Privacy policy

Subject

This privacy policy is intended to inform you about our practices regarding the collection, use, and sharing of information that you may provide to us when you consult or purchase our brands "Cotélac," "acoté," and "Cotélac Homme" presented on the websites (hereinafter referred to as "websites") or when you visit the stores that we operate directly or that are operated by our subsidiaries or commercial partners (hereinafter referred to as "Stores"), by the company COTELAC, SAS with a capital of 1,360,800 euros, Rue du Professeur Luc Montagnier, ZA en Pragnat Nord – 01500 AMBERIEU en BUGEY, registered with the RCS of Bourg under number 378 239 974 (hereinafter referred to as "Cotélac"), exclusively for individuals who are not traders and are of legal age. Cotélac attaches great importance to the protection and respect of your personal data in the above context and in the context of any other contact we may have.

CONSENT

Cotélac does not collect, use, or disclose your personal data without your consent. By using this website, its services, or interacting in any other way with us, our stores, and/or websites, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, storage, transmission, and disclosure of the personal data we collect through the websites, stores in accordance with this Privacy Policy. If you do not consent to this Privacy Policy, please do not visit this website, create a user account, and do not use or submit your personal data to this website or our stores in any way.

PROCESSING OF YOUR PERSONAL DATA

The term "Personal Data" as used in this Privacy Policy means any information directly or indirectly identifying a natural person (e.g., name, registration number, phone number, photograph, date of birth, town of residence, fingerprint...) that you choose to communicate or share with us or with third parties when you use the websites or visit one of our stores. We will process your personal data in accordance with the General Data Protection Regulation 2016/679 of the European Parliament and of the Council of April 27, 2016, as well as in compliance with the laws applicable in the country in which your personal data is collected. We reserve the right to carry out additional data processing when required by law or in the context of a criminal case, investigation, or procedure.

PERSONAL DATA WE COLLECT

  1. Source of Personal Data

    • Websites distributing our products: when you place an order on our websites; when you fill out forms, create or modify a user account, create a favorites list, or participate in promotional offers.
    • Stores: when you fill out the customer card request and/or customer sheet, informally discuss with our store employees, interact with us, or purchase our products.
    • Events: when you participate in our events, surveys, market research, contests, and other promotions, including online through third-party sites or networks such as Facebook, Twitter, and Instagram.
    • Customer service: when you contact us by phone, email, or any other means of communication.
    • Letters, emails, SMS, and other electronic messages: any communication between you and us.

    If you provide us with personal data about third parties (e.g., family members, our customers, or prospects), you must ensure that these third parties are informed and have authorized the use of their personal data as described in this Privacy Policy.

  2. Types of Personal Data

We may collect and use various types of personal data, depending on the specific purpose sought and as described below:
  • Personal information, such as first name, last name, gender, age/date of birth, billing country, delivery country, and any other personal information to the extent permitted by law.
  • Contact details, such as address, email, landline and mobile phone numbers, fax number (if applicable), and any other contact details to the extent permitted by law.
  • Bank details, such as payment method (credit card, debit card, check) and, if necessary, a copy of your ID card front/back when required for fraud prevention or under applicable anti-money laundering laws.
  • Information about purchases made, such as date, products or services, place of purchase, VAT number, complaints, returns, refunds, and any other information to the extent permitted by law.
  • Habits and profiles, such as data related to your purchases, information related to customer relationship management activity and offers, shopping habits, and leisure preferences to the extent permitted by law.
  • Information about your family situation, such as marital status to the extent permitted by law.

HOW WE USE YOUR PERSONAL DATA

We may use your personal data for:

  • Management of Online Purchases on our websites or in our stores as identified in the general terms and conditions of sale.
  • Management of Sales and After-Sales Services including invoices, returns, warranties, taxation, fraud prevention, and the management of the delivery of purchased goods.
  • Compliance with Legal Obligations imposed by law, regulations, or European laws, and to establish or defend our rights in legal proceedings.
  • Providing Requested Services such as creating your user account, managing authentication on websites, handling accounts, assisting you, managing your claims, managing your favorites lists, and responding to your inquiries or contact requests submitted to us, including through after-sales service.
  • Customer Relationship Management (CRM) and Personalized Services offering promotions and other personalized services, sending newsletters, advertising communications about our products and services, invitations to brand-related events (organized by us or our partners), surveys and market research, invitations to participate in contests, draws, and other offers.
  • Analysis for Profiling and Customization analyzing your interactions with us, your interests, purchasing habits, and creating individualized or aggregated profiles based on this information to determine how to provide you with better service, including a personalized shopping experience in our stores.

The communication of your personal data for inclusion in the CRM system is optional and free, and only if you provide your personal data for both marketing and profiling/customization purposes or for either one. You can unsubscribe or choose not to participate at any time.

It is necessary that you provide us with your personal data for the purposes described above; in case of refusal, you will not be able to make a purchase on our websites or enter our CRM and benefit from our personalized programs and services.

HOW WE SHARE YOUR PERSONAL DATA

We share your personal data collected from our subsidiaries and franchisees, including those established in other countries, as well as with other companies that provide services on our behalf (as described below), either under our direction or that of a third party. We will provide these companies and organizations with only the personal data necessary for the delivery of services, and we will prohibit them from using your personal data for any other purpose.

  1. Sharing with Subcontractors:

    • On our websites, your personal data may be shared with third parties providing services to the seller (order preparation, order delivery, credit and debit card payment management, fraud checks, web agency, and website hosting provider).
    • Controlling and analyzing website activity, providing technical and organizational services for the aforementioned reasons, including maintaining our customer database, providing marketing assistance, and managing emails, market studies, surveys, contests, draws, and promotions.

    In our subsidiaries, business partners, and stores, your personal data may be shared with third parties for CRM purposes and on our instructions as a subcontractor.

    These third parties may access, store, and process your personal data to provide these services on our behalf, either in your country or abroad. Our service providers are not authorized to use your personal data for any purpose other than providing the services under a contract between us and the service provider.

  2. Sharing with Other Third Parties:

    • In the event of the transfer of assets or any other similar operation (e.g., merger or acquisition, reorganization, or liquidation), customer data will constitute one of the transferred assets, and we may share it with one of our legal successors, to the extent permitted by law and in our legitimate interest. Unless otherwise agreed, your personal data will remain subject to any pre-existing privacy policy.

    We may also disclose your personal data to third parties in accordance with EU law or the law of a Member State in the context of legal proceedings, in response to a request from a public authority based on a legitimate basis, or to protect our rights, privacy, security, or property, or the public.

    The complete list of engaged subcontractors and third parties to whom your personal data is communicated can be obtained by writing to Cotélac ZA en Pragnat Nord, Rue du professeur Luc Montagnier, 01500 Ambérieu-en-Bugey.

PRIVACY PROTECTION FOR CHILDREN

Our websites are designed for and intended for the general public; our services are intended for individuals aged at least 18 years. We do not voluntarily request or collect personal data from individuals under the age of 18, whether online or in our stores and/or points of sale. If we become aware or discover that we have collected personal data from a child, we will delete it as soon as possible. We may use your personal data to conduct age checks and enforce our age-related rules.

If you are not 18 years old, please do not create a user account or make an online purchase, and ask an adult, your guardian, or legal representative to perform the necessary steps.

STORAGE, ACCESSIBILITY, AND TRANSFER OF PERSONAL DATA

Personal data collected through websites is primarily processed electronically, including web analytics services hosted by service providers selected by us both within and outside the European Union. In our stores, personal data may also be processed on paper. In both cases, personal data is recorded in our centralized, secure database and will be managed by our Customer Service and sales and marketing teams.

Only our employees and agents who need it for their mission may access personal data. Our employees and agents are subject to confidentiality obligations in accordance with legal provisions. If you consent to the processing of your personal data for CRM purposes, your personal data may be read, modified, and updated by our employees and the employees of stores and/or online (especially sales and marketing personnel).

If we need to transfer your personal data abroad to achieve one of the purposes described in this Privacy Policy, including to countries where data protection laws differ from those in your country, we will take all necessary measures to ensure that these communications comply with European data protection regulations or any other standard of the country where we collect the data, to ensure the security and confidentiality of your personal data.

SECURITY AND CONFIDENTIALITY OF YOUR PERSONAL DATA

We have implemented reasonable measures to ensure the security of your personal data and prevent any accidental loss and unauthorized access, use, destruction, and disclosure of your personal data:

  • We use Secure Socket Layer (SSL) technology, an encryption tool that ensures the security of information when transmitted over the Internet.
  • We also use firewalls, password systems, and other technologies and safeguards to ensure the proper functioning of our websites and the protection of our databases. Access to your personal data is restricted to prevent unauthorized access, modification, or misuse, and is only authorized for our employees and agents who need it for their mission.

In the unlikely event that we believe the security of your personal data in our possession or within our control has or may have been compromised, we will inform you in accordance with legal requirements and methods provided by law.

YOUR RIGHTS REGARDING YOUR PERSONAL DATA – WHO TO CONTACT?

You can, at any time:

  • Ask us not to contact you in the future:

    • whether by mail, via our newsletters, or by SMS.
  • Ask for a copy of the personal data we hold about you.

  • Ask us to correct, update, or delete your personal data in our databases.

For this purpose, you can contact us by email at contact@cotelac.fr or by mail at Cotélac ZA en Pragnat Nord, Rue du Professeur Luc Montagnier, 01500 Ambérieu-en-Bugey.

Requests for the deletion of your personal data are subject to compliance with legal obligations regarding document retention that fall under our responsibility.

When you contact us to exercise your rights, make sure to provide your name, email, postal address, and/or your telephone number(s) to ensure your identification and the processing of your request within a period of thirty (30) days.

If you no longer wish to participate in any CRM programs, you can unsubscribe from our newsletters or SMS campaigns at any time using the unsubscribe links and tools.

DATA RETENTION

Your personal data may be retained for the duration of the business relationship and as long as necessary for the purposes described in this Privacy Policy. At the end of this period, your personal data will only be retained to comply with our legal and regulatory obligations or to allow us to retain evidence regarding our respective rights and obligations.

Personal data related to the details of your purchases and processed for profiling and marketing purposes will be retained for a limited period in accordance with the maximum duration allowed by law. Upon expiration of this period, personal data will be permanently deleted or anonymized.

COOKIE POLICY

Internal cookies are installed by the website that the user is visiting.

Third-party cookies are installed by third parties compared to the manager of the website that the user is visiting. In this case, cookies can be read by entities other than those managing the internet page viewed by the user.

When you browse websites, these cookies may be installed. If you do not wish to have cookies installed on your computer, we recommend not browsing the website.

DATA COLLECTION VIA THE NEOSTORE APPLICATION

Information collected via the Neostore solution is recorded in Cotelac's customer file.

The purposes and legal bases are as follows:

  • Sending commercial communications (consent)
  • Creating your customer account (execution of pre-contractual measures)
  • Sending your receipt/invoice by email if applicable (legitimate interest for the receipt and execution of the sales contract for the invoice)
  • Handling tax refund if applicable (execution of the sales contract)

Data marked with an asterisk in the form must be provided to create your customer account.

The collected data is accessible to Cotelac's internal teams and is not shared with third parties. This data is hosted in the European Union by the customer file software provider. Neostore does not store the data provided in the form.

They are kept for 6 years from your last order.

To unsubscribe from commercial communications, you can follow the steps below:

  • To stop receiving emails: you can follow the unsubscribe link included in communication emails.
  • To stop receiving mail and/or calls: you can write to contact@cotelac.fr or by mail to Cotélac ZA en Pragnat Nord, Rue du Professeur Luc Montagnier, 01500 Ambérieu-en-Bugey.
  • To stop receiving SMS: you can send Stop SMS to XXXX

To exercise your other rights, you can refer to the article "YOUR RIGHTS REGARDING YOUR PERSONAL DATA - WHO TO CONTACT?" in this Privacy Policy.