Privacy policy

1. PREAMBLE

1.1. This Privacy Policy forms an integral part of the General Terms and Conditions, so the definitions used in the latter are reused in this Privacy Policy.

1.2. The purpose of this Privacy Policy is to inform Customers about how their Personal Data is collected from the Website, its variations on different terminals as well as during your purchases in store or, more generally, whenever you interact with us, how this is processed by the Data Controller and finally the Specific Rights that Customers have with regard to this processing as defined below.

1.3. This Privacy Policy is in accordance with the European directive e-Privacy (transposed into French law) as well as the General Data Protection Regulation (GDPR).

1.4. This Privacy Policy may be modified or updated at any time. It is recommended that you consult it regularly, particularly during each interaction with the relevant services, to stay informed about our Personal Data protection practices and how to exercise your rights.

2. DEFINITIONS

2.1. The following terms, whether used in the singular or plural in this Privacy Policy, shall have the following definitions:

Intermediate Archiving: This refers to the retention of Personal Data that is no longer necessary for the original purpose of its processing, but which still has administrative value for the Data Controller, particularly in the event of a legal obligation to retain it or for the management of litigation. This Personal Data is moved to a separate database, logically or physically separated, and whose access is, in any case, strictly limited to authorized personnel and subject to enhanced security measures. This archive is an intermediate step before the final deletion of the Personal Data concerned or its anonymization;

CG : refers to the General Terms and Conditions;

Privacy Policy : refers to this privacy and personal data protection policy for Clients implemented by the Data Controller;

Customer : refers to the natural person browsing the Website or making a purchase and whose Personal Data processing by the Data Controller is governed by the Privacy Policy. When certain Processing is based on consent, the Customer guarantees, if under 15 years of age, that they have obtained the authorization of the holder of parental authority to consent to the Processing of their Personal Data as defined in the Privacy Policy;

Account : refers to the Client's personal account, accessible on the Website via personal identifiers, confidential to the Client which he/she cannot disclose to a third party, and from which he/she can place an order;

RECIPIENT : This refers to any natural or legal person, public authority, agency, or other body to which Personal Data is disclosed, whether a third party or not. The Recipient may use the data for its own purposes or to comply with a legal obligation. However, authorities that may receive Personal Data in the context of a specific inquiry are not considered recipients within the meaning of the GDPR.

Data or Personal Data : refer to the Client's personal data, as defined by the Personal Data Regulations, collected and processed by the Data Controller in connection with the use of the Website;

Specific Rights : refer to the rights granted by the Personal Data Regulations to Customers regarding the processing of their Personal Data and developed in Article 12 of the Privacy Charter;

Purpose : designates the main purpose of the use of Personal Data;

Products : refer to the products offered for sale in store or on the website by SEKAYA.

Regulations on Personal Data : refers to Law No. 78-17 of 6 January 1978 relating to information technology, files and freedoms, in application of the Community Regulation of 27 April 2016 published in the Official Journal of the European Union on 4 May 2016 relating to the protection of natural persons with regard to the processing of personal data and on the free movement of such data (known as "GDPR" for General Data Protection Regulation);

Data controller : refers to the legal entity that determines the purposes and essential means of processing Personal Data (see Article 3). The Data Controller ensures that the processing it carries out complies with applicable data protection regulations and ensures that data subjects can exercise their Specific Rights;

Website: refers to the website and its local versions on which this Privacy Policy is hosted;

Subcontractor : refers to any natural or legal person who processes Personal Data on behalf of the Data Controller and according to their instructions. The Sub-Data Processor-The processor undertakes to process Personal Data only for the purposes determined by the Data Controller, to implement appropriate technical and organizational security measures, and to offer sufficient guarantees regarding compliance with the GDPR.

Terminal(s): refers to the hardware equipment (computer, tablet, smartphone, telephone, etc.) used by the Client to access or view the Website.

Treatment : refers to any operation or set of operations, whether or not performed by automated means, applied to Personal Data. This may include, in particular, the collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission or dissemination, alignment, restriction, erasure or destruction of Personal Data.

3. THE DATA CONTROLLER

SEKAYA, a simplified joint-stock company with a capital of 1,000 euros, whose registered office is located at 38 Cours Albert 1er 75008 Paris, France, registered with the Paris Trade and Companies Register under number 889 278 057, is responsible for the processing of personal data collected on this Site, unless otherwise stated.

