Last update: May 25, 2018
The website www.courreges.com ("COURREGES Website") can potentially collect and process specific personal data, within the meaning of the EU General Data Protection Regulation No 2016/679 on data protection and privacy dated April 27, 2016 (“GDPR”) and the national laws transposing the GDPR into domestic law.
Who is the data controller in charge of data processing on the COURREGES Website?
The data controller in charge of data processing on the COURREGES Website is Groupe COURREGES, a French société par actions simplifiée (simplified joint stock company) with a share capital of EUR 4,222,221 euros, registered in Paris under number 319 921 854, whose head office is located 40 rue François 1er - 75008 Paris (France), represented by its President, Madame Christina Ahlers (hereinafter "Courrèges", "We", "Us" or "Our").
- What type of personal data is collected by COURREGES?
When you use the COURREGES Website and, for example, you place an order on the Website, We collect and process certain personal data concerning You.
The data concerned is the following:
- some data is collected automatically, such as the IP address of the computer terminal You are using, the date and time of connection, the type of computer used, the operating system and browser software used, your screen resolution and the identity of your internet access provider. We also keep a record of your orders and the pages of the Website that You visit. This data enables Us to customize your experience on the website, to guarantee a smooth connection, to assess system security and to establish user statistics. It is collected by using “cookies”, i.e. small text files that are stored on the storage medium of your terminal;
- some data is collected because You have accepted to provide it to Us, i.e. when You place an order on the COURREGES Website. The data thus collected is: Your login (if You have created an account on the COURREGES Website), name, first name(s), postal address, email address, telephone number, bank account information, and garment size. Some of this data is essential to process Your order and is identified by an asterisk. We may also collect personal data concerning You if you write to Us.
As a principle, the COURREGES Website is not designed for collecting or processing personal data considered as “sensitive”, within the meaning of the GDPR and the relevant transposition laws.
On what legal basis is personal data collected and processed?
COURREGES does not engage in any unlawful collection or processing of personal data. The COURREGES Website collects and processes personal data on duly identified legal bases:
- the data collected automatically is necessary for Our legitimate business purposes (particularly for establishing statistics on connections to the Courrèges Website), and the collection and processing of such data does not in any way interfere with Your interests or fundamental rights. The data concerned is ordinary technical data of the type that is currently collected by most websites;
- the other data We collect and process is done so based on Your consent and on Our need for that data to process your order or reply to Your requests. Moreover, any sensitive personal data We may collect and/or process is done so based exclusively on Your consent. We recommend, however, that you only provide us with information that is strictly necessary.
For what purpose do We use the data We collect via the COURREGES Website?
As indicated above, COURREGES uses the personal data collected via the COURREGES Website solely for the following purposes:
- the information is used to enable you to browse the COURREGES Website more easily. The objective is to allow the COURREGES Website to be properly displayed on Your terminal’s screen and to be able to identify You so that a customized selection of items can be presented to You on the COURREGES Website. This is the case where automatically collected data is concerned;
- the information is also useful, and even essential, to enable us to properly process Your order. This is the case where your contact details are concerned;
- lastly, certain information is useful to Us for managing the COURREGES Website. We analyze it (directly or via third party contractors We hire) to establish browsing statistics (e.g. to assess which pages are the most visited) and improve the COURREGES Website by enhancing its features and functionalities. It also potentially enables us to improve our products. We may also use Your IP address to combat certain fraudulent acts, such as identity theft. Lastly, We may use Your email address to send You Our newsletter.
To whom do we transfer the data We collect via the COURREGES Website?
The personal data We collect via the COURREGES Website is primarily of use to COURREGES, as We are responsible for processing Your order. The data is therefore intended for COURREGES’ e-commerce, marketing and IT departments.
The data may also be transferred to a limited number of recipients, such as:
- the authorities: we will cooperate, where necessary, with the State, administrative or judicial authorities, and especially the authorities in charge of enforcing the GDPR and the relevant transposition laws, if We are required to do so. Consequently, We reserve the right to disclose information collected via the COURREGES Website to the relevant authorities when We are ordered to do so, for example in the scope of an investigation following a bank card theft.
