PERSONAL DATA PROTECTION POLICY
We place great importance on respecting your privacy and are committed to building strong, lasting relationships with you. Protecting the personal data you share with us is a key part of this relationship.
Our Privacy and Personal Data Protection Policy aims to inform you as clearly as possible about how we process and use your personal data.
What is personal data?
Personal data refers to any information relating to an identified or identifiable natural person, either directly or indirectly, particularly by reference to an identifier such as a name, identification number, location data, online identifier, or to one or more elements specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
Who is responsible for your personal data?
The person(s) or legal entity(ies) responsible for your personal data, referred to as “Data Controller(s)”, are those who, alone or jointly with others, determine the purposes and means of the processing. The Data Controller(s) is/are responsible for all personal information collected from customers.
In this regard, we are committed to collecting, processing, and storing your personal data only for useful, legitimate, and relevant purposes.
When and how do we collect your personal data?
We may collect your personal data when you request a quote, purchase an item or service (either directly or indirectly through our trusted third-party partners), use our website or any other site accessible through our website, participate in a survey or competition, or contact us.
All information collected is accessible upon request via the form available on our website, by email at contact@moodbox.fr, or by post at the following address: Moodbox, 16 rue de l'ancienne mairie, 92100 Boulogne-Billancourt, France.
The categories of information we may collect include:
-
Name, home address, email address, phone number, passport or identity document details (if applicable), credit/debit card or other payment information
-
Your order history
-
Details of purchases made through us or, where applicable, through our trusted partners
-
Information on the use of our website or social media pages
-
Communications sent to us by post, email, phone, or via social media
-
Addresses, including real-time geographic location of your computer and your IP address
Why do we use this data?
Your data may be used for the following purposes:
-
To provide the products and services you request: we use the information you provide to enter into and fulfil a sales contract
-
To inform you about the products or services you enquired about, including updates to your orders and deliveries. These communications are not marketing-related and cannot be disabled
-
To conduct credit card or other payment method verification: your payment information is used for accounting, billing, verification, and to detect and/or prevent fraud
-
To carry out statistical and business analysis, system testing, customer surveys, maintenance, and development, or to resolve disputes and claims. We may carry out profiling using the data we collect for statistical and business analysis. This profiling will only be performed with your prior consent, ensuring all data is accurate. By providing your data, you explicitly consent to this profiling
-
To cooperate with health, safety, and crime prevention/detection authorities. We may disclose your data to governmental or regulatory authorities
-
To manage our customer relationship and enhance our services and your experience via email, SMS or postal notifications
-
To contact you for marketing purposes (by email or post) to share promotions, product news, events, or competitions. You can choose whether to receive such communications during purchase and unsubscribe via the links in our newsletters
We will only process your personal data when legally permitted to do so. The legal basis will depend on the reasons for which the data was collected and used.
At no point will your personal data be sold to third parties for commercial purposes.
We may share it only with trusted third parties for service provision or with business partners (marketing and advertising providers).
We may use and compile data for profiling purposes. Profiling involves the automated processing of personal data to evaluate, analyse, and predict preferences, interests, and behaviour.
This helps us provide personalised and relevant product information and offers.
You can change your consent preferences for each communication type at any time, online, via newsletter links or data management sites.
Data Retention
We will not retain your data longer than necessary to fulfil the purposes for which it is processed. We assess the appropriate retention period by considering the quantity, nature, and sensitivity of the data, the purposes of processing, and whether these purposes can be achieved by other means.
We must also consider how long we may need to retain the data to meet legal obligations or handle complaints and disputes.
Once your data is no longer needed, it will be securely deleted or destroyed.
International Data Transfers
The Data Controller(s) may work with companies in various countries, including those outside the EU, such as Morocco. As some of these countries may not have data protection laws equivalent to those in the EU, we ensure our service providers handle your data securely and in compliance with French and EU data protection laws.
Before any data transfer outside the EU, we implement all necessary measures to secure such transfers in accordance with applicable regulations.
Subcontracting
We may use subcontractors for:
-
Fraud prevention
-
Personalisation of website and mobile app content
-
Technical maintenance and development of the website
This policy applies to all services provided by the Data Controllers, both online and offline. It is subject to the French Data Protection Act (Law No. 78-17 of 6 January 1978, as amended in 2004) and the EU General Data Protection Regulation (Regulation (EU) 2016/679 of 27 April 2016).
Under applicable regulations, you have the right to access, rectify, and object to the use of your personal data. Since 25 May 2018, you may also exercise your right to restrict processing, request data deletion, data portability, and not be subject to automated decisions, including profiling.
The Data Controllers take various measures to ensure your data is secure from loss, misuse, unauthorised access, disclosure, alteration, or destruction. Database access is strictly limited to authorised personnel.
Ms Stéphanie Delord, President of Moodbox, is also the Data Protection Officer (D.P.O.).
The D.P.O. will respond to you within 30 days.
You can exercise your rights:
-
Online: [Click here to access the form]
-
By email at: contact@moodbox.fr (for the attention of the D.P.O.)
-
By post:
Moodbox
For the attention of the D.P.O.
16, rue de l'ancienne mairie
92100 Boulogne-Billancourt
Please include your email address for a faster reply.
For confidentiality and security reasons, please include a signed copy of an identity document with your request.
If you are not satisfied with the response, you may refer the matter to the CNIL (French Data Protection Authority).
Under Article 40-1 of the French Data Protection Act, you may also send us instructions regarding the retention, deletion, and communication of your data after your death. These instructions may be general or specific.
The Data Controllers reserve the right to modify this Data Protection Policy at any time. If significant changes occur, such as introducing a new purpose, we will notify you beforehand to ensure you have enough time to exercise your rights.
We encourage you to consult the Policy regularly to stay informed about how your personal information is protected.