4. DATA COLLECTED

4.1.In particular, within the context of creating an Account, managing the Site or browsing, the Data Controller collects and processes the following Personal Data :

  • Name,
  • First name,
  • Civility,
  • Date of birth,
  • Email address,
  • Phone number,
  • User name,
  • Delivery postal address,
  • Billing mailing address
  • Company name, if applicable
  • Information relating to an order (purchase history, payment data via online payment provider),
  • Amount, date and time of transactions carried out ;
  • Invoices,
  • Customer connection data during browsing on the Website (including date, time, IP address, page viewed),
  • Reason(s) for exclusion, if applicable (including all elements demonstrating actions that occurred less than one month ago and justify the exclusion),
  • Content saved in the Customer Account (including correspondence with Customer Service, preferences, loyalty program membership, health data),
  • Any other Personal Data provided during exchanges or received from external suppliers.

4.2. This Personal Data is provided directly by the Client or collected automatically during their browsing on the Site, in accordance with the applicable legal bases, and in particular when their collection is based on the consent of the person concerned.

4.3. All Personal Data indicated as such in the Account creation form is essential to benefit from the services of the Data Controller.

5. THE LEGAL BASIS FOR PROCESSING

5.1. In accordance with the Personal Data Regulations, the Processing designated in this Privacy Charter is supported by a specific legal basis.

5.2. Consent

5.2.1. Where required, the Processing of Personal Data is based on the free, specific, informed and unambiguous consent of the Client.

5.2.2. The Client consents to the Processing of their Personal Data for one or more specific Purposes, including :

  • Sending newsletters and marketing communications ;
  • Participation in certain specific marketing operations ;
  • Registration for the loyalty program.

5.2.3. The Website collects the Client's express consent prior to the implementation of any specific processing, in accordance with the information provided at the time of collecting this consent.

5.2.4. The Client may withdraw their consent at any time, without having to justify the reason, and this withdrawal does not affect the lawfulness of the Processing carried out before its exercise, and this under the conditions of paragraph 12 – Exercise of Specific Rights of Clients.

5.3. Contract Performance

5.3.1. Certain Processing is necessary for the performance of a contract to which the Client is a party or for the performance of pre-contractual measures taken at the Client's request.

5.3.2. In order to use the Website and benefit from its services, the Client has accepted at least the General Terms and Conditions.These documents formalize a contractual relationship between the Client and the Data Controller, serving in particular as the legal basis for the collection and processing of the Client's Personal Data by the Data Controller.

5.3.3. This Data is necessary for the performance of a number of processing operations related to the execution of the contractual relationship between the Client and the Data Controller, in particular :

  • Creating and managing the Customer Account ;
  • Order processing and tracking ;
  • Delivery management ;
  • Billing and payments ;
  • After-sales service and returns.

5.4. The legal obligation

5.4.1. Certain processing operations are necessary for compliance with legal obligations to which the data controller is subject, in particular :

  • The retention of invoices and accounting documents ;
  • The fight against tax fraud ;
  • Managing requests to exercise Specific Rights ;
  • Obligations related to the legal guarantee.

5.4.2. The Processing of Personal Data may also be necessary to comply with a legal obligation to which the Data Controller is subject, such as the retention of access logs to the Website, in accordance with Decree No. 2011-219 of 25 February 2011 relating to the retention and communication of data enabling the identification of any person who has contributed to the creation of content posted online.

5.5. Legitimate interest

5.5.1. Certain Processing is necessary for the purposes of the legitimate interests pursued by the Controller or by a third party, unless the interests or fundamental rights and freedoms of the Client which require protection of Personal Data prevail, in particular when the Client is a child.

5.5.2. The Data Controller may have a legitimate interest justifying the processing of the Client's Personal Data, in particular :

  • Securing the Website ;
  • Improving the Site and the user experience ;
  • Customer review management ;
  • The fight against payment fraud.

5.5.3. The Data Controller ensures that the Processing in question is indeed necessary for the achievement of its legitimate interest and assesses the consequences of this Processing on the Client, in particular taking into account the nature of the Data processed, and the way in which it is processed.

5.5.4. The Client may, at any time, object to all or part of the Processing described in this Privacy Policy, as well as implement his Specific Rights, under the conditions of paragraph 12 – Exercise of Specific Rights of Clients.

