
Welcome to BOARD SAILOR!
PRIVACY POLICY
1. Designation of the Parties
The website www.bombelliparis.com (hereinafter the “Site”) is published and operated by: The company MARINERO, a simplified joint stock company with capital of 5,000 euros, whose head office is located at 30 rue de la Maladrerie, 28120 ILLIERS COMBRAY,
Registered in the Trade and Companies Register of Chartes under number 933 817 462. Community VAT: FR54 933 817 462. (hereinafter "BOMBELLI" or "We") BOMBELLI is therefore the controller of the personal data (hereinafter "Personal Data" or "Data") of Internet users (hereinafter "Users" or "You") who access and browse the Site, in accordance with General Data Protection Regulation No. 2016/679 (hereinafter "GDPR") and Law No. 78-17 of 6 January 1978 relating to information technology, files and freedoms (hereinafter "LIL") (together the "Legislation").
personal data”).
2. Purpose
2.1 The purpose of this Privacy Policy (hereinafter the “Policy”) is to inform You of the terms and conditions of the processing of your Data within the framework of its activities including on the Site, of your rights under the Personal Data Legislation and the terms of their exercise, as well as of the cookies used on the Site.
2.2 When You access the Site, We strongly encourage You to carefully read all the provisions of the Policy before continuing to browse. When You use certain features of the Site, You may be asked to read the Policy before being able to use the feature. You can always read the Policy on the Site, accessible from the bottom of each of its pages.
2.3 The Policy is supplemented by the Cookies Policy, accessible from the bottom of each page of the Site.
2.4 The Policy may be updated at any time. In this case, however, the Policy will only be binding on Users from the time it is posted online. Consequently, the applicable Policy is the one in force at the time you browse the Site. If necessary, BOMBELLI will inform you of any changes made, in particular when processing requires your consent.
3. General information
3.1 Personal Data is any information relating to an identified or identifiable natural person, directly (e.g. your name, your photograph) or indirectly (e.g. your postal address, your bank card number), whether the identification of the natural person can be carried out from a single piece of data (e.g. name) or from the cross-referencing of a set of data (e.g. a customer residing at such an address, with such a telephone number).
3.2 Processing of Personal Data means any operation or set of operations which is performed on Data, including, but not limited to, collection, recording, organization, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction of Personal Data.
personal data.
3.3 Processing of Personal Data must always, in particular, be carried out for a specific, explicit and legitimate purpose (e.g.: collecting your address to deliver your order to you; using your email address to inform you of the status of your order).
4. Processing of your personal data
4.1 When requesting contact
When You contact Us, We collect and process Your email address, telephone number, and/or postal address, depending on how You contacted Us. We also collect any Data that You send Us, in particular the subject of Your request (e.g.: information on a product, difficulty related to the delivery of an order, request under legal guarantees, etc.). Your Personal Data that We collect during a contact request are processed only to allow Us to respond to You and, depending on Your, in accordance with the following terms: Data Controller
treatment: BOMBELLI
Purpose(s): Respond to your request; Archive our exchanges Legal basis(s):
Where your request concerns a contract concluded with Us (e.g. an order), the performance of the contract concluded with you (art. 6'1 b) of the GDPR);
For any other request, and for the archiving of our exchanges, BOMBELLI's legitimate interest in responding to your request and keeping the history of our exchanges (art. 6.1 f) of the GDPR).
Recipients:
Your personal data is intended for Customer Service. Depending on the purpose of your request, it may be transmitted:Internally, to the relevant department(s) (management, accounting, logistics, etc.);Externally, to our relevant service provider(s) (carrier, accountant, legal, etc.).
Retention period(s):
5 years from the execution of a contract concluded with
you; In other cases, 6 months at the most from the
resolution of your request.
Consequence(s) of not providing your personal data:
We will not be able to contact you and therefore process and respond to your request.
Profiling or fully automated decision-making:
Your request is not subject to action or decision-making.
fully automated.
4.2 When placing an order
4.2.1 When You wish to place an order, We collect and process:
(i) Mandatory, your email address, first name, last name, delivery address, subject of your
order, and selected delivery method; (ii) If applicable, billing address, additional delivery instructions, discount code.
The Personal Data that We collect when placing an order is processed solely to enable Us to process your order and deliver the products ordered to You, in accordance with the following terms:
Data controller: BOMBELLI
Purpose(s):
To enable us to process and fulfil your order, including
including its delivery and tracking;Archive your orders and our related exchanges;
Archive business documents relating to your
order.
