Privacy Policy

Last Updated: 01/05/2025

At MB Atelier, we place great importance on the privacy and security of your personal data. This privacy policy aims to inform you about how your data is collected, used, stored, and protected when you use our website www.mb-atelier.com, particularly when creating and using a customer account.

1. Data Controller

The data controller is:
MB Atelier – Sole Proprietorship
SIRET: 94005421600012
Head Office: 29 rue de la Fontanelle, 12800 Naucelle, France
Contact: mb-atelier@outlook.com

2. Data Collected

When you create a customer account or use our services, we collect certain personal data, including:

  • First and Last Name

  • Email Address

  • Password (encrypted)

  • Mailing Address (for delivery/billing)

  • Phone Number (if provided)

  • Order and interaction history

Other data may be collected automatically during your browsing: IP address, browser, pages viewed, visit duration (via cookies or analytics tools).

3. Purposes of Processing

Your data is collected for the following purposes:

  • Creation and management of your customer account

  • Processing orders, payments, and deliveries

  • Sending transactional emails (confirmation, invoice, etc.)

  • Customer service and follow-up of requests

  • Improving the user experience on the website

  • Compliance with legal and tax obligations

4. Legal Basis for Processing

In accordance with Article 6 of the GDPR, data processing is based on the following legal grounds:

  • Contract execution: account and order management

  • Consent: newsletter subscription (if offered)

  • Legal obligation: invoicing, accounting retention

  • Legitimate interest: site security, fraud prevention

5. Data Recipients

Personal data is never sold.

It may be shared only with trusted technical service providers or partners for:

  • Website hosting (Hostinger)

  • Secure payment (e.g., Stripe, PayPal)

  • Shipping/delivery (if applicable)

These providers are committed to maintaining the confidentiality and security of your data.

6. Data Retention Period

  • Customer account data: as long as your account is active

  • Billing data: 10 years (legal obligation)

  • Audience measurement cookies: up to 13 months

  • Prolonged inactivity (2 years): anonymization or deletion

You can request the deletion of your account at any time.

7. Security

We implement all necessary technical and organizational measures to protect your data:

  • HTTPS connection

  • Encrypted password (hashed)

  • Access restricted to authorized personnel only

  • Regular backups

8. Your Rights

In accordance with Articles 15 to 22 of the GDPR, you have the following rights:

  • Right of access to your data

  • Right to rectification

  • Right to erasure ("right to be forgotten")

  • Right to restrict processing

  • Right to object to processing

  • Right to data portability

  • Right to withdraw your consent at any time

To exercise these rights, please contact us at: mb-atelier@outlook.com

If you believe your rights have not been respected, you can also file a complaint with the CNIL (www.cnil.fr).

9. Cookies

For more information, please refer to our Cookie Policy (link to dedicated page or section).

10. Changes

This privacy policy may be updated at any time. In case of significant changes, you will be informed by email or during your next login.