Data Protection Policy
This data protection policy describes how we collect, use, and protect your personal information when you use our site.
1. Data Collected
We collect and process the following data:
- Email address: used to contact you as part of delivering the service related to your purchase.
- First name, last name, and photo: used exclusively to personalize your user profile in your dedicated interface.
- Banking information: used only at the time of payment and transmitted directly to our payment processor, Stripe. We do not store this information.
- Billing name and address: collected to generate your invoices. This information is transmitted to and managed directly by Stripe; we do not store it ourselves.
We also use cookies, described in our Cookie Policy.
2. Legal Basis for Processing
We process your personal data in accordance with the GDPR (General Data Protection Regulation) on the following bases:
- Contract performance: to provide the services you have purchased.
- Legal obligation: for issuing invoices in compliance with our accounting obligations.
- Consent: when you voluntarily provide information to personalize your profile, or accept non-essential cookies.
3. Data Sharing
We only share your personal data with:
- Stripe, for the secure management of payments and your billing information.
- Google (Google Analytics), for our audience statistics, only if you have accepted audience measurement cookies.
Stripe and Google may process your data outside the European Union, particularly in the United States. This transfer is governed by the safeguards provided for under the GDPR, such as the European Commission's standard contractual clauses.
4. Retention Period
- Your account data (email, name, photo): kept as long as your account is active, deleted upon request.
- Accounting documents and invoices: kept for a minimum of 7 years after the close of the relevant financial year, in accordance with our accounting obligations.
- Billing address: since it is not stored by us, its retention period is determined by Stripe.
5. Your Rights
In accordance with the GDPR, you have the following rights:
- Access your personal data.
- Rectify inaccurate or incomplete data.
- Request the deletion of your data.
- Restrict or object to the processing of your data.
- Lodge a complaint with the competent authority.
To exercise your rights, contact us at pierre@miniggiodev.fr.
The competent supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), the supervisory authority competent for MiniggioTech OÜ. If you reside in another European Union country, the data protection authority of your own country is also competent.
6. Data Protection
We use technical and organizational measures to ensure the security of your personal data and prevent any unauthorized access.
7. Changes to This Policy
We reserve the right to modify this policy at any time. Any change will be published on this page.