Privacy Policy
LAGA Paris is committed to complying with current legislation regarding the protection of privacy and personal data, and in particular, the European General Data Protection Regulation (GDPR) of April 27, 2016, and Law No. 78-17 of January 6, 1978, relating to Information Technology, Files, and Freedoms.
The purpose of this privacy policy (hereinafter "Privacy Policy") is to:
-enable you to communicate your personal information with confidence and confidentiality when you browse and place orders on the website www.lagaeyewear.com (hereinafter "the Site")
-inform you of the purposes for which data collected by LAGA Paris is processed;
-inform you of the measures taken to ensure the confidentiality and security of your personal data;
-and generally, to clarify your rights regarding personal data.
1- Identity of the data controller
The data controller, within the meaning of applicable personal data regulations, is LAGA Eyewear (LAGA Paris), a simplified joint-stock company with a share capital of €10,000, whose registered office is located at 231 rue Saint-Honoré 75001 PARIS, registered with the Romans Trade and Companies Register under number 941 428 427.
2- Definition of personal data
Personal data are specific or personal information relating to an identified or identifiable natural person (for example, your name, telephone number, postal address, email address). Non-private data ("pseudonyms") are information relating to a particular person or account that is not sufficient to identify that person.
3- When does LAGA Paris collect personal data?
When you interact with LAGA Paris, by any means whatsoever, particularly when you visit, browse, or place an order on the Site, you may be required to provide a certain amount of personal data concerning you, i.e., information allowing your direct or indirect identification (for example, your name, telephone number, postal address, email address). In particular, you will be required to provide personal data to:
-Browse the Site,
-Fill your shopping cart,
-Place or return a product order on the Site,
-Contact us via the Site through our contact form or any other means provided by LAGA Paris.
LAGA Paris collects your personal data explicitly and transparently through either information notices or express reference to the Privacy Policy.
Some personal data that may be requested from you is mandatory. The mandatory nature of the collected data is indicated by an asterisk; other data are optional. Failure to provide mandatory personal data will result in the inability to access all services offered by LAGA Paris.
4- What categories of personal data does LAGA Paris collect?
LAGA Paris may collect the following personal data from you:
Identification data:
-Title, first name, and last name
-Phone number
-Email address
-Postal address
Connection and browsing data:
-Activity logs (IP address, browser type, visit duration, pages viewed, etc.), via the use of cookies
-Information about the devices you use to access the Site, via the use of cookies
-Your choices and preferences (products and services), via the use of cookies
Financial data:
-Payment method
-Last four digits of the credit card
-Transaction amount
Full bank details (card number, expiration date, cryptogram) are collected exclusively by the payment service provider and do not pass through LAGA Paris. For all other data collected elsewhere, the data collection form will describe the rules applicable to the data thus collected in the event that they differ from the rules in this policy.
5- For what purposes does LAGA Paris collect this personal data?
During your relationship with LAGA Paris, regardless of the nature of that relationship, LAGA Paris may collect personal data from you for several purposes:
-placing an order,
-payment for your orders: when you pay on the Site, your payments are secured. LAGA Paris does not collect your payment data but only a payment identifier and the last 4 digits of your card to allow you to recognize the card used for payment. All of your bank details are collected only by our payment service providers who ensure payment security,
-execution and tracking of your orders,
-customer file management,
-management of customer returns and refunds,
-management of disputes and unpaid invoices,
-management of inquiries from prospects,
-management of your requests for information concerning marketed products or your complaints,
-sending marketing newsletters, solicitations, and promotional messages, with your consent, to keep you informed of new products,
-conducting satisfaction and opinion surveys,
-compliance with our legal and regulatory obligations, including managing your requests relating to your rights as described in Article 10.
Generally, the personal information you consent to provide us allows you to place orders on the Site and enables us to provide our online sales service, administer our Site, and improve our marketing and security policy. The personal data processing we carry out is always based on an identified legal basis, namely:
-Consent: when you voluntarily provide us with personal data or expressly authorize us to process your personal data (for example, for newsletter subscriptions). Your consent can then be withdrawn at any time under the conditions set out in Article 10 of this Privacy Policy.
-Performance of a contract: to ensure the monitoring, execution, and management of the order (order placement, payment, invoicing, management of potential unpaid invoices and disputes, return management, responding to your complaints, etc.)
-Legal obligations: To comply with our legal, tax, social, and accounting obligations.
-Legitimate interest: to ensure the development of LAGA Paris's activities, improvement of customer service, administration, maintenance and security of the Site, fraud prevention, analysis, and improvement of the user experience on the Site.
