Back to website

Privacy Policy

This privacy policy explains how LePetitPrince collects, uses, stores, and protects personal data in connection with this website and related business activities. This document is intentionally detailed and formal in order to support transparency and legal compliance.

Data Controller

The data controller is LePetitPrince (Entrepreneur individuel), represented by Quentin Mouilhaud, operating from 50 Route de Royan, 17132 Meschers-sur-Gironde, France. Main contact: [email protected]. Privacy and digital-services contact: [email protected].

Categories of Data

Depending on user interaction, we may process contact data (name, email address, telephone details voluntarily submitted), professional data (organization and role context), communication records (inbound and outbound messages), and technical access data (request metadata, approximate geolocation inferred from IP, user agent, and security logs).

We do not intentionally request sensitive personal data through generic contact channels. Users are asked not to send special categories of personal data unless strictly necessary and explicitly requested under an applicable legal basis.

Purposes and Legal Bases

Recipients and Processors

Personal data may be accessed by authorized internal personnel and by carefully selected service providers acting as processors (for example hosting, infrastructure, communication, and productivity providers), strictly to the extent necessary for their mission. Processors are contractually bound to confidentiality and security obligations.

Data may also be disclosed when required by law, legal process, or competent authority request. We do not sell personal data as a business model.

International Transfers

Some providers may process data outside the country where users are located. Where required, international transfers are framed using approved safeguards such as adequacy decisions, standard contractual clauses, or equivalent compliant mechanisms.

Given distributed internet infrastructure, technical routing may involve multiple jurisdictions. We seek to minimize unnecessary exposure and apply security controls proportionate to risk.

Retention Periods

Retention durations vary by purpose and legal requirements. Contact and inquiry records are retained for a reasonable period to manage follow-up and accountability. Contract-related records are retained for the duration of the relationship and applicable limitation periods. Accounting and fiscal records are retained according to statutory obligations.

At the end of applicable retention periods, data is deleted, anonymized, or archived in restricted form where legally required.

Data Subject Rights

Subject to legal conditions, individuals may request access, rectification, erasure, restriction, portability, and objection. Individuals may also withdraw consent where processing relies on consent, without affecting prior lawful processing.

Requests can be submitted to [email protected]. We may request additional identity verification proportional to the sensitivity of the request. Individuals may lodge a complaint with their competent supervisory authority if they consider their rights have not been respected.

Security Measures

We apply technical and organizational measures designed to protect personal data against unauthorized access, accidental loss, unlawful destruction, alteration, and disclosure. Measures may include secure transport encryption, access control, audit logging, and provider risk management.

No internet transmission or storage system can be guaranteed absolutely secure. In the event of a legally reportable data breach, notification procedures will follow applicable law.

Policy Updates

This policy may be revised periodically to reflect legal, technical, or operational changes. The latest published version applies from its publication date. Users are encouraged to review this policy on a regular basis.