6. PURPOSES OF DATA PROCESSING

6.1.The Customer's Personal Data is necessary to enable them to access, use and improve the Website, and to enable the Data Controller, in particular, to:

  • Managing all operations related to its commercial relationship with the Client, i.e. concerning the issuance of invoices, accounting, monitoring of the "customer relationship" with a Client, such as conducting satisfaction surveys, managing complaints, use of the Website and more generally of services, etc.;
  • Allow the Customer access to the Account and provide them with all the information contained therein, such as their orders, address book, the products they have saved, their preferences;
  • To ensure the placement of an order and the monitoring of the delivery of products;
  • Manage after-sales service, support requests and commercial complaints;
  • To personalize its communication for Customers, in particular through informational emails, based on their observed preferences, their use of services and/or the Website;
  • Carry out commercial solicitation operations;
  • To allow customers to access personalized offers on products ;
  • Develop commercial statistics, analyses and marketing tools (including classification, scoring, etc.);
  • Optimize the Customer's navigation on the Website by remembering their preferences and simplifying any subsequent purchases on the Website;
  • Manage customer reviews or comments on the website ;
  • To improve the quality of the website, services and user experience, particularly through the analysis of browsing data ;
  • To ensure compliance with its legal obligations, particularly those of an accounting and tax nature.
  • Manage requests to exercise Specific Rights under the conditions of paragraph 12 – Exercise of Specific Customer Rights;
  • Participate in the fight against fraud and money laundering;
  • Managing unpaid invoices, preventing payment defaults, and handling debt collection procedures ;
  • Preventing disputes and managing any potential litigation with the Client;
  • Ensuring the security of the Website, detecting and preventing fraudulent activities ;
  • To process any other Personal Data that the Customer provides during their interactions with customer service or the company ; And
  • Manage, where applicable, specific situations of exclusion from the service and the elements justifying these measures.

7. STORAGE OF PERSONAL DATA

7.1. The Website is hosted by the company whose contact details are available by clicking here.

7.2. All precautions have been taken to store Customer Personal Data in a secure environment and to prevent it from being altered, damaged, or accessed by unauthorized third parties. Information provided by the Customer will never be transmitted to third parties for commercial purposes, nor sold or exchanged.

7. RECIPIENTS OR CATEGORIES OF RECIPIENTS, IF ANY

&8.1.The Data Controller does not, under any circumstances, sell or rent your Personal Data to third parties, particularly for commercial prospecting purposes.

8.2.For the purposes listed below, the Data Controller shares your Personal Data with :

Actors

Data Recipient Categories

Purpose of the envisaged transfer

Shopify

Accommodation service provider

Hosting the Website

Start&Brand

Website development and management providers

Administration of the website's "back-office" and management of the database containing customers' personal data.

Start&Brand

IT integrator and maintenance

To provide remote maintenance of the Data Controller's information system, including the Website

Gorgias

Publisher of the customer management software

Enabling the management of customer relationships

Klaviyo

Email routing provider

Allow the sending of newsletters

Klaviyo

Telephone flow manager

To enable monitoring of different calls and telephone flows


Provider of support in managing customer vigilance and complaints

Improve customer complaint handling and ensure material safety


Provider of auditing and regulatory compliance services

Ensure the information system complies with regulations on medical and cosmetic products


Electronic document management provider

Electronic invoice management


Publisher of economic analysis software tools

Enable sales forecasting


Social networks and advertising services, including social network management

Managing communication on the Facebook website and the Instagram mobile application


SEO and statistical tools service

Ensure the website's search engine optimization and analyze website data.

SAY

Numbered

Communication agency

Receive communication advice


Cookie management provider

Collecting customer consent for the placement of cookies and subsequent recognition of the customer and their consent

Mollie

Shopify payment

Payment service provider

Enable payments on the Website

BigBlue

Wise

Shopify

Publisher of warehouse logistics management software

Enable the connection of the IT system with the warehouses

BigBlue

Parcel delivery service provider

To enable the shipment of products ordered by Customers


9.TRANSFERS OUTSIDE THE EUROPEAN ECONOMIC AREA

9.1. The Data Controller endeavors to process the Client's Personal Data within the European Economic Area (EEA).

9.2. However, some Service Providers or partners likely to be involved in the Processing may be located outside the EEA or process Personal Data from a third country.

9.2.1. Any transfer of Personal Data to a country outside the EEA is governed in accordance with the provisions of Articles 44 et seq. of the GDPR.

9.2.2. These transfers can only take place :

  • To countries that are the subject of an adequacy decision by the European Commission ; Or
  • When appropriate safeguards to ensure its full legality have been put in place (in particular the Data Privacy Framework in the United States) and the Client has enforceable Specific Rights and effective remedies ; Or
  • In the limited cases provided for by the GDPR (Article 49), in particular when the transfer is necessary for the performance of a contract concluded with the Client or when the Client has given explicit consent to the transfer.

