATA RETENTION
Personal Data is stored in accordance with applicable French and European standards.
Personal data will be kept for 5 years from the date of your last order or, in all other cases, from the date of collection. At the end of this period, and without renewal of your consent, it will be destroyed by the Company.
The User may request the erasure or modification of their Personal Data at any time. The Company will implement all necessary technical and organizational measures to protect the confidentiality and security of the User's Personal Data collected through the Company's websites.
These measures include storing Personal Data in secure operating environments that are not accessible to the public and are only accessible to authorized Company staff members, as well as agents and contractors specifically authorized for this purpose.
7. RIGHTS OF THE DATA SUBJECT
In accordance with French and European standards relating to the protection of personal data, and particularly with the General Data Protection Regulation No. 2016/679 of 27 April 2016 (GDPR), applicable since 25 May 2018, the User has a right of access, rectification, restriction of processing, erasure, objection to processing and portability.
Furthermore, he has the option to withdraw his consent for processing that requires it. In this case, the data will be deleted.
Users wishing to make requests regarding the portability of their Personal Data, or to exercise any other right indicated above, may contact the Company:
- Either by email to the following address : contact@chateau-thioulet.com,
- Or by mail to the following address: EARL MJL SERVENS / chateau-thioulet.com - 10 chemin de tioulet - 33670 SADIRAC
The User also has the option of submitting complaints to the Personal Data supervisory authority.
In France, the User can contact the National Commission for Information Technology and Freedoms (the “CNIL”), whose website can be accessed here: https://www.cnil.fr/ .
For other states, the complete list of competent local data protection authorities can be found on the following institutional website:
http://ec.europa.eu/newsroom/article29/item-detail.cfm?item_id=612080