6- How long is your personal data stored?
LAGA Paris retains personal data for the time necessary to fulfill its purpose. This period may be extended by the statutory limitation period under common law to allow us to manage any potential disputes. When the purposes for which personal data were collected are accomplished, they are archived or deleted. Data deletion may involve anonymization, where applicable. More specifically, you can find in the table below the data retention periods applied by LAGA Paris for each purpose.
Purpose of processing: Order management
Retention period: Maximum 5 years from the last transaction, with the exception of contracts over 120 euros including tax where the period is extended to 10 years in accordance with our legal obligations.
Purpose of processing: Payment management
Retention period: - The time necessary for the transaction to be completed, plus the withdrawal period provided for distance selling of goods
- Until the withdrawal of your consent and/or the expiry of the credit card data's validity in the event that you authorize us to retain your data to facilitate future purchases
Purpose of processing: Customer file management
Retention period: Maximum 5 years from the last transaction, unless specific legal obligations require a longer period
Purpose of processing: Returns and refunds management
Retention period: Maximum 5 years from the last transaction, unless specific legal obligations require a longer period
Purpose of processing: Management of complaints, disputes, and unpaid invoices
Retention period: Maximum 5 years from the last transaction, unless specific legal obligations require a longer period
Purpose of processing: Management and follow-up of inquiries from prospects
Retention period: Until consent is withdrawn or 3 years from the last contact
Purpose of processing: Management of your requests for information concerning marketed products
Retention period: Until consent is withdrawn or 3 years from the last contact
Purpose of processing: Sending newsletters and marketing communications
Retention period: Until consent is withdrawn or 3 years from the last contact
Purpose of processing: Conducting opinion and satisfaction surveys
Retention period: Until consent is withdrawn or 3 years from the last contact
7- To whom may LAGA Paris disclose your personal data?
The personal data you provide to us is intended for LAGA Paris and is neither sold nor exchanged in any way with another company without reason or without your consent, outside the scope of use defined below. Your personal data may only be transmitted to third parties if you have given your express consent, if the Law authorizes or requires it, or if this transmission is necessary for the performance of the contract binding us. In this regard, we inform you that we may share your personal data with the following entities:
-authorized staff members involved in carrying out the missions resulting from the purposes identified above;
-service providers who perform certain services on our behalf in connection with the services we provide to you, such as our hosting provider, our payment service provider, our transport providers. The service providers we use only receive the data necessary for the execution of your order or our contract. In this context, they can only use this data to perform their mission. We only share your personal data with trusted partners who allow us to provide our services, provided they agree to keep this information confidential;
-legal auxiliaries and ministerial officers within the scope of their mission of dispute management and debt recovery: in the event of a dispute, we may share your personal data for the defense of our rights;
-administrations for social and tax declarations;
-third parties when you have given your express consent to such sharing.
We also reserve the right to disclose your personal data to other parties in cases where the law, a current regulatory provision, a court order or regulation requires or authorizes it, or if such disclosure is necessary in the context of an investigation or proceeding, nationally or internationally.
8- Is your data transferred outside the European Union?
In principle, personal data processed by LAGA Paris is not intended to be transferred outside the European Union. This data is hosted on servers located within the European Union. By exception, personal data processed by LAGA Paris may be communicated to subcontractors located outside the European Union, in order to pursue the purposes specified in this Privacy Policy. In such a case, LAGA Paris will take, prior to said transfer, all necessary measures and guarantees to secure such transfers and undertakes to ensure that this transfer is covered by either:
- an adequacy decision by the European Commission in accordance with Article 45 of the European General Data Protection Regulation,
- standard contractual clauses issued by the European Commission or a Supervisory Authority in accordance with Article 46 of the European General Data Protection Regulation,
- binding corporate rules approved by a competent Supervisory Authority under Article 47 of the European General Data Protection Regulation.
We also inform you that when you choose to contact us via our social networks (Facebook, Instagram, Whatsapp, TikTok, etc.), the personal data you may communicate to us is, in fact, subject to data transfer outside the European Union, since these social networks are published and managed by companies located outside the European Union (generally in the United States). LAGA Paris is not responsible for subsequent processing carried out by third-party social networks, which act as separate data controllers. You are invited to consult the privacy policy of these entities to understand the implications of using these networks on your privacy.
9- How is your personal data protected?
LAGA Paris is committed to ensuring the security of the data you transmit to it. To prevent any unauthorized access, use, modification, destruction, loss, damage or disclosure, appropriate technical and organizational measures are taken to protect the collected data. In particular, the security of your data is ensured:
-by using TLS (Transport Layer Security) and SSL (Secure Socket Layer) protocols to secure your data,
-through traceability measures, by keeping computers and servers used to store identifiable personal data in a secure environment,
-by limiting access to your data to authorized employees only, who need to perform specific work (for example, invoicing or customer service).
To help in this process of protecting your data, it is recommended to avoid using an overly obvious username or password, as well as to regularly change your password and ensure that you do not communicate your password to anyone. If you wish to know in detail the list of technical and organizational measures implemented by LAGA Paris, you can request this by email at the address given in article 10, by proving your identity. However, the transmission of information via the Internet is not completely secure. Although LAGA Paris undertakes to do everything possible to protect your personal data, it cannot fully guarantee the security of your data. In the event of a breach of your personal data posing a risk to your rights and freedoms, please be aware that LAGA Paris has an obligation to notify the competent supervisory authority and, if applicable, to inform you as soon as possible of any personal data breach likely to pose a high risk to your rights and freedoms, to enable you to take useful measures.
10- What are your rights?
In accordance with the regulations, you have the right to access your personal data, to modify it, to erase it, to be forgotten by LAGA Paris, to limit the processing of your data, to receive the personal data concerning you, provided to LAGA Paris, in a structured, commonly used and machine-readable format, and, for a legitimate reason, to object to the processing of your personal data. When the processing is based on your consent, you also have the right to withdraw it. You also have the right to lodge a complaint with the CNIL or a data protection authority of a European Union member state and to define post-mortem directives concerning the fate of your data. These rights can be exercised at any time:
-Either by email at the following address: contact.lagaparis@gmail.com.
-Or by postal mail to: LAGA Paris, 231 rue Saint-Honoré 75001 PARIS
To enable LAGA Paris to respond quickly, please provide your last name, first name, email, and postal address. LAGA Paris may request any reasonable proof to verify the identity of the applicant when there is serious doubt about their identity, in accordance with Article 12.6 of the GDPR. A response will then be sent to you, except in special cases, within one (1) month of receiving the request. Finally, we inform you of the existence of the telephone canvassing opposition list "Bloctel", on which you can register here: https://www.bloctel.gouv.fr/.
11- Cookies
During your visits to our websites, a "cookie" may be placed on your computer, tablet or smartphone. Cookies are small files stored on your device that collect various data to enable exchanges with our system via your internet browser. They facilitate your browsing (for example, by pre-filling your login information or saving your shopping cart from page to page), improve the security of data processing, and offer a better, more personalized user experience (recommendations based on your history, etc.).
- "Accept all": if you consent to the use of all cookies and other connection trackers,
- "Reject all": if you object to the use of all cookies and other connection trackers (excluding "necessary" cookies),
- "Customize": if you wish to configure the cookies you wish to accept and those you wish to reject, according to their purposes. The drop-down menu presents the different types of cookies used by our website, where applicable.
Details of the cookies used on the Site, their purposes, retention periods, and configuration methods are accessible at any time via the cookie management module available on the Site. Cookies have a maximum lifespan of 13 months. Information collected through cookies is retained for a maximum of 25 months.
12- Log files
Any access to the Websites results in the transmission, by the browser, of usage data which is stored in server log files ("logs"). The recorded data contains the following information: date and time of consultation, name of the site consulted, IP address, referrer URL, volume of data transferred, product, and information on the version of the browser used. We analyze this data for the purposes of server maintenance and optimization, and improvement of the Website and related services. They also allow us to detect errors and correct them before they impact the user experience. Finally, this data allows us to prevent denial-of-service ("DDoS") attacks that can make a site inoperable for a short time by saturating it with requests.
13- Social networks
The Websites may use "plug-ins" or social modules. These include small buttons providing access to third-party social networks such as Facebook, Instagram, YouTube which you can find on the Websites. When you visit a page on the Websites containing social plug-ins or modules, a connection is established with the servers of the social networks concerned, which are then informed that you have accessed the corresponding page of the site consulted, even if you do not have a user account.
14- Modification of the Privacy Policy
We may revise or supplement this Privacy Policy, particularly to take into account new purposes or changes in legislation. Such modifications will be effective from their publication. To keep informed of any changes, please regularly review this page.
15- Contact LAGA Paris
For any comments or questions relating to this document, you can write to us at the contact details provided in article 10.