NHECTAR, a one-person simplified joint stock company with share capital of 1,000,000 euros, registered with the Paris Trade and Companies Registry under number 910 244 201, whose registered office is located at 11 rue Tronchet, 75008 PARIS (hereinafter “DIX HECTARES”), pays particular attention to the protection of personal data and undertakes to protect them in compliance with applicable regulations and in particular Regulation (EU) n°2016/679 of April 27, 2016 known as the “General Data Protection Regulation” or “GDPR” and Law n° 78-17 of January 6, 1978 as amended, known as the “Data Protection Law” as amended (hereinafter the “Applicable Data Protection Law”).
In the context of this privacy policy (hereinafter the “Privacy Policy”), terms identified by a capital letter, if not defined herein, have the meaning given to them in the General Terms and Conditions of Sale.
When it collects personal data (hereinafter the “Personal Data”) from users of the Site (hereinafter the “Data Subjects”), DIX HECTARES implements processing thereof for which it is qualified as a “data controller”, within the meaning of the aforementioned texts.
DIX HECTARES undertakes to comply at all times with the requirements of Applicable Data Protection Law and to process Personal Data only in accordance with the conditions set out below.
1. Mapping personal data processing
DIX HECTARES processes the Personal Data of Data Subjects as follows:
Purpose |
Legal basis |
Categories of data processed |
Management of account opening and use |
Execution of general terms and conditions of sale and use |
First and last name |
Newsletter |
Consent |
E-mail address |
Product ordering and billing |
Execution of the general terms and conditions of sale |
Login logs |
Product delivery |
Fulfilment of terms and conditions |
Full name |
Operational management of the Site (including support and after-sales service) |
Execution of sales conditions |
All Personal Data processed through the Data Subject's account |
Communication with the Person Concerned by any means made available on the Site (contact email, contact telephone, etc.) |
Consent |
Email address |
Improving Site performance and functionality
|
Legitimate interest of DIX HECTARES |
Usage statistics (cookies) |
Litigation management |
Legitimate interest of DIX HECTARES |
All Personal Data |
Fraud prevention and detection, malware and security incident management |
Legitimate interest of DIX HECTARES & legal obligation |
Connection logs |
2. Duration of storage of personal data
In accordance with the Site's general terms and conditions of use, the Personal Data of the Person Concerned is collected via his/her account and during his/her use of the Site, and is kept for as long as the Person Concerned uses the Site. The Data Subject's Personal Data is stored:
With regard to browsing on the Site: for the duration of his or her visit to the Site and, once the visit is over, for the duration of cookie retention, as mentioned in the table below;
With regard to communications with DIX HECTARES, by any means whatsoever: for a period of three (3) years;
With regard to banking data, in the context of the purchase of Products, for the period stipulated by DIX HECTARES' subcontracted payment service providers.
Beyond the aforementioned periods, Personal Data is archived by DIX HECTARES, in a secure environment, for the legal period of prescription for the purposes of proof for the establishment, exercise or defence of a legal claim.
3. Recipients of personal data
Unless legally or judicially obliged to do so, DIX HECTARES will never disclose, assign, rent or transmit the Personal Data it processes to third parties other than the following recipients:
-
The following service providers, it being understood that they act as “subcontractors” of DIX HECTARES within the meaning of the Applicable Data Protection Law, on the instructions of DIX HECTARES which communicates to them the data strictly necessary for the performance of their tasks, under the contractual conditions signed with DIX HECTARES which cannot derogate from the present article and which comply with the Applicable Data Protection Law:
- The hosting provider for the Site and its databases, Google LLC, in its datacenters located at 1600 Amphitheatre Parkway Mountain View, CA 94043, USA, for the purposes of providing technical hosting and database management services. For further information on the processing of Personal Data by the host, the Data Subject is invited to read the privacy policy of Dix Hectares (Nhectar), which can be viewed at the following address: https://dixhectares.com/pages/privacy-policy/ ;
- The payment service provider Shopify, for the purposes of carrying out the online payment service. The following are processed: personal identification data and bank details, in compliance with applicable banking regulations. For further information on the processing of Personal Data by this service provider, the Data Subject is invited to read its privacy policy, which can be viewed at the following address: https://dixhectares.com/pages/privacy-policy/ ;
- Third-party cookie publishers, under the conditions set out below.
4. Safety measures implemented
DIX HECTARES undertakes to use its best efforts to :
- Ensure the physical and logical security of the servers on which the Site is hosted and, in particular, the integrity of the network and servers against any external malicious act or any known computer attack. The servers are protected against intrusions by a firewall. Security updates for operating systems and anti-virus software are installed regularly;
- Implement and maintain security and confidentiality measures for the Site, which take into account the principles of Personal Data protection and applicable banking security rules, and are adapted to the risk generated by their processing on the rights and freedoms of Data Subjects, in accordance with the requirements of Applicable Data Protection Law. These measures aim to (i) protect Personal Data against destruction, loss, alteration or disclosure to unauthorized third parties, and (ii) ensure the restoration of availability and access to Personal Data within appropriate timeframes in the event of a physical or technical incident. DIX HECTARES also implements a procedure to regularly test, analyze and evaluate the effectiveness of the aforementioned security measures.
