Privacy Policy

Published 22 January 2024

At LIPITT, protecting your personal data is our priority.


When browsing the website www.lipitt.com (the "Website") or when using the Website as our client (the “Client”), we may collect personal data about you.


The purpose of this policy is to inform you about how we process your personal data in compliance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR") and French Data Protection Law n° 78-17 of 6 January 1978 (together the "Applicable Regulations").

At LIPITT, protecting your personal data is our priority.


When browsing the website www.lipitt.com (the "Website") or when using the Website as our client (the “Client”), we may collect personal data about you.


The purpose of this policy is to inform you about how we process your personal data in compliance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR") and French Data Protection Law n° 78-17 of 6 January 1978 (together the "Applicable Regulations").

At LIPITT, protecting your personal data is our priority.


When browsing the website www.lipitt.com (the "Website") or when using the Website as our client (the “Client”), we may collect personal data about you.


The purpose of this policy is to inform you about how we process your personal data in compliance with Regulation (EU) 2016/679 of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter the "GDPR") and French Data Protection Law n° 78-17 of 6 January 1978 (together the "Applicable Regulations").

Who is the data controller?

The data controller is LIPITT, a simplified joint-stock company registered with the Registry of Trade and Companies of Evry under the number 980 765 531 and whose head office is located at 7, avenue de la Laponie – 91940 LES ULIS (“Us” or “We”) when browsing on our Website or when using your account on our Website as our Client (the « Account »).


However, when our Clients use our services for professional purposes, we process personal data on their behalf and for their own purposes. Our Clients act therefore as data controllers in accordance with Article 4 of GDPR while we act as data processor.

What personal data we collect?

Personal data is a data that identifies an individual directly or indirectly, in particular by reference to an identifier such as a name.


We may collect the following personal data:

  • Identification data (e.g. full name, email and postal addresses, telephone number);

  • Face data (photo, and video footage of your face including your voice);

  • Login data (e.g. logs, IP address);

  • Browsing data (IP address, pages viewed, date and time of connection, browser used, operating system, user ID, MAID, user behavior (mouse tracking));

  • If you choose to sign in using a third-party authentication service (e.g., Google or Microsoft), certain data such as your name and email may be collected from that service. By choosing this method, you agree that the service may share this information with us. We do not collect your third-party account password;

  • Data related to your credit cards;

  • Any information you wish to send us as part of your contact request;

  • Any personal data you upload through the Website.


We inform you, when collecting your personal data, whether some of these data are mandatory or optional.

On what legal basis, for what purposes and for how long do we keep your personal data?

Objectives

Objectives (O)

Legal basis

Legal basis (L)

Data retention period

Data retention period (R)

To provide you with our services available on our Website through your account

(O) To provide you with our services available on our Website through your account

Performance of a contract to which you are party and/or taking steps at your request prior to entering into a contract

(L) Performance of a contract to which you are party and/or taking steps at your request prior to entering into a contract

When you have created your account: personal data are retained for the duration of your account.


Your connection logs are kept for 6 months.


If your account is inactive for a period of 2 years, it will be deleted if you do not respond to our reactivation email.


In addition, personal data may be archived for probationary purposes for a period of 5 years.

(R) When you have created your account: personal data are retained for the duration of your account.


Your connection logs are kept for 6 months.


If your account is inactive for a period of 2 years, it will be deleted if you do not respond to our reactivation email.


In addition, personal data may be archived for probationary purposes for a period of 5 years.

To perform operations related to contracts, orders, invoices, and customer relationship management

(O) To perform operations related to contracts, orders, invoices, and customer relationship management

Performance of a contract to which you are party

(L) Performance of a contract to which you are party

Personal data are retained for the duration of our business relationship.


In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years.


The data related to your credit card are retained by our payment service provider for the duration of your subscription to the services.


The CVV2 (Card Verification Value), listed on your credit card details, will not be stored.

(R) Personal data are retained for the duration of our business relationship.


In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years.


The data related to your credit card are retained by our payment service provider for the duration of your subscription to the services.


The CVV2 (Card Verification Value), listed on your credit card details, will not be stored.

To create a database of customers and prospects

(O) To create a database of customers and prospects

Our legitimate interest in developing and promoting our business

(L) Our legitimate interest in developing and promoting our business

For our customers: their personal data are retained for the duration of our business relationship.


For our prospects: their personal data are retained for a period of 3 years starting from the last contact with us (e.g. communication,

action).


In addition, personal data may be archived for probationary purposes for a period of 5 years.

(R) For our customers: their personal data are retained for the duration of our business relationship.


For our prospects: their personal data are retained for a period of 3 years starting from the last contact with us (e.g. communication,

action).


In addition, personal data may be archived for probationary purposes for a period of 5 years.

To send newsletters, requests and direct marketing mailings

(O) To send newsletters, requests and direct marketing mailings

For our Clients: our legitimate interest in winning customer loyalty and informing our customers of our latest news


BtoB: our legitimate interest in winning Clients loyalty and informing our Clients of our latest news

(L) For our Clients: our legitimate interest in winning customer loyalty and informing our customers of our latest news


BtoB: our legitimate interest in winning Clients loyalty and informing our Clients of our latest news

Personal data are retained for a period of 3 years starting from the last contact with us (e.g. communication, action).

(R) Personal data are retained for a period of 3 years starting from the last contact with us (e.g. communication, action).

To manage your opinions on our products, services or content

(O) To manage your opinions on our products, services or content

Our legitimate interest in collecting your opinions on our products, services

(L) Our legitimate interest in collecting your opinions on our products, services

2 years from the publication of the opinion.

(R) 2 years from the publication of the opinion.

To comply with our legal obligations to report illegal content on the Website

(O) To comply with our legal obligations to report illegal content on the Website

Comply with our legal and regulatory obligations imposed in connection with our Website

(L) Comply with our legal and regulatory obligations imposed in connection with our Website

Your identification data is kept for 5 years after the end of the validity of the Terms of Use, the closing of your account or the closing of the report.


Other information provided by the user, including payment information, is kept for one year from the end of the validity of the Terms of Use, the closing of your account or the closing of the report.


The technical data allowing to identify the source of the connection or those relating to the terminal equipment used are kept for a period of one year as from the connection or the use of the terminal equipment.

(R) Your identification data is kept for 5 years after the end of the validity of the Terms of Use, the closing of your account or the closing of the report.


Other information provided by the user, including payment information, is kept for one year from the end of the validity of the Terms of Use, the closing of your account or the closing of the report.


The technical data allowing to identify the source of the connection or those relating to the terminal equipment used are kept for a period of one year as from the connection or the use of the terminal equipment.

To answer to your information request and other inquiries

(O) To answer to your information request and other inquiries

Our legitimate interest in responding to your inquiries

(L) Our legitimate interest in responding to your inquiries

Personal data are retained during the processing of your request and is deleted once the request has been processed.

(R) Personal data are retained during the processing of your request and is deleted once the request has been processed.

To comply with our legal and regulatory obligations

(O) To comply with our legal and regulatory obligations

Legal and regulatory obligations

(L) Legal and regulatory obligations

Invoices are archived for a period of 10 years.


In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years.

(R) Invoices are archived for a period of 10 years.


In addition, the data relating to your transactions (with the exception of your banking data) are archived for probationary purposes for a period of 5 years.

To process your applications and to manage interview (pre-selection of candidates, contact to evaluate the candidate's ability to fill the position, finalization of the recruitment process)

(O) To process your applications and to manage interview (pre-selection of candidates, contact to evaluate the candidate's ability to fill the position, finalization of the recruitment process)

Execution of precontractual measures

(L) Execution of precontractual measures

Your data is kept in an active database for the duration of the recruitment process until the hiring decision is made.


If your application is rejected, your data may be kept for 3 months after the end of the recruitment process, in order to be able to provide you with explanations on the reasons that led to the rejection of your application.


Your data may be kept in an intermediate archive for evidential purposes for 5 years from the date of the hiring decision.

(R) Your data is kept in an active database for the duration of the recruitment process until the hiring decision is made.


If your application is rejected, your data may be kept for 3 months after the end of the recruitment process, in order to be able to provide you with explanations on the reasons that led to the rejection of your application.


Your data may be kept in an intermediate archive for evidential purposes for 5 years from the date of the hiring decision.

To create a CV database

(O) To create a CV database

Your consent

(L) Your consent

The data is kept for two years from the last contact with the data subject.

(R) The data is kept for two years from the last contact with the data subject.

