Last updated : October 15, 2021
We collect and process Your personal data in compliance with the applicable French and European legislation, including Act No. 78-17 of 6 January 1978 on information technology, data files and civil liberties, amended by Act No. 2004-801 of 6 August 2004 and by Act No. 2018-493 of 20 June 2018 ("Law Informatique et Libertés"), Regulation (EU) No. 2016/679 of the European Parliament and the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data ("RGPD") and Directive 2002/58/EC of 12 July 2002 as amended by Directive 2009/136/EC ("ePrivacy Directive"), and any national transposition text or any subsequent text that may follow them ("Applicable Regulations").
By accessing and/or using the Services, You agree that Your personal data will be collected and processed under the terms and conditions set forth below. If You do not agree to this Policy, You shall cease all use of the Services.
The Charter is an integral part of the Terms and Conditions ("T&C") and must be read together with such T&C.
The data controller is BUFU S.A.S., a French société par actions simplifiée, with a share capital of EUR 1,000, its registered office at 5 avenue du Général De Gaulle, 94160 Saint-Mandé, France, registered with the Trade and Companies Register of Créteil under number 890 556 368.
Contact details :
The terms "personal data"("Personal Data"), "process/processing", "data controller", "processor", "recipient(s)", "consent", and "filing system", have the same meaning as in Article 4 of the GDPR.
The Company may collect some Personal Data:
Information fields marked with an asterisk are required fields.
You can always refuse to complete these required fields, in which case We will inform You of the consequences of this refusal.
Personal Data is collected directly by the Company, when You use the Services and when You contact the Company.
Your Personal Data is collected when You :
collect Your Personal Data?
The following persons will have access to some of Your Personal Data :
The Website is hosted by AWS, whose servers are located in the United States. However, the Company offers to its users an option to host their Personal Data within the European Union.
Furthermore, depending on the subcontractors, some Personal Data can be transferred outside the European Union.
The transfer of Your Personal Data outside the European Union, if any, is secured as follows:
The Company undertakes not to keep Your Personal Data beyond the period strictly necessary for the purposes for which it was collected, and in accordance with the Applicable Regulations.
The Company undertakes to anonymize or delete Your Personal Data as soon as the purpose and/or the duration of their established retention expire.
CATEGORYRETENTION PERIODAudience measurement and service customization, management of cookies and other trackers13 months from the receipt of the cookie or other tracker------Information relating to transactions carried out by credit cardSuch data is not retained beyond payment, which may include the regularization of any fees applicable during a check-out, unless You have consented to the saving of such data.Information about services purchased10 years from the date of the last purchase or the last full payment of the last service providedUser preference information5 years from full payment of the last service providedPersonal Data processed as part of solicitations and promotional operations, sending offers and news3 years from the end of the relationship with the User or from the last interaction initiated by the UserPersonal Data relating to the management of requests for the exercise of rights and questions on Personal Data3 years from the last interaction initiated by the UserInformation about managing customer service interactions3 years from the last interaction initiated by the User
Nevertheless, Personal Data may be archived beyond the applicable periods for the purposes of researching, investigating, and prosecuting criminal offenses with the sole purpose of allowing, as needed, the provision of such Personal Data to the judicial authorities, or for other retention obligations, in particular for accounting or fiscal purposes. Archiving implies that this Personal Data will be subject to access restrictions and will no longer be available online but will be retrieved and kept on a secure and independent device.
The maximum retention periods set out in the table below apply unless You request that Your Personal Data be erased before the expiry of these periods, in accordance with Article 6 above.
The Company undertakes to take all useful precautions, organizational and technical measures appropriate to preserve the security, integrity and confidentiality of Your Personal Data and in particular to avoid their destruction, loss, theft, alteration or unauthorized access.
In order to reinforce the security of Your Personal Data, We invite You to choose a complex password and to take all precautions to keep it secret, to log out after each session, to avoid logging in on a computer that does not belong to you, and to avoid logging in to Your account via a public wifi network.
We do not support Do Not Track ("DNT"). Do Not Track is a preference You can set in Your web browser to inform websites that You do not want to be tracked.
You can enable or disable Do Not Track by visiting the preferences or settings page of Your web browser.
You have the following rights regarding Your Personal Data:
These instructions can be general, i.e. they concern all of Your Personal Data. In this case, they must be transmitted to a trusted digital third party certified by the CNIL.
These directives may be specific, i.e. they relate only to Your Personal Data processed by the Company. In this case, they must be transmitted to the Company.
You may change or revoke Your instructions at any time.
For any additional information, do not hesitate to go on the website of the CNIL.
To exercise Your rights, You can contact the Company at the following e-mail address firstname.lastname@example.org and provide a photocopy of Your identity card with Your signature.
To exercise Your right to send a complaint to the CNIL, You can contact the CNIL on its website or by mail at the following address :
CNIL - Service des Plaintes 3 Place de Fontenoy - TSA 80715 75334 PARIS CEDEX 07
To report security vulnerabilities You can contact the Company at the following e-mail address email@example.com