GDPR - Smial


Purpose of the processing (purpose and legal basis)

The company, whose head office is located in Saint-Germain-sur-Avre (27320), 12 place de l’église, has an Internet site of on-line sale. This site allows us to receive orders from our customers and the data collected on this occasion are recorded and processed in a customer file.

This file allows you to:

  • Manage orders, payment and delivery.
  • To conduct marketing operations (loyalty, promotions) and to send advertising by e-mail to our customers who have not objected or who have agreed to it:
    • On products similar to those they have ordered.
    • On other products offered by the company.
    • On the promotion of features available on the website

Legal basis of the processing

  • Order management: the legal basis for the processing is the execution of a contract (see Article 6.1.b) of the European Data Protection Regulation).
  • Sending commercial solicitations by e-mail on products similar to those ordered by customers: the legal basis for the processing is the legitimate interest of the company (see Article 6.1.f of the European Data Protection Regulation), namely to promote our products to our customers.
  • Sending of commercial solicitations by e-mail on other products offered by the company the legal basis of the treatment is the consent (Cf. article 6.1.a of the European Regulation on data protection), as required by article L. 34-5 of the code of posts and electronic communications.
  • Bookkeeping involving the retention of data for a period of 10 years: the legal basis for the processing is the legal obligation (see Article 6.1.c of the European Data Protection Regulation).

Data categories

  • Identity: title, surname, first name, address, delivery address, telephone number, e-mail address, date of birth, internal processing code allowing the identification of the customer, data relating to registration on opposition lists.
  • Order data: transaction number, purchase details, purchase amount, invoice payment data (payments, outstanding payments, discounts), product returns.
  • Data relating to the means of payment: bank card number, expiry date of the bank card, visual cryptogram (which is immediately erased).
  • Data necessary for the realization of loyalty and prospecting actions: purchase history.

Recipients of the data

  • The customer and billing departments of are the recipients of all categories of data.
  • The company Stancer, responsible for the online payment by our customers of their orders (subscriptions and products), is recipient of the identity, e-mail address, telephone number and information of the means of payment used during the order.
  • The company Brevo, our CRM and e-mailing solution provider, is the recipient of the e-mail addresses of customers who have accepted it

Duration of data retention

  • Data necessary for the management of orders and invoicing: for the entire duration of the commercial relationship and ten (10) years for accounting purposes.
  • Data necessary for the realization of loyalty actions and prospecting: for the entire duration of the commercial relationship and three (3) years from the last purchase.
  • Data relating to payment methods: this data is not kept by the company For more information on how Stancer handles your data, please refer to its privacy policy:
  • Data concerning the lists of opposition to receive prospecting: three (3) years.

Your rights

If you no longer wish to receive advertising from (exercise of the right to object or withdrawal of consent already given), contact us

If, after having consented to the transmission of your data to our commercial partners, you wish to reverse this choice and no longer receive advertising from them, contact us.

You can access your data, rectify it or have it deleted. You also have a right to portability and a right to limit the processing of your data (see the website for more information on your rights).

To exercise these rights or if you have any questions about the processing of your data in this scheme, you can contact our DPO.

The Data Protection Officer SAS
12, place de l’église
27320 Saint-Germain-sur-Avre

If, after contacting, you feel that your “Data Protection” rights have not been respected, you can submit a complaint online to the CNIL.

Smial, it's serious
Reactive customer care

If you have a problem we are here to help you

Secure payment

Payment is fully encrypted and secure to protect you

No commitment

You can stop your subscription at any time without any additional cost

Secure data

Your data are protected and are not sold to third parties

Loader Please wait...