5. Transfer of personal data outside the European Union
DIX HECTARES undertakes not to transfer Personal Data to countries outside the European Union that have not been recognized by the European Commission as providing an adequate level of protection (i) without having first obtained the customer's express and written authorization and (ii) without the implementation of legal instruments recognized as appropriate by Applicable Data Protection Law to govern the transfer(s) concerned.
In the event that DIX HECTARES is required by law to transfer data to a country outside the European Union or to an international organization, DIX HECTARES undertakes to inform the Data Subject in advance, unless the law in question prohibits such information for important reasons of public interest.
6. Rights of Data Subjects to their Personal Data
Data Subjects have the following rights to their Personal Data at all times:
- Right of access: to obtain confirmation of the processing of their Personal Data, as well as a certain amount of information on the processing, it being understood that this information is in any case given in the present document;
- Right of rectification: to obtain rectification of Personal Data that is inaccurate or incomplete;
- Right to erasure, also known as the “right to be forgotten”: obtain the erasure of Personal Data when it is no longer necessary for the purposes for which it was collected, or when the Data Subject objects to the processing of his/her Personal Data;
- Right to the limitation of processing: to obtain the limitation of the processing of Personal Data when the Data Subject disputes the accuracy of the data, when the retention period for the Personal Data has expired but the Data Subject still needs to retain the Personal Data for the establishment, exercise or defense of legal claims, or if the Data Subject has objected to the processing;
- Right to portability: to obtain communication of the Personal Data that the Data Subject has communicated to DIX HECTARES in a readable format, or to request that DIX HECTARES transmit the Personal Data that the Data Subject has communicated to another controller;
- Right to object: to object at any time, for reasons relating to his or her personal situation, to the processing of his or her Personal Data, in particular where such objection concerns commercial prospecting, including profiling;
- Withdrawal of consent: to withdraw one's consent to the future processing of one's Personal Data by DIX HECTARES, where such processing is based on consent;
- Right to lodge a complaint: lodge a complaint with the Commission Nationale de l'Informatique et des Libertés (“CNIL”) if the Data Subject considers that the processing carried out by DIX HECTARES constitutes a violation of his/her Personal Data. The CNIL can be contacted : By telephone: 01 53 73 22 22 ; Via an online form available here: https://www.cnil.fr/webform/nous-contacter
- The rights of Data Subjects to their Personal Data may be exercised at any time by contacting DIX HECTARES by e-mail at the following address: bonjour@dixhectares.com.
7. Hypertext links
The Site may contain hypertext links to third-party websites. DIX HECTARES has no control over the content of third-party websites referenced by hypertext links. These websites are published by third-party companies independent of DIX HECTARES. DIX HECTARES therefore assumes no responsibility whatsoever for the content, advertising, services or any other information or data available on or from these sites. Consequently, the Person Concerned acknowledges that he/she alone is responsible for accessing and using these sites. DIX HECTARES shall not be liable for any damages or losses, actual or alleged, arising out of or in connection with the use of or reliance on any content, goods or services available on such sites.
The Person Concerned is not authorized to create hypertext links to the Site. The creation of links to the Site is only possible with the express prior consent of DIX HECTARES.
8. Cookie management
DIX HECTARES uses cookies for the proper operation of the Site and to monitor and analyze traffic on the Site. A “cookie” is a small data file sent to the Data Subject's browser by a web server and stored on the hard disk of the Data Subject's computer or other data storage medium. They do not in any way risk damaging the said medium.
The information collected via cookies is solely and strictly intended for use by DIX HECTARES, in compliance with applicable data protection law. Cookies from third-party publishers (Google, Meta) enable these publishers to access the information collected via their cookies, according to the methods specified in the table below.
DIX HECTARES uses the following cookies:
Strictly necessary cookies
Certain cookies used by DIX HECTARES are strictly necessary for the proper functioning of the Site. They are generally only established in response to actions carried out by the Person Concerned on the Site and which require a request for services or filling in forms. The Person Concerned may set his/her web browser parameters to block the use of these cookies, but certain Site functions will no longer be accessible. These cookies do not store any personally identifiable information about the Data Subject.
Performance cookies
These cookies enable the Site to provide functionalities and a personalized user experience, based on previous visits and selections.
Advertising targeting cookies
These cookies may be set by DIX HECTARES' advertising partners via the Site and may be used to build up a profile of the Data Subject's interests with a view to presenting him or her with relevant advertising on other websites.
The Person Concerned is free to consent to the use of all or some of the cookies (other than those strictly necessary for the operation of the Site) used by DIX HECTARES on the Site. The Person Concerned can make his/her choice when he/she first connects by clicking on the categories of cookies he/she accepts. The Data Subject is also free to withdraw his/her consent to the use of cookies at any time. Contact bonjour@dixhectares.com
The Data Subject may also set his/her browser to accept or disable cookies.
Cookie instructions for the most commonly used browsers are available at the following links: