- how their personal data is collected and processed in accordance with current legislation and in particular the European Regulation, No. 2016/679 of the Parliament and of the Council of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data, which came into force on May 25, 2018. Personal data must include all data that is likely to identify a user. This includes the user's first name, surname, age, postal address, e-mail address, location and IP address:
- what rights users have concerning this data;
- who is responsible for processing the personal data collected and processed ;
- to whom these data are transmitted ;
1. Data collected and processed and method of collection
Ordering products on the site www.www.diega.fr
When the Customer makes a purchase on the site www.www.diega.fr the following personal data are collected:
- First name
- Mailing address,
- Phone number,
- Mail address
SARL C.P. will keep all data collected on the site's computer systems under reasonable security conditions.
SARL C.P will regularly review the personal data it holds and delete any that is no longer required. No personal data will be held for more than five years. After this period, data may be anonymized and retained by SARL C.P for legal or statistical purposes.
The user's bank details are not kept beyond the purchase. In any case, the cryptogram is never kept by SARL C.P.
Subject to the user's express consent, obtained when registering for the SARL C.P newsletter, the following personal data is collected:
- Mail address
2. Transmission of data to a third party
SARL C.P may pass on personal data to its subcontractors, service providers and suppliers. For example, when the customer makes a purchase on the site, his/her details will be communicated to the delivery service provider.
The data collected and processed by the site is exclusively hosted and processed in France.
3. Data controller and data protection officer
The person responsible for processing personal data is: SARL C.P
He can be contacted by email, at the address : email@example.com or by post to :
SARL C.P, 6 rue Béranger, 75003, Paris.
The Data Controller is responsible for determining the purposes and means of processing personal data.
Obligations of the data controller
The data controller undertakes to protect the personal data collected, and to respect the purposes for which the data was collected.
The site has a T.LS certificate to guarantee that information and data transfer via the site are secure. The purpose of this certificate is to secure the data exchanged between the user and the site.
The data controller undertakes to notify the user of any rectification or deletion of data, unless this would entail disproportionate formalities, costs or steps for the user.
In the event that the integrity, confidentiality or security of the user's personal data is compromised, the data controller undertakes to inform the user by any means necessary.
4. User rights
In accordance with regulations governing the processing of personal data, the user has the following rights:
Right of access, rectification and deletion
Users may access, update, modify or request the deletion of their personal data.
If he/she has one, the user has the right to request the deletion of his/her personal space.
Right to data portability
Users have the right to request the portability of their data held by the site to another party.
Right to limit and object to data processing
The user has the right to request the limitation of or to object to the processing of his/her data by the site, without the site being able to refuse, unless it can demonstrate the existence of legitimate and overriding reasons, which may prevail over the interests and rights and freedoms of the user.
For any information concerning these rights, or to exercise them, the user should write to the data controller at the following address : SARL C.P, 6 rue Béranger, 75003, Paris.
In order for the data controller to comply with the user's request, the user must provide the following information: first and last name, e-mail address and, if relevant, account or personal space number or subscriber number.
The Data Controller must reply to the user within 30 days.
Right to contact the competent authority
If the data controller does not respond to the user's request, or if it believes that the user's rights have been infringed, the user is entitled to refer the matter to the CNIL or any competent court.