Your CBD Extract Wholesaler
Privacy policy
PERSONAL DATA PROTECTION CHARTER
At K-LAB, protecting your personal data is a priority.
When you use the https://legrossisteducbd.fr website (hereinafter the " Site ") and/or when you order the products we offer for sale, we may collect and process personal data about you.
The purpose of this charter is to inform you about how we process this data in compliance with Regulation (EU) 2016/679 of April 27, 2016 on the protection of individuals with regard to the processing of personal data and on the free movement of such data (hereinafter the " RGPD ").
-
Who is the data controller?
The data controller is K-LAB, a société par actions simplifiée (simplified joint stock company), registered with the Toulouse Trade and Companies Register under number 900 723 891 and whose registered office is located at 17 Avenue Hermes 31240 L'Union (hereinafter referred to as " We ").
-
What data do we collect?
Personal data is data that can be used to identify an individual, either directly or by cross-referencing with other data.
We collect data in the following categories:
- Identification data (surname, first name, e-mail and postal address, telephone number);
- Data relating to your orders;
- Connection data (connection logs, encrypted passwords) ;
- Browsing data (IP address, pages viewed, date and time of connection, browser used, operating system, user ID, IFA);
- Data from recordings of telephone calls between you and our customer care service (e.g. call content, call dates) ;
- Any information you wish to send us as part of your contact request.
Mandatory data is indicated when you provide us with your data. They are marked with an asterisk and are necessary to provide you with our services.
-
On what legal grounds, for what purposes and for how long do we store your personal data?
Goals | Legal basis | Shelf life |
Fulfill your order, carry out customer management operations concerning contracts, orders, deliveries, invoices, loyalty programs and customer relations. | Fulfilment of a contract you have signed | Personal data is kept for the duration of the contractual relationship, plus 3 years from the end of the relationship.
In addition, your data (with the exception of your bank details) is archived for evidentiary purposes for a period of 5 years. |
Build a file of customers and prospects |
Our legitimate interest in developing and promoting our business | For customers: data is kept for the duration of the commercial relationship and is deleted 3 years after the end of the commercial relationship.
For prospects: data is kept for a period of 3 years from your last contact. |
Send newsletters, requests and promotional messages |
Our legitimate interest in developing and promoting our business | Data is kept for 3 years from the date of your last contact. |
Responding to your requests for information |
Our legitimate interest in responding to your requests | Data is kept for the time required to process your request for information and is deleted once the request for information has been processed. |
Comply with legal obligations applicable to our business |
Comply with our legal and regulatory obligations | Invoices: Invoices are archived for 10 years.
Data relating to your transactions (with the exception of bank details) are kept for 5 years. |
Organize contests and promotions |
Our legitimate interest in retaining our customers and offering them gifts |
Data is kept for the duration of the games or promotional operations and may be archived for 5 years for evidentiary purposes. |
Managing requests to exercise rights |
Comply with our legal and regulatory obligations |
If we ask you for proof of identity, we keep it only for the time needed to verify your identity. Once verification has been completed, the proof of identity is deleted.
If you exercise your right to object to canvassing: we keep this information for 3 years. |
Who will receive your data?
We will have access to your personal data:
- Our staff ;
- Our subcontractors: transport service provider, hosting service provider, customer relationship management (CRM) tool, payment service provider; audience analysis and measurement service provider, newsletter sending service provider;
- Where applicable: public and private bodies, exclusively to meet our legal obligations.
Is your data likely to be transferred outside the European Union?
Your data is kept and stored for the duration of the processing on O2 Switch's servers, located in the European Union.
In the context of the tools we use (see article on recipients concerning our subcontractors), your data may be transferred outside the European Union. The transfer of your data in this context is secured using the following tools:
- or the data is transferred to a country that has been judged to offer an adequate level of protection by a decision of the European Commission;
- or we have concluded a specific contract with our subcontractors governing transfers of your data outside the European Union, based on the standard contractual clauses between a data controller and a subcontractor approved by the European Commission;
- or we have recourse to the appropriate guarantees provided by the applicable regulations.
6. What are your rights regarding your data?
You have the following rights with regard to your personal data:
- Right to information: this is precisely why we have drawn up this policy. This right is provided for in Articles 13 and 14 of the RGPD.
- Right of access: you have the right to access all your personal data at any time, pursuant to Article 15 of the RGPD.
- Right of rectification: you have the right to rectify inaccurate, incomplete or obsolete personal data at any time in accordance with Article 16 of the GDPR.
- Right to limitation: you have the right to obtain the limitation of the processing of your personal data in certain cases defined in Article 18 of the GDPR.
- Right to erasure: you have the right to demand that your personal data be erased, and to prohibit any future collection of it for the reasons set out in Article 17 of the RGPD
- Right to lodge a complaint with a competent supervisory authority (in France, the CNIL), if you consider that the processing of your personal data constitutes a breach of the applicable texts. (Article 77 of the RGPD)
- The right to define directives concerning the conservation, deletion and communication of your personal data after your death, in accordance with article 40-1 of the French Data Protection Act.
- Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the RGPD states that you may withdraw your consent at any time. This withdrawal will not call into question the legality of the processing carried out prior to the withdrawal.
- Right to portability: under certain conditions specified in Article 20 of the RGPD, you have the right to receive the personal data you have provided to us in a standard machine-readable format and to demand its transfer to the recipient of your choice.
- Right to object: under Article 21 of the GDPR, you have the right to object to the processing of your personal data. Please note, however, that we may continue to process them despite this objection, for legitimate reasons or the defense of legal rights.
You can exercise these rights by writing to us using the contact details below. We may ask you to provide additional information or documents to prove your identity.
7.personal data contact point
Contact email: [email protected]
Contact address: 17 Avenue Hermes 31240 L'Union
8. Modifications
We may modify this policy at any time, in particular in order to comply with any regulatory, legal, editorial or technical developments. These modifications will apply as of the effective date of the modified version. You are therefore invited to consult the latest version of this policy on a regular basis. Nevertheless, we will keep you informed of any significant changes to this privacy policy.
Effective date: (*)