To organize contests and promotional operations

(O) To organize contests and promotional operations

Our legitimate interest in winning clientele loyalty and offering them gifts

(L) Our legitimate interest in winning clientele loyalty and offering them gifts

The personal data is kept for the duration of the contests or promotional operations and may be archived for 5 years for evidential purposes.

(R) The personal data is kept for the duration of the contests or promotional operations and may be archived for 5 years for evidential purposes.

To elaborate analytics of navigation, Website audience, purchases and Client favorite services and habits on the Website

(O) To elaborate analytics of navigation, Website audience, purchases and Client favorite services and habits on the Website

Our legitimate interest in analyzing the composition of our Clients base and improving our services

(L) Our legitimate interest in analyzing the composition of our Clients base and improving our services

The personal data are retained for 25 months.

(R) The personal data are retained for 25 months.

To display personalized advertising

(O) To display personalized advertising

Your consent

(L) Your consent

The personal data are retained for 25 months.

(R) The personal data are retained for 25 months.

To process data subjects’ requests to exercise their rights

(O) To process data subjects’ requests to exercise their rights

Our legitimate interest in responding to your requests and keeping records of them

(L) Our legitimate interest in responding to your requests and keeping records of them

If we ask you a proof of identity: we only retain it for the necessary time to verify your identity. Once the verification has been carried out, the proof is deleted.


If you exercise your right to object to direct marketing: we keep this information for 3 years.

(R) If we ask you a proof of identity: we only retain it for the necessary time to verify your identity. Once the verification has been carried out, the proof is deleted.


If you exercise your right to object to direct marketing: we keep this information for 3 years.

Who are the recipients of your personal data?

The following categories of recipients will have access to your personal data:

1) The staff of our company;

2) Our processors: Scaleway, Stripe, Google Analytics;

3) Our partners: OpenAI, ElevenLabs;

4) If applicable: public and private organisations, exclusively to comply with our legal obligations.

Are your personal data likely to be transferred outside the European Union?

Your personal data is hosted for the duration of the processing on the servers of Scaleway, located in the European Union.

What rights can you exercise on your personal data?

You have the following rights with regard to your personal data:

  • Right to be informed: this is precisely why we have drafted this privacy policy as defined by articles 13 and 14 of the GDPR;

  • Right of access: you have the right to access all your personal data at any time as defined by article 15 of the GDPR;

  • Right to rectification: you have the right to rectify your inaccurate, incomplete or obsolete personal data at any time as defined by article 16 of the GDPR;

  • Right to restriction of processing: you have the right to restrict the processing of your personal data in certain cases defined in article 18 of the GDPR;

  • Right to erasure (“right to be forgotten”): you have the right to request that your personal data be deleted and to prohibit any future collection as defined by article 17 of the GDPR;

  • Right to file a complaint to a competent supervisory authority (in France, the CNIL), under article 77 of the GDPR, if you consider that the processing of your personal data constitutes a breach of applicable regulations;

  • Right to define instructions related to the retention, deletion and communication of your personal data after your death;

  • Right to withdraw your consent at any time: for purposes based on consent, Article 7 of the GDPR provides that you may withdraw your consent at any time. Such withdrawal will not affect the lawfulness of the processing carried out before the withdrawal;

  • Right to data portability: under specific conditions defined in article 20 of the GDPR, you have the right to receive the personal data you have provided us in a standard machine-readable format and to require their transfer to the recipient of your choice;

  • Right to object: You have the right to object to the processing of your personal data as defined by article 21 of the GDPR. Please note that we may continue to process your personal data despite this opposition for legitimate reasons or for the defense of legal claims.


You can exercise these rights by writing us using the contact details below. For this matter we may ask you to provide us with additional information or documents to prove your identity.

What cookies do we use?

For more information on cookies management, please consult our Cookies Policy.

Contact information for data privacy matters

Contact email: [email protected]

Contact address: 7, avenue de la Laponie – 91940 LES ULIS.

Modifications

We may modify this privacy policy at any time, in particular in order to comply with any regulatory, jurisprudential, editorial or technical change. These modifications will apply on the date of entry into force of the modified version. Please regularly consult the latest version of this privacy policy. You will be kept posted of any significant change of the privacy policy.


Entry into force: 22/01/2024