9.2.3. The Data Controller shall in all cases ensure that appropriate technical, organisational and legal safeguards are implemented to ensure a level of protection substantially equivalent to that guaranteed in the EEA.

9.2.4. The Client can obtain further information on transfers outside the EEA or on applicable safeguards by contacting the Data Controller in accordance with the procedures set out in paragraph 12 of this Privacy Policy.

10. STORAGE TIMES

10.1. The Data Controller retains Personal Data only for the period necessary to achieve the Purposes for which it was collected.

10.2. Data may be kept for longer periods in intermediate archiving when necessary for the management of litigation or to meet a legal obligation.

10.3.For the purposes listed below, the Data Controller retains your Personal Data for:

Purpose of the Processing

Duration in active base

Intermediate archiving period

Customer Account Management

3 years from the last contact with the Data Controller

5 years for evidence in case of a commercial dispute

Order management (purchase, delivery, after-sales service)

Duration of the contractual relationship

5 years for the civil statute of limitations

Billing and accounting management

10 years from the date of the order


Bank card details stored on the Website (excluding the security code)

Expiry date + 1 day (subject to the storage times indicated below)


Bank card details, whether stored or not (excluding the security code), are used for the purpose of handling potential claims.

  • For immediate debit cards : 13 months from the date of payment ;
  • For deferred debit cards : 15 months from the date of payment.


Sales prospecting management

3 years from the last contact with the Data Controller


Cookies and trackers

13 months from the date of consent


Identity document provided in the context of exercising Specific Rights

1 year from the date of receipt by the Data Controller



10.4. At the end of these periods, Personal Data is deleted or anonymized, unless otherwise required by law.

11. SECURITY

11.1. The Data Controller implements appropriate technical and organizational measures, proportionate to the nature of the Personal Data processed and the risks involved in its processing, to ensure the security and confidentiality of your Personal Data. These measures aim in particular to prevent any alteration, loss, destruction, as well as any unauthorized access to Personal Data.

11.1.1.In this capacity, the Data Controller may implement, as needed, in particular :

  • Strict access control, limited to authorized staff members only, based on their duties. ;
  • Specific contractual measures, particularly when a Subcontractor or Recipient processes this Personal Data on its behalf ;
  • Data Protection Impact Assessments (DPIAs) are required when such processing activities are necessary. ;
  • Regular reviews of internal data protection practices and policies ;
  • Physical and logical security measures, including enhanced authentication, the use of firewalls and antivirus software, pseudonymization, encryption of Personal Data and any other appropriate measures to ensure the integrity, availability and confidentiality of Personal Data.

11.2. In accordance with the General Terms and Conditions, the Website uses the technology of the various payment companies offered on the Website, to secure the banking transactions of Customers.

11.2.1. Thus, when paying on the Website, the Client's bank details are transmitted in encrypted form to the relevant payment company.

11.2.2. To exercise his rights such as those identified in paragraph 12 – Specific Rights, relating to his bank card details, the Customer is invited to contact the relevant payment company directly.

12. SPECIFIC RIGHTS

12.1. In accordance with the Personal Data Regulations, the Client may, at any time, exercise the following Specific Rights:

  • information
  • access,
  • correction,
  • erasure,
  • limitation of a treatment,
  • opposition,
  • withdrawal of consent
  • portability,
  • definition of post-mortem directives,
  • filing a complaint with a supervisory authority.

12.2 Rights to Information

12.2.1. The Data Controller shall provide the Client with clear, transparent, understandable and easily accessible information concerning the methods of Processing his Personal Data, in accordance with Articles 12 to 14 of the GDPR.

12.2.2. This information includes in particular: the identity and contact details of the Data Controller; the Purposes and legal bases of the Processing; the categories of Personal Data collected; the Recipients of the Personal Data; any transfers to countries outside the EEA; the period of retention of the Personal Data; as well as the existence of Specific Rights available to Customers (access, rectification, erasure, limitation, portability, objection, withdrawal of consent, etc.).

12.2.3. The Client is informed of these elements in this Privacy Policy, at the time of collection of his Personal Data or, when the Data is not collected directly from him, within a reasonable time after obtaining it.

12.3. Access rights

12.3.1.The Client has the right to obtain from the Data Controller confirmation as to whether or not Personal Data concerning him or her is being processed and, where that is the case, access to said Personal Data as well as the following information:

a) the purposes of the processing;

b) the categories of Personal Data;

c) the Recipients or categories of Recipients to whom the Personal Data have been or will be communicated;

d) where possible, the envisaged period for which the Personal Data will be stored, or, where this is not possible, the criteria used to determine that period;

e) the existence of the right to request from the Data Controller rectification or erasure of Personal Data, or restriction of processing of Personal Data, or the right to object to such processing;

f) the right to lodge a complaint with the data protection supervisory authority (in France, the CNIL);

(g) where Personal Data is not collected from the Client, any available information as to its source;

(h) the existence of automated decision-making, including profiling, and, at least in such cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the Client;

12.3.2. When Personal Data is transferred to a third country or an international organization, the Client has the right to be informed of the appropriate safeguards governing this transfer.

12.3.3. The Data Controller provides a copy of the Personal Data being processed.

12.3.4. The Data Controller may require payment of reasonable fees, based on administrative costs, for any additional copies requested by the Client or in the event of a request to transmit Personal Data on paper and/or physical media.

12.3.5. When the Client submits their request electronically, the information is provided in a commonly used electronic format, unless otherwise requested by the Client.

12.3.6. The Client's right to obtain a copy of their Personal Data must not infringe on the rights and freedoms of others.

12.4. Rights of rectification

12.4.1. The Client has the possibility to obtain from the Data Controller the rectification of Personal Data concerning him/her which is inaccurate.

12.4.2. He also has the possibility of having incomplete Personal Data completed, including by providing a supplementary statement.

12.4.3. The Data Controller undertakes to carry out this rectification as soon as possible and to inform, where appropriate, any Recipient to whom the Personal Data has been communicated, except where this communication proves impossible or requires disproportionate effort.

12.5. Rights to erasure

12.5.1.The Client has the right to obtain from the Data Controller the erasure, without undue delay, of Personal Data concerning him or her when one of the following grounds applies:

a) The Personal Data are no longer necessary in relation to the purposes for which they were collected or otherwise processed by the Data Controller;

b) The Client has withdrawn their consent for the processing of their Personal Data and there is no other legal basis for the processing;

c) The Client exercises their right to object under the conditions recalled below and there is no overriding legitimate reason for the Processing;

d) The Personal Data has been processed unlawfully;

e) Personal Data must be erased to comply with a legal obligation;

f) The Personal Data was collected from a child.

12.5.2. However, the right to erasure cannot be exercised when the processing is necessary:

  • to the exercise of the right to freedom of expression and information;
  • to comply with a legal obligation or to carry out a mission of public interest or relating to the exercise of public authority;
  • for reasons of public interest in the field of health;
  • for archiving purposes in the public interest, for scientific or historical research purposes, or for statistical purposes, where erasure is likely to render impossible or seriously impair the achievement of the objectives of the processing;
  • to the establishment, exercise or defense of legal rights.

12.6. Rights to limitation

12.6.1. The Client has the option to obtain from the Data Controller the restriction of the Processing of their Personal Data when one of the following grounds applies:

a) The Data Controller verifies the accuracy of Personal Data following a dispute by the Client regarding the accuracy of the Personal Data,

b) The processing is unlawful and the Client objects to the erasure of Personal Data and instead demands the restriction of its use;

c) The Data Controller no longer needs the Personal Data for the purposes of the initial Processing but the Client still needs them for the establishment, exercise or defence of legal claims;

d) The Client has objected to the Processing based on legitimate interest and the Data Controller verifies whether the legitimate grounds pursued prevail over those of the Client.

12.6.2. When Processing is limited, Personal Data may not, with the exception of its retention:

  • to be processed only with the Client's consent;
  • be processed for the establishment, exercise or defense of legal rights; or
  • be processed for the protection of the rights of another natural or legal person; or
  • be processed for important reasons of public interest of the European Union or of a Member State.

12.6.3. The Data Controller informs the Client before the restriction on processing is lifted.

12.7. Rights of objection

12.7.1. The Client may object at any time, for reasons relating to his or her particular situation, to the Processing of Personal Data concerning him or her based on the legitimate interest of the Data Controller.The latter will then no longer process the Personal Data, unless it demonstrates that there are compelling and legitimate grounds for the Processing which prevail over the interests and rights and freedoms of the Client, or may retain them for the establishment, exercise or defence of legal claims.

