Last update: June 25, 2020
The respect of of your private life is of the utmost importance for Parissa Sarandi, who is responsible for this website.
- the way your personal information is collected and processed. “Personal information” means any information that could identify you, such as your name, your mailing address, your email address, your location and your IP address. “Personal information” is a synonym for “personal data” within the meaning of the Regulation 2016/679 of European Union (General Data Protection Regulation);
- your rights regarding your personal information;
- who is responsible for the processing of the collected and processed information;
- to whom the information is transmitted;
- if applicable, the website’s policy regarding cookies.
COLLECTION OF PERSONAL INFORMATION
We collect the following personal information:
- Last Name
- First name
- Mailing address
- Postal code
- Email address
- Phone and/or fax number
- Credit card number
- Date of birth/age
The personal information we collect is collected through the collection methods described in the following section.
FORMS AND METHODS OF COLLECTION
Your personal information is collected through the following methods:
- Order form
- Survey form
We use the collected data for the following purposes:
- Order tracking
- Special offers
- Managing the website
Your personal information is also collected through the interactivity between you and the website. This personal information is collected through the following methods:
- Information for promotional offers
We use the personal information thus collected for the following purposes:
- Website management
COOKIES AND LOG FILES
We collect information through log files and cookies. These allow us to process statistics and information on trafic on the Website, to ease navigation and improve your experience for your comfort.
Your consent is considered to be valid for a maximum period of thirteen (13) months. At the end of that period, we will ask again for your consent to save cookies and log files on your hard disk.
a) Cookies used by the Website
The cookie files used by the Website are the following:
- Pages visited and queries
- Day and time of connection
The use of such files allows us to achieve the following purposes:
- Improvement of the service and personalized welcome
- Personalized consumption profiles
- Order tracking
- Statistical surveys
You have the right to object to the recording of these cookies and log files by configuring your web browser.
Once you have deactivated cookies and log files, you may continue your use pf the Website. However, any malfunction resulting from this deactivation may not be considered of our making.
SHARING OF PERSONAL INFORMATION
We are committed to not selling to third parties or otherwise commercialize the personal information we collect. However, we may share this information with third parties for the following reasons:
- Order fulfillment
STORAGE PERIOD OF PERSONAL INFORMATION
The controller will keep in its computer systems, in reasonable security conditions, the entirety of the personal information collected for the following duration: 5 years.
HOSTING OF PERSONAL INFORMATION
Our website is hosted by: Godaddy, located at the following address:
14455 North Hayden Road Suite 219 Scottsdale, AZ 85260 United States.
The host may be contacted at the following phone number: 1-480-505-8877.
Personal information we collect and process is transferred to the following countries: USA.
- a) Controller
The “Controller” is: Parissa Sarandi. The Controller may be contacted as follows:
The Controller is in charge of determining the purposes for which personal information is processed and the means at the service of such processing.
b) Obligations of the Controller
The Controller is committed to protecting the personal information collected, to not transmit it to third parties without informing you, and to respect the purposes for which personal information was collected.
In the event that the integrity, confidentiality or security of your personal information is compromised, the Controller is committed to notify you.
RIGHT OF OBJECTION AND OF WITHDRAWAL
You have the right to object to the processing of your personal information by the website (“right to object”). You also have the right to request that your personal information does not appear, for example, on a mailing list (“right to withdraw”).
If you wish to exercise the right to object or the right to withdraw, you must follow the procedure described hereinafter:
RIGHT OF ACCESS, OF RECTIFICATION AND OF REMOVAL
You have the right to consult, update, modify or request the removal of information about you by following the procedure described hereinafter:
If you have a personal account, you may request its removal by following the procedure described hereinafter:
GENERAL PRINCIPLES RELATING TO THE COLLECTION AND PROCESSING OF PERSONAL DATA UNDER EUROPEAN REGULATION 2016/679
In accordance with the provisions of Article 5 of European Regulation 2016/679, the collection and processing of your personal data comply with the following principles:
- Lawfulness, fairness and transparency: your personal data may only be collected and processed with your consent. Every time you personal data is collected, you will be informed that your personal data is collected and for which reasons your personal data is collected;
- Data minimisation: only personal data necessary for the purpose to which it is necessary is collected;
- Storage limited in time: personal data is stored for a limited time, of which you are notified;
- Integrity and confidentiality of collected and processed personal data: the Controller is committed to guarantee the integrity and confidentiality of the collected personal data.
In order to be lawful and to comply with Article 6 or European Regulation 2016/679, collection and processing will only occur if one of the following applies:
- You have given your express consent;
- Processing is necessary for the performance of a contract;
- Processing is necessary for compliance with a legal obligation;
- Processing is necessary in order to protect your vital interests or those of another physical person;
- Processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority;
- Processing is necessary for the purposes of the legitimate interests pursued by the Controller or a third party.
DATA PROTECTION OFFICER PURSUANT TO EUROPEAN REGULATION 2016/679
The following person has been appointed as the Data Protection Officer (also referred to as DPO): Parissa Sarandi.
The purpose of the Data Protection Officer is to ensure the successful implementation of the applicable European legislative provisions relating to the collection and processing of personal data.
The Data Protection Officer may be reached as follows:
By email : firstname.lastname@example.org
ADDITIONAL RIGHTS PURSUANT TO EUROPEAN REGULATION 2016/679
In accordance with European regulation relating to the processing of personal data, you also have the rights listed below.
In order for the Controller to grant your request, you must provide your first and last name, your email address, and if relevant, your personal account or membership number.
The Controller must answer your request within a period of thirty (30) days.
a) Right to portability of personal data
You have the right to request the portability of your personal data held by the Website to another site by following the procedure described below:
b) Right of not being the object of a decision based only on automated processing
In accordance with the provisions of the European Regulation 2016/679, you have the right of not being the subject of decision based solely on automated processing if the decision produces legal effecting concerning you or significantly affects you.
c) Right to submit a complaint to the competent authority
In the event that the Controller does not answer your request, you wish to challenge his or her decision or you believe one of your rights has been infringed upon, you have the right to submit a complaint to the competent authority.
Personal information we collect is stored in a secured environment. People working for us are obligated to respect the confidentiality of your personal information.
To ensure the security of you personal information, we use the following methods:
- SSL (Security Sockets Layer) Protocol
- SET (Secure Electronic Transaction) Protocol
- Access management – person authorized
- Access management – person concerned
- Network surveillance software
- Automatic backup
- Digital certificate
We are committed to maintaining a high degree of confidentiality by integrating the latest technological innovations that allow us to ensure the confidentiality of your transactions. Nevertheless, no mechanism can ensure a complete security and transmitting personal informations on the Internet always entail a part of risk.
Our commitments relating to the protection of personal information meet the standards of the following program(s):
- TRUSTe: https://truste.org
We are committed to respect the legislative provisions as specified in:
Personal Information Protection and Electronic Documents Act, SC 2000, c 5; and/or
Act Respecting the Protection of Personal Information in the Private Sector, CQLR cP-39.1 ; and
General Data Protection Regulation, Regulation (EU) 2016/679 of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC.