Data Protection Policy
ARTICLE 1: FOREWORD
The GDPR and you…
The protection of personal data is one of our major concerns. This privacy policy is part of a legal framework defined by the European General Data Protection Regulation (EU Regulation 2016/679 of April 27, 2016), applicable since May 25, 2018, and the French Data Protection Act No. 78-17 of January 6, 1978, as amended, relating to information technology, data files, and civil liberties.
Thus, the purpose of this data protection policy is to inform you about:
… The controller of personal data
… The manner in which your data is collected and processed. Personal data is data that can identify a natural person.
… Your rights regarding the use of your personal data
… The recipients to whom your data is transmitted
… The website’s policy regarding cookie management
This privacy policy complements the legal notices on the website and the general terms and conditions of sale.
ARTICLE 2: GLOSSARY
We promise, you’ll understand us!
Personal Data (or Personal Data) is any information relating to an identified or identifiable person, i.e., information that allows them to be identified directly (e.g., first and last name) or indirectly (e.g., cookies).
Personal Data Processing is any operation or set of operations (automated or not) applied to personal data or sets of personal data, such as: the collection, recording, organization, storage, transmission of data (…)
The Data Controller determines the purposes (objectives of the processing) and the means of the processing.
The Processor processes personal data on behalf of the Data Controller and under their instructions.
ARTICLE 3: GENERAL PRINCIPLES
We have legal obligations! In accordance with the provisions of Article 5 of the General Data Protection Regulation (GDPR), the collection and processing of your personal data comply with the following principles:
Lawfulness, fairness, and transparency: The collection and processing of personal data may only be based on a previously defined legal basis (performance of a contract, legal obligation, consent, legitimate interest, preservation of vital interests).
Limited purposes: The collection and processing of personal data are carried out to meet one or more defined objectives.
Minimization of data collection and processing: Only data strictly necessary for the proper execution of the objectives pursued are collected.
Limited data retention period: The data controller is required to define retention periods for the personal data processed.
Integrity and confidentiality of data collected and processed: The data controller undertakes to guarantee the integrity and confidentiality of the data collected.
ARTICLE 4: DATA CONTROLLER AND PROCESSOR
We are responsible for the data entrusted to us! As the data controller, NEGOMARKETS undertakes to comply with the obligations arising from the Regulation and the amended Data Protection Act regarding the collection and processing of personal data. In accordance with Article 32 of the GDPR, we implement all technical and organizational measures to ensure the protection of your personal data.
As a subcontractor for distributors, NEGOMARKETS undertakes to process the customer’s personal data only to the extent necessary for the performance of the contract. NEGOMARKETS undertakes to follow the customer’s written instructions, in accordance with Article 28 of the GDPR.
ARTICLE 5: PERSONAL DATA COLLECTED AND PROCESSED: WHAT DATA?
What do we know about you?
In accordance with the principle of minimization, we only collect the data necessary to carry out our missions. Thus, as part of our business, NEGOMARKETS may collect and process the following information:
– Identity: first name, last name, age
– Professional: position held, place of work, personal email address
– Login information: usernames and passwords
– Internet: IP address, connection history, cookies, trackers
Personal information: personal postal address, personal telephone number, personal email address
Economic information: bank details, bank details
We do not collect any sensitive data such as religion, union membership, racial and ethnic origin, criminal convictions, or health-related data.
ARTICLE 6: PERSONAL DATA COLLECTED AND PROCESSED: FOR WHAT REASONS?
We hold
Let me explain!
In all these situations, NEGOMARKETS acts as “Data Controller” within the meaning of the GDPR.
You can consult the document here: Data Protection Policy
ARTICLE 7: PERSONAL DATA: WHO HAS ACCESS TO YOUR PERSONAL DATA?
We don’t share it with just anyone!
NEGOMARKETS undertakes to only share your personal data with authorized internal personnel and third parties such as the tax, customs, or economic authorities, the justice system, the police, and the gendarmerie, as well as the social welfare and health authorities.
NEGOMARKETS may, if necessary, transmit your personal data to subcontractors such as:
– PRESTASHOP: for the provision of business software (customer records, supplier records, invoices, etc.)
– LENGOW: for the provision of marketplace order flow management software
The use of these service providers is necessary for the proper provision of our services. We undertake to verify and ensure their compliance with the GDPR and the amended French Data Protection Act.
Apart from the recipients listed above, NEGOMARKETS undertakes not to transmit your personal data to third parties or external organizations without your express consent.
NEGOMARKETS does not and will not sell, transfer, or otherwise disclose your personal data to unauthorized third parties.
NEGOMARKETS does not use any automated decision-making based on your personal data. ARTICLE 8: YOUR RIGHTS
You hold all the cards! 8.1 Your Rights
Your GDPR Rights
In accordance with current regulations, you have the following rights regarding your personal data:
– Right of access (You may, at any time, access the personal data we hold about you.)
– Right of rectification (You may request the completion, correction, or clarification of your personal information.)
– Right to object (You retain the right, at any time, to object to the use of your personal data in the context of our company’s activities regarding the processing of your data.)
– Right to restriction (You may request the restriction of future processing of your personal data under certain conditions.)
– Right to erasure (You may also request the deletion of your personal data.)
– Right to portability (You have the right to receive your personal data in a structured, commonly used, and machine-readable format.) You can also request that we transfer your personal data to another organization.
– Digital Death (You can decide what happens to your digital personal data after your death.)
8.2 The DPO
NEGOMARKETS has appointed a Data Protection Officer (DPO). To exercise your rights, you can contact our Data Protection Officer (DPO) at the following address:
Name: OPTIMEX DATA NEGOMARKETS
Email: rgpd@bobochicparis.com
Address: 58-58b rue de Dantzig, 75015 Paris
Telephone number: +33 1 55 76 90 90
8.3 Complaints to the CNIL
You may file a complaint with the competent authority, the French Data Protection Authority (CNIL), at any time by following the link below: https://www.cnil.fr/fr/plaintes.
8.4 Ways to block commercial solicitations
You can opt out of receiving new solicitations in the following ways, particularly in the case of email solicitations, by clicking on the unsubscribe link provided for this purpose.
ARTICLE 9: SECURITY MEASURES
You entrust us with your data, we take care of it!
NEGOMARKETS is concerned about the security of personal data, which it undertakes to process securely and only for the duration necessary to achieve the intended purpose.
NEGOMARKETS has implemented technical and organizational measures to ensure a level of data protection appropriate to the nature and purpose of the processing.
Thus, in accordance with Article 32 of the GDPR relating to the security of processing, NEGOMARKETS has implemented:
– Pseudonymization and encryption of personal data;
– Means to guarantee the ongoing confidentiality, integrity, availability, and resilience of processing systems and services.
– Means to restore data availability and access within appropriate timeframes in the event of a physical or technical incident;
– A procedure for regularly testing, analyzing and evaluating the effectiveness of technical and organizational measures for
Ensure the security of processing.
The security obligation, however, remains an obligation of means, meaning that we make every effort to guarantee the confidentiality and integrity of your personal data.
All persons with access to your personal data have been made aware of data protection best practices. They are bound by an obligation of confidentiality, and if they fail to comply with this provision, they are liable to disciplinary action.
ARTICLE 10: DATA TRANSFERS OUTSIDE THE EUROPEAN UNION
A well-organized trip!
As part of our business and to manage your requests, we are not required to directly transfer your data outside the European Union.
However, if your personal data is transferred outside the European Union, we will ensure that these countries guarantee a sufficient and appropriate level of data protection. We undertake to inform you in advance of the possibility of transferring data outside the European Union, and we will therefore inform you of the safeguards in place to ensure a sufficient and appropriate level of protection.
ARTICLE 11: COOKIES
You have the choice between eating cookies or going on a diet.
As with most websites, our website uses cookies that can be classified into five categories:
– Advertising: These cookies allow us to offer you more relevant and targeted advertising from our partners based on your browsing and customer profile.
– Social media: These cookies allow you to share your activity on our site with social media companies.
– Functionality: These cookies remember the choices you make to improve your experience on our website and make your visit more personalized. The information these cookies collect may be anonymized and cannot under any circumstances be used to track your activities on websites other than ours.
– Performance/analytics: These cookies collect anonymous information about your use of our website. The information collected by these cookies is used only to improve your experience of our website and never for identification purposes.
Strictly necessary: These cookies facilitate your navigation between the pages of our website and are necessary to allow you to benefit from certain features, such as creating your user account and securing your connection when you wish to access pages reserved for you. These cookies expire when you close your internet browser.
If you wish to limit your tracking, it is recommended to refuse them by default via the cookie management banner that we have implemented on our website.
You will also find in our cookie policy the procedure to follow to accept, customize, or refuse cookies by expressing your choice using the banner that appears at the bottom of your screen.
ARTICLE 12: UPDATE OF THE DATA PROTECTION POLICY
You’ve reached the right point, you’re almost done reading! This personal data protection policy may change from time to time.
It was last updated on January 1, 2025
