PRIVACY POLICY - COOKIES

Update: August 9th 2018

PREAMBLE

As part of its activities, PYRENEX offers an e-commerce service accessible from the website www.pyrenex.com (the "Site"). As a result, PYRENEX collects personal data. The collection of this data is done via the Site or by telephone.

The purpose of this section is to provide clear, simple and complete information to the persons concerned ("you" or "your") about how PYRENEX ("PYRENEX", "we" or "our"), as data controller, collects and uses personal data about you and the means available to you to control such use and exercise your rights therein.

We respect your privacy and PYRENEX is committed to ensuring the highest level of protection regarding your personal data. Thus, PYRENEX makes sure to adopt and comply with a data processing policy compliant with the regulations currently in force. As such, PYRENEX fully respects the applicable European law regarding the protection of personal data, and in particular the European General Data Protection Regulation No. 2016/679 of 27th April 2016 (known as "GDPR") and French legislation applicable on the basis of the GDPR.

Every time you complete information on the Site, you will be informed as to how data in the form is collected, the obligatory or optional nature of the answers requested (indicated by an asterisk) and the consequences of a lack of response, the length of time your data is kept, the recipients of these data, as well as the existence and methods of exercising your rights.

This section will also inform you about cookies that may be placed on your device when you visit the Site and the options and rights you retain in terms of the use of cookies.

PYRENEX may modify its privacy policy at any time. If so, we will notify you by changing the date at the top of this section and, in some cases, we will provide you with additional notifications (for example, by sending an email). We recommend that you review this section whenever interact with the Company so that you are fully aware of our privacy and cookie protection policy and the processes you can use to control the use of your personal data in order to protect your privacy.

1. WHO IS RESPONSIBLE FOR PROCESSING YOUR PERSONAL DATA?

The company that collects your personal data and implements the processing of your data is:

PYRENEX, a joint stock company with a capital of 3,864,920 euros, whose head office is located at 75 rue de Papin Industrial Zone of Péré - 40500 Saint-Sever (France), French business registration number 302 306 626 (Companies register Mont-de-Marsan) - telephone +33 (0) 5 58 76 03 40 - email address: eshop@pyrenex.fr.

2. WHEN IS YOUR PERSONAL DATA COLLECTED AND WHAT INFORMATION DO WE COLLECT?

2.1 Your personal data is collected, depending on the case, either automatically as a result of your visits and / or actions on the Site, or directly from you (via a form that you voluntarily filled out or when you ordered our products over the phone), or via your friends and familiy (if they are purchasing a product as a gift) or via our partners or social networks.

PYRENEX therefore collects your personal data when:

-          You browse the Site,

-          You subscribe to our newsletter and / or sign up for emails regarding our commercial offers,

-          You create your customer account on the Site,

-          You add products to your basket,

-          You or your friends / family members place an order on the Site

-          You contact our Customer Service (by email or phone)

-          You request a return/refund/exchange,

-          You share or view Site content on our Facebook, Instagram or YouTube pages.

PYRENEX may also receive personal data about you from:

-          Some of its partners - this only concerns information communicated by third parties with whom you are in contact and you have authorised to share your personal data with PYRENEX for commercial prospecting or targeted advertising purposes,

-          Social networks - this is information that you yourself have provided when you accessed these networks via the Site (especially when you post product reviews or comment about our service on these networks). Please note that the communication of your data on these social networks is governed by the personal data protection policies of these social networks to which you are referred by us.

2.2 PYRENEX takes into account the principles of data minimisation, as well as data protection by design and by default. As a result, only personal data that is relevant, adequate and limited to what is necessary for the purposes for which it is processed are collected.

PYRENEX collects and processes your surname, first name, date of birth, shipping and billing addresses, email address, phone number, password and ID, IP address, connection and navigation data, information on your chosen payment method (including your credit/debit card number and its expiry date, as well as the name of the credit/debit card holder when you make a payment online), order history, products consulted, products purchased and product baskets, language chosen and the selected country.

In certain caseswe may also collect information that you provide about other people (such as when you decide to buy and ship one of our products to friends or family). We only use this information to respond to your request and will not send commercial communications to your contacts unless they choose to receive communications from us.

Personal data that's required in order to answer your enquiries is indicated by an asterisk on the forms. If you fail to complete these required fields, we will not be able to respond to your enquiries or handle any orders you place.

Apart from this mandatory information, all other personal data that you provide is on an optional basis. However, such a decision could result in limited access to certain services or products offered by PYRENEX, or other Site functionalities.

3. WHY IS YOUR PERSONAL DATA COLLECTED, WHAT ARE THE LEGAL BASES AND FOR HOW LONG IS THIS INFORMATION STORED?

3.1 Why is your personal data collected?

Your personal data is collected for specific, explicit and legitimate purposes.

Depending on the case, your personal data may be used for:

-          The management of your customer account, your shopping basket, your orders, your deliveries,

-          The payment of your orders,

-          The management and the follow-up of customer service issues (telephone calls / emails), the follow-up of your orders, the management of your complaints, our after-sales service, your product returns and refunds,

-          Facilitate your navigation on the Site,

-          In order to send out newsletters and commercial offers in accordance with the choices you indicated on the site,

-          Customise and improve our services and online advertising,

-          Site safety,

-          For statistical and performance purposes in order analyse activity on the Site and improve the services offered (in particular we measure the number of pages viewed, the number of visits, as well as your activity on the Site),

-          To provide tools that allow sharing on social media.

PYRENEX may also use your personal data for administrative purposes or for any other purpose imposed by applicable law.

3.2 What are the legal bases?

Your personal data is processed by PYRENEX only in cases allowed by the applicable regulations, and in particular under the following conditions:

  • When you have expressed free, specific, informed and unambiguous consent regarding the processing of your personal data (eg subscription to our newsletter and the opening of your customer account),
  • When undertaking contractual or pre-contractual measures at your request (eg: placing your orders, delivery and payment of products, invoicing, execution of any other current or future service in relation to the use of the Site),
  • With respect to PYRENEX's legal and regulatory compliance (for example keepng invoices on record, fight against fraud),
  • When the legitimate interests of PYRENEX justify the treatment of such information (eg: manage and improve the Client/Customer relationship, promote our products and services, including the promotion of services adapted to your geographical location, the implementation of computer security measures).

Information in accordance with the applicable law is provided in each case.

3.3 For how long do we keep your data?

Most of your personal data is kept for as long as you are an "active" customer of the Site and have not asked PYRENEX to delete such information. In any case, your personal data will not be kept for more than 3 years after your last activity on the Site (which may be, for example, your last purchase or the last time you logged into your account) or your last visit if you are simply visiting the Site.

Your personal data will then be archived, with restricted access, for an additional duration strictly defined (legal obligations or for probative purposes) and authorised by law (payment, unresolved litigation, guarantee period...) or for anonyumous statistical information. Once the archive period is over, your personal data will be deleted.

However, there are special cases where the data retention period may be shorter. In this respect cookies will be stored on your device for 13 months after they have been placed. Similarly, your IP addresses relating to your consultations on the Site are retained (after being anonymised) for a period not exceeding 13 months. Finally, with regard to the data relating to your debit/credit cards, these are in principle suppressed once the transaction is completed, that is to say as soon as you have finalised a purchase. However, we may postpone the deletion of this data until you have received the product you ordered from us, plus, if applicable, the withdrawal period that you may have been offered.

In the case of a payment by a debit/credit card, the card number and expiry date may be retained as proof in case of an eventual dispute of the transaction. This data is stored in intermediary archives, for the duration 13 months after the card has been debited. This period may be extended to 15 months to take into account the use of deferred debit/credit cards. This data can only be used only in case of a transactional dispute.

The data relating to debit/credit cards can be kept longer subject to obtaining your express consent once you've been informed of the reason (for example facilitating payments made by regular customers). In other words personal data will be kept for the duration necessary to fulfill the purpose for which this data was collected. Your consent is confirmed when you check the relevant box.

Data on the CVV visual cryptogram on the back of your debit/credit card will not be stored. All card-related data is deleted once your debit/credit card expires.

4. WHO RECEIVES YOUR PERSONAL DATA?

The personal data collected is intended for PYRENEX, who is responsible for data processing and more specifically to the following internal departments: Marketing, Sales Administration, Customer Service, Accounting and Logistics.