Legal basis(s): The performance of the contract concluded with you (art. 6.1 b) of the GDPR);
BOMBELLI's legitimate interest in having a history of orders and keeping documents capable of justifying their execution (art. 6§1 f) fu GDPR);
The execution of BOMBELLI's legal obligations, in particular the obligation to keep accounting documents and supporting documents (art. L. 122-23 of the French Commercial Code) and to keep contracts concluded online with consumers (L. 213-1 of the French Consumer Code).
Recipients: Your personal data may be transmitted:
internally, to the relevant department(s) (sales, accounting, logistics);
externally, to our relevant service provider(s)
(carrier, payment service provider, accountant).
Retention period(s):
In principle, 5 years after the execution of the sales contract,
the exception of Personal Data:
Appearing on the documents and accounting records, kept for a period of 10 years from the end of the fiscal year in which the sale took place;
In the event of a dispute relating to the sales contract, kept for the
duration of the dispute, including the enforcement of any decision.
Consequence(s) of not providing your personal data:
You will not be able to complete the transfer of your
order.
Profiling or fully automated decision-making:
Placing an order, its execution and its monitoring are not subject to fully automated action or decision-making.
4.2.2 In addition, when paying for your order, We must process your Banking Data for the payment of your order, namely:
(i) The selected payment method;
(ii) The status of your payment (accepted/declined).
However, BOMBELLI does not collect or access data specific to your payment methods, such as your bank card number or the name of its holder. This Data is processed by the payment service provider, depending on the payment method selected (see below, article 5.3. of the Policy).
The Banking Data processed when paying for your order are used only to allow you to make your payment and to allow Us, where applicable, to reimburse you in cases where you exercise your right of withdrawal or cancellation of your order, as well as to manage payment disputes. Your Data is also processed to prevent online payment fraud, according to the following terms:
Data controller: BOMBELLI
Purpose(s): Payment of the price of your order;
Where applicable, reimbursement of the price of all or part of your order;
Preventing online payment fraud.
Legal basis(s): The performance of the contract concluded with you (art. 6.1 b) of the GDPR);
The execution of BOMBELLI's legal obligations, in particular the execution of the right of withdrawal (art. L. 221-18 et seq. of the Consumer Code);
BOMBELLI's legitimate interest in preventing and protecting against online payment fraud (art. 6§1 f) of the GDPR).
Recipients: Your Banking Data is collected and/or processed by: Your banking institution; and/or, The selected online payment service provider.
Duration(s) of
conservation :
The data relating to the means of payment used are kept for the duration necessary for the full payment of your order, increased by:
Of the period provided in the event of exercising your right of withdrawal
and/or cancellation of your order;
13 months, following the debit date or 15 months in the event of
deferred debit payment cards, your banking data
being thus preserved in intermediate archiving for purposes
proof in the event of a payment dispute.
Consequence(s) of not providing your personal data:
You will not be able to complete your order.
Profiling or fully automated decision-making:
Placing an order is not subject to any fully automated action or decision-making by BOMBELLI. In particular, We do not keep any traces of fraudulent behavior that could result in a refusal of sale. However, please be aware that your banking institution and/or systems
online payment services may carry out such processing operations.
4.3 When subscribing to our newsletter
When You wish to subscribe to our newsletter, We collect and process your email address, as well as the date and time of your registration. Your collected Data is processed only to allow Us to register you and periodically send you our newsletter, and if necessary, to prove that you have consented to subscribe to our newsletter, according to the following terms: Data Controller
BOMBELLI
Purpose(s)
Allow you to subscribe to our newsletter;
Prove that you have consented to subscribe to our
newsletter.
Legal basis(s) Your consent;
BOMBELLI's legitimate interest in preventing and protecting itself
against online payment fraud (art. 6.1 f) of the GDPR).
Recipients Your Data is intended for Customer Service. Duration(s) of
conservation
Your Data is kept until you withdraw your consent, or in the event of inactivity 3 years from the last active contact with You.
Consequence(s) of the failure to provide
We will not be able to subscribe you to our newsletter.
and therefore to send you our newsletter. your personal data
Profiling or fully automated decision-making.
Subscribing to our newsletter does not involve any action or
fully automated decision making.