For how long does Courrèges store Your personal data?
COURREGES stores Your personal data in an identifiable form for the time strictly necessary to fulfill the purpose of the processing operations concerned. Thus, broadly speaking:
- automatically collected data concerning Your browser session on the COURREGES Website is automatically erased when You disconnect;
- the data concerning your orders on the COURREGES Website, including your purchase history, is stored in accordance with the rules applicable under the French Commercial Code (Code de Commerce) to archiving accounting documents, and in accordance with the provisions of the French Consumer Code (Code de la Consommation) applicable to storing contracts concluded on line;
- all other data, including statistics, is stored in an anonymous form that does not enable Your identification.
In this regard, You are entitled to give instructions concerning the storage, erasure and disclosure of Your personal data after your lifetime. To do so, please write to the following address: firstname.lastname@example.org. In the absence of any such instructions, Your personal data will be stored in accordance with the above, unless Your heirs request the early erasure thereof.
What are Your rights in respect of Your personal data?
COURREGES complies with the rights granted to You under the GDPR and the relevant transposition laws.
Thus, You have the right to request access to Your personal data stored by COURREGES and the correction or erasure thereof, as well as the restriction of processing of Your personal data and the right to object to the processing thereof.
However, in the event of any restriction or objection concerning processing, COURREGES may no longer be able to provide You with customized access to the COURREGES Website and may not be able to properly process Your order. Moreover, in case of exercise of the right to object or the “right to be forgotten”, COURREGES may nevertheless store certain information to enable it to comply with its legal obligations.
To exercise these rights, You can send an email to the following address: email@example.com.
Notwithstanding the foregoing, and where Google Analytics is concerned, You can prevent the collection of data concerning your use of the COURREGES Website (particularly your IP address) by way of cookies and the processing of such data by Google if you click on the link below and download the plug-in corresponding to Your browser: http://tools.google.com/dlpage/gaoptout.
Furthermore, please note that You can object to cold calling if You register on the website www.bloctel.fr.
Lastly, You have the right to lodge a complaint at any time with the relevant data protection supervisory authority. For this purpose, you can contact the relevant data protection supervisory authority in the region where you live or, in any event, the CNIL in France at the following address: www.cnil.fr.
How is Your personal data protected?
In its capacity as data controller, COURREGES undertakes to implement and maintain, at its cost, appropriate technical and organizational measures for the processing and security of personal data, in compliance with Articles 32 to 34 of the GDPR.
Courrèges ensures that these technical and organizational measures are always adapted to the specific risks inherent to its processing operations, in view of the nature of the information potentially provided on the COURREGES Website, especially to protect Your personal data against any accidental or unlawful destruction, loss, alteration, unauthorized disclosure or access.
Thus, regarding the technical measures implemented by COURREGES:
- all personal data is stored on servers located in France;
- all information concerning banking transactions is encrypted during its transfer via an SSL connection from the source to the target. COURREGES does not store any banking data;
- administrative access to our servers is limited to specific IP addresses declared to our hosting services provider.
Regarding organisational measures:
- only specific members of COURREGES’ personnel are authorized to access Your personal data;
- access to the data is protected by logins and passwords;
- the servers used are monitored by security groups.
COURREGES further undertakes to maintain, update and keep complete and accurate records concerning the personal data processed on the COURREGES Website. These records provide details of its processing operations.
Is any data transferred abroad?
As a principle, Your personal data is stored on servers located in France.
However, as an exception to this principle, certain data (relating to browsing) processed via Google Analytics is transferred to and stored by Google on servers located in the United States. Google is committed to maintaining the security and confidentiality of the data it processes, being specified that such data does not contain any identifiers such as names, addresses, etc. For more information, please consult the following webpage: https://support.google.com/analytics/answer/6004245.
Data Protection Officer appointed by COURREGES
For further information concerning the manner in which COURREGES collects and processes Your personal data, please contact our Data Protection Officer at the following address: firstname.lastname@example.org.