This data may also be transmitted to our suppliers or subcontractors who contribute to the processing of orders placed on the Site, such as the companies responsible for the execution of orders, their payment, their delivery, our service providers and Site and database management companies. All of these third parties are subject to non-disclosure agreements.

Your data will not be transmitted to third parties for advertising and prospecting. Similarly, PYRENEX will not sell or rent any information or personal data about you without your express and prior agreement.

In addition, PYRENEX may have to transmit your data to the police authorities in the context of legal requisitions concerning the fight against fraud or to customs services for deliveries abroad.

Data (in particular relating to your identification) may also shared with third parties when you use the social media links/buttons that feature on the Site. This use is governed by the conditions of use of the social networks concerned, which we advise you to consult.

5. HOW IS YOUR PERSONAL DATA KEPT SAFE?

Your personal data is protected by technical and organisational measures compliant with French and European legal and regulatory requirements designed to ensure its security and confidentiality.

PYRENEX uses protection technologies that include encryption systems, individual authentication, firewalls and "fail2ban" attack detection software. We also regularly update our server software, antivirus systems and daily backup procedures.

Any payments made on the Site are made via secure payment systems. This confidential payment data is encrypted using an SSL (Secure Socket Layer) protocol and directly transmitted to the corresponding institution.

PYRENEX ensures, under written commitments and signed contracts, that its service providers or subcontractors provide the necessary guarantees and implement sufficient security measures to ensure the protection of the personal data that they process and to do so in accordance with the requirements laid down by the regulations in force on the protection of personal data.

Although PYRENEX takes reasonable measures to protect your personal data, no transmission or storage technology is completely foolproof.

In accordance with applicable regulations, in the event of proven violation of your personal data that could create a high risk for your rights and freedoms, PYRENEX undertakes to communicate this violation to the competent supervisory authority and, where required by the said regulations, to the persons concerned (individually or in general as the case may be).

Without prejudice to the above, it is your responsibility to exercise caution to prevent unauthorised access to your personal data and your devices (computer, smartphone, tablet...).

In addition, the Site offers links to third party websites that may interest you. PYRENEX has no control over the content of these third party sites or how these third parties protect the personal data they may collect. Consequently, PYRENEX declines any responsibility regarding the processing by these third parties of your personal data that is not subject to our privacy policy. It is your responsibility to inform yourself about these third party privacy policies.

6. WHAT ARE YOUR RIGHTS REGARDING YOUR PERSONAL DATA AND HOW TO EXERCISE THEM?

6.1. Your Rights

Subject to the limits set by the regulations in force, you have the following rights in respect of your personal data:

6.1.1 Right of access

You are entitled to obtain confirmation from us that your personal data is being processed or not and, where applicable, to request access to such personal data, including, without limitation, the nature of the personal data concerned, the purposes of the processing and the recipients. This right is not absolute, however, as we must take into account the rights and freedoms of others.

In this respect, you can request to receive an electronic copy (for any additional copy, PYRENEX is entitled to demand the eventual payment of reasonable fees based on the administrative costs incurred).

Before responding to your request, we are required by current regulations to verify your identity. We may also be required to ask you to provide us with more information in order to respond to your request.

If you have a customer account, you can directly access the data contained in your online account, the history of your transactions, as well as your subscription choices regarding our newsletter and commercial correspondence.

6.1.2 Right to rectification

You can ask for personal data to be corrected and limit its use while this data is being corrected. You also have the right, depending on the purposes of the processing, to request that your incomplete personal data be completed. If this is the case we are likely to ask you for supporting documents.

If you can not access your account or if the data you want to correct can not be corrected via access to your account, contact us via the means provided in Article 6.2.

6.1.3 Right of objection

When the collection and processing of your personal data is based on your consent (such as the creation of your customer account, the subscription to our newsletter, receiving commerical correspondence, the use of cookies on the Site), you have the right at any time to withdraw your consent.

For example, you can exercise this right by changing your newsletter subscription options, withdrawing your consent for the use of cookies or by removing information requested when opening your account.