5. Additional information on the recipients of your Data and their processing
related
5.1 The transfer of your personal data and methods
We do not sell or rent your Personal Data to third parties.
However, we may transfer your Data to third-party providers, including third parties acting as subcontractors, on our own behalf and according to our instructions. We strive to select third-party providers located in the territory of the European Union. However, it is possible that our third-party providers are located outside this territory. In this case, We try to select third-party providers in countries whose
the legal framework provides a satisfactory level of security. Failing this, We supervise the transfer of your Data with appropriate guarantees, in particular the signing of standard contractual clauses. Furthermore, when the law, regulations or a court decision requires Us to do so, please be aware that your Personal Data may be transmitted to public authorities or administrations.
5.2 The Site’s e-commerce solutions services
We use Shopify Inc., a provider of e-commerce solutions for managing the Site. This service provider accesses your Data when you use the Site, in particular when you make a purchase or to display targeted advertising. To learn more about managing your consent to cookies, we invite you to consult the Cookie Policy. This service is provided by the company Vimeo, Inc., a company incorporated under the laws of the State of Ontario (Canada), located at 150 Elgin Street, Suite 800, Ottawa, Ontario K2P 1L4 (Canada). You will find the personal data protection policy of the company Stripe Inc. at
the address: https://www.shopify.com/fr/legal/privacy/app-users.
5.3 The Site's online payment services We offer several payment methods to pay for your order on the Site. Depending on the payment method selected, your Banking Data is collected and processed by
the providers of these tools. When you use Apple Pay, Google Pay or PayPal, the providers of these tools may collect information relating to your purchase, its amount, the date and time of the transaction. Payment service providers implement processing aimed at preventing and combating payment fraud.
When you select:
(i) Payment by bank card, the payment service provider is the company [name], [company information].
You will find the company's personal data protection policy
[name] at the address:
[link]
(ii) Payment by PayPal, the payment provider is the company incorporated under Luxembourg law
PayPal (Europe) S.à rl et Cie, SCA, located at 22-24 Boulevard Royal L-2449, Luxembourg.
You will find the personal data protection policy of the PayPal company
(Europe) S.à rl et Cie at the address:
https://www.paypal.com/fr/webapps/mpp/ua/privacy-full
(iii) Payment by Apple Pay, the payment service provider is the English company Apple Europe Limited, 1 Hanover Street, London W1S 1YZ (United Kingdom). You will find the personal data protection policy of the company Apple Europe Limited at the address:
https://www.apple.com/legal/privacy/data/en/apple-pay/
(iv) Payment by Google Pay, the payment service provider is the Irish company Google Ireland Ltd, Gordon House, Barrow Street, Dublin 4 (Ireland). You will find the personal data protection policy of the company Google Ireland Ltd at: https://support.google.com/googlepay/answer/10223752?hl=fr&co=GENIE.Platform%3DAndroid#zipp
y=%2Cinformation-that-google-pay-may-collect%2Cinformation-that-google-wallet-may-
collect%2Ctell-third-party-companies-that-you-use-google-pay
5.4 The Site’s delivery services
We offer to deliver your order via Colissimo. This service provider
accesses your Data necessary for the delivery of your order.
This service is provided by the company La Poste SA, a public limited company with capital of
3,800,000,000.00 euros, registered in the Paris Trade and Companies Register under number 356 000 000, located at 9 rue du Colonel Pierre Avia, 75015 Paris (France). You will find the personal data protection policy of La Poste SA at the following address:
https://www.laposte.fr/donnees-personnelles-et-cookies.
When the delivery of your order occurs outside French territory, La Poste SA may subcontract said delivery to its local partners in the destination countries. In this context, it is required to process the information in accordance with the legislation relevant to the Personal Data Legislation.
5.5 Exchanges of Personal Data with social network operators
The Site integrates the plug-in of the social network Instagram. This network and BOMBELLI are responsible
jointly with the collection and processing of your Data carried out by this plug-in. This plug-in has the following purposes:
(i) Allow you to access the Page and interact with Us on social networks;
(ii) Allow us to obtain anonymized statistics on page traffic
BOMBELLI.
These treatments are based on BOMBELLI's legitimate interest in displaying multimedia content on its Site and developing its relationships with its customers via social networks (art. 6.1 f) of the GDPR). However, when these treatments are carried out using cookies, the legal basis for the treatments is article 6§1a) of the GDPR, namely your express consent.
