Privacy policy

ARTICLE 1: PREAMBLE

This privacy policy applies to the site: https: //www.prepastrat.com.
The purpose of this privacy policy is to explain to users of the site:
how their personal data is collected and processed. Personal data is any data that is likely to identify a user. This includes, in particular, first and last names, age, postal address, e-mail address, user location and IP address;
What rights users have concerning this data;
Who is responsible for processing the personal data collected and processed;
To whom this data is transmitted;
Where applicable, the site's cookie policy.
This privacy policy supplements the legal notice and the General Terms of Use, which users can consult in the footers:

ARTICLE 2: GENERAL PRINCIPLES OF DATA COLLECTION AND PROCESSING

In accordance with the provisions of Article 5 of European Regulation 2016/679, the collection and processing of site users' data complies with the following principles:
Lawfulness, fairness and transparency: data may only be collected and processed with the consent of the user who owns the data. Whenever personal data is collected, the user will be informed that his or her data is being collected, and for what purposes his or her data is being collected;
Limited purposes: the collection and processing of data is carried out to meet one or more purposes determined in these general terms of use;
Minimization of data collection and processing: only the data necessary for the proper execution of the objectives pursued by the site is collected;
Data retention reduced in time: data is retained for a limited period, of which the user is informed. If the storage period cannot be communicated to the user;
Integrity and confidentiality of the data collected and processed: the data controller undertakes to guarantee the integrity and confidentiality of the data collected.
In order to be lawful, and in accordance with the requirements of Article 6 of European Regulation 2016/679, the collection and processing of personal data may only take place if they comply with at least one of the conditions listed below:
The user has expressly consented to the processing;
The processing is necessary for the proper performance of a contract;
The processing meets a legal obligation;
The processing is explained by a necessity linked to safeguarding the vital interests of the data subject or another natural person;
Processing may be necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
Processing and collection of personal data are necessary for the purposes of the legitimate and private interests pursued by the controller or by a third party.

ARTICLE 3: PERSONAL DATA COLLECTED AND PROCESSED WHEN BROWSING THE SITE

A. DATA COLLECTED AND PROCESSED AND METHOD OF COLLECTION

The personal data collected on the PrepaStrat site is as follows:
First name, Last name, Schools, Postal address, E-mail address, Bank details,
This data is collected when the user carries out one of the following operations on the site:
When the user creates an account
When the user buys a product
Furthermore, when a payment is made on the site, proof of the transaction, including the order form and the invoice, will be kept in the site editor's computer systems.
The data controller will keep all data collected in the site's computer systems, guaranteeing its security, for a maximum period of 5 years before deleting it completely. In the event of a partnership with a school, this data will also be kept for a maximum of 5 years. If the contractual relationship is terminated before this period, your data will be deleted in its entirety on the date of termination of the contractual relationship.


Data is collected and processed for the following purposes:
The user's personal data is collected in order to better understand his/her profile and personalize the commercial relationship with him/her.

B. TRANSFER OF DATA TO THIRD PARTIES

Data may be transmitted to the following third parties:
Google, Facebook, Stripe for targeted commercial advertising purposes.

C. DATA HOSTING

The PrepaStrat website is hosted by : 1&1, whose head office is located at the following address:
7 place de la gare, 57200 SARREGUEMINES
The host can be contacted at the following telephone number: +33970808911
The data collected and processed by the site are exclusively hosted and processed in France.

ARTICLE 4: DATA CONTROLLER AND DATA PROTECTION OFFICER

A. THE DATA CONTROLLER

The person responsible for processing personal data is: Pierre-Adrien Justice. He can be contacted as follows:
By e-mail: contact@prepastrat.com
The data controller is responsible for determining the purposes and means of processing personal data.

B. OBLIGATIONS OF THE DATA CONTROLLER

The data controller undertakes to protect the personal data collected, not to pass it on to third parties without the user's knowledge, and to respect the purposes for which the data was collected.
The site has an SSL certificate to guarantee that information and data transfer via the site are secure.
An SSL certificate ("Secure Socket Layer" Certificate) is used to secure data exchanged between the user and the site.
In addition, the data controller undertakes to notify the user in the event of rectification or deletion of data, unless this would entail disproportionate formalities, costs and steps for the user.
In the event that the integrity, confidentiality or security of the user's personal data is compromised, the data controller undertakes to inform the user by any means.

C. THE DATA PROTECTION OFFICER

Furthermore, the user is informed that the following person has been appointed Data Protection Officer: Pierre-Adrien Justice.
The role of the Data Protection Officer is to ensure the proper implementation of national and supranational provisions relating to the collection and processing of personal data. He is sometimes referred to as the Data Protection Officer (DPO).
The Data Protection Officer can be contacted as follows:
By e-mail: contact@prepastrat.com

ARTICLE 5: USER RIGHTS

In accordance with the regulations governing the processing of personal data, the user has the following rights. In order for the data controller to comply with the user's request, the user must provide the following information: first and last name, e-mail address and, if relevant, account number, personal space number or subscriber number.
The data controller must respond to the user's request within a maximum of 30 (thirty) days.

A. PRESENTATION OF THE USER'S RIGHTS WITH REGARD TO DATA COLLECTION AND PROCESSING

a. Right of access, rectification and deletion

The user may view, update, modify or request the deletion of data concerning him/her, by following the procedure set out below:
The user must send an e-mail to the person responsible for processing personal data, specifying the subject of his/her request and using the contact e-mail address provided above.
If he/she has one, the user has the right to request the deletion of his/her personal space by following the procedure set out below:
The user must send an e-mail to the person responsible for processing personal data, specifying his/her personal space number. The deletion request will be processed within 10 working days.

b. Right to data portability

The user has the right to request the portability of his/her personal data, held by the site, to another site, by complying with the following procedure:
The user must make a request for the portability of his/her personal data to the data controller, by sending an e-mail to the address provided above.

c. Right to limit and object to data processing

The user has the right to request the limitation of or to object to the processing of his/her data by the site, without the site being able to refuse, unless it can demonstrate the existence of legitimate and overriding reasons, which may prevail over the interests and rights and freedoms of the user.
In order to request the limitation of the processing of his/her data or to formulate an objection to the processing of his/her data, the user must follow the following procedure:
The user must make a request for the limitation of the processing of his/her personal data to the data controller, by sending an e-mail to the address provided above.

d. Right not to be subject to a decision based exclusively on an automated process

In accordance with the provisions of Regulation 2016/679, the user has the right not to be subject to a decision based exclusively on an automated process if the decision produces legal effects concerning him, or significantly affects him in a similar way.

e. Right to determine the fate of data after death

Users are reminded that they can organize what should happen to their collected and processed data if they die, in accordance with law no. 2016-1321 of October 7, 2016.

f. Right to appeal to the competent supervisory authority

In the event that the data controller decides not to respond to the user's request, and the user wishes to contest this decision, or if he believes that one of the rights listed above has been infringed, he is entitled to refer the matter to the CNIL (Commission Nationale de l'Informatique et des Libertés, https://www.cnil.fr) or to any competent court.

B. PERSONAL DATA OF MINORS

In accordance with the provisions of Article 8 of European Regulation 2016/679 and the French Data Protection Act, only minors aged 15 or over may consent to the processing of their personal data.
If the user is a minor under the age of 15, the consent of a legal representative will be required in order for personal data to be collected and processed.
The site editor reserves the right to verify by any means that the user is over the age of 15, or that he/she has obtained the consent of a legal representative before browsing the site.

ARTICLE 6: CONDITIONS FOR MODIFYING THE PRIVACY POLICY

This confidentiality policy can be consulted at any time at the foot of the site.
The site editor reserves the right to modify it in order to ensure its compliance with current legislation.
Consequently, the user is invited to consult this confidentiality policy on a regular basis in order to keep up to date with the latest changes.
The user is hereby informed that this confidentiality policy was last updated on: 19/01/2019.

ARTICLE 7: ACCEPTANCE BY THE USER OF THE PRIVACY POLICY

By browsing the site, the user certifies that he/she has read and understood the present privacy policy and accepts its conditions, particularly with regard to the collection and processing of his/her personal data.