If you delete data that is mandatory in order to create your account or access our services, you will no longer be able to benefit from the services linked to your account or place an order on the Site.

However, we will be entitled to refuse your request in the event that we demonstrate that there are legitimate and compelling reasons for the processing of your personal data that prevail over the interests and rights and freedoms of the data subject, or for the establishment, exercise or defense of rights in court. In accordance with the regulations in force, the withdrawal of your consent is only valid for the future and cannot therefore call into question the lawfulness of data processing carried out before this withdrawal.

6.1.4 Right not to be the subject of a decision based exclusively on automated processing

Subject to certain limitations, you have the right to object to a decision based solely on automated processing, including profiling, producing legal effects that affect it or significantly affecting it.

6.1.5     Right to Data Deletion / Right to be Forgotten

You can also request the deletion of your personal data in the following cases:

  • The data is no longer necessary in relation to the purposes for which it was collected or otherwise processed,
  • You want to withdraw your consent with regard to the processing of your personal data by us and there is no other legal basis for this data processing,
  • You believe and can establish that your personal data has been subject to unlawful processing,
  • Your personal data must be deleted to comply a legal obligation.

You may alternatively, within the limits provided by law, request the restriction of processing of your personal data.

Please note that notwithstanding the exercise of your right to deletion or limitation, we may retain certain personal data about you when required by law or when we have a legitimate reason to do so (for example, you have a pending order that has not yet been delivered, you have made purchases and we are legally obliged to keep some of your data for accounting purposes) for the fiscal year or for defending legal rights (this would be the case if we consider that you have violated our General Conditions of Use and Sale).

6.1.6 Right to limit the processing of your personal data

The applicable regulations state that this right may be invoked in certain cases, in particular the following:

  • When you dispute the accuracy of your personal data,
  • When you consider and can establish that the processing of your personal data is illegal but that you oppose the deletion of personal data and instead require the restriction of its use,
  • When PYRENEX no longer needs your personal data, but you still need it for the purposes of ascertaining, exercising or defending legal rights,
  • When you oppose the treatment of data that is based on the legitimate interest of the controller, during verification as to whether the legitimate grounds pursued by the controller will prevail over your own.

6.1.7 Right to personal data portability

You may, within the limits provided by law, ask PYRENEX:

  • on the one hand, to recover, in a structured, commonly used and machine-readable format, the personal data that you have communicated to us and
  • on the other hand, to transmit this personal data to another controller without PYRENEX being able to oppose it.

6.1.8 The right to lodge a complaint with a supervisory authority

If despite the efforts of PYRENEX to protect the confidentiality of your personal data, you believe that your rights have not been respected, you may file a complaint with a supervisory authority.

A list of supervisory authorities is available on the European Commission website available on: https://ec.europa.eu/info/law/law-topic/data-protection_en.

For France, it is the CNIL (https://www.cnil.fr/fr).

6.1.9 Right to decide the fate of your personal data after death

Finally, you have the right to decide the fate of your personal post-mortem data by adopting general or specific guidelines. PYRENEX undertakes to respect these guidelines. In the absence of guidelines, PYRENEX recognises that your heirs have the possibility of exercising certain rights, in particular the right of access and the right of opposition to proceed, in particular to close the deceased Customer's account and to oppose the treatment of the latter's personal data.

6.2. How to exercise your rights

For any question relating to our privacy policy and / or to exercise your rights as described in article 6.1, you can contact PYRENEX by email or by post, by sending a letter specifying the right (s) that you wish to enforce accompanied by a copy of proof of identity to the following email address: eshop@pyrenex.fr or PYRENEX - Service de gestion des données personnelles – 75 rue de Papin, zone industrielle de Péré, 40500 Saint-Sever – France.

PYRENEX undertakes to respond as soon as possible, and in any event, within one month from the receipt of your request.

If necessary, this period may be extended by two months, given the complexity and the number of requests addressed to PYRENEX. In this case, you will be informed of this extension and the reasons for the postponement.

If your application is submitted electronically, we will also reply to you electronically where possible, unless you specifically request otherwise.

If we do not respond to your request, we will give you the reasons why and you will then have the opportunity to lodge a complaint with a supervisory authority (in France the CNIL) and / or to launch a judicial appeal.

7. IS YOUR PERSONAL DATA TRANSFERRED OUTSIDE THE EUROPEAN UNION? WHAT ARE THE GUARANTEES?

We normally keep your personal data in the European Union. However, it is possible that the data that we collect when you use the Site or our services are transferred outside the European Union to countries whose personal data protection legislation differs from that applicable within the European Union.

This is especially the case with regard to the data transmitted to our service providers or subcontractors located outside the European Union who we use to deliver our products to you when your delivery address is located in a country that is not part of the European Union. When our subcontractor is located in a country whose legislation has not been based on an adequacy finding on the part of the European Commission, we make sure that the transfer of your personal data is supervised by the standard contractual clauses of the European Commission that ensure a sufficient level of protection of privacy and the fundamental rights of persons or equivalent guarantees or, for the United States, that our subcontractor adheres to security principles (Privacy Shield).

8. HOW IS YOUR PERSONAL DATA USED WITH RESPECT TO SOCIAL NETWORKS?

The Site uses third-party computer applications that allow you to share content from our site with other people or to inform these other people of your opinion or your opinion about content of our Site. This is particularly the case of the "Share" and "Like" buttons from social networks (Facebook, Instagram, YouTube, etc.).

Your use of social networks to interact with PYRENEX is likely to result in data exchanges between PYRENEX and these social networks.

Practically and by way of example, if you are connected to the social network Facebook on your computer and you visit a Site page, Facebook is likely to collect this information. Similarly, if you click on the "Instagram" button on a Site page, Instagram will collect this information.

If you do not want the social network to link information collected through the Site to your user account, you must disconnect from the social network before visiting the Site.

In any event, we advise you to consult the privacy policies of these social networks to learn about the personal data they can collect through these plug-ins and the purposes for collecting your data, including for advertising purposes. You will be able to configure access and data confidentiality directly on the social networks.

Finally, we inform you that we may collect certain information and personal data about you related to your activity on PYRENEX's social media pages for advertising purposes (especially targeted advertising) and to improve our commercial relationship. This information and personal data thus collected are governed by this privacy policy.

9. WHAT ARE THE COOKIES USED ON THE SITE AND HOW TO MANAGE THEIR SETTINGS?

PYRENEX pays particular attention to your settings regarding the use of cookies. This section aims to make you aware of the use of cookies, inform you as to how they are used and tell you how to set your devices to refuse cookies.

What is a Cookie?

A cookie is a text file of limited size deposited by the browser and stored on your device (computer, tablet, smartphone...) during your visit to a website.

When you visit the Site, we may, subject to your choices that you can change at any time, be required to install cookies on your device.

Only the issuer of a cookie can read the information contained therein.

A cookie does not identify you directly, but rather identifies your browser or your device.

Cookies that may be written to a computer system

Some cookies are essential for the use of the Site, others allow to us to optimise and personalise the content and advertisements displayed or allow the collection of statistical data or ensure the security of your online payments.

These cookies are deposited either by PYRENEX or by third parties (Google Analytics and Prestashop).

In cases where these cookies are filed by third parties, their issue and use are subject to the third party's cookies policies and they are the only organisations that will able to access the information the said cookies contain. We wish to inform you that we do not transmit any of your personal data in this respect.

Thus, when you connect to the Site, five types of cookies may be installed in your terminal:

  • technical cookies including cookies strictly necessary for browsing the Site (such as session IDs), as well as feature cookies that allow you to access specific features, in particular to recognise you, to report your visit to a particular page and to improve your browsing experience:
  • memorise information relating to a form that you have filled in on the Site or concerning products that you have chosen on the Site (contents of your basket etc.),
  • allow you to access the reserved and personal areas of the Site such as your customer account, thanks to identifiers or data that you have previously entrusted to us,
  • implement security measures, e.g. when asked to sign in again to a content or service after a certain amount of time has lapsed,
  • adapt the presentation of the Site to the display preferences of your device (operating system used, language used, display resolution etc.), customise the content we offer.

You may object to the use of this type of cookies and delete them via your browser settings, however you may no longer be able to access the Site and / or certain services.

  • cookies to secure your online paymentsto prevent Internet payment fraud.

You may object to the use of this type of cookies and delete them via your browser settings, however you may no longer be able to access certain services on the Site.

  • audience measurement cookies allowing PYRENEX to measure the audience of the various contents and sections of the Site in order to evaluate and better organise them, and in particular to:
  • establish statistics and traffic to the Site allowing us to improve the value and usability of our services,
  • to adapt the presentation of the Site to your device display preferences (language, screen resolution, operating system, etc.) when you visit our website, according to the hardware, viewing or reading software that your device has.

Audience measurement cookies are issued by PYRENEX or its service providers (Google Analytics and Prestashop). In addition to traffic analyses, they allow, if necessary, to detect navigation problems and therefore improve the usability of our services. The traffic analysis services used by the Site produce and forward to our technical service providers only aggregated statistics and traffic volumes, to the exclusion of any individual information.

You may object to the use of this type of cookies and delete them via your browser settings, however you may no longer be able to access certain services on the Site.

  • advertising cookiesallowing PYRENEX to:
  • count the number of users who clicked on each advertisement and, if applicable, the subsequent actions performed by these users on the pages to which these advertisements lead,
  • adapt the advertising content of the Site as well as our offers, depending on the navigation of your terminal on the Site or the purchases that you can make and / or according to the location data (longitude and latitude) transmitted by your terminal (with your prior agreement).

You may object to the use of this type of cookies and delete them via your browser settings, however you may no longer be able to access certain services on the Site.

  • sharing cookies allowing you to share the contents of the Site on Facebook, YouTube, Instagram and other similar social networks with other persons or to make known to those other persons your consultation or your opinion concerning a content of the Site. This is particularly the case of the "Share" and "Like" buttons from social networks present on the Site.

When you visit a page on the Site that contains this type of plug-in, your browser establishes a direct connection with the servers of the social network and

  • if you are connected to the social network during your navigation, the application buttons are used to link the pages viewed to your account on the social network;
  • if you interact via plug-ins, for example by clicking on the "Like" button or leaving a comment, the corresponding information will be transmitted to the social network and published on your social network account.

If you do not want the social network to link information collected through the Site to your user account, you must disconnect from the social network before visiting the Site.

We invite you to consult their privacy policies to learn about the purposes of use, including advertising, and navigation information that these social networks can collect.

You can object to the use of this type of cookies (directly deposited in your device by these social networks) and delete them using your browser settings, however you may not be able to access certain services on the Site.

How long are cookies stored for?

In this respect cookies will be stored on your device for 13 months after they have been placed.

How to set the placement of cookies?

Your choices are never final. You can at any time disable all or some of the cookies, according to the process described below.

If your browser is configured to refuse all cookies, you will not be able to create your customer account or benefit from essential features of the Site.

To manage cookies and your choices, each browser configuration is different.

Your browser's help menu will tell you how to change your cookie preferences. You can disable or delete cookies using your browser options.

How to exercise your choice, depending on the browser you use?
For Internet Explorer ™: http://windows.microsoft.com/fr-FR/windows-vista/Block-or-allow-cookies,
For Safari ™: http://docs.info.apple.com/article.html?path=Safari/3.0/fr/9277.html,
For Chrome ™: http://support.google.com/chrome/bin/answer.py?hl=fr&hlrm=en&answer=95647,
For Firefox ™: http://support.mozilla.org/fr/kb/Activer%20et%20d%C3%A9sactiver%20les%20cookies,
For Opera ™: http://help.opera.com/Windows/10.20/fr/cookies.html

For other browsers, please refer to their help menus.

If you share the use of your device with other people

If your device is used by several people and when the same device has multiple browsers, we can not ensure with certainty that the services and advertisements sent to your device will correspond to your use of this device and not to that of another user of this device.

As a result, sharing your device with other people and configuring your browser settings for cookies is your choice and your responsibility.

10. HOW DO WE COMPILE AND USE IP ADDRESSES?

Finally, the IP addresses related to your Site visit are collected and stored in order to determine your country of connection and for the establishment of statistics, after being anonymised by removing the last two bytes of the IP address.

IP addresses are stored for up to 13 months from your first visit to the Site.