12.7.2. The Client also has an absolute right to object to the Processing of their Personal Data for marketing purposes, including profiling when related to such marketing. In this case, the Personal Data will no longer be processed for these purposes.

12.8. Rights to withdraw consent

12.8.1. When the Processing of certain Personal Data is based on the Client's consent, that-This consent can be withdrawn at any time, without having to justify the reason.

12.8.2. Withdrawal of consent has no retroactive effect and does not affect the lawfulness of processing carried out before its implementation.

12.8.3. Once consent is withdrawn, the Personal Data concerned will no longer be processed for the corresponding Purposes.

12.9. Data Portability Rights

12.9.1. The Client has the option to receive from the Data Controller their Personal Data in a structured, commonly used and machine-readable format when:

a) The processing of personal data is based on consent or on the performance of a contract; and

b) The processing is carried out using automated processes.

12.9.2. The Client has the right to have Personal Data transmitted directly by the Data Controller to another data controller designated by the Client where technically feasible.

12.9.3. The right to portability of the Client's Personal Data must not infringe on the rights and freedoms of others and does not apply to Processing necessary for the performance of a task carried out in the public interest or in the exercise of official authority.

12.10. Rights to define post-mortem directives

12.10.1. The Client has the option of providing the Data Controller with instructions regarding the retention, deletion, and disclosure of their Personal Data after their death. These instructions may also be registered with a certified digital trusted third party. These instructions, or a kind of "digital will," may designate a person responsible for their execution; otherwise, the Client's heirs will be designated.

12.10.2. In the absence of any instructions, the Client's heirs may contact the Data Controller in order to:

  • access to the processing of Personal Data enabling "the organisation and settlement of the deceased's estate";
  • to receive communication of "digital assets" or "data resembling family memories, transmissible to heirs";
  • to proceed with the closure of the Customer's Account on the Website and to object to the continued Processing of their Personal Data.

12.10.3. In any event, the Client has the option to indicate to the Data Controller, at any time, that he does not wish, in the event of his death, for his Personal Data to be communicated to a third party.

12.10.4. The Data Controller implements the post--mortem duly registered, under the conditions and limits provided for by the applicable regulations.

12.10.5.Specific guidelines can be modified or deleted at any time by the Client.

12.11. Rights to lodge a complaint with a supervisory authority

12.11.1. The Client has the right to lodge a complaint with a competent supervisory authority, and in particular with the Commission Nationale de l'Informatique et des Libertés (CNIL) in France, if he considers that the Processing of his Personal Data constitutes a violation of the applicable regulations on the protection of Personal Data.

12.11.2. The Client may exercise this right without prejudice to any other administrative or judicial remedy.

12.11.3. The CNIL's contact details are as follows:

  • National Commission for Information Technology and Freedoms (CNIL)

3 Place de Fontenoy – TSA 80715 – 75334 Paris Cedex 07

Telephone: +33 (0)1 53 73 22 22

Website: www.cnil.fr

12.11.4. The Client may also contact the supervisory authority of the Member State of the European Union in which his habitual residence, place of work or the place where the alleged infringement took place is located.

12.12. The Client also has Specific Rights relating to Cookies, mentioned in the Cookie Policy: XXX. 

13. EXERCISE OF SPECIFIC CUSTOMER RIGHTS

13.1. These Specific Rights may be exercised at any time with the Data Controller:

  • By email to the following address: dpo@ydes-avocats.com
  • By mail to the following address:
    SEKAYA
    Data protection department
    38 Cours Albert 1er 
    75008 Paris France

13.2. In order to exercise his Specific Rights under the conditions referred to above, the Data Controller may ask him to prove his identity by stating his surname, first name, email address and to accompany his request with a copy of a valid identity document, as well as any information or document that may allow his identity to be verified.

13.3. A response will be sent to the Client within a maximum period of one (1) month following the date of receipt of the request.

13.4. If necessary, this period may be extended by two (2) months by the Data Controller, who will notify the Client, taking into account the complexity and/or number of requests.

14. COOKIES AND TRACKERS

14.1. In order to improve the browsing experience and to offer services tailored to the interests of its Customers, SEKAYA uses Cookies and other trackers.

14.2. The operating procedures of these tools, the purposes pursued, the retention periods as well as the means made available to the user to accept, refuse or configure these cookies are detailed in the Site's Cookie Policy.

14.3. The user is invited to consult this Cookie Policy at any time by clicking on the following link: XXX. 

14.4. Use of the Site implies acceptance of the terms of use of cookies as defined in said Charter.


Version : April 2026