The Instagram service is provided by the Irish company Meta Ireland Ltd., located at 4 Grand Canal Square, Grand Canal Harbour, D2 Dublin (Ireland). You can find the personal data protection policy of Meta Ireland Ltd. at: https://fr-fr.facebook.com/privacy/policy/?entry_point=data_policy_redirect&entry=0.
6. Security of your Personal Data
We strive to implement the necessary precautions to preserve the confidentiality and security of your Personal Data processed in order to prevent their alteration, destruction, loss, disclosure or any unauthorized access to such data, accidentally or illicitly. BOMBELLI has implemented technical and organizational security measures, taking into account the state of the art. The security measures are
proportional to the risks presented by the processing and the nature of the personal data processed, as well as to the costs of implementing these measures.
However, we draw your attention to the fact that the Internet network is not secure. It is also your responsibility to take all appropriate measures to protect your Personal Data accordingly.
7. Your rights
In application of the Personal Data Legislation, You have the following rights: Right of access You have the right to us:
Ask about the nature and methods of processing your data
Data carried out by BOMBELLI;
Request a copy of your Data that BOMBELLI holds at
your regard.
Right of rectification You have the right to ask BOMBELLI to correct your
Data that is incorrect or incomplete.
Right to object You have the right, at any time, to object to the processing of your Data, when such processing is carried out on the basis
legal basis of BOMBELLI's legitimate interest. When you object to our processing of your Data:
For advertising purposes, you can object without
tell us the reason(s) justifying your request;
For all other purposes, you must then indicate the
the compelling reason(s) motivating your request to exercise
right of objection.
Your opposition to the processing(s) of your personal data
applies to the future.
The withdrawal of your
consent
You have the right, at any time, to withdraw your consent to the
processing of your Data, when these processes are carried out on
the legal basis for your consent. You can withdraw your
consent without indicating to BOMBELLI any reason(s) justifying your
request.
Right to erasure You have the right to ask us to erase your Data. In this context, BOMBELLI deletes the Data as much as possible
personal data concerned. However, please be aware that such a request
cannot affect BOMBELLI’s right to retain your Data necessary:
To meet its legal obligations;
In the event of a complaint and/or dispute relating to your orders, your products and/or subscribed services.
Right to limitation You have the right to ask BOMBELLI to limit the processing of your Data, in one of the following cases:
When you contest the accuracy of this Data or consider that BOMBELLI would process it in contravention of its obligations, but you do not wish, immediately, its deletion;
When BOMBELLI no longer needs this Data, but you need it to claim, exercise and/or defend your rights.
Right to portability You have the right to ask us to transmit to you and/or to the third party of your choice your Personal Data, in a format technically usable by you or by said third party.
Right to give instructions
You have the right to give BOMBELLI instructions regarding the
fate of your Data after your death.
If you consider that BOMBELLI does not process your Data in compliance with the Personal Data Legislation, you have the right to lodge a complaint with the CNIL (via the dedicated form or by post to the CNIL, Complaints Department, 3 Place de Fontenoy, TSA 80715, 75334 PARIS CEDEX 07, France) or any other competent supervisory authority.
8. How to exercise your rights
You can exercise your rights by contacting BOMBELLI:
(i) By email, to the address contact@bombelliparis.com; or,
(ii) By post, to the address 13 rue Léon Giraud, 75019 Paris (France).
You may also object or withdraw your consent to receiving
advertising communications by email by clicking on the unsubscribe link located at the bottom of each of our communications.
No payment will be required from you for exercising your rights, except in the case of repetitive and manifestly unfounded requests. After receiving your request:
(i) Your Data transmitted on this occasion as well as your subsequent correspondence with BOMBELLI will be kept in the form of archives for a period of 5 years from the final processing of your request;
(ii) BOMBELLI may ask you for additional information to confirm your identity; this additional data will be deleted once your identity has been confirmed.
The legal basis for the processing of this Personal Data is Article 6, paragraph 1 f) of the GDPR, namely the legitimate interest of BOMBELLI. The legitimacy of this processing is to be able to prove that BOMBELLI has processed your request to exercise your rights.
9. Modifications
The Privacy Policy may be updated, in particular in application of legislative developments or BOMBELLI's activities. The version of this Policy, as made accessible, is always the one currently in force. Therefore, we invite you to consult it regularly. If necessary, we will inform you by email